wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Kajar

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

Which of the following is considered a passive reconnaissance action?

a)

Conducting a man-in-the-middle attack

b)

Searching through the local paper

c)

Using the nmap -sT command

d)

Setting up a rogue hot spot

e)

Calling Human Resources

2.

Why is it important to scan your target network slowly?

a)

To avoid alerting the IDS

b)

To evade the firewall

c)

Services may not have started, so scanning slowly ensures that you capture services that started late

d)

It is not necessary to scan the network slowly

3.

You are the senior manager in the IT department for your company. What is the most cost effective way to prevent social engineering attacks?

a)

Ensure that all patches are up-to-date

b)

Implement user awareness training

c)

Monitor and control all email activity

d)

Install HIDS

4.

In which phase within the ethical hacking framework do you alter or delete log information?

a)

Scanning and enumeration

b)

Gaining access

c)

Reconnaissance

d)

Covering tracks

5.

A hacker is conducting the following on the target workstation: nmap --sT 192.33.10.5. The attacker is in which phase?

a)

Covering tracks

b)

Gaining access

c)

Enumeration

d)

Scanning and enumeration

6.

What does a SYN scan accomplish?

a)

It establishes only a "half open" connection

b)

It detects all closed ports on a target system

c)

It opens an ACK connection with the target

d)

It establishes a full TCP connection

7.

In which phase is an attacker who is currently conducting a successful man-in-the-middle attack?

a)

Reconnaissance

b)

Covering Tracks

c)

Gaining Access

d)

Maintaining Access

8.

What is the default TTL values for Microsoft Windows 7 OS?

a)

256

b)

128

c)

64

d)

255

9.

As a penetration tester, only you and a few key selected individuals from the company will know of the targeted network that will be tested. You also have zero knowledge of your target other than the name and location of the company. What type of assessment is this called?

a)

Gray box testing

b)

White box testing

c)

Black box testing

d)

Blue box testing

10.

As an attacker, you found your target. You spend the next two weeks observing and watching personnel move in and move out of the facility. You also observe how the front desk handles large packages that are delivered as well as people who do not have access badges. You finally come up with a solid schedule of security patrols that you see being conducted. What is it that you are doing?

a)

Maintaining access

b)

Reconnaissance

c)

Gaining access

d)

Casing the target

11.

Which scanning tool is more likely going to yield accurate results for the hacker?

a)

Ping

b)

NsLookup

c)

Nmap

d)

Ncat

12.

Which password is more secure?

a)

Keepyourpasswordsecuretoyourself

b)

I9Apple

c)

pass123!!

d)

P!@$$\w0rD

13.

You are sitting inside of your office and you notice a strange person in the parking lot with what appears to be a tall antenna connected to a laptop. What is the stranger most likely doing?

a)

Bluesnarfing

b)

Wardriving

c)

Warflying

d)

Brute-forcing their personal electronic device

14.

Which of following actions is the last step in scanning a target?

a)

Discover open ports

b)

Scan for vulnerabilities

c)

Identify live systems

d)

Identify the OS and servers

15.

Of the following methods, which one acts as a middleman between an external network and the private network by initiating and establishing the connection?

a)

Router

b)

Switch

c)

Proxy server

d)

Firewall

16.

What default port does SSH utilize?

a)

Port 25

b)

Port 443

c)

Port 22

d)

Port 21

17.

As a pentester, you are hired to conduct an assessment on a group of systems for your client. You are provided with a list of critical assets, a list of domain controllers, and a list of virtual share drives. Nothing else was provided. What type of test are you conducting?

a)

Gray box testing

b)

White hat testing

c)

Gray hat testing

d)

White box testing

18.

What is the role of an individual who interrogates a system with permission?

a)

Red hat

b)

White hat

c)

Gray hat

d)

Black hat

19.

What port is used by DNS?

a)

25

b)

21

c)

53

d)

80

20.

Which operating system build provides a suite of tools for network defense purposes?

a)

Kali linux

b)

Security Onion

c)

FreeBSD

d)

Windows Server

21.

Which operating system build provides a suite of tools for network offensive (attack your target) purposes?

a)

Security Onion

b)

Kali linux

c)

Windows Server

d)

FreeBSD

22.

A network of zombie computers used to execute a DDoS on a target system is called?

a)

Botnet

b)

Malware

c)

Social Engineering

d)

Whaling

23.

Which of the following is used for recording key strokes at a terminal or keyboard using malicious software?

a)

Recordware

b)

Malware

c)

Trojan

d)

Keylogger

24.

Software that creates pop-up advertisement messages while visiting websites is known as what?

a)

Adware

b)

Malware

c)

Pop-up blocker

d)

Freeware

25.

The ability for information or services that must be accessible at a moment's notice is called what?

a)

CIA

b)

Redundancy

c)

Survivability

d)

Availability

26.

