NEW
Font size
WorksheetsCEH - 11/12 Practice - Part 3
Total questions: 55
Worksheet time: 55mins
An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalBank.com", that the user is directed to a phishing site. Which file does the attacker need to modify?
Sudoers
Networks
Hosts
Boot.ini
You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use?
c:\compmgmt.msc
c:\gpedit
c:\ncpa.cp
c:\services.msc
______ is a set of extensions to DNS that provide the origin authentication of DNS data to reduce the threat of DNS poisoning, spoofing, and similar attacks types.
Resource transfer
Zone transfer
Resource records
DNSSEC
What is the purpose of a demilitarized zone on a network?
To contain the network devices you wish to protect
To scan all traffic coming through the DMZ to the internal network
To only provide direct access to the nodes within the DMZ and protect the network behind it
To provide a place to put the honeypot
Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?
Wireshark
Metasploit
Cain & Abel
Maltego
You have gained physical access to a Windows 2008 R2 server which has an accessible disc drive. Which Linux-based tool is a software utility for resetting or blanking local passwords used by Windows NT, 2000, XP, Vista, 7, 8, 8.1 and 10. It does this by editing the SAM database where Windows stores password hashes.
SET
Cain & Abel
CHNTPW
John the Ripper
The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?
ACK
SYN-ACK
SYN
RST
During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?
DynDNS
DNSSEC
Split DNS
DNS Scheme
Based on the below log, which of the following sentences are true? Mar 1, 2016, 7:33:28 AM 10.240.250.23 - 54373 10.249.253.15 - 22 tcp_ip
Application is SSH and 10.240.250.23 is the server and 10.249.253.15 is the server
SSH communications are encrypted it's impossible to know who is the client or the server
Application is FTP and 10.240.250.23 is the client and 10.249.253.15 is the server
Application is SSH and 10.240.250.23 is the client and 10.249.253.15 is the server
Which of the following is an attack type for a rogue Wi-Fi access point that appears to be a legitimate one offered on the premises, but actually has been set up to eavesdrop on wireless communications? It is the wireless version of the phishing scam. An attacker fools wireless users into connecting a laptop or mobile phone to a tainted hotspot by posing as a legitimate provider. This type of attack may be used to steal the passwords of unsuspecting users by either snooping the communication link or by phishing, which involves setting up a fraudulent web site and luring people there.
Evil Twin
Man-in-the-Middle
Bluejacking
Wardriving
You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8. While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP. Therefore, the Internal IP's are sending data to the Public IP. After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised. What kind of attack does the above scenario depict?
Botnet Attack
Advanced Persistent Threats
Rootkit Attack
Spear Phishing Attack
Some clients of TPNQM SA were redirected to a malicious site when they tried to access the TPNQM main site. Bob, a system administrator at TPNQM SA, found that they were victims of DNS Cache Poisoning. What should Bob recommend to deal with such a threat?
The use of double-factor authentication
The use of security agents in clients' computers
The use of DNSSEC
Client awareness
Which of the following provides a security professional with most information about the system's security posture?
Social engineering, company site browsing, tailgating
Phishing, spamming, sending trojans
Wardriving, warchalking, social engineering
Port scanning, banner grabbing, service identification
What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?
SSH
Through Web servers utilizing CGI (Common Gateway Interface) to send a malformed environment variable to a vulnerable Web server
SYN Flood
Manipulate format strings in text fields
A technician is resolving an issue where a computer is unable to connect to the Internet. When the technician examines the IP addresses, he sees the computer is pointing to the Gateway with the IP address of 172.16.20.1 and the IP address of the computer is 192.168.1.24. Which of the following has occurred?
The computer is using an invalid IP address.
The computer is not using a private IP address.
The gateway and the computer are not on the same network.
The gateway is not routing to a public IP address.
Due to a slowdown of normal network operations, the IT department decided to monitor internet traffic for all of the employees. From a legal stand point, what would be troublesome to take this kind of measure?
IT department would be telling employees who the boss is
The network could still experience traffic slow down.
Not informing the employees that they are going to be monitored could be an invasion of privacy.
All of the employees would stop normal work activities
In Risk Management, how is the term "likelihood" related to the concept of "threat?"
Likelihood is a possible threat-source that may exploit a vulnerability.
Likelihood is the probability that a threat-source will exploit a vulnerability.
Likelihood is the likely source of a threat that could exploit a vulnerability.
Likelihood is the probability that a vulnerability is a threat-source.
Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything, except?
Work at the Data Link Layer
Authenticate
Encrypt
Protect the payload and the headers
In an internal security audit, the white hat hacker gains control over a user account and attempts to acquire access to another account's confidential files and information. How can he achieve this?
Shoulder-Surfing
Privilege Escalation
Hacking Active Directory
Port Scanning
Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ ports, which can have direct internet access, and block the access to workstations. Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA. In this context, what can you say?
