wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CEH - 11/12 Practice - Part 3

Total questions: 55

Worksheet time: 55mins

Name
Class
Date
1.

An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", that the user is directed to a phishing site. Which file does the attacker need to modify?

a)

Sudoers

b)

Networks

c)

Hosts

d)

Boot.ini

2.

You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use?

a)

c:\compmgmt.msc

b)

c:\gpedit

c)

c:\ncpa.cp

d)

c:\services.msc

3.

______ is a set of extensions to DNS that provide the origin authentication of DNS data to reduce the threat of DNS poisoning, spoofing, and similar attacks types.

a)

Resource transfer

b)

Zone transfer

c)

Resource records

d)

DNSSEC

4.

What is the purpose of a demilitarized zone on a network?

a)

To contain the network devices you wish to protect

b)

To scan all traffic coming through the DMZ to the internal network

c)

To only provide direct access to the nodes within the DMZ and protect the network behind it

d)

To provide a place to put the honeypot

5.

Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?

a)

Wireshark

b)

Metasploit

c)

Cain & Abel

d)

Maltego

6.

You have gained physical access to a Windows 2008 R2 server which has an accessible disc drive. Which Linux-based tool is a software utility for resetting or blanking local passwords used by Windows NT, 2000, XP, Vista, 7, 8, 8.1 and 10. It does this by editing the SAM database where Windows stores password hashes.

a)

SET

b)

Cain & Abel

c)

CHNTPW

d)

John the Ripper

7.

The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

a)

ACK

b)

SYN-ACK

c)

SYN

d)

RST

8.

During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?

a)

DynDNS

b)

DNSSEC

c)

Split DNS

d)

DNS Scheme

9.

Based on the below log, which of the following sentences are true? Mar 1, 2016, 7:33:28 AM 10.240.250.23 - 54373 10.249.253.15 - 22 tcp_ip

a)

Application is SSH and 10.240.250.23 is the server and 10.249.253.15 is the server

b)

SSH communications are encrypted it's impossible to know who is the client or the server

c)

Application is FTP and 10.240.250.23 is the client and 10.249.253.15 is the server

d)

Application is SSH and 10.240.250.23 is the client and 10.249.253.15 is the server

10.

Which of the following is an attack type for a rogue Wi-Fi access point that appears to be a legitimate one offered on the premises, but actually has been set up to eavesdrop on wireless communications? It is the wireless version of the phishing scam. An attacker fools wireless users into connecting a laptop or mobile phone to a tainted hotspot by posing as a legitimate provider. This type of attack may be used to steal the passwords of unsuspecting users by either snooping the communication link or by phishing, which involves setting up a fraudulent web site and luring people there.

a)

Evil Twin

b)

Man-in-the-Middle

c)

Bluejacking

d)

Wardriving

11.

You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8. While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP. Therefore, the Internal IP's are sending data to the Public IP. After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised. What kind of attack does the above scenario depict?

a)

Botnet Attack

b)

Advanced Persistent Threats

c)

Rootkit Attack

d)

Spear Phishing Attack

12.

Some clients of TPNQM SA were redirected to a malicious site when they tried to access the TPNQM main site. Bob, a system administrator at TPNQM SA, found that they were victims of DNS Cache Poisoning. What should Bob recommend to deal with such a threat?

a)

The use of double-factor authentication

b)

The use of security agents in clients' computers

c)

The use of DNSSEC

d)

Client awareness

13.

Which of the following provides a security professional with most information about the system's security posture?

a)

Social engineering, company site browsing, tailgating

b)

Phishing, spamming, sending trojans

c)

Wardriving, warchalking, social engineering

d)

Port scanning, banner grabbing, service identification

14.

What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?

a)

SSH

b)

Through Web servers utilizing CGI (Common Gateway Interface) to send a malformed environment variable to a vulnerable Web server

c)

SYN Flood

d)

Manipulate format strings in text fields

15.

A technician is resolving an issue where a computer is unable to connect to the Internet. When the technician examines the IP addresses, he sees the computer is pointing to the Gateway with the IP address of 172.16.20.1 and the IP address of the computer is 192.168.1.24. Which of the following has occurred?

a)

The computer is using an invalid IP address.

b)

The computer is not using a private IP address.

c)

The gateway and the computer are not on the same network.

d)

The gateway is not routing to a public IP address.

