NEW
Font size
WorksheetsCEH - 11/12 Practice - Part 1
Total questions: 65
Worksheet time: 1hrs 5mins
Which initial procedure should an ethical hacker perform after being brought into an organization?
Assess what the organization is trying to protect
Turn over deliverable documents
Begin security testing
Sign a formal contract with non-disclosure
Which of the following act requires employer's standard national numbers to identify them on standard transactions?
DMCA
SOX
PCI-DSS
HIPAA
A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer's software and hardware without the owner's permission. Their intention can either be to simply gain knowledge or to illegally make changes. Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?
Black Hat
Gray Hat
Suicide Hacker
White Hat
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
At least once a year and after any significant upgrade or modification
At least once every two years and after any significant upgrade or modification
At least once every three years or after any significant upgrade or modification
At least twice a year or after any significant upgrade or modification
What is not a PCI compliance recommendation?
Limit access to card holder data to as few individuals as possible.
Use a firewall between the public network and the payment card data.
Use encryption to protect all transmission of card holder data over any public network.
Rotate employees handling credit card transactions on a yearly basis to different departments.
The white box testing methodology enforces what kind of restriction?
Only the external operation of a system is accessible to the tester.
The internal operation of a system is only partly accessible to the tester.
The internal operation of a system is completely known to the tester.
Only the internal operation of a system is known to the tester.
Bob, your senior colleague, has sent you a mail regarding a deal with one of the clients. You are requested to accept the offer and you oblige. After 2 days, Bob denies that he had ever sent a mail. What do you want to "know" to prove yourself that it was Bob who had send a mail?
Authentication
Integrity
Confidentiality
Non-Repudiation
The collection of potentially actionable, overt, and publicly available information is known as
Human intelligence
Open-source intelligence
Real intelligence
Social intelligence
A hacker named Jack is trying to compromise a bank's computer system. He needs to know the operating system of that computer to launch further attacks. What process would help him?
SSDP Scanning
IDLE/IPID Scanning
UDP Scanning
Banner Grabbing
DNS cache snooping is a process of determining if the specified resource address is present in the DNS cache records. It may be useful during the examination of the network to determine what software update resources are used, thus discovering what software is installed. What command is used to determine if the entry is present in DNS cache?
nslookup -nonrecursive update.antivirus.com
nslookup -fullrecursive update.antivirus.com
dns --snoop update.antivirus.com
dnsnooping -rt update.antivirus.com
What is the main theme of the sub-policies for Information Technologies?
Authenticity, Integrity, Non-repudiation
Confidentiality, Integrity, Availability
Availability, Non-repudiation, Confidentiality
Authenticity, Confidentiality, Integrity
What is the least important information when you analyze a public IP address in a security alert?
DNS
Geolocation
ARP
Whois
On performing a risk assessment, you need to determine the potential impacts when some of the critical business process of the company interrupt its service. What is the name of the process by which you can determine those critical business?
Risk Mitigation
Business Impact Analysis (BIA)
Disaster Recovery Planning (DRP)
Emergency Plan Response (EPR)
What type of analysis is performed when an attacker has partial knowledge of inner-workings of the application?
Grey-box
Announced
White-box
Black-box
Which of the following is a low-tech way of gaining unauthorized access to systems?
Social Engineering
Sniffing
Scanning
Enumeration
Which regulation defines security and privacy controls for Federal information systems and organizations?
PCI-DSS
EU Safe Harbor
NIST-800-53
HIPAA
Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking. What should you do?
Ignore the data and continue the assessment until completed as agreed.
Immediately stop work and contact the proper legal authorities.
Confront the client in a respectful manner and ask her about the data.
Copy the data to removable media and keep it in case you need it.
It has been reported to you that someone has caused an information spillage on their computer. You go to the computer, disconnect it from the network, remove
the keyboard and mouse, and power it down. What step in incident handling did you just complete? What step in incident handling did you just complete?
Discovery
Containment
Eradication
Recovery
What network security concept requires multiple layers of security controls to be placed throughout an IT infrastructure, which improves the security posture of an organization to defend against malicious attacks or potential vulnerabilities?
Network-Based Intrusion Detection System
Security through obscurity
Host-Based Intrusion Detection System
Defense in depth
If executives are found liable for not properly protecting their company's assets and information systems, what type of law would apply in this situation?
Criminal
Civil
International
Common
The company ABC recently contract a new accountant. The accountant will be working with the financial statements. Those financial statements need to be
approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the
accountant was not modified once he approved it. What is the following options can be useful to ensure the integrity of the data?
The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document
The CFO can use a hash algorithm in the document once he approved the financial statements
The CFO can use an excel file with a password
The document can be sent to the accountant using an exclusive USB for that document
Which access control mechanism allows for multiple systems to use a central authentication server (CAS) that permits users to authenticate once and gain access to multiple systems?
