WorksheetsCEH - 11/12 Practice - Part 4
Total questions: 80
Worksheet time: 1hrs 20mins
An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed?
Reverse Social Engineering
Announced
Piggybacking
Tailgating
Which of the following is the best countermeasure to encrypting ransomwares?
Keep some generation of off-line backup
Analyze the ransomware to get decryption key of encrypted data
Pay a ransom
Use multiple antivirus softwares
Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?
Produces less false positives
Cannot deal with encrypted network traffic
Can identify unknown attacks
Requires vendor updates for a new threat
In Wireshark, the packet bytes panes show the data of the current packet in which format?
ASCII only
Decimal
Binary
Hexadecimal
Which of the following is the BEST way to defend against network sniffing?
Restrict Physical Access to Server Rooms hosting Critical Servers
Using encryption protocols to secure network communications
Use Static IP Address
Register all machines MAC Address in a Centralized Database
You have successfully gained access to a Linux server and would like to ensure that the succeeding outgoing traffic from this server will not be caught by Network-Based Intrusion Detection Systems (NIDS).
What is the best way to evade the NIDS?
Encryption
Out of band signaling
Protocol Isolation
Alternate Data Streams
The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. He also needs to permit all FTP traffic
to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access to the ftp, and the permitted hosts
cannot access the Internet. According to the next configuration, what is happening in the network?
The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router
The ACL 104 needs to be first because is UDP
The ACL 110 needs to be changed to port 80
The ACL for FTP must be before the ACL 110
When conducting a penetration test, it is crucial to use all means to get all available information about the target network. One of the ways to do that is by sniffing the network. Which of the following cannot be performed by the passive network sniffing?
Modifying and replaying captured network traffic
Capturing a network traffic for further analysis
Identifying operating systems, services, protocols and devices
Collecting unencrypted information about usernames and passwords
Steve, a scientist who works in a governmental security agency, developed a technological solution to identify people based on walking patterns and implemented this approach to a physical control access. A camera captures people walking and identifies the individuals using Steve's approach. After that, people must approximate their RFID badges. Both the identifications are required to open the door. In this case, we can say:
Although the approach has two phases, it actually implements just one authentication factor
Biological motion cannot be used to identify people
The solution will have a high level of false positives
The solution implements the two authentication factors: physical object and physical characteristic
Which Intrusion Detection System is the best applicable for large environments where critical assets on the network need extra security and is ideal for observing sensitive network segments?
Honeypots
Network-based intrusion detection system (NIDS)
Firewalls
Host-based intrusion detection system (HIDS)
Which protocol is used for setting up secure channels between two devices, typically in VPNs?
SET
IPSEC
PEM
PPP
You need a tool that can do network intrusion prevention and intrusion detection, function as a network sniffer, and record network activity. What tool would you most likely select?
Nessus
Cain & Abel
Snort
Nmap
Firewalls are the software or hardware systems that are able to control and monitor the traffic coming in and out the target network based on pre-defined set of rules. Which of the following types of firewalls can protect against SQL injection attacks?
Web application firewall
Data-driven firewall
Stateful firewall
Packet firewall
Shellshock allowed an unauthorized user to gain access to a server. It affected many Internet-facing services, which OS did it not directly affect?
Linux
Unix
OS X
Windows
Which of the following program infects the system boot sector and the executable files at the same time?
Multipartite Virus
Macro Virus
Polymorphic virus
Stealth virus
An IT employee got a call from one of our best customers. The caller wanted to know about the company's network infrastructure, systems, and team. New opportunities of integration are in sight for both company and customer. What should this employee do?
Since the company's policy is all about Customer Service, he/she will provide information.
Disregarding the call, the employee should hang up.
The employee should not provide any information without previous management authorization.
The employees cannot provide any information; but, anyway, he/she will provide the name of the person in charge.
What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?
Residual risk
Inherent risk
Deferred risk
Impact risk
A hacker has managed to gain access to a Linux host and stolen the password file from /etc/passwd. How can he use it?
The password file does not contain the passwords themselves.
The file reveals the passwords to the root user only.
He can open it and read the user ids and corresponding passwords.
He cannot read it because it is encrypted.
