wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Page 1

Total questions: 150

Worksheet time: 1hrs 15mins

Name
Class
Date
1.

Which best defines reconnaissance in ethical hacking?

a)

Executing exploits to gain shell access

b)

Collecting target information via observation

c)

Restoring systems after an intrusion

d)

Encrypting data to protect communications

2.

In the scenario, what routine enables the hacker to plan physical entry?

a)

Driver’s daily timed deliveries

b)

Weekly software updates

c)

Monthly payroll processing

d)

Random visitor arrivals

3.

Why do security personnel unlock the door for the delivery driver?

a)

He uses a personal PIN code

b)

He submits a signed manifest

c)

He presents a temporary badge

d)

They recognize his regular pattern

4.

What vulnerability did the hacker exploit at the loading dock?

a)

Trust in familiar procedures

b)

Unpatched server firmware

c)

Weak cryptographic protocols

d)

Open Wi‑Fi guest network

5.

Which action demonstrates passive reconnaissance?

a)

Planting a rogue access point

b)

Tailgating through the door

c)

Phishing the office manager

d)

Observing from the parking lot

6.

What social engineering technique is primarily used when the driver holds the door?

a)

Baiting via removable media

b)

Vishing with caller ID spoofing

c)

Tailgating with pretext

d)

Watering‑hole web compromise

7.

Which control would best reduce this specific risk?

a)

Daily full disk encryption audits

b)

Quarterly vulnerability scanning

c)

Longer password rotation policy

d)

Strict mantrap with badge checks

8.

What information patterns are most valuable during reconnaissance?

a)

How, when, and where tasks occur

b)

Exact CPU model of servers

c)

Number of paper clips in office

d)

Favorite colors of employees

9.

Which behavior from security staff contributes to the breach?

a)

Remote door unlock by recognition

b)

Two‑factor identity verification

c)

Escort policy for all deliveries

d)

Immediate incident report filing

10.

Which is the most appropriate immediate response after noticing tailgating?

a)

Share guest Wi‑Fi password

b)

Challenge and verify identity

c)

Ignore and continue working

d)

Offer help carrying packages

11.

Which action allowed the hacker to silently install malware on the receptionist’s computer?

a)

Brute-forcing the receptionist’s login credentials

b)

Sending a phishing email with a malicious link

c)

Using an unlocked computer without a password

d)

Exploiting an outdated web browser plugin

12.

What behavior pattern did the hacker exploit at the front desk?

a)

Manager routinely reviewing access logs each hour

b)

Receptionist enforcing strict USB port lockdown

c)

Visitors required to present government identification

d)

Receptionist leaving the desk to get the manager

13.

What is the primary goal of reconnaissance in the described scenario?

a)

Gain physical access by observing routines

b)

Collect encrypted credentials via packet sniffing

c)

Launch a distributed denial-of-service attack

d)

Plant ransomware through remote desktop

14.

What immediate step did the hacker take after installing the software?

a)

Uploaded data to a remote command server

b)

Deleted system logs to hide all traces

c)

Changed the system password to lock users out

d)

Removed the USB drive and exited quickly

15.

The Medical Associates network was compromised via what mechanism?

a)

A Trojaned system bypassing checkpoints

b)

A weak WPA2 key on guest Wi‑Fi

c)

A SQL injection in patient portals

d)

A misconfigured firewall allowing telnet

16.

Competitive intelligence primarily involves gathering information about what?

a)

Internal payroll and human resources data

b)

Competitors’ products, markets, and technologies

c)

Government regulations and legal case law

d)

Personal social media posts of employees

17.

Which characteristic best describes most competitive intelligence activities?

a)

Nonintrusive and benign to the target

b)

Covert and highly illegal by design

c)

Destructive and aims to sabotage rivals

d)

Expensive and requires physical infiltration

18.

Why are SpyFu and KeywordSpy recommended in the exercises?

a)

They are easy to use and completely passive

b)

They enable brute-force password recovery

c)

They provide packet capture for web traffic

d)

They automate spear-phishing campaigns

19.