Discretionary Access Control (DAC)
Role Based Access Control (RBAC)
Windows authentication
Single sign-on
A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer decides to start by using netcat to port 80. The engineer receives this output: HTTP/1.1 200 OK Server: Microsoft-IIS/6 Expires: Tue, 17 Jan 2011 01:41:33 GMT Date: Mon, 16 Jan 2011 01:41:33 GMT Content-Type: text/html Accept-Ranges: bytes Last-Modified: Wed, 28 Dec 2010 15:32:21 GMT ETag: "b0aac0542e25c31:89d" Content-Length: 7369
Banner grabbing
Cross-site scripting
Whois Database Query
SQL injection
Look at the following output. What did the hacker accomplish (picture Q156.jpg)?
The hacker listed DNS records on his own domain.
The hacker successfully transferred the zone and enumerated the hosts.
The hacker used the "fierce" tool to brute force the list of available domains.
The hacker used who is to gather publicly available records for the domain.
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?
Perform a vulnerability scan of the system.
Determine the impact of enabling the audit feature.
Allocate funds for staffing of audit log review.
Perform a cost/benefit analysis of the audit feature.
A large mobile telephony and data network operator has a data that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup?
Network elements must be hardened with user ids and strong passwords. Regular security tests and audits should be performed.
As long as the physical access to the network elements is restricted, there is no need for additional measures.
There is no need for specific security measures on the network elements as long as firewalls and IPS systems exist.
The operator knows that attacks and down time are inevitable and should have a backup site.
Which of the following incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an organization?
Preparation phase
Identification phase
Recovery phase
Containment phase
Which type of security feature stops vehicles from crashing through the doors of a building?
Mantrap
Bollards
Receptionist
Turnstile
In which phase of the ethical hacking process can Google hacking be employed? This is a technique that involves manipulating a search string with specific operators to search for vulnerabilities.
Gaining Access
Scanning and Enumeration
Reconnaissance
Maintaining Access
Seth is starting a penetration test from inside the network. He hasn't been given any information about the network. What type of test is he conducting?
Internal, Blackbox
Internal, Whitebox
External, Whitebox
External, Blackbox
You are performing a penetration test. You achieved access via a buffer overflow exploit and you proceed to find interesting data, such as files with usernames and passwords. You find a hidden folder that has the administrator's bank account password and login information for the administrator's bitcoin account. What should you do?
Report immediately to the administrator.
Do not report it and continue the penetration test.
Do not transfer the money but steal the bitcoins.
Transfer money from the administrator's account to another account.
Which system consists of a publicly available set of databases that contain domain name registration contact information?
CAPTCHA
IETF
IANA
WHOIS
It is a regulation that has a set of guidelines, which should be adhered to by anyone who handles any electronic medical data. These guidelines stipulate that all medical practices must ensure that all necessary measures are in place while saving, accessing, and sharing any electronic medical data to keep patient data secure.
HIPAA
ISO/IEC 27002
FISMA
COBIT
Which results will be returned with the following Google search query? site:target.com -site:Marketing.target.com accounting
Results from matches on the site marketing.target.com that are in the domain target.com but do not include the word accounting.
Results matching "accounting" in domain target.com but not on the site Marketing.target.com
Results matching all words in the query.
Results for matches on target.com and Marketing.target.com that include the word "accounting"
As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics of the testing, the associated violations, and essentially protects both the organization's interest and your liabilities as a tester?
Service Level Agreement
Rules of Engagement
Project Scope
Non-Disclosure Agreement
A well-intentioned researcher discovers a vulnerability on the web site of a major corporation. What should he do?
Exploit the vulnerability without harming the web site owner so that attention be drawn to the problem.
Try to sell the information to a well-paying party on the dark web.
Ignore it.
Notify the web site owner so that corrective action be taken as soon as possible to patch the vulnerability.
Your team has won a contract to infiltrate an organization. The company wants to have the attack be as realistic as possible; therefore, they did not provide any information besides the company name. What should be the first step in security testing the client?
Reconnaissance
Escalation
Scanning
Enumeration
A medium-sized healthcare IT business decides to implement a risk management strategy. Which of the following is NOT one of the five basic responses to risk?
Delegate
Mitigate
Accept
Avoid
John is an incident handler at a financial institution. His steps in a recent incident are not up to the standards of the company. John frequently forgets some steps. Which of the following actions should John take to overcome this problem?
Create an incident checklist
Select someone else to check the procedures
Increase his technical skills
Read the incident manual every time it occurs
It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of the following terms best matches the definition?
Risk
Attack
Vulnerability
Threat
When you return to your desk after a lunch break, you notice a strange email in your inbox. The sender is someone you did business with recently, but the subject line has strange characters in it. What should you do?
Delete the email and pretend nothing happened.
Forward the message to your supervisor and ask for her opinion on how to handle the situation.
Forward the message to your company's security response team and permanently delete the message from your computer.
Reply to the sender and ask them for more information about the message contents.
The "gray box testing" methodology enforces what kind of restriction?
The internal operation of a system is completely known to the tester.
Only the external operation of a system is accessible to the tester.
The internal operation of a system is only partly accessible to the tester.