Chandler works as a pen-tester in an IT-firm in New York. As a part of detecting viruses in the systems, he uses a detection method where the anti-virus executes the malicious codes on a virtual machine to simulate CPU and memory activities. Which type of virus detection method did Chandler use in this context?
Heuristic Analysis
Integrity checking
Scanning
Code Emulation
You are monitoring the network of your organizations. You notice that: There are huge outbound connections from your Internal Network to External IPs. On further investigation, you see that the external IPs are blacklisted, some connections are accepted, and some are dropped. You find that it is a CnC communication. Which of the following solution will you suggest?
Update the Latest Signatures on your IDS/IPS
Clean the Malware which are trying to Communicate with the External Blacklist IP's
Block the Blacklist IP's @ Firewall
Both B and C
Which of the following security policies defines the use of VPN for gaining access to an internal corporate network?
Network security policy
Information protection policy
Remote access policy
Access control policy
To determine if a software program properly handles a wide range of invalid input, a form of automated testing can be used to randomly generate invalid input in an attempt to crash the program. What term is commonly used when referring to this type of testing?
Mutating
Randomizing
Bounding
Fuzzing
Which of the following statements is TRUE?
Sniffers operate on both Layer 2 & Layer 3 of the OSI model.
Sniffers operate on Layer 2 of the OSI model
Sniffers operate on Layer 3 of the OSI model
Sniffers operate on the Layer 1 of the OSI model.
Bob finished a C programming course and created a small C application to monitor the network traffic and produce alerts when any origin sends "many" IP packets, based on the average number of packets sent by all origins and using some thresholds. In concept, the solution developed by Bob is actually:
Just a network monitoring tool
A signature-based IDS
A behavior-based IDS
A hybrid IDS
When tuning security alerts, what is the best approach?
Decrease the false positives
Decrease False negatives
Tune to avoid False positives and False Negatives
Rise False positives Rise False Negatives
You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet. The IP address was blacklisted just before the alert. You are staring an investigation to roughly analyze the severity of the situation. Which of the following is appropriate to analyze?
Event logs on domain controller
Internet Firewall/Proxy log
IDS log
Event logs on the PC
A virus that attempts to install itself inside the file it is infecting is called?
Cavity virus
Stealth virus
Polymorphic virus
Tunneling virus
Sam is working as a pen-tester in an organization in Houston. He performs penetration testing on IDS in order to find the different ways an attacker uses. What is the primary goal of Sam's penetration testing on IDS?
To identify vulnerabilities in the IDS
To upgrade the IDS software
To monitor network traffic
To train employees
Sam sends a large amount of packets to the target IDS that generates alerts, which enable Sam to hide the real traffic. What type of method is Sam using to evade IDS?
False Positive Generation
Denial-of-Service
Obfuscating
Insertion Attack
An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network. Which AAA protocol is the most likely able to handle this requirement?
RADIUS
DIAMETER
TACACS+
Kerberos
Bob received this text message on his mobile phone: "Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: scottsmelby@yahoo.com". Which statement below is true?
This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees.
Bob should write to scottsmelby@yahoo.com to verify the identity of Scott.
This is a scam because Bob does not know Scott.
This is probably a legitimate message as it comes from a respectable organization.
An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?
He will repeat this action so that it escalates to a DoS attack.
He will repeat the same attack against all L2 switches of the network.
He will create a SPAN entry on the spoofed root bridge and redirect traffic to his computer.
He will activate OSPF on the spoofed root bridge.
Which access control mechanism allows for multiple systems to use a central authentication server (CAS) that permits users to authenticate once and gain
access to multiple systems?
Discretionary Access Control (DAC)
Single sign-on
Windows authentication
Role Based Access Control (RBAC)
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being
run?
Tunneling virus
Stealth/ Tunneling virus
Cavity virus
Polymorphic virus
If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used?
TCP Connect scan
TCP SYN
Idle scan
Spoof Scan
ShellShock had the potential for an unauthorized user to gain access to a server. It affected many internet-facing services, which OS did it not directly affect?
Linux
OS X
Unix
Windows
A network administrator discovers several unknown files in the root directory of his Linux FTP server. One of the files is a tarball, two are shell script files, and the third is a binary file is named "nc." The FTP server's access logs show that the anonymous user account logged in to the server, uploaded the files, and extracted the contents of the tarball and ran the script using a function provided by the FTP server's software. The ps command shows that the nc file is running as process, and the netstat command shows the nc process is listening on a network port.