Bob can be right since DMZ does not make sense when combined with stateless firewalls
Bob is partially right. He does not need to separate networks if he can create rules by destination IPs, one by one
Bob is partially right. DMZ does not make sense when a stateless firewall is available
Bob is totally wrong. DMZ is always relevant when the company has internet servers and workstations
How does the Address Resolution Protocol (ARP) work?
It sends a reply packet for a specific IP, asking for the MAC address.
It sends a request packet to all the network elements, asking for the domain name from a specific IP.
It sends a reply packet to all the network elements, asking for the MAC address from a specific IP.
It sends a request packet to all the network elements, asking for the MAC address from a specific IP.
Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications an unpatched security flaws in a computer system?
Metasploit
Maltego
Wireshark
Nessus
What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?
Back up everything on the laptop and store the backup in a safe place.
Use a strong logon password to the operating system.
Encrypt the data on the hard drive.
Set a BIOS password
What is the role of test automation in security testing?
Test automation is not usable in security due to the complexity of the tests.
It should be used exclusively. Manual testing is outdated because of low spend and possible test setup inconsistencies.
It is an option but it tends to be very expensive.
It can accelerate benchmark tests and repeat them with a consistent test setup. But it cannot replace manual testing completely.
Which Metasploit Framework tool can help penetration tester for evading Anti-virus Systems?
msfd
msfpayload
msfcli
msfencode
An attacker attaches a rogue router in a network. He wants to redirect traffic to a LAN attached to his router as part of a man-in-the-middle attack. What measure on behalf of the legitimate admin can mitigate this attack?
Make sure that legitimate network routers are configured to run routing protocols with authentication.
Disable all routing protocols on the network.
Increase the bandwidth of the legitimate routers.
Change the IP address of the legitimate routers frequently.
A penetration test was done at a company. After the test, a report was written and given to the company's IT authorities. A section from the report is shown below:
Access List should be written between VLANs.
Port security should be enabled for the intranet.
A security solution which filters data packets should be set between intranet (LAN) and DMZ. A WAF should be used in front of the web applications.
According to the section from the report, which of the following choice is true?
Possibility of SQL Injection attack is eliminated.
There is access control policy between VLANs.
MAC Spoof attacks cannot be performed.
A stateful firewall can be used between intranet (LAN) and DMZ.
In IPv6 what is the major difference concerning application layer vulnerabilities compared to IPv4?
Due to the extensive security measures built in IPv6, application layer vulnerabilities need not be addresses.
Vulnerabilities in the application layer are greatly different from IPv4.
Vulnerabilities in the application layer are independent of the network layer. Attacks and mitigation techniques are almost identical.
Implementing IPv4 security in a dual-stack network offers protection from IPv6 attacks too.
An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their job. The attacker gain access to the DNS server and redirect the direction www.google.com to his own IP address. Now when the employees of the office
Smurf Attack
ARP Poisoning
DNS spoofing
MAC Flooding
The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE's Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the transport layer security (TLS) protocols defined in RFC6520. What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy?
Root
Shared
Public
Private
What is the correct process for the TCP three-way handshake connection establishment and connection termination?
Connection Establishment: SYN, SYN-ACK, ACK Connection Termination: FIN, ACK-FIN, ACK
Connection Establishment: ACK, ACK-SYN, SYN Connection Termination: FIN, ACK-FIN, ACK
Connection Establishment: FIN, ACK-FIN, ACK Connection Termination: SYN, SYN-ACK, ACK
Connection Establishment: SYN, SYN-ACK, ACK Connection Termination: ACK, ACK-SYN, SYN
What is the Shellshock bash vulnerability attempting to do to a vulnerable Linux host?
env x='(){ :;};echo exploit' bash -c 'cat/etc/passwd'
Add new user to the passwd file
Removes the passwd file
Display passwd content to prompt
Changes all passwords in passwd
You have successfully logged on a Linux system. You want to now cover your track. Your login attempt may be logged on several files located in /var/log. Which file does NOT belong to the list:
wtmp
auth.log
btmp
user.log
What is the purpose of DNS AAAA record?
IPv6 address resolution record
Authorization, Authentication and Auditing record
Address database record
Address prefix record
You are performing a penetration test for a client and have gained shell access to a Windows machine on the internal network. You intend to retrieve all DNS records for the internal domain. If the DNS server is at 192.168.10.2 and the domain name is abccorp.local, what command would you type at the nslookup prompt to attempt a zone transfer?
ls -d abccorp.local
list server=192.168.10.2 type=all
Iserver 192.168.10.2 -t all
list domain=abccorp.local type=zone
Which command can be used to show the current TCP/IP connections?
Netsh
netstat
Net use
Net use connection
You are performing information gathering for an important penetration test. You have found pdf, doc, and images in your objective. You decide to extract metadata from these files and analyze it. What tool will help you with the task?
