Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Gathering Techniques Quiz

Total questions: 21

Worksheet time: 11mins

Name
Class
Date
1.

What type of information is considered as personally identifiable information (PII) when gathered about employees during the reconnaissance phase?

a)

Geographical information, entry control systems, and vendor traffic

b)

Intellectual property, critical business functions, and management hierarchy

c)

Names, phone numbers, email addresses, fax numbers, and addresses

d)

Security policies and network mapping

2.

Which of the following is included in physical security information gathered by malicious actors?

a)

Names, contact information, and account numbers of vendors

b)

Intellectual property, critical business functions, and management hierarchy

c)

Geographical information, entry control systems, employee routines, and vendor traffic

d)

Security policies and network mapping

3.

What is the focus of attackers when gathering information about an organization's information systems?

a)

Employee personal details

b)

Vendor contact information and account numbers

c)

Intellectual property and critical business functions

d)

Operating systems, applications, security policies, and network mapping

4.

Which of the following best describes passive information gathering techniques used by attackers?

a)

Directly interface with the organization's systems and leverage open-source tools

b)

Pose a greater danger to malicious actors because of exposure

c)

Rely on publicly available information sources such as the organization's website, brochures, press releases, etc.

d)

Gather names, contact information, and account numbers of vendors

5.

What is a characteristic of active information gathering techniques?

a)

Pose little risk for the malicious actors

b)

Rely on publicly available information sources

c)

Pose a greater danger to malicious actors because of exposure

d)

Include geographical information and vendor traffic

6.

What is Google Earth primarily used for?

a)

Providing a street view of houses, businesses, roadways, and topologies.

b)

Streaming digital cameras that show video of places, people, and activity.

c)

Providing current and historical satellite imagery of most locations.

d)

Pulling information from social media postings.

7.

What does the Wayback Machine offer?

a)

A web mapping service that provides a street view.

b)

A catalog of old site snapshots that may contain information removed from the internet.

c)

A tool to find relationships between companies, people, email addresses, and other information.

d)

A satellite imagery tool that provides images of locations.

8.

What type of information does the search operator "link:website" provide?

a)

All information about a website.

b)

Lists web pages that contain links to websites.

c)

Displays websites similar to the one listed.

d)

Displays websites in which directory browsing has been enabled.

9.

Which tool can be used to pull information from social media postings that were made using location services?

a)

Google Maps

b)

Webcams

c)

Echosec

d)

Maltego

10.

What is the purpose of Maltego in internet research?

a)

To provide street views of different locations.

b)

To stream videos from digital cameras online.

c)

To pull information from social media postings and find relationships between entities.

d)

To provide historical satellite imagery.

11.

What is the purpose of website and email footprinting in network reconnaissance?

a)

To provide details on information flow, operating systems, filenames, and network connections.

b)

To create a network map without entering the physical location of the network.

c)

To find hosts and other objects on a network using DNS network addressing.

d)

To administer IP addresses and ASNs in support of the operation and growth of the internet.

12.

What can be created using a mailing address in the context of network footprinting?

a)

satellite imagery: Google Earth

b)

mapping that provides a street view of houses, businesses, roadways, and topologies: Google Earth

c)

gather the names, contact information, and account numbers of vendors.

13.

Which tool is described as a web-based utility used to gather information about a target network, including things like ownership, IP addresses, domain name location, server type, and the date the site was created?

a)

nslookup

b)

American Registry for Internet Numbers (ARIN)

c)

Whois lookup

d)

Network mapping software

14.

What information can you obtain by using the nslookup tool?

a)

IP addresses & ASNs

b)

information about the host network

c)

IP addresses, domain name, location, server type

d)

a network map without entering the physical location of the network.

15.

What is the role of the American Registry for Internet Numbers (ARIN)?

a)

A web-based utility used to gather information about a target network.

b)

Lists web pages that contain links to websites. 

c)

a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the internet.

16.

What is the purpose of the nmap utility?

a)

To create a secure connection between hosts

b)

For network discovery and security auditing

c)

To increase the speed of the network

d)

To manage user permissions on a network

17.

What does the '-sS' flag in the nmap command do?

a)

Scans the entire range of ports starting with port 1

b)

Scans only the top 50 ports on the host

c)

Initiates a TCP SYN scan that scans thousands of ports per second

d)

Specifies the ports to scan with a list

18.

What is the default flag for the nmap command?

a)

-p

b)

-sS

c)

--top-ports

d)

-p-200

19.

How do you scan only port 22 using the nmap command?

a)

nmap -p 22 hostname/IP address

b)

nmap -p-22 hostname/IP address

c)

nmap --top-ports 22 hostname/IP address

d)

nmap -sS 22 hostname/IP address

20.

Which nmap command option scans the top ports used based on Fyodor's latest internet research on open ports?

a)

nmap -sS

b)

nmap -p

c)

nmap --top-ports

d)

nmap -p-200

21.

What does the command 'nmap --top-ports 50 172.26.125.24' do?

a)

Scans all ports on host 172.26.125.24

b)

Scans the entire range of ports starting with port 1 on host 172.26.125.24

c)

Scans only port 50 on host 172.26.125.24

d)

Scans only the top 50 ports on host 172.26.125.24