WorksheetsPage 1
Total questions: 150
Worksheet time: 1hrs 15mins
Which statement best distinguishes ethical hackers from malicious hackers?
They use similar tools but aim to identify and reduce risks
They avoid using hacker tools to prevent legal issues
They exploit weaknesses for personal gain and fame
They only work on physical systems, not computer networks
What is the primary purpose of penetration testing conducted by ethical hackers?
To extract confidential data for testing backups
To identify security risks so countermeasures can be applied
To ensure hackers cannot access the Internet
To replace existing security teams with automated tools
According to the material, what misconception about hackers is highlighted?
Hackers focus on hardware faults rather than software
Hackers instantly obtain passwords by typing a few commands
Hackers only attack when paid by companies
Hackers are mostly unskilled but numerous
Why should security professionals learn the same tools used by hackers?
To legally attack competitors for market advantage
To understand and defend against malicious techniques
To remove the need for network monitoring teams
To simplify software development lifecycles
What is the initial goal of the first chapter described in the material?
To mandate legal procedures for cybercrime prosecution
To introduce the world of hackers and define terminology
To provide in-depth exploit code for attacks
To teach cryptography proofs in mathematics
What best describes the realm of hackers and how they operate, as perceived by most professionals?
Only relevant to outdated legacy systems
Defined entirely by physical security practices
Well documented and widely understood by everyone
Unknown to most computer and security professionals
Which term is commonly used as a shortened name for penetration testing?
Pen testing
Risk scanning
Threat mapping
Code auditing
What ethical stance is emphasized for those guided through the hacking process in the book?
Act as a good guy focusing on defense
Exploit systems first to learn faster
Prioritize speed over safety in assessments
Ignore legal considerations while testing
Which activity is incorrectly associated with ethical hacking in the material?
Learning attacker techniques to build defenses
Using tools to find vulnerabilities in networks
Conducting assessments to mitigate identified risks
Hacking for profit by selling stolen credentials
What outcome is expected after identifying risks and vulnerabilities during a pen test?
The network is shut down to prevent future attacks
All user data is anonymized for compliance only
The system is left unchanged to observe attackers
A countermeasure is implemented to reduce the risk
Which action best differentiates an ethical hacker from a malicious hacker during a penetration test?
Operating without explicit client permission
Gaining prior authorization from data owners
Exploiting systems for personal financial gain
Avoiding documentation to remain stealthy
What is the primary goal of using the same tools as malicious hackers in ethical hacking?
Create zero-day exploits for higher bounties
Bypass enterprise monitoring permanently
Identify weaknesses to apply fixes or patches
Demonstrate tool superiority to clients
Which legal consideration is emphasized for ethical hackers before using hacking techniques?
Encrypting all traffic with proprietary algorithms
Only following the client company policy document
Complying with state, national, and international laws
Consulting social media for jurisdictional advice
Why must ethical hackers act in a professional manner during penetration tests?
To ensure tests are undetectable by defenders
To reduce tool licensing costs for the project
To guarantee zero vulnerabilities are reported
To gain client trust and avoid harming systems
Which statement best describes the ongoing nature of ethical hacking work?
It repeats only when attackers change motivation
It ends once the first vulnerability is discovered
It continues as new weaknesses and patches emerge
It pauses until regulators certify each fix
Which role most commonly performs ethical hacking according to the passage?
Product managers coordinating releases
Finance auditors with data analytics skills
Security professionals or penetration testers
Help desk technicians with basic scripting
Which step comes immediately after discovering a security weakness in ethical hacking practice?
Erase evidence to preserve confidentiality
Apply or recommend the necessary mitigation
Notify attackers of the new opportunity
Sell the exploit to software vendors
What permission is highlighted as critical before accessing a computer system for testing?
Implicit consent from network users
Verbal agreement with system admins
Written approval from data owners
Assumed approval after contract signing
Which phrase best captures the purpose of ethical hacking as described?