16.

Due to a slowdown of normal network operations, the IT department decided to monitor internet traffic for all of the employees. From a legal stand point, what would be troublesome to take this kind of measure?

a)

IT department would be telling employees who the boss is

b)

The network could still experience traffic slow down.

c)

Not informing the employees that they are going to be monitored could be an invasion of privacy.

d)

All of the employees would stop normal work activities

17.

In Risk Management, how is the term "likelihood" related to the concept of "threat?"

a)

Likelihood is a possible threat-source that may exploit a vulnerability.

b)

Likelihood is the probability that a threat-source will exploit a vulnerability.

c)

Likelihood is the likely source of a threat that could exploit a vulnerability.

d)

Likelihood is the probability that a vulnerability is a threat-source.

18.

Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything, except?

a)

Work at the Data Link Layer

b)

Authenticate

c)

Encrypt

d)

Protect the payload and the headers

19.

In an internal security audit, the white hat hacker gains control over a user account and attempts to acquire access to another account's confidential files and information. How can he achieve this?

a)

Shoulder-Surfing

b)

Privilege Escalation

c)

Hacking Active Directory

d)

Port Scanning

20.

Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ ports, which can have direct internet access, and block the access to workstations. Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA. In this context, what can you say?

a)

Bob can be right since DMZ does not make sense when combined with stateless firewalls

b)

Bob is partially right. He does not need to separate networks if he can create rules by destination IPs, one by one

c)

Bob is partially right. DMZ does not make sense when a stateless firewall is available

d)

Bob is totally wrong. DMZ is always relevant when the company has internet servers and workstations

21.

How does the Address Resolution Protocol (ARP) work?

a)

It sends a reply packet for a specific IP, asking for the MAC address.

b)

It sends a request packet to all the network elements, asking for the domain name from a specific IP.

c)

It sends a reply packet to all the network elements, asking for the MAC address from a specific IP.

d)

It sends a request packet to all the network elements, asking for the MAC address from a specific IP.

22.

Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications an unpatched security flaws in a computer system?

a)

Metasploit

b)

Maltego

c)

Wireshark

d)

Nessus

23.

What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?

a)

Back up everything on the laptop and store the backup in a safe place.

b)

Use a strong logon password to the operating system.

c)

Encrypt the data on the hard drive.

d)

Set a BIOS password

24.

What is the role of test automation in security testing?

a)

Test automation is not usable in security due to the complexity of the tests.

b)

It should be used exclusively. Manual testing is outdated because of low spend and possible test setup inconsistencies.

c)

It is an option but it tends to be very expensive.

d)

It can accelerate benchmark tests and repeat them with a consistent test setup. But it cannot replace manual testing completely.

25.

Which Metasploit Framework tool can help penetration tester for evading Anti-virus Systems?

a)

msfd

b)

msfpayload

c)

msfcli

d)

msfencode

26.

An attacker attaches a rogue router in a network. He wants to redirect traffic to a LAN attached to his router as part of a man-in-the-middle attack. What measure on behalf of the legitimate admin can mitigate this attack?

a)

Make sure that legitimate network routers are configured to run routing protocols with authentication.

b)

Disable all routing protocols on the network.

c)

Increase the bandwidth of the legitimate routers.

d)

Change the IP address of the legitimate routers frequently.

27.

A penetration test was done at a company. After the test, a report was written and given to the company's IT authorities. A section from the report is shown below:

Access List should be written between VLANs.

Port security should be enabled for the intranet.

A security solution which filters data packets should be set between intranet (LAN) and DMZ. A WAF should be used in front of the web applications.

According to the section from the report, which of the following choice is true?

a)

Possibility of SQL Injection attack is eliminated.

b)

There is access control policy between VLANs.

c)

MAC Spoof attacks cannot be performed.

d)

A stateful firewall can be used between intranet (LAN) and DMZ.

28.