What type of insight do tools like SpyFu and KeywordSpy provide about a website?

a)

Keywords associated with the website

b)

Encrypted VPN tunnel configurations

c)

The physical server rack location

d)

Employee salaries and titles

20.

In sales and marketing, competitive intelligence is used primarily to do what?

a)

Determine criminal liability for data breaches

b)

Understand how competitors position products

c)

Calculate subnet masks for network design

d)

Design kernel-level device drivers

21.

Which initial step is required when using SpyFu for competitive intelligence?

a)

Run a local crawler against the site

b)

Enter target domain in search field

c)

Upload a sitemap XML for parsing

d)

Install a browser extension for SpyFu

22.

After obtaining a SpyFu report, what is the primary task?

a)

Determine valuable keywords and links

b)

Export cookies for session analysis

c)

Scan ports for open services

d)

Measure page load performance metrics

23.

What is the website used to access SpyFu?

a)

www.spfy.com

b)

www.spyfuel.com

c)

www.spyfu.com

d)

www.spyfoo.org

24.

Which tool focuses on gathering competitive intelligence through keyword research and similar reports?

a)

Nmap

b)

Burp Suite

c)

KeywordSpy

d)

Wireshark

25.

What is the core input required by KeywordSpy to start research?

a)

Provide server IP address range

b)

Type a keyword or domain name

c)

Enter Google Analytics tracking ID

d)

Upload HTML source repository

26.

Which action follows running KeywordSpy according to the instructions?

a)

Set up affiliate tracking pixels

b)

Perform cross-site scripting tests

c)

Review the report for valuable information

d)

Change DNS records for the domain

27.

In the SpyFu interface shown, what does the search field expect?

a)

An email address for alerts

b)

A JSON API endpoint URL

c)

A compressed log archive

d)

A domain or keyword entry

28.

KeywordSpy’s navigation includes which primary research mode?

a)

Packet Capture tab

b)

Container Orchestration tab

c)

Binary Exploit tab

d)

Keyword Research tab

29.

Which outcome best describes the goal of using these tools?

a)

Identify competitive keywords and links

b)

Design custom networking hardware

c)

Benchmark CPU microarchitecture

d)

Crack encrypted user passwords

30.

When entering a target address into these tools, which format is most appropriate?

a)

Raw HTML snippet body tag

b)

MAC address colon-separated

c)

IPv6 link-local with scope id

d)

Full domain like example.com

31.

Which primary purpose does the EDGAR database serve for public companies?

a)

Provide market data and real-time quotes

b)

Host investor relations chat forums

c)

Publish quarterly earnings conference calls

d)

Store all SEC filings for public firms

32.

What is the first step to gather information using EDGAR in the described workflow?

a)

Determine the company stock symbol

b)

Download the SEC mobile application

c)

Create an EDGAR user account

d)

Subscribe to SEC RSS news feeds

33.

Which website should you navigate to when starting the EDGAR search process?

a)

www.edgar.gov standalone site

b)

www.yahoo.com finance page

c)

www.nasdaq.com via portal

d)

www.sec.gov in a web browser

34.

On the SEC homepage, which link is clicked to access filing searches?

a)

Investor Education center link

b)

EDGAR Filers link on the right

c)

Company News tab on top

d)

About the SEC organizational page

35.

Which menu do you use to query filings by company name or stock symbol?

a)

Search For Filings menu option

b)

Company Profiles dropdown list

c)

SEC Enforcement archives menu

d)

Market Statistics navigation tab

36.

What type of information can be learned from EDGAR filings according to the process?

a)

Real-time stock quote streaming

b)

Third-party analyst price targets

c)

Daily insider trading summaries

d)

Where the company is registered

37.

Which external directory is suggested to complement EDGAR lookups?

a)

LinkedIn company pages section

b)

Bloomberg corporate registry portal

c)

Google Business Profile directory

d)

Yahoo! yellow pages at yp.yahoo.com

38.