Collecting data for competitive advantage
Disrupting services to measure resilience
Strengthening security by proactive testing
Compromising systems to showcase skill
Which misconception is directly addressed when the author says, “That’s an oxymoron”?
Hacking only targets small business networks
Hacking tools are obsolete in enterprises
Hacking requires advanced mathematics
Hacking can never be lawful or ethical
Which term describes a hacker who uses skills for destructive purposes such as spreading malware or launching DoS attacks?
Security administrator role
Penetration tester only
White‑hat ethical hacker
Cracker or malicious hacker
What primary goal distinguishes a white‑hat hacker from a black‑hat hacker?
Defending systems with permission
Earning bounties without consent
Destroying data for notoriety
Evading detection at all times
Which action is critical before any ethical hacking activity?
Collecting password dumps
Running automated exploits
Using anonymous networks
Obtaining explicit authorization
Black‑hat hackers are best characterized by which behavior?
Auditing configurations routinely
Violating system integrity with intent
Reporting vulnerabilities responsibly
Testing defenses under contract
Gray‑hat hackers are most accurately described as individuals who
Never cause policy violations
May act ethically or not, situationally
Are defensive analysts only
Always operate with written consent
Which outcome is commonly associated with black‑hat intrusions after gaining access?
Training staff on procedures
Hardening systems and patching
Documenting risks for stakeholders
Destroying data and denying service
Why are white‑hat hackers prime candidates for security certification exams?
They work without formal rules
They know tools and countermeasures
They avoid learning exploit chains
They focus on social popularity
In professional terminology, another name for a cracker is a
Malicious hacker
Network auditor
Bug bounty tester
Blue team leader
Which practice most clearly violates ethical hacking principles?
Exploiting a flaw without consent
Coordinated vulnerability disclosure
Writing a risk assessment report
Running tests in a lab sandbox
A former gray‑hat becomes a security professional and now uses skills ethically. Which hat category do they fit?
Black hat category now
Remain gray hat only
Unclassifiable category
White hat category now
Which statement best characterizes gray-hat hackers?
They explore systems without intent to harm
They never disclose security weaknesses publicly
They only perform work with prior permission
They always act maliciously for personal gain
What primarily differentiates white hats from gray hats in terms of ethics?
Use of social engineering techniques
Explicit permission before testing systems
Access to advanced zero-day exploits
Technical skill level and certifications
Why might some people view certain gray-hat actions as a 'courtesy'?
They replace vulnerable hardware for free
They break in and then explain how to fix holes
They donate funds to secure infrastructure
They inform law enforcement before testing
Which scenario exemplifies gray-hat behavior described in the material?
Deploying ransomware to force security upgrades
Finding a flaw and notifying the bank to fix it
Exploiting a bank service and selling data
Pen-testing a client network under contract
What legal risk do unsolicited security audits (tiger team) pose for gray hats?
They could breach non-disclosure agreements
They can be sued for patent infringement
They may face charges for unauthorized access
They risk violating export encryption laws
Why do many companies respond negatively to self-proclaimed ethical hackers offering fixes 'for a price'?
It breaches mandatory union rules for consultants
It implies ownership transfer of sensitive data
It resembles extortion after unauthorized access
It violates environmental compliance standards
From a curiosity standpoint, what motivates some gray hats?
Interest in tools rather than causing damage
Profit from selling stolen credentials
Desire to publish exploit code for fame
Goal of shutting down competitor networks
What consequence transforms a gray hat’s good intentions into unethical behavior?
Refusing to accept payment for work
Lacking the correct permission to test
Disclosing bugs to vendors immediately
Using open-source tools for scanning
How might victims perceive unsolicited vulnerability reports from gray hats?
As helpful guidance with clear liability waivers
As routine maintenance approved by policy
As guaranteed compliance evidence for audits
As potential legal issues requiring police action
Which balanced interpretation reflects the debate around gray-hat hacking?
