wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Gathering Quiz

Total questions: 20

Worksheet time: 13mins

Name
Class
Date
1.

Which of the following is a fast and easy way to gather information about a company?

a)

Conduct port scanning.

b)

Perform a zone transfer of the company's DNS server.

c)

View the company's Web site.

d)

Look for company ads in phone directories.

2.

To find information about the key IT personnel responsible for a company's domain, you might use which of the following tools?

a)

Whois

b)

Whatis

c)

SamSpade

d)

Nbtstat

3.

___ is one of the components most vulnerable to network attacks.

a)

TCP/IP

b)

WINS

c)

DHCP

d)

DNS

4.

Which of the following contains host records for a domain?

a)

DNS

b)

WINS

c)

Linux server

d)

UNIX Web clients

5.

Which of the following is a good Web site for gathering information on a domain?

a)

www.google.com

b)

www.namedroppers.com

c)

www.samspade.org

d)

www.arin.net

e)

All of the above

6.

A cookie can store information about a Web site's visitors. True or False?

4 lines
7.

Which of the following enables you to view all host computers on a network?

a)

SOA

b)

Ipconfig

c)

Zone transfers

d)

HTTP HEAD method

8.

What's one way to gather information about a domain?

a)

View the header of an e-mail you send to an e-mail account that doesn't exist.

b)

Use the Ipconfig command.

c)

Use the Ifconfig command.

d)

Connect via Telnet to TCP port 53.

9.

Which of the following is one method of gathering information about the operating systems a company is using?

a)

Search the Web for e-mail addresses of IT employees.

b)

Connect via Telnet to the company's Web server.

c)

Ping the URL and analyze ICMP messages.

d)

Use the ipconfig /os command.

10.

To determine a company's primary DNS server, you can look for a DNS server containing which of the following?

a)

Cname record

b)

Host record

c)

PTR record

d)

SOA record

11.

When conducting competitive intelligence, which of the following is a good way to determine the size of a company's IT support staff?

a)

Review job postings on Web sites such as www.monster.com or www.dice.com.

b)

Use the Nslookup command.

c)

Perform a zone transfer of the company's DNS server.

d)

Use the host -t command.

12.

If you're trying to find newsgroup postings by IT employees of a certain company, which of the following Web sites should you visit?

a)

http://groups.google.com

b)

www.google.com

c)

www.samspade.com

d)

www.arin.org

13.

Which of the following tools can assist you in finding general information about an organization and its employees?

a)

www.google.com

b)

http://groups.google.com

c)

Netcat

d)

Nmap

14.

What's the first method a security tester should attempt to find a password for a computer on the network?

a)

Use a scanning tool.

b)

Install a sniffer on the network.

c)

Ask the user.

d)

Install a password-cracking program.

15.

Many social engineers begin gathering the information they need by using which of the following?

a)

The Internet

b)

The telephone

c)

A company intranet

d)

E-mail

16.

Discovering a user's password by observing the keys he or she presses is called which of the following?

a)

Password hashing

b)

Password crunching

c)

Piggybacking

d)

Shoulder surfing

17.

Shoulder surfers can use their skills to find which of the following pieces of information?

a)

Passwords

b)

ATM PINs

c)

Long-distance access codes

d)

Open port numbers

18.

Entering a company's restricted area by following closely behind an authorized person is referred to as which of the following?

a)

Shoulder surfing

b)

Piggybacking

c)

False entering

d)

Social engineering

19.

What social-engineering technique involves telling an employee that you're calling from the CEO's office and need certain information ASAP?

a)

Urgency

b)

Status quo

c)

Position of authority

d)

Quid pro quo

20.

Before conducting a security test by using social-engineering tactics, what should you do?

a)

Set up an appointment.

b)

Document all findings.

c)

Get written permission from the person who hired you to conduct the security test.

d)

Get written permission from the department head.