Font size
S
M
L
XL
WorksheetsModule 2B. Active Reconnaissance - Enumeration
Total questions: 24
Worksheet time: 12mins
Name
Class
Date
1.
Which of the following is the main reason why some protocols are not considered secure?
a)
Subjected to malware
b)
Only command-line option
c)
IDS alerts
d)
Plaintext traffic
2.
Which of the following attacks is NOT facilitated by unencrypted traffic?
a)
Sniffing attacks
b)
Man in the Middle attacks
c)
DOS attacks
d)
Authentication attacks
3.
Which of the following is an insecure protocol to connect to a virtual terminal on another computer?
a)
FTP
b)
Telnet
c)
IMAP
d)
SMTP
4.
Which of the following is an insecure protocol to transfer files between computers?
a)
FTP
b)
Telnet
c)
IMAP
d)
SMTP
5.
Which of the following is an insecure protocol to upload email messages to Mail Transfer Agent servers?
a)
FTP
b)
Telnet
c)
IMAP
d)
SMTP
6.
Which of the following is an insecure protocol to download email messages from Mail Delivery Agent servers?
a)
FTP
b)
Telnet
c)
IMAP
d)
SMTP
7.
Which of the following is an insecure protocol to transfer web pages?
a)
FTP
b)
Telnet
c)
HTTP
d)
SMTP
8.
Which of the following is NOT a default port for insecure protocols?
a)
80
b)
21
c)
443
d)
23
9.
Which of the following is a protocol to provide shared access to printers and other resources on a network originally developed for Windows systems?
a)
SMTP
b)
SMB
c)
SSH
d)
NFS
10.
Which of the following is the correct name for shared resources using SMB?
a)
Public
b)
Exports
c)
Shares
d)
Samba
11.
Which of the following is NOT a type of information that we can find by enumerating SMB?
a)
Users
b)
Shares
c)
Groups
d)
Passwords
12.
Which of the following is NOT a tool to enumerate SMB?
a)
smbaccess
b)
smbmap
c)
enum4linux
d)
smb-enum-shares NSE script
13.
Which of the following is a protocol to share directories and files over a network originally developed for Unix systems?
a)
SMTP
b)
SMB
c)
SSH
d)
NFS
14.
Which of the following is the correct name for shared resources using NFS?
a)
Public
b)
Exports
c)
Shares
d)
RPC
15.
Which of the following is a misconfiguration for DNS server?
a)
Sensitive directories exposure
b)
Unauthenticated access
c)
Unauthenticated zone transfer
d)
Anonymous login
16.
Which of the following is a misconfiguration for Telnet servers?
a)
Sensitive directories exposure
b)
Unauthenticated access
c)
Unauthenticated zone transfer
d)
Anonymous login
17.
Which of the following is a misconfiguration for FTP servers?
a)
Sensitive directories exposure
b)
Unauthenticated access
c)
Unauthenticated zone transfer
d)
Anonymous login
18.
Which of the following is the term used to describe a file with multiple candidate passwords for online attacks?
a)
Rockyou
b)
Wordlist
c)
Rainbow table
d)
Seclist
19.
Which of the following tools is specialized in online password attacks?
a)
Hashcat
b)
Hydra
c)
John the ripper
d)
Nmap
20.
Which of the following is a website that lists all publicly categorized vulnerabilities?
a)
Common Vulnerability Scoring System (CVSS)
b)
CVE-details
c)
National Vulnerability Database
d)
Exploit-DB
21.
Which of the following is a website that provides a friendly interface to CVE vulnerability data?
a)
Common Vulnerability Scoring System (CVSS)
b)
CVE-details
c)
National Vulnerability Database
d)
Exploit-DB
22.
Which of the following provides a way to capture the main characteristics of a vulnerability and produce a numerical score for it?
a)
Common Vulnerability Scoring System (CVSS)
b)
CVE-details
c)
National Vulnerability Database
d)
Exploit-DB
23.
Which of the following is a vulnerability scanner?
a)
Nessus
b)
Hydra
c)
Ncrack
d)
Rockyou
24.
Which of the following attacks can be facilitated by weak or default credentials? (Pick 2)
a)
Brute-force
b)
Credential dump
c)
Dictionary
d)
Keylogging
Reset