It is harmless entertainment without impact
It can be helpful yet legally problematic
It is ethical only when data is destroyed
It is always purely criminal activity
Which term refers to testing the security of a system or network by simulating intruder actions?
Red teaming, full spectrum
Penetration test, or pen test
Forensic incident analysis
Security awareness program
What primarily distinguishes an ethical hacker from a malicious hacker during a test?
Use of completely different tools
Authorization and reporting obligations
Superior technical brilliance
Working only on offline systems
According to the passage, what is a common myth about hackers breaking into systems?
It only happens through physical access
It needs expensive proprietary tools
It depends on social etiquette skills
It requires a mysterious leap of brilliance
What do ethical hackers commonly rely on to breach target systems during testing?
Persistence and well-known tricks
Pure hardware fault injection
Quantum encryption attacks
Random chance and luck
When hired, what is one of the first things an ethical hacker asks an organization?
What needs protection and from whom
If backups can be ignored
Which brand of laptop to use
Whether to skip log collection
What is the main purpose of a pen test report?
Compile potential risks and findings
Market the tester's services
Replace the organization’s policies
Provide user training materials
Which activity is critical for presenting findings in a pen test report?
Encrypting all endpoint drives
Taking screenshots or saving logs
Erasing temporary tool traces
Disabling antivirus permanently
Which of the following lists the four basic elements of security mentioned?
Confidentiality, Authenticity, Integrity, Availability
Confidentiality, Accountability, Integrity, Auditability
Privacy, Authenticity, Integrity, Resilience
Secrecy, Attribution, Accuracy, Redundancy
In practice, how does a pen test typically proceed?
Using the same tools as attackers
Bypassing documentation entirely
Only testing physical perimeters
Inventing new zero-day exploits
Why is building a penetration test plan useful for an organization?
To satisfy vendor hardware quotas
To align tests with data and risks
To eliminate patch management
To avoid any need for evidence
Which security element is the primary target in a denial-of-service (DoS) attack?
Authentication of connected devices
Availability of systems and networks
Integrity of stored information
Confidentiality of user credentials
The main purpose of a DoS attack is to
Exhaust system resources or bandwidth
Alter cipher text to change meaning
Steal password hashes in transit
Bypass MAC filtering on routers
Information theft of data traveling in cleartext across trusted networks primarily compromises
Confidentiality of communications
Availability of network services
Non-repudiation of messages
Integrity of stored backups
Why are bit-flipping attacks categorized as integrity attacks?
They expose plaintext credentials during transit
They impersonate devices to join the network
They overwhelm services to deny access to users
They tamper with cipher text causing predictable changes
In a bit-flipping attack, the attacker’s action primarily involves
Capturing cleartext traffic to read sensitive data
Cloning a station’s MAC address to gain access
Flooding a target with packets to consume bandwidth
Modifying cipher text to alter the plain text predictably
Applying a bit-flipping attack to digitally signed messages can enable an attacker to
Recover the secret signing key from the signature
Encrypt plaintext with a stronger cipher algorithm
Change the meaning of a signed statement without detection
Replay the same message to cause DoS conditions
MAC address spoofing is best described as an attack on
Availability of wireless spectrum resources
Authentication mechanisms in network access
Integrity of files stored on backup tapes
Confidentiality of encrypted payload contents
Which scenario most closely illustrates a confidentiality breach described?
Passwords sent in cleartext across a trusted LAN
A server crash from a UDP flood on port 80
A changed cipher text altering a payment amount
A rogue laptop cloning a MAC to join Wi‑Fi
Which outcome is a realistic risk of DoS attacks highlighted in the material?
Multiple victims beyond the target system controls
Exposure of private keys used for signatures
Unauthorized reading of encrypted messages
Silent alteration of database tuples
Why can MAC address spoofing defeat network controls like MAC filtering?
It corrupts ARP tables to erase device entries
It decrypts traffic to reveal access credentials
It forces routers to drop all unauthorized traffic
It allows an intruder to assume a legitimate station’s identity
Which quality is emphasized as essential for ethical hackers due to the long payoff time of many attacks?