What kind of vulnerability must be present to make this remote attack possible?
Directory traversal
Privilege escalation
File system permissions
Brute force login
By using a smart card and pin, you are using a two-factor authentication that satisfies
Something you have and something you are
Something you are and something you remember
Something you know and something you are
Something you have and something you know
An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an
organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of
many of the logged events do not match up. What is the most likely cause?
Proper chain of custody was not observed while collecting the logs.
The security breach was a false positive.
The attacker altered or erased events from the logs.
The network devices are not all synchronized.
An enterprise recently moved to a new office and the new neighborhood is a little risky. The CEO wants to monitor the physical perimeter and the entrance doors
24 hours. What is the best option to do this job?
Use an IDS in the entrance doors and install some of them near the corners.
Install a CCTV with cameras pointing to the entrance doors and the street.
Use lights in all the entrance doors and along the company's perimeter.
Use fences in the entrance doors.
Bob learned that his username and password for a popular game has been compromised. He contacts the company and resets all the information. The company
suggests he use two-factor authentication; which option below offers that?
A new username and password
Disable his username and use just a fingerprint scanner
A fingerprint scanner and his username and password
His username and a stronger password
Which of the following programs is usually targeted at Microsoft Office products?
Macro virus
Polymorphic virus
Stealth virus
Multipart virus
What does a firewall check to prevent particular ports and applications from getting packets into an organization?
Application layer port numbers and the transport layer headers
Network layer headers and the session layer port numbers
Presentation layer headers and the session layer port numbers
Transport layer port numbers and application layer headers
Which of the following programming languages is most susceptible to buffer overflow attacks, due to its lack of a built-in-bounds checking mechanism?
Code:
#include <string.h> int main(){ char buffer[8];
strcpy(buffer, ""11111111111111111111111111111"");
}
Output:
Segmentation fault
C#
Python
Java
C++
A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a
user from the IT department had a dial-out modem installed. Which security policy must the security analyst check to see if dial-out modems are allowed?
Remote-access policy
Firewall-management policy
Acceptable-use policy
Permissive policy
Jimmy is standing outside a secure entrance to a facility. He is pretending to have a tense conversation on his cell phone as an authorized employee badges in.
Jimmy, while still on the phone, grabs the door as it begins to close.
What just happened?
Whaling
Phishing
Masquerading
Tailgating
In both pharming and phishing attacks an attacker can create websites that look similar to legitimate sites with the intent of collecting personal identifiable
information from its victims. What is the difference between pharming and phishing attacks?
In a pharming attack a victim is redirected to a fake website by modifying their host configuration file or by with a URL that is either misspelled or looks similar to the actual exploiting vulnerabilities in DNS. In a phishing attack an attacker provides the victim websites domain name.
Both pharming and phishing attacks are purely technical and are not considered forms of social engineering
In a pharming attack a victim is redirected to a fake website by modifying their host configuration file or by exploiting vulnerabilities in DNS. In a phishing attack an attacker provides the victim with a URL that is either misspelled or looks similar to the actual websites domain name.
Both pharming and phishing attacks are identical.
A hacker has successfully infected an internet-facing server which he will then use to send junk mail, take part in coordinated attacks, or host junk email content.
Which sort of trojan infects this server?
Turtle Trojans
Banking Trojans
Botnet Trojan
Botnet Trojan
Ransomware Trojans
Todd has been asked by the security officer to purchase a counter-based authentication system. Which of the following best describes this type of system?
An authentication system that uses passphrases that are converted into virtual passwords.
A biometric system that bases authentication decisions on physical attributes.
A biometric system that bases authentication decisions on behavioral attributes.
An authentication system that creates one-time passwords that are encrypted with secret keys.
In many states sending spam is illegal. Thus, the spammers have techniques to try and ensure that no one knows they sent the spam out to thousands of users
at a time. Which of the following best describes what spammers use to hide the origin of these types of e-mails?
Tools that will reconfigure a mail server's relay component to send the e-mail back to the spammers occasionally.
A blacklist of companies that have their mail server relays configured to allow traffic only to their specific domain name.
Mail relaying, which is a technique of bouncing e-mail from internal to external mails servers continuously.