In IPv6 what is the major difference concerning application layer vulnerabilities compared to IPv4?

a)

Due to the extensive security measures built in IPv6, application layer vulnerabilities need not be addresses.

b)

Vulnerabilities in the application layer are greatly different from IPv4.

c)

Vulnerabilities in the application layer are independent of the network layer. Attacks and mitigation techniques are almost identical.

d)

Implementing IPv4 security in a dual-stack network offers protection from IPv6 attacks too.

29.

An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their job. The attacker gain access to the DNS server and redirect the direction www.google.com to his own IP address. Now when the employees of the office

a)

Smurf Attack

b)

ARP Poisoning

c)

DNS spoofing

d)

MAC Flooding

30.

The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE's Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the transport layer security (TLS) protocols defined in RFC6520. What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy?

a)

Root

b)

Shared

c)

Public

d)

Private

31.

What is the correct process for the TCP three-way handshake connection establishment and connection termination?

a)

Connection Establishment: SYN, SYN-ACK, ACK Connection Termination: FIN, ACK-FIN, ACK

b)

Connection Establishment: ACK, ACK-SYN, SYN Connection Termination: FIN, ACK-FIN, ACK

c)

Connection Establishment: FIN, ACK-FIN, ACK Connection Termination: SYN, SYN-ACK, ACK

d)

Connection Establishment: SYN, SYN-ACK, ACK Connection Termination: ACK, ACK-SYN, SYN

32.

What is the Shellshock bash vulnerability attempting to do to a vulnerable Linux host?

env x='(){ :;};echo exploit' bash -c 'cat/etc/passwd'

a)

Add new user to the passwd file

b)

Removes the passwd file

c)

Display passwd content to prompt

d)

Changes all passwords in passwd

33.

You have successfully logged on a Linux system. You want to now cover your track. Your login attempt may be logged on several files located in /var/log. Which file does NOT belong to the list:

a)

wtmp

b)

auth.log

c)

btmp

d)

user.log

34.

What is the purpose of DNS AAAA record?

a)

IPv6 address resolution record

b)

Authorization, Authentication and Auditing record

c)

Address database record

d)

Address prefix record

35.

You are performing a penetration test for a client and have gained shell access to a Windows machine on the internal network. You intend to retrieve all DNS records for the internal domain. If the DNS server is at 192.168.10.2 and the domain name is abccorp.local, what command would you type at the nslookup prompt to attempt a zone transfer?

a)

ls -d abccorp.local

b)

list server=192.168.10.2 type=all

c)

Iserver 192.168.10.2 -t all

d)

list domain=abccorp.local type=zone

36.

Which command can be used to show the current TCP/IP connections?

a)

Netsh

b)

netstat

c)

Net use

d)

Net use connection

37.

You are performing information gathering for an important penetration test. You have found pdf, doc, and images in your objective. You decide to extract metadata from these files and analyze it. What tool will help you with the task?

a)

DMitry

b)

Metagoofil

c)

Armitage

d)

cdpsnarf

38.

When you are collecting information to perform a data analysis, Google commands are very useful to find sensitive information and files. These files may contain information about passwords, system functions, or documentation. What command will help you to search files using Google as a search engine?

a)

domain: target.com archieve:xls username password email

b)

site: target.com file:xls username password email

c)

site: target.com filetype:xls username password email

d)

inurl: target.com filename:xls username password email

39.

You have just been hired to perform a pen test on an organization that has been subjected to a large-scale attack. The CIO is concerned with mitigating threats and vulnerabilities to totally eliminate risk. What is one of the first things you should do when given the job?

a)

Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to acceptable levels.

b)

Start the wireshark application to start sniffing network traffic.

c)

Establish attribution to suspected attackers

d)

Interview all employees in the company to rule out possible insider threats

40.

A pen-tester is configuring a Windows laptop for a test. In setting up Wireshark, what river and library are required to allow the NIC to work in promiscuous mode?

a)

Libpcap

b)

Winpsw

c)

Winpcap

d)

Winprom

41.

During a blackbox pen test you attempt to pass IRC traffic over port 80/TCP from a compromised web enabled host. The traffic gets blocked; however, outbound HTTP traffic is unimpeded. What type of firewall is inspecting outbound traffic?

a)

Stateful

b)

Application

c)

Circuit

d)

PAcket filtering

42.