Creativity and improvisation only
Patience, persistence, perseverance
Charisma and team motivation
Rapid decision-making speed
Why is in-depth knowledge of targeted platforms like Windows, Unix, and Linux important for ethical hackers?
It guarantees faster incident response
It improves general coding style
It reduces hardware costs significantly
It enables testing on relevant systems
In some organizations, an ethical hacker may serve on a “tiger team.” What is the primary purpose of this team?
Testing systems to find vulnerabilities
Maintaining daily network operations
Designing new security policies
Training staff on basic computing
Which skill set is listed as useful for performing ethical hacking and vulnerability testing?
Office productivity software
Web programming and databases
Graphics design and UX
Digital marketing analytics
What does the term “threat” most accurately refer to in security analysis?
A patched vulnerability on a host
An environment or situation risking breach
A user with minimal privileges
A backup copy of critical data
Which statement best distinguishes ethical hackers from malicious hackers, according to the terminology section?
Malicious hackers pose threats using techniques
Malicious hackers only test with permission
Ethical hackers never write code
Ethical hackers ignore vulnerabilities
What is an exploit in the context of computer security?
A defensive firewall configuration
A software piece leveraging a vulnerability
A compliance reporting template
A user education program for phishing
Why are many exploits implemented as small strings of code executed on a system?
Small code avoids antivirus scanning
Small code efficiently exposes vulnerabilities
Small code simplifies user training
Small code guarantees persistence
Which misconception is addressed regarding the need to create exploits to be an ethical hacker?
You must always develop custom malware
You need advanced math for all tests
You must avoid using any tools available
You do not need to write exploits to practice
Which scenario best illustrates prioritizing threats during a security analysis?
Cataloging all patches released this year
Focusing first on high-impact, likely risks
Rebooting servers every maintenance window
Writing a new policy draft for later
Which term describes a defined method used to breach an IT system by targeting a vulnerability?
Patch procedure for risk mitigation
Exploit used to trigger a weakness
Audit script for compliance checks
Protocol enforcing secure defaults
What best defines a vulnerability in the context of system security?
A user policy for account access
An intentional security backdoor
A bug or design flaw enabling faults
A normal reboot causing downtime
What is the primary goal when ethical hackers test high‑value Targets of Evaluation (TOEs)?
To encrypt all user files by default
To replace legacy systems immediately
To detect vulnerabilities and patch them
To exfiltrate data for benchmarking
In security terminology, what does TOE stand for?
Test of Exploitation
Target of Evaluation
Threat Operations Engine
Tool for Ethical testing
Which statement best distinguishes a remote exploit from a local exploit?
Remote changes hardware; local changes software
Remote is internal; local is always external
Remote is over a network; local requires access
Remote needs prior access; local does not
Which scenario exemplifies a remote attack?
An employee uses an unlocked admin console
A worm sends payloads across the internet
A contractor installs a keylogger physically
A technician boots from a USB on site
Why are information security policies based on “need to know” and “least privilege” critical for preventing local exploits?
They remove all software vulnerabilities
They block all external traffic forever
They minimize access an insider can abuse
They guarantee perfect network isolation
Which group most commonly perpetrates local attacks inside organizations?
Random internet users
Employees or trusted insiders
Unaffiliated open‑source coders
Third‑party ISPs abroad
Ethical hackers use tools to locate systems vulnerable to exploits primarily to:
Plan and perform data exfiltration
Prevent attacks by remediation
Sell discovered bugs to bidders
Confuse attackers with honeypots
Which misconception about hackers is corrected by the material?
Most attacks are external remote hacks
Most attacks always need zero‑days
Most attacks are harmless pranks
Most attacks are blocked by firewalls
Which phase of ethical hacking focuses on gathering information about a target without their knowledge?