Why is identifying the stock symbol before using EDGAR beneficial?

a)

Automatically downloads all filings

b)

Bypasses login with faster access

c)

Unlocks premium SEC account features

d)

Improves accuracy of filing searches

39.

When conducting competitive intelligence, how do SEC filings primarily assist?

a)

Provide contact names and addresses

b)

Offer marketing campaign templates

c)

Supply confidential trade secrets

d)

List employee performance reviews

40.

Which action follows after clicking EDGAR Filers on the SEC site in the outlined steps?

a)

Email the SEC investor relations team

b)

Open the enforcement actions archive

c)

Enter company name or symbol to search

d)

Register for an EDGAR filer number

41.

Which activity is described as a passive information-gathering source that can determine a web server’s operating system and version?

a)

Deploying active vulnerability scanners

b)

Using Netcraft to profile web servers

c)

Running Nmap with aggressive probes

d)

Launching credential-stuffing attempts

42.

In the context of reconnaissance, what is the primary purpose of using Google Groups and job-posting websites when researching organization names?

a)

Download internal configuration files

b)

Extract payroll data from postings

c)

Collect emails for phishing campaigns

d)

Identify IT roles hinting at system types

43.

According to the seven-step methodology, which two steps fall under footprinting?

a)

Detect operating systems; map the network

b)

Unearth initial information; locate network range

c)

Ascertain active machines; detect OS

d)

Discover open ports; uncover services

44.

After locating the network range, which step logically follows in the sequence shown?

a)

Uncover services on ports

b)

Detect operating systems

c)

Map the network

d)

Ascertain active machines

45.

Which step is required before attempting to detect operating systems in the methodology?

a)

Discover open ports/access points

b)

Locate the network range

c)

Map the network topology

d)

Unearth initial information

46.

What is the main distinction between passive and active information gathering as implied by the material?

a)

Passive requires authenticated sessions

b)

Passive sends crafted probes to hosts

c)

Passive exploits services to gain access

d)

Passive avoids direct interaction with targets

47.

Which step directly precedes “Map the Network” in the seven-step process?

a)

Detect operating systems

b)

Locate the network range

c)

Ascertain active machines

d)

Uncover services on ports

48.

What insight can job postings provide that is useful during reconnaissance?

a)

Encrypted database dumps for analysis

b)

Indications of network types and systems

c)

Administrator passwords for devices

d)

Exact IP addresses of core routers

49.

Which tool is mentioned as being discussed further in a later chapter and is suitable for passive web reconnaissance?

a)

Burp Suite scanner

b)

Wireshark capture

c)

Netcraft website

d)

Metasploit framework

50.

Which step would most likely involve ping sweeps or ARP scans to identify reachable hosts?

a)

Unearth initial information

b)

Map the network

c)

Ascertain active machines

d)

Uncover services on ports

51.

Which statement best defines footprinting in cybersecurity?

a)

Creating a network blueprint for a target

b)

Exploiting vulnerabilities to gain access

c)

Encrypting data to prevent disclosure

d)

Installing defensive monitoring tools

52.

What is the primary goal during the initial step of footprinting?

a)

Scan ports for open services

b)

Determine the target system or location

c)

Deploy phishing emails to users

d)

Bypass intrusion detection rules

53.

Which method is emphasized as nonintrusive for gathering information during footprinting?

a)

Reviewing the organization’s public web pages

b)

Running credential-stuffing attacks

c)

Brute-forcing administrative portals

d)

Intercepting internal traffic flows

54.

Which item is typically collected to understand network addressing during footprinting?

a)

Physical desk arrangements

b)

Employee salary histories

c)

GPU specifications on servers

d)

Specific IP addresses in use

55.

Before launching an exploit, what must be uncovered to tailor the attack effectively?

a)

Preferred office software suites

b)

Printer toner stock levels

c)

Employee vacation schedules

d)

Operating system and version used

56.