A blacklist of companies that have their mail server relays configured to be wide open.
What mechanism in Windows prevents a user from accidentally executing a potentially malicious batch (.bat) or PowerShell (.ps1) script?
Windows firewall
User Access Control (UAC)
Address Space Layout Randomization (ASLR)
Data Execution Prevention (DEP)
What is the code written for (199.jpg)?
Bruteforce
Denial-of-service (DoS)
Encryption
Buffer Overflow
Jesse receives an email with an attachment labeled "Court_Notice_21206.zip". Inside the zip file named "Court_Notice_21206.docx.exe" disguised as a word
document. Upon execution, a window appears stating, "This word document is corrupt". In the background, the file copies itself to Jesse APPDATA\local directory
and begins to beacon to a C2 server to download additional malicious binaries.
What type of malware has Jesse encountered?
Worm
Key-Logger
Trojan
Macro Virus
Rebecca commonly sees an error on her Windows system that states that a Data Execution Prevention (DEP) error has taken place. Which of the following is
most likely taking place?
A race condition is being exploited, and the operating system is containing the malicious process.
A page fault is occuring, which forces the operating system to write data from the hard drive.
Malicious code is attempting to execute instruction a non-executable memory region.
Malware is executing in either ROM or a cache memory area.
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's Computer to
update the router configuration. What type of an alert is this?
False positive
False negative
True positive
True negative
You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing the source email to her boss's email (boss@company). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your machine gets infected. You now have access to the company network. opens the links, and her malicious links (these links contain malware) and send back the modified pdf, saying that the links don't work. She reads your email, What testing method did you use?
Tailgating
Piggybacking
Eavesdropping
Social engineering
Which of the following describes the characteristics of a Boot Sector Virus?
Modifies directory table entries so that directory entries point to the virus code instead of the actual program.
Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR.
Moves the MBR to another location on the RAM and copies itself to the original location of the MBR.
Overwrites the original MBR and only executes the new virus code.
Which of the following is the least-likely physical characteristic to be used in biometric control that supports a large company?
Height and Weight
Voice
Fingerprints
Iris patterns
Matthew, a black hat, has managed to open a meterpreter session to one of the kiosk machines in Evil Corp's lobby. He checks his current SID, which is S-1-521-
1223352397-1872883824-861252104-501. What needs to happen before Matthew has full administrator access?
He must perform privilege escalation.
He already has admin privileges, as shown by the "501" at the end of the SID.
He needs to disable antivirus protection.
He needs to gain physical access.
Log monitoring tools performing behavioral analysis have alerted several suspicious logins on a Linux server occuring during non-business hours. After further examination of all login activities, it is notices that none of the logins have occurred during typical work hours. A Linux administrator who is investigating this problem realized the system time on the Linux server is wrong by more than twelve hours. What protocol used on Linux serves to synchronize the time has stopped working?
OSPF
NTP
PPP
TimeKeeper
Which of the following statements is FALSE with respect to Intrusion Detection Systems?
Intrusion Detection Systems can be configured to distinguish specific content in network packets
Intrusion Detection Systems can examine the contents of the data in context of the network protocol
Intrusion Detection Systems can easily distinguish a malicious payload in an encrypted traffic
Intrusion Detection Systems require constant update of the signature library
You have several plain-text firewall logs that you must review to evaluate network traffic. You know that in order to do fast, efficient searches of the logs you
must use regular expressions. Which command-line utility are you most likely to use?
Relational Database
MS Excel
Grep
Notepad
Tremp is an IT Security Manager, and he is planning to deploy an IDS in his small company. He is looking for an IDS with the following characteristics:
-Verifies success or failure of an attack
- Monitors system activities
- Detects attacks that a network-based IDS fails to detect.
- Near real-time detection and response
-Does not require additional hardware
- Lower entry cost. Which type of IDS is best suited for Tremp's requirements?
Host-based IDS
Network-based IDS
Gateway-based IDS
Open source-based IDS
You just set up a security system in your network. In what kind of system would you find the following string of characters used as a rule within its configuration?
alert tcp any any ->192.168.100.0/24 21 (msg:""FTP on the network!"";)
FTP Server rule
An Intrusion Detection System
A Router IPTable
a firewall IPTable
Which of the following DoS tools is used to attack target web applications by starvation of available sessions on the web server? The tool keeps sessions at halt using never-ending POST transmissions and sending an arbitrarily large content-length header value.