Active reconnaissance activities
Passive reconnaissance activities
Privilege escalation activities
Covering tracks activities
In the five-phase model of hacking, which phase typically comes immediately after reconnaissance?
Covering tracks phase
Gaining access phase
Scanning phase
Maintaining access phase
What is the primary goal of the scanning phase in the hacking process?
Establish persistence mechanisms
Collect legal disclosures
Probe systems to find openings
Hide evidence of prior activities
Which phase involves obtaining entry into the target system after identifying vulnerabilities?
Gaining access phase
Reconnaissance phase
Covering tracks phase
Maintaining access phase
Maintaining access most directly aims to achieve which outcome?
Immediate data exfiltration only
One-time password compromise
Complete log erasure first
Long-term foothold in systems
Covering tracks commonly includes which type of action?
Deleting or altering logs
Adding new administrator users
Patching all discovered flaws
Running exhaustive port scans
Why do ethical hackers follow a process similar to malicious hackers when testing security?
To reduce system performance overhead
To realistically assess vulnerabilities
To benchmark user interface design
To perfectly imitate malware behavior
Which statement best differentiates passive from active reconnaissance?
Passive uses phishing emails; active collects OSINT only
Passive uses external data sources; active interacts directly
Passive requires vulnerability scans; active uses public records
Passive changes target settings; active avoids any contact
According to the five phases shown in the figure, which is the correct order for the last two phases?
Gaining access then reconnaissance
Scanning then covering tracks
Maintaining access then covering tracks
Covering tracks then maintaining access
During an ethical assessment, what is the most appropriate reason to limit information disclosure based on “need to know”?
It ensures perfect anonymity online
It prevents all phishing attempts
It accelerates vulnerability scanning
It minimizes privilege escalation risks
Which statement best describes passive reconnaissance in ethical hacking?
Probing hosts and services to elicit responses
Exploiting vulnerabilities to gain system access
Monitoring publicly available data without interaction
Modifying packets to bypass security controls
In the context of reconnaissance, information gathering using open Internet searches is considered
Vulnerability exploitation phase
Privilege escalation procedure
Active intrusion testing technique
Passive information-gathering activity
Which practice is commonly cited as a passive information-gathering technique alongside social engineering?
Port knocking on perimeter firewalls
Dumpster diving for discarded records
Running credential brute-force tools
Crafting spear-phishing payloads
Why is sniffing network traffic attractive to many ethical hackers at the beginning?
It requires specialized hardware investments
It guarantees undetectable access to hosts
It reveals encrypted payloads by default
It exposes visible flows and destinations of traffic
Which risk is most associated with using sniffing tools on a network?
They anonymize the operator’s machine
They display only metadata but never content
They may reveal usernames and passwords
They inherently block suspicious connections
Active reconnaissance differs from passive reconnaissance primarily because it
Avoids touching target systems entirely
Uses social networks to profile employees
Probes hosts and services to elicit replies
Relies only on physical surveillance methods
The phrase rattling the doorknobs most closely refers to which activity?
Hijacking established TCP sessions
Bypassing multi-factor authentication flows
Lightly probing network services for responses
Encrypting stolen data before exfiltration
Why does active reconnaissance increase the chance of detection compared to passive reconnaissance?
It cannot be linked to operator identifiers
It exclusively uses out-of-band data sources
It always requires insider credentials
It generates traffic traceable to the scanning system
A realistic security concern when administrators first use sniffing tools is that they
Learn that encryption makes monitoring impossible
Find that all passwords are always hashed in transit
Confirm that hidden networks never leak any data
Realize how much sensitive data traverses in cleartext
Both passive and active reconnaissance can ultimately lead to the discovery of
Valuable details about systems and services
Network segmentation diagrams only
Unrelated marketing analytics data
User interface design patterns only
During the scanning phase of an ethical hacking engagement, the primary purpose of using tools like port scanners and network mappers is to
install software on the target hosts remotely
conceal the attacker’s presence within systems
examine the network using gathered reconnaissance data
exploit discovered vulnerabilities immediately
Which tool category is most directly used to identify open communication endpoints on a host during scanning?