Which of the following pieces of information helps map how users authenticate?

a)

Authentication mechanisms employed

b)

Cable tray routing diagrams

c)

Desktop wallpaper policies

d)

Office cafeteria vendor list

57.

Which item from the footprinting list relates to segmenting the organization’s address space?

a)

Building evacuation routes

b)

Network blocks assigned

c)

Laptop screen resolutions

d)

Corporate mission statement

58.

Which example illustrates social engineering supported by footprinting?

a)

Defragmenting storage arrays

b)

Using personnel directories for bios

c)

Modifying kernel memory addresses

d)

Compiling source code in containers

59.

What insight does compiled footprinting information provide to an attacker?

a)

Which teams prefer agile ceremonies

b)

How to optimize database indexing

c)

Where valuable data is stored and accessed

d)

Best times for cafeteria discounts

60.

Which security control is explicitly mentioned as part of the footprinting data?

a)

Air-gapped backup rotations

b)

Intrusion detection system details

c)

Quantum key distribution links

d)

Zero-trust microsegmentation tags

61.

Which activity best describes footprinting in a security context?

a)

Encrypting all traffic with strong ciphers

b)

Collecting public data about a target environment

c)

Installing exploits on a production server

d)

Writing custom malware for targeted systems

62.

What is the primary purpose of the preparatory phase that includes footprinting?

a)

Deploy intrusion detection systems company-wide

b)

Patch servers and update firmware routinely

c)

Train employees on phishing awareness only

d)

Learn system architecture to identify vulnerabilities

63.

Which tool is commonly used to obtain domain registration details?

a)

Whois

b)

Traceroute

c)

Nmap

d)

Netcat

64.

Open source information for footprinting can typically include which item?

a)

Internal VPN configurations

b)

Encrypted passwords from databases

c)

Phone numbers and physical addresses

d)

Proprietary source code repositories

65.

Performing DNS table lookups during reconnaissance helps mainly to:

a)

Bypass network firewalls directly

b)

Disable remote services automatically

c)

Install keyloggers on endpoints

d)

Map hostnames to IP addresses

66.

Why does footprinting reduce the chance of detection compared to direct attacks?

a)

Erases evidence with secure wiping

b)

Spoofs user credentials in logs

c)

Runs kernel-level exploits silently

d)

Uses passive information-gathering methods

67.

Which statement about tool selection during reconnaissance is most accurate?

a)

Use tools that modify production configurations

b)

Choose tools that require admin credentials

c)

Always prefer Windows-only scanning utilities

d)

Eliminate tools incompatible with the target systems

68.

What is a realistic outcome of footprinting a company’s systems?

a)

Identifying remote access capabilities and services

b)

Obtaining administrator passwords instantly

c)

Encrypting the target’s data without keys

d)

Crashing servers through packet floods

69.

Which web search activity is mentioned as useful for gathering information?

a)

Downloading pirated software bundles

b)

Posting questions on unrelated forums

c)

Running Google searches about employees

d)

Streaming video content for clues

70.

Which item from the list is a lookup utility relevant to footprinting?

a)

Nslookup

b)

Photoshop

c)

Wireshark

d)

Metasploit

71.

Which Google operator restricts results to a specific website or domain when placed before a colon?

a)

filetype

b)

site

c)

cache

d)

link

72.

What does the filetype operator do when used in a Google query?

a)

Searches inside hyperlinks

b)

Searches within a domain

c)

Searches specific document formats

d)

Searches cached page versions

73.

Which operator helps identify pages linking to a given URL?

a)

inurl

b)

link

c)

site

d)

intitle

74.

To view Google's stored version of a web page, which operator should be used with the page URL after the colon?

a)

intitle

b)

cache

c)

inurl

d)

filetype

75.

Which operator limits matches to terms appearing in the page title?

a)

inurl

b)

site

c)

link

d)

intitle

76.

Which operator restricts search to terms found within the web address itself?

a)

cache

b)

inurl

c)

intitle

d)

site

77.