A device that facilitates connections and acts as a middleman between a trusted zone and an untrusted zone is referred to as what?

a)

Man-in-the-middle attack

b)

Proxy server

c)

Firewall

d)

Gateway

27.

As a black hat, you are conducting a reconnaissance operation on a potential target. You gather intelligence by using publicly available information, conducting stakeouts of the facility, and observing workers as they enter and leave the premises from across the street. What phase of the hacking methodologies are you operating within?

a)

Passive reconnaissance

b)

Fingerprinting

c)

Active surveillance

d)

Footprinting

28.

As a black hat, you forge an identification badge and dress in clothes associated with a maintenance worker. You attempt to follow other maintenance personnel as they enter the power grid facility. What are you attempting to do?

a)

Tailgating

b)

Social engineering

c)

Piggybacking

d)

Reconnaissance

29.

Chris decides to download some music from a website while at work. When he opens the music files, a pop-up notification informs Chris that he must send $600 US dollars to a PayPal account using the email address Shoju@scorpion.ru if he wants access to his system again. What do you think Chris may have installed?

a)

Cryptoware

b)

Adware

c)

Ransomware

d)

Trojan

30.

Which term best describes the absence or weakness of a safeguard related to an asset?

a)

Vulnerability

b)

Exploit

c)

Risk

d)

Threat

31.

As a black hat, you use ToneLoc to dial random numbers in order to connect to a modem that is providing service to a server. What type of attack are you conducting?

a)

Wardriving

b)

Scanning

c)

Wardialing

d)

DoS

32.

As a white hat, your customer asks what type of assessments you can conduct. What are they?

a)

Risk, vulnerability, and exploits

b)

Risk, mitigation, and vulnerability

c)

Malware, risk, and exploit

d)

Risk, threat, and vulnerability

33.

When a black hat is querying for a number of services or login information on a target system, what are they trying to accomplish?

a)

Footprinting

b)

Scanning

c)

Enumeration

d)

Fingerprinting

34.

Which of the following allows the adversary to obtain passwords online in a passive manner?

a)

Account creation

b)

Password cracking

c)

Man in the middle Attack

d)

Sniffing

35.

What is accomplished by a combination of ping sweeping and enumerating a target?

a)

Fingerprinting

b)

Reconnaissance

c)

Identification

d)

Footprinting

36.

Which switch in Nmap allows for a full TCP connect scan?

a)

-sS

b)

-sU

c)

-fC

d)

-sT

37.

As a black hat, you call into the city manager's office claiming to be a part of the help desk team. You ask the clerk for her username and password to install the latest Microsoft Office suite. What type of attack are you conducting?

a)

Masquerading

b)

Tailgating

c)

Piggybacking

d)

Impersonating

38.

Which of the following applications is used to inspect packets?

a)

NMap

b)

Wireshark

c)

Cain & Able

d)

Aircrack

39.

How would an administrator set a password for a user in Linux?

a)

chmod pass user pass123

b)

passwd user pass123

c)

password user pass123

d)

pass user pass123

40.

Which is the second phase in the ethical hacking methodology?

a)

Reconnaissance

b)

Scanning and Enumeration

c)

Covering tracks

d)

Maintaining Access

41.

Your company has been targeted by a series of phishing emails. In order to deter the attack, you quickly tell your users to verify senders. How do you go about implementing this?

a)

Ensure the email was not encrypted

b)

Reply back to their message and ask for their public key

c)

Ensure the email is digitally signed

d)

Call the sender and verify

42.

A user side-loaded a popular app from an unauthorized third-party app store. When the user installed the app, it displayed a screen asking for payment and stating that if the payment was not received, the user would lose all access to data that was stored on their phone. What was installed on the user’s phone?

a)

Spyware

b)

Malware

c)

Trojan

d)

Ransomware

43.

Which of the following is considered open-source information?

a)

Newspaper

b)

Information from man in the middle attack

c)

Trade secret

d)

Information from dumpster diving

44.

Which of the following tools allows a user to monitor network activity?

a)

Metasploit

b)

Wireshark

c)

Netcraft

d)

Cain & Able

45.

What is the default command port for FTP?

a)

24

b)

21

c)

23

d)

22

46.

Which of the following has no flags set and does not respond if a port is open?

a)

XMAS scan

b)

ACK scan

c)

NULL scan

d)

Half-open connection

47.

To establish a TCP connection, what must be sent first?

a)

SYN

b)

Hello Packet

c)

ACK

d)

Broadcast

48.

Which is the last step of the CEH hacking methodology?

a)

Corrupt data

b)

Maintaining Access

c)

Cover your tracks

d)

Scrub the logs

49.

Which of the following is a malware that does not need a host or human interaction to disrupt and corrupt data?

a)

Keylogger

b)

Trojan

c)

Worm

d)

Virus

50.

What is the main purpose of installing a Trojan?

a)

To cause DoS on a computer

b)

To encrypt system

c)

To delete files on a computer

d)

To install backdoor