Only the internal operation of a system is known to the tester.
The "black box testing" methodology enforces what kind of restriction?
The internal operation of a system is only partly accessible to the tester.
Only the internal operation of a system is known to the tester.
Only the external operation of a system is accessible to the tester.
The internal operation of a system is completely known to the tester.
This phase will increase the odds of success in later phases of the penetration test. It is also the very first step in Information Gathering and it will tell you the "landscape" looks like. What is the most important phase of ethical hacking in which you need to spend a considerable amount of time?
footprinting
gaining access
network mapping
escalating privileges
Which of the following is assured by the use of a hash?
Integrity
Confidentiality
Authentication
Availability
Risks=Threats x Vulnerabilities is referred to as the:
BIA equation
Disaster recovery formula
Threat assessment
Risk equation
During the security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
Conduct compliance testing
Terminate the audit
Create a procedures document
Identify and evaluate existing practices
What is the process of logging, recording, and resolving events that take place in an organization?
Security Policy
Metrics
Internal Procedure
Incident Management Process
The change of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. Calculate the SLE, ARO, and ALE.
Assume the EF = 1(100%). What is the closest approximate cost of this replacement and recovery operation per year?
$1320
$100
$440
$146
This international organization regulates billions of transactions daily and provides security guidelines to protect personally identifiable information (PII). These security controls provide a baseline and prevent low-level hackers sometimes known as script kiddies from causing a data breach. Which of the following organization is being described?
Center for Disease Control (CDC)
International Security Industry Organization (ISIO)
Institute of Electrical and Electronics Engineers (IEEE)
Payment Card Industry (PCI)
Which of these options is the most secure procedure for storing backup tapes?
Inside the data center for faster retrieval in a fireproof safe
In a cool dry environment
On a different floor in the same building
In a climate controlled facility offsite
Which security strategy requires using several, varying methods to protect IT systems against attacks?
Exponential backoff algorithm
Defense in depth
Three-way handshake
Covert channels
Which of the following statements regarding ethical hacking is incorrect?
An organization should use ethical hackers who do not sell vendor hardware/software or other consulting services
Testing should be remotely performed offsite.
Ethical hacking should not involve writing to or modifying the target systems.
Ethical hackers should never use tools or methods that have the potential of exploiting vulnerabilities in an organization's systems
Which of the following is a component of a risk assessment?
Administrative safeguards
Physical security
DMZ
Logical interface
Peter is surfing the internet looking for information about DX Company. Which hacking process is Peter doing?
System Hacking
Footprinting
Scanning
Enumeration
Jim's company regularly performs backups of their critical servers. But the company cannot afford to send backup tapes to an off-site vendor for long-term storage and archiving. Instead, Jim's company keeps the backup tapes in a safe in the office. Jim's company is audited each year, and the results from this year's audit show a risk because backup tapes are not stored off-site. The Manager of Information Technology has a plan to take the backup tapes home with him and wants to know what two things he can do to secure the backup tapes while in transit?
Hash the backup tapes and transport them in a lock box.
Encrypt the backup tapes and use a courier to transport them.
Degauss the backup tapes and transport them in a lock box.
Encrypt the backup tapes and transport them in a lock box.
Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of the target company. The phishing message will often use the name of the company CEO, President, or Managers. Which phase does this activity belong to?
Exploration
Reconnaissance
Investigation
Enumeration
Your business has decided to add credit card numbers to the data it backs up to tape. Which of the following represents the best practice your business should observe?
Do not back up either the credit card numbers or their hashes.
Hire a security consultant to provide direction.
Back up the hashes of the credit card numbers not the actual credit card numbers.
Encrypt backup tapes that are sent off-site.
Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that, another security risk assessment was performed showing that risk has decreased to 10%. The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with the most business profit?
Avoid the risk
Mitigate the risk
Introduce more controls to bring risk to 0%
Accept the risk
Which of the following steps for risk assessment methodology refers to vulnerability identification?
Assigns values to risk probabilities; Impact values
Identifies sources of harm to an IT system (Natural, Human, Environmental)
Determines risk probability that vulnerability will be exploited (High, Medium, Low)
Determines if any flaws exist in systems, policies, or procedures
Which of the following is the trustworthiness of data or resources in the prevention of improper and unauthorized changes—the assurance that information is sufficiently accurate for its purpose?
Availability
Integrity
Non-repudiation
Confidentiality
In which of the following hacking phases does an attacker try to detect listening ports to find information about the nature of services running on the target machine?
Gaining access
Clearing tracks
Scanning
Maintaining access
What type of information is gathered by an attacker through Whois database analysis and tracerouting?
Usernames, passwords, and so on
Publicly available email addresses
Background of the organization
DNS records and related information
What is the output returned by search engines when extracting critical details about a target from the Internet?
Search engine results pages (“SERPs”)
Open ports and services
Operating systems, location of web servers, users, and passwords
Advanced search operators
Which of the following techniques is used to create complex search engine queries?
Yahoo search
Bing search
DuckDuckGo
Google hacking