When using filetype, which formatting rule is correct for specifying the extension?

a)

Add quotes around the ext

b)

Use square brackets around ext

c)

Avoid a leading period

d)

Include a leading period

78.

A researcher wants pages about "BorderManager information alert" where the phrase appears in the title. Which query component is most appropriate?

a)

site:novell.com

b)

cache:novell.com

c)

intitle:"BorderManager information alert"

d)

filetype:pdf

79.

Which combined approach best locates potentially vulnerable web applications by searching parameters in URLs and specific script files?

a)

filetype with cache and an IP

b)

link with intitle and a domain

c)

site with cache and quoted phrase

d)

inurl with filetype and a script name

80.

Corporate job postings can reveal which kind of technical information to a researcher?

a)

Exact payroll amounts

b)

Encrypted password files

c)

Servers and infrastructure types

d)

Customer purchase histories

81.

Which best describes DNS enumeration in an information-gathering phase?

a)

Locating all DNS servers and records for an organization

b)

Scanning open ports to identify running network services

c)

Decrypting SSL/TLS traffic to inspect hidden payloads

d)

Brute-forcing login credentials for administrative access

82.

During profiling, what proportion of time is commonly spent gathering information versus launching an attack?

a)

About ninety percent gathering, ten percent launching

b)

About fifty percent gathering, fifty percent launching

c)

About ten percent gathering, ninety percent launching

d)

About seventy percent gathering, thirty percent launching

83.

Which data can internal and external DNS servers reveal during enumeration?

a)

Financial records and payroll details of employees

b)

Source code repositories and commit histories

c)

Encrypted session keys and TLS certificates of clients

d)

Usernames, computer names, and IP addresses of targets

84.

Which tools can be used to perform DNS enumeration according to the material?

a)

OpenSSL, GPG, Hashcat, and John

b)

NSlookup, DNSstuff, ARIN, and Whois

c)

Wireshark, Tcpdump, Aircrack, and Kismet

d)

Nmap, Metasploit, Burp, and Nikto

85.

What is NSlookup primarily used for across Unix, Linux, and Windows systems?

a)

Generating SSL certificates for secure domains

b)

Exploiting buffer overflows in services

c)

Capturing packets to analyze network traffic

d)

Querying DNS servers for record information

86.

Hacking tools such as Sam Spade typically include which functionality relevant to DNS?

a)

Wireless network cracking with WEP attacks

b)

Automated SQL injection against web databases

c)

Real-time ransomware deployment modules

d)

Built-in NSlookup capabilities for record queries

87.

How can information from Whois support further discovery with NSlookup?

a)

Bypass firewall rules to access internal zones

b)

Replace DNS records to poison resolver caches

c)

Use authoritative name servers to find more host IPs

d)

Decrypt TLS traffic to view hidden DNS queries

88.

Given an authoritative name server like AUTH1.NS.NYI.NET, what practical outcome can NSlookup achieve?

a)

Recover hashed passwords for domain admins

b)

Enumerate users from an LDAP directory

c)

Extract API keys from public repositories

d)

Discover the IP address of the mail server

89.

Why might an organization have both internal and external DNS servers relevant to enumeration?

a)

To accelerate CPU performance on DNS resolvers

b)

To enforce VLAN segmentation on core switches

c)

To separate inside host records from public-facing records

d)

To enable symmetric encryption of DNS responses

90.

Which statement aligns with ethical use of DNS enumeration tools in security assessments?

a)

Leverage them to break TLS on email gateways

b)

Exploit them to replace registrant contact details

c)

Deploy them to disrupt name resolution in production

d)

Use them to map target systems with authorization

91.

Which command-line tool is traditionally used to query DNS records for a domain?

a)

NSlookup DNS query tool

b)

Traceroute network path tool

c)

Netstat socket listing tool

d)

Ping utility for domain queries

92.

What web-based service mentioned allows online DNS record searches without command-line switches?

a)

Whois lookup portal

b)

DNSstuff online service

c)

Shodan device index

d)

Nmap scanning site

93.