R-U-Dead-Yet? (RUDY)
Stacheldraht
MyDoom
LOIC
What kind of detection techniques is being used in antivirus software that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it's made on the provider's environment.
Honypot based
Behavioral based
Cloud based
Heuristics based
You are monitoring the network of your organizations. You notice that: step 1-There are huge outbound connections from your Internal Network to External Ips step 2-On further investigation, you see that the external IPs are blacklisted step3 --Some connections are accepted, and some are dropped step 4-You find that it is a CnC communication Which of the following solution will you suggest?
Update the Latest Signatures on your IDS/IPS
Block the Blacklist IP's @ Firewall as well as Clean the Malware which are trying to Communicate with the External Blacklist IP's.
Clean the Malware which are trying to Communicate with the External Blacklist IP's
Block the Blacklist IP's @ Firewall
A company's policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Using Wireshark to examine the captured traffic, which command can be used as display filter to find unencrypted file transfers?
tcp.port ! = 21
tcp port = = 21
tcp.port = = 21 | | tcp.port = =22
tcp. port = 23
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, small sized packets to the target computer, making it very difficult for an IDS to detect the attack signatures. Which tool can be used to perform session splicing attacks?
tcpsplice
Whisker
Burp
Hydra
An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet traffic was captured by the IDS and saved to a PCAP file. What type of network tool can be used to determine if these packets are genuinely malicious or simply a false positive?
Network sniffer
Protocol analyzer
Vulnerability scanner
Intrusion Prevention System (IPS)
CompanyXYZ has asked you to assess the security of their perimeter email gateway. From your office in New York, you craft a specially formatted email message and send it across the Internet to an employee of CompanyXYZ. The employee of CompanyXYZ is aware of your test. Your email message looks like this:
From: jim_miller@companyxyz.com To: michelle_saunders@companyxyz.com
Subject: Test message
Date: 4/3/2017 14:37
The employee of CompanyXYZ receives your email message.
This proves that CompanyXYZ's email gateway doesn't prevent what?
Email Spoofing
Email Harvesting
Email Phishing
Email Masquerading
You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?
tcp.dstport= = 514 && ip.dst= = 192.168.0.150
tcp.dstport= = 514 && ip.dst= = 192.168.0.99
tcp.srcport= = 514 && ip.src= = 192.168.0.99
tcp.srcport= = 514 && ip.src= = 192.168.150
To reach a bank web site, the traffic from workstations must pass through a firewall. You have been asked to review the firewall configuration to ensure that workstations in network 10.10.10.0/24 can only reach the bank web site 10.20.20.1 using https. Which of the following firewall rules meets this requirement?
If (source matches 10.20.20.1 and destination matches 10.10.10.0/24 and port matches 443) then permit
If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 443) then permit
If (source matches 10.10.10.0 and destination matches 10.20.20.1 and port matches 443) then permit
If (source matches 10.10.10.0/24 and destination matches 10.20.20.1 and port matches 80 or 443) then permit
What is the minimum number of network connections in a multihomed firewall?
3
2
4
5
Which of the following is an extremely common IDS evasion technique in the web world?
Unicode Characters
Spyware
Port Knocking
Subnetting
Which of the following techniques is used by an attacker to mimic legitimate institutions such as banks and steal sensitive information such as login passwords and credit-card and bank-account data?
Malvertising
Spear-phishing sites
Social-engineered click-jacking
Black-hat SEO
Which of the following techniques is used by an attacker to gain unauthorized access to a target network and remain undetected for a long period of time?
Diversion theft
Insider threat
Advanced persistent threat
Spear-phishing sites
Which of the following port numbers is used by the Trojans Zeus, OceanSalt, and Shamoon?
Port 443
Port 11000
Port 8080
Port 80
What is the TCP/IP-based protocol used for exchanging management information between devices connected to a network?
POP
IMAP
NNTP
SNMP
Which of the following IOS Global commands is used to configure the number of DHCP packets per second (pps) that an interface can receive?
show ip dhcp snooping
ip dhcp snooping
ip dhcp snooping trust
ip dhcp snooping limit rate