DMitry
Metagoofil
Armitage
cdpsnarf
When you are collecting information to perform a data analysis, Google commands are very useful to find sensitive information and files. These files may contain information about passwords, system functions, or documentation. What command will help you to search files using Google as a search engine?
domain: target.com archieve:xls username password email
site: target.com file:xls username password email
site: target.com filetype:xls username password email
inurl: target.com filename:xls username password email
You have just been hired to perform a pen test on an organization that has been subjected to a large-scale attack. The CIO is concerned with mitigating threats and vulnerabilities to totally eliminate risk. What is one of the first things you should do when given the job?
Explain to the CIO that you cannot eliminate all risk, but you will be able to reduce risk to acceptable levels.
Start the wireshark application to start sniffing network traffic.
Establish attribution to suspected attackers
Interview all employees in the company to rule out possible insider threats
A pen-tester is configuring a Windows laptop for a test. In setting up Wireshark, what river and library are required to allow the NIC to work in promiscuous mode?
Libpcap
Winpsw
Winpcap
Winprom
During a blackbox pen test you attempt to pass IRC traffic over port 80/TCP from a compromised web enabled host. The traffic gets blocked; however, outbound HTTP traffic is unimpeded. What type of firewall is inspecting outbound traffic?
Stateful
Application
Circuit
PAcket filtering
You are attempting to man-in-the-middle a session. Which protocol will allow you to guess a sequence number?
UPX
TCP
ICMP
UPD
You are tasked to configure the DHCP server to lease the last 100 usable IP addresses in subnet 10.1.4.0/23. Which of the following IP addresses could be leased as a result of the new configuration?
10.1.255.200
10.1.5.200
10.1.4.254
10.1.4.156
You are analyzing a traffic on the network with Wireshark. You want to routinely run a cron job which will run the capture against a specific set of IPs. "192.168.8.0/24". What command you would use?
sudo tshark -f "net 192.168.8.0/24"
wireshark -capture -local -masked 192.168.8.0 -range 24
wireshark -fetch "192.168.8/ (star symbol)"
tshark -net 192.255.255.255 mask 192.168.8.0
Initiating an attack against targeted business and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in exploits that target unpatched vulnerabilities. The attackers run exploits on well-known and trusted sites likely to be visited by their targeted victims. Aside from carefully choosing sites to compromise, these attacks are known to incorporate zero-day malware infections. Thus, the targeted entities are left with little or no defense against these exploits. What type of attack is outlined in the scenario?
Spear Phishing Attack
Heartbeat Attack
Watering Hole Attack
Shellshock Attack
Which utility will tell you in real time which ports are listening or in another state?
Netsat
TCPView
Nmap
Loki
Why are containers less secure than virtual machines?
Containers may fulfill disk space of the host.
Host OS on containers has a larger surface attack.
A compromise container may cause a CPU starvation of the host.
Containers are attached to the same virtual network.
DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switchers leverages the DHCP snooping database to help prevent man-in-the-middle attacks?
Spanning tree
Port security
Layer 2 Attack Prevention Protocol (LAPP)
Dynamic ARP Inspection (DAI)
Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not encrypt email, leaving the information in the message vulnerable to being read by an unauthorized person. SMTP can upgrade a connection between two mail servers to use TLS. TLS is encrypted. What is the name of the command used by SMTP to transmit email over TLS?
FORCETLS
UPGRADETLS
OPPORTUNISTICTLS
STARTTLS
Why is a penetration test considered to be more thorough than vulnerability scan?
It is not - a penetration test is often performed by an automated tool, while a vulnerability scan requires active engagement.
The tools used by penetration testers tend to have much more comprehensive vulnerability databases.
A penetration test actively exploits vulnerabilities in the targeted infrastructure, while a vulnerability scan does not typically involve active exploitation.
Vulnerability scans only do host discovery and port scanning by default.
Given below are the different steps involved in the post-assessment phase of vulnerability management.
1. Remediation
2. Monitoring
3. Risk assessment
4. Verification
Identify the correct sequence of steps in the Post Assessment Phase.
3 → 2 → 4 → 1
1 → 2 → 3 → 4
2 → 1 → 3 → 4
3 → 1 → 4 → 2
Which of the following types of software vulnerability occurs due to coding errors and allows attackers to gain access to the target system?
Unpatched servers
Misconfiguration
Buffer overflow
Open services
In which of the following password attacks does an attacker gather a password database, split each password entry into two- and three-character syllables to develop a new alphabet, and then match it with the existing password database?
Combinator attack
PRINCE attack
Markov-chain attack
Fingerprint attack
Which of the following misconfigured services allows attackers to deploy Windows OS without the intervention of an administrator?
Service object permissions
Modifiable registry autoruns
Unquoted service paths
Unattended installs
Which of the following types of rootkits replaces original system calls with fake ones to hide information about the attacker?
Library-level rootkit
Hardware/firmware rootkit
Hypervisor-level rootkit
Boot-loader-level rootkit