In the sample A record lookup for eccouncil.org, what type of information does the A record provide?

a)

Mail server hostnames list

b)

Alias mappings for subdomains

c)

Authoritative name servers

d)

IPv4 address of the host

94.

Why might some DNS lookup results appear quickly for users worldwide, as noted in the figure?

a)

Peer-to-peer sharing accelerates

b)

SSL certificates speed responses

c)

Results precomputed weekly

d)

Cached data reduces query time

95.

What is a practical advantage of using DNSstuff over the command-line NSlookup tool?

a)

It avoids complex command switches

b)

It blocks all non-authoritative answers

c)

It guarantees anonymous queries

d)

It eliminates DNS server traversal

96.

In the described search of www.eccouncil.org, what additional information beyond aliases can be discovered?

a)

User credentials for admin

b)

Associated IP addresses and name servers

c)

TLS private keys and ciphers

d)

Open ports on the web server

97.

When performing information gathering, what is the role of DNS record searches?

a)

They authenticate users to services

b)

They prevent phishing attempts

c)

They reveal domain infrastructure details

d)

They encrypt traffic end-to-end

98.

Which statement best describes a non-authoritative answer in DNS lookups?

a)

Response from a caching resolver

b)

Reply from the domain registrar

c)

Answer signed with DNSSEC keys

d)

Message returned only by AXFR

99.

What does the note imply about the freshness of the displayed DNS results?

a)

They are archived monthly snapshots

b)

They are generated in real time

c)

They are anonymized historical logs

d)

They are synthetic test datasets

100.

If you need to view all name servers for a domain, which approach fits the material?

a)

Scan with traceroute for routers

b)

Run ipconfig to list adapters

c)

Query SMTP for MX records

d)

Use DNSstuff to list NS records

101.

Which component of the URL www.Microsoft.com identifies the domain name?

a)

Microsoft.com portion

b)

www prefix label

c)

top-level path segment

d)

https scheme tag

102.

What is the primary purpose of the Whois tool?

a)

Scan open service ports

b)

Trace packet routes

c)

Encrypt domain traffic

d)

Query registration database

103.

ICANN’s role regarding domain names is to

a)

Sell advertising services

b)

Manage browser extensions

c)

Provide email hosting

d)

Ensure single-company usage

104.

In a URL, the hostname or alias in www.Microsoft.com is represented by

a)

www label alias

b)

Microsoft registrar

c)

com country code

d)

DNSStuff toolkit

105.

Which information can SmartWhois help you find about a domain or IP?

a)

TLS cipher suite list

b)

Browser cookie settings

c)

CPU architecture specs

d)

Administrator contact details

106.

ARIN lookups are associated most directly with

a)

File compression ratios

b)

Password hashing methods

c)

Web page rendering

d)

IP address registration

107.

Why did Whois originate from the Unix operating system?

a)

Multimedia playback needs

b)

Graphical desktop utilities

c)

Early network registry tools

d)

Local printer discovery

108.

When using DNSStuff’s free tools, which listed tool would show route to host?

a)

Traceroute option

b)

Whois Lookup

c)

IP Information

d)

SmartWhois

109.

Which statement best describes what the Whois query returns?

a)

Contact registration data

b)

Packet latency metrics

c)

SSL certificate chain

d)

Directory file listings

110.

What does ICANN require regarding domain name registration?

a)

Public DNS zone transfers

b)

Monthly renewal billing

c)

Registration to prevent duplicates

d)

Two-factor admin authentication

111.

Which database is specifically mentioned as containing owners of static IP addresses and can be queried via a Whois tool?

a)

IANA registry portal

b)

ARIN public database

c)

BGP route tables

d)

RFC archive index

112.

During a WHOIS lookup of a company URL, which item is typically identified along with technical and DNS contacts?

a)

SSL cipher suites

b)

Registered address

c)

Server uptime metric

d)

Firewall vendor

113.