You are attempting to man-in-the-middle a session. Which protocol will allow you to guess a sequence number?

a)

UPX

b)

TCP

c)

ICMP

d)

UPD

43.

You are tasked to configure the DHCP server to lease the last 100 usable IP addresses in subnet 10.1.4.0/23. Which of the following IP addresses could be leased as a result of the new configuration?

a)

10.1.255.200

b)

10.1.5.200

c)

10.1.4.254

d)

10.1.4.156

44.

You are analyzing a traffic on the network with Wireshark. You want to routinely run a cron job which will run the capture against a specific set of IPs. "192.168.8.0/24". What command you would use?

a)

sudo tshark -f "net 192.168.8.0/24"

b)

wireshark -capture -local -masked 192.168.8.0 -range 24

c)

wireshark -fetch "192.168.8/ (star symbol)"

d)

tshark -net 192.255.255.255 mask 192.168.8.0

45.

Initiating an attack against targeted business and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in exploits that target unpatched vulnerabilities. The attackers run exploits on well-known and trusted sites likely to be visited by their targeted victims. Aside from carefully choosing sites to compromise, these attacks are known to incorporate zero-day malware infections. Thus, the targeted entities are left with little or no defense against these exploits. What type of attack is outlined in the scenario?

a)

Spear Phishing Attack

b)

Heartbeat Attack

c)

Watering Hole Attack

d)

Shellshock Attack

46.

Which utility will tell you in real time which ports are listening or in another state?

a)

Netsat

b)

TCPView

c)

Nmap

d)

Loki

47.

Why are containers less secure than virtual machines?

a)

Containers may fulfill disk space of the host.

b)

Host OS on containers has a larger surface attack.

c)

A compromise container may cause a CPU starvation of the host.

d)

Containers are attached to the same virtual network.

48.

DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switchers leverages the DHCP snooping database to help prevent man-in-the-middle attacks?

a)

Spanning tree

b)

Port security

c)

Layer 2 Attack Prevention Protocol (LAPP)

d)

Dynamic ARP Inspection (DAI)

49.

Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not encrypt email, leaving the information in the message vulnerable to being read by an unauthorized person. SMTP can upgrade a connection between two mail servers to use TLS. TLS is encrypted. What is the name of the command used by SMTP to transmit email over TLS?

a)

FORCETLS

b)

UPGRADETLS

c)

OPPORTUNISTICTLS

d)

STARTTLS

50.

Why is a penetration test considered to be more thorough than vulnerability scan?

a)

It is not - a penetration test is often performed by an automated tool, while a vulnerability scan requires active engagement.

b)

The tools used by penetration testers tend to have much more comprehensive vulnerability databases.

c)

A penetration test actively exploits vulnerabilities in the targeted infrastructure, while a vulnerability scan does not typically involve active exploitation.

d)

Vulnerability scans only do host discovery and port scanning by default.

51.

Given below are the different steps involved in the post-assessment phase of vulnerability management.

  1. 1. Remediation

  2. 2. Monitoring

  3. 3. Risk assessment

  4. 4. Verification

Identify the correct sequence of steps in the Post Assessment Phase.

a)

3 → 2 → 4 → 1

b)

1 → 2 → 3 → 4

c)

2 → 1 → 3 → 4

d)

3 → 1 → 4 → 2

52.

Which of the following types of software vulnerability occurs due to coding errors and allows attackers to gain access to the target system?

a)

Unpatched servers

b)

Misconfiguration

c)

Buffer overflow

d)

Open services

53.

In which of the following password attacks does an attacker gather a password database, split each password entry into two- and three-character syllables to develop a new alphabet, and then match it with the existing password database?

a)

Combinator attack

b)

PRINCE attack

c)

Markov-chain attack

d)

Fingerprint attack

54.

Which of the following misconfigured services allows attackers to deploy Windows OS without the intervention of an administrator?

a)

Service object permissions

b)

Modifiable registry autoruns

c)

Unquoted service paths

d)

Unattended installs

55.

Which of the following types of rootkits replaces original system calls with fake ones to hide information about the attacker?

a)

Library-level rootkit

b)

Hardware/firmware rootkit

c)

Hypervisor-level rootkit

d)

Boot-loader-level rootkit