What is one potential ethical use of information found in ARIN Whois results?

a)

Exploit buffer overflow in servers

b)

Identify who is responsible for an IP

c)

Encrypt email traffic end-to-end

d)

Bypass multi-factor authentication

114.

Which action helps verify whether WHOIS contact details align with official organizational information?

a)

Inspect TLS certificate chain

b)

Check the company’s website

c)

Trace route to the DNS server

d)

Run a port scan on the domain

115.

Why should security professionals be aware of data in public databases like ARIN?

a)

They provide malware signatures for antivirus

b)

They reveal sensitive network ownership details

c)

They enforce GDPR compliance automatically

d)

They determine password complexity policies

116.

When examining WHOIS results, which additional contact detail might be listed along with contact email?

a)

VPN pre-shared key

b)

Contact phone number

c)

SSH public key

d)

Physical server rack

117.

What risk is associated with publicly available WHOIS/ARIN information if mishandled?

a)

Enabling social-engineering attacks

b)

Automatic DNSSEC failures

c)

Accidental firmware downgrade

d)

Forced IPv6-only routing

118.

Which step can help infer an organization’s email naming convention from public sources?

a)

Scrape robots.txt for hidden paths

b)

Review TLS session resumption

c)

Analyze CDN cache headers

d)

Search employee names or emails

119.

Figure 2.4 is described as an ARIN Whois search for a major website. What general type of information did it show?

a)

Source code repositories

b)

Addresses, emails, contact info

c)

Kernel version of servers

d)

Exact firewall rule sets

120.

What best practice should organizations follow regarding data visible in ARIN and similar databases?

a)

Publish all employee phone numbers

b)

Minimize unnecessary public contact data

c)

Disable DNS for external domains

d)

Use only dynamic IP addresses

121.

Which organization provides IP registry services specifically for North America?

a)

ARIN for North American regions

b)

APNIC for Asia Pacific regions

c)

RIPE NCC for Europe and nearby regions

d)

LACNIC for Latin American regions

122.

What is the primary purpose of a Whois search in network reconnaissance?

a)

To scan internal network subnets automatically

b)

To encrypt server communications securely

c)

To benchmark web server performance metrics

d)

To retrieve domain registration and contact details

123.

Which registry is responsible for Europe, the Middle East, and parts of Central Asia?

a)

APNIC for Asia Pacific regions

b)

ARIN for North American regions

c)

LACNIC for Caribbean territories

d)

RIPE NCC for Europe and adjacent areas

124.

A security analyst needs data for a domain in the Asia Pacific region. Which registry should be queried?

a)

ARIN servicing North America

b)

APNIC servicing Asia Pacific

c)

RIPE NCC servicing Europe

d)

LACNIC servicing Latin America

125.

Which statement best describes LACNIC?

a)

Registry for Latin American and Caribbean networks

b)

Registry for European and Middle Eastern networks

c)

Registry for North American and Canadian networks

d)

Registry for Asia Pacific and Oceania networks

126.

When analyzing Whois output, which information is commonly found?

a)

Firewall vendors protecting the domain

b)

Server-side scripting language versions

c)

Registrant name and administrative contacts

d)

TLS certificate cipher suites used

127.

Which practical method is suggested for running a Whois search?

a)

Install a mail server and query MX records

b)

Deploy an IDS to capture registry traffic

c)

Compile a custom kernel with networking flags

d)

Use a browser to visit a Whois-enabled website

128.

In the ARIN web output for a domain, what type of result is typically displayed?

a)

Source code of the target web application

b)

Real-time packet captures and flows

c)

Browser cache statistics and cookie data

d)

IP block allocations with organization details

129.

Why should analysts be aware of multiple regional Internet registries?

a)

Different regions use distinct registries for allocations

b)

Registries determine DNS recursion policies globally

c)

Using multiple registries weakens encryption standards

d)

Only one registry can be used per organization

130.

Which example domain is mentioned for demonstrating a Whois search?

a)

www.networksolutions.com for DNS hosting

b)

www.apnic.net for traceroute analysis

c)

www.yahoo.com for SSL testing purposes

d)

www.eccouncil.org as a sample query

131.

In a WHOIS record, which field identifies the domain string itself?

a)

Registrar field

b)

Status field

c)

Registrant Name field

d)

Domain Name field

132.

What piece of information indicates when the domain was initially registered?

a)

Created On timestamp

b)

Last Updated timestamp

c)

Expiration Date timestamp

d)

Registrar ID code

133.

Which entity is responsible for managing the domain registration in this record?

a)

Domain ID string

b)

Registrant City

c)

Registrant Organization

d)

Sponsoring Registrar

134.

Which field lists the individual associated with the domain registration?

a)

Status field

b)

Domain ID field

c)

Created On field

d)

Registrant Name field

135.

What does the Status: OK line generally signify about a domain’s registration?

a)

The domain is pending transfer to another registrar

b)

The domain is locked and cannot be updated

c)

The domain is active and in good standing

d)

The domain has expired and is inactive

136.

If the Expiration Date is 14-Dec-2006 10:13:06 UTC, what does that time represent?

a)

When the current registration term ends

b)

When the domain was first created

c)

When the registrar changed ownership

d)

When the record was last modified

137.

Which part of the WHOIS output provides the registrant’s city and state?

a)

Domain Name and ID fields

b)

Registrant City and State fields

c)

Created On and Updated fields

d)

Status and Sponsoring fields

138.

What is the typical use of the Domain ID in a WHOIS record?

a)

A unique identifier for the domain entry

b)

The numerical code for the registrant’s phone

c)

The server IP address for DNS queries

d)

A hash of the registrar’s legal name

139.

Which contact channel is shown for direct phone communication with the registrant?

a)

Registrar support email

b)

Registrant Phone number

c)

Registrant FAX number

d)

DNS admin ticket portal

140.

You need to verify ownership of a domain. Which fields together most strongly evidence ownership details?

a)

Registrar and Sponsoring

b)

Domain ID and Status

c)

Registrant Name and Organization

d)

Created On and Expiration

141.

Which field typically contains the administrator’s full name in a WHOIS-style record?

a)

Tech Name field

b)

Admin FAX field

c)

Admin City field

d)

Admin Name field

142.

In the shown record, what type of information is stored in 'Admin Country'?

a)

Postal routing number

b)

International phone code

c)

Two-letter country code

d)

City district code

143.

What is the likely purpose of 'Admin Phone Ext.' in contact records?

a)

Lists fax service provider

b)

Stores alternate country

c)

Indicates mobile carrier code

d)

Adds internal extension

144.

Which field is most appropriate for storing '67 Wall Street, 22nd Floor'?

a)

Admin Email field

b)

Admin Street1 field

c)

Admin Postal field

d)

Admin State/Province field

145.

Why might both 'Admin Email' and 'Tech Email' be present in a domain record?

a)

Split roles and responsibilities

b)

Duplicate contact entries

c)

Comply with phone regulations

d)

Encrypt sensitive fields

146.

Which field appropriately stores '10005-3198'?

a)

Admin Postal Code

b)

Admin Phone Number

c)

Admin City Name

d)

Tech Organization

147.

What data type best fits the 'Admin Phone' value '+1.2127098253'?

a)

Boolean true/false

b)

Floating-point number

c)

Integer numeric type

d)

String with formatting

148.

Which field indicates the organization affiliated with the administrator?

a)

Tech ID

b)

Admin State/Province

c)

Admin Street2

d)

Admin Organization

149.

What is a potential privacy risk when publishing 'Admin Email' in WHOIS records?

a)

Reduced postal accuracy

b)

Corrupted phone extensions

c)

Loss of DNS records

d)

Increased spam targeting

150.

Which role is associated with 'Tech Name: Jacob Eckel' in the record?

a)

Fax service provider

b)

Administrative city official

c)

Postal routing manager

d)

Technical contact person