ICMP scanners
Vulnerability scanners
Dialers
Port scanners
ICMP scanners and ping sweeps are primarily used to
perform denial-of-service pretests
capture credentials from unencrypted sessions
map application dependencies across servers
discover live hosts and basic reachability
Simple Network Management Protocol (SNMP) sweepers are used in scanning mainly to
perform stack-based buffer overflow tests
brute-force SSH passwords on routers
enumerate network devices and basic details
inject configuration changes into switches
Which item is typically a target of information gathering during scanning?
Database table schemas
User accounts on systems
Encryption keys in memory
Firmware source code
In the overall process, scanning follows reconnaissance because it
needs prior information to focus the examination
immediately exploits weaknesses without context
requires physical access before network checks
replaces all recon steps with automated probes
Which statement best describes the transition from scanning to gaining access?
Gaining access uses exposed weaknesses to penetrate
Scanning fixes vulnerabilities before exploitation
Gaining access only occurs on offline systems
Reconnaissance replaces scanning in later stages
A hacking attack during the gaining access phase can be delivered via
only the public Internet connection
either LAN, wireless, or local access paths
exclusively mobile cellular networks
air-gapped systems without any contact
Which example aligns with the gaining access phase rather than scanning?
Mapping hosts with a network mapper
Launching a stack-based buffer overflow
Running a ping sweep across subnets
Identifying OS versions with banners
Session hijacking in this context most appropriately fits as
an exploitation technique in gaining access
a scanning method to list active sessions
a post-exploitation data exfiltration stage
a defensive countermeasure for networks
In the context of hacking phases, what is the primary goal of maintaining access after initial compromise?
To immediately exfiltrate every available dataset
To notify administrators of the intrusion for forensics
To patch the system against all vulnerabilities
To keep control for future exploitation and attacks
When hackers harden a compromised system to secure their exclusive access, which technique aligns with this behavior?
Isolating the host from every network segment
Upgrading the operating system and firmware
Disabling all user accounts and backups
Installing backdoors, rootkits, and Trojans
A system that has been owned by a hacker and used to launch further attacks is often referred to as what?
Honeypot host
Air-gapped server
Beacon node
Zombie system
Which action best represents the covering tracks phase of an intrusion?
Brute-forcing remote desktop passwords
Escalating privileges to kernel level
Scanning subnets for open ports
Removing log evidence to avoid detection
Which example is specifically cited as a method to conceal activity during covering tracks?
Encrypting disks using full-disk encryption
Compressing logs with archival utilities
Hashing data with SHA-256 digests
Steganography to hide data within files
What is the common purpose of using tunneling protocols in the post-compromise phase?
To replace the need for encryption entirely
To permanently disable intrusion detection
To speed up file transfers across networks
To bypass detection by routing traffic covertly
Trojan horses, backdoors, and rootkits are collectively categorized as what?
Standard operating system services
Forensic tools used by responders
Patches for vulnerability mitigation
Malware installed after exploitation
Which statement best distinguishes buffer overflows and SQL injection in intrusion contexts?
Both are methods to gain access, often against application servers
Both are post-exploitation tools for persistence on endpoints
Only SQL injection affects compiled binaries at runtime
Only buffer overflows target databases through query strings
Which artifact is most likely targeted for alteration to evade detection following an attack?
Timezone configuration settings
Wallpaper preferences for users
Printer spooler default options
System log files capturing events
Which scenario most accurately illustrates the term owning a system in hacker terminology?
An attacker gains control and can use the system at will
A phishing email is sent but no one clicks it
A vulnerability is scanned but no exploit is executed
A temporary DoS prevents users from logging in
Most hacking tools exploit weaknesses in which four general areas listed here?
Operating systems, applications, shrink-wrap code, misconfigurations
Hardware drivers, databases, cloud services, encryption keys
Firewalls, antivirus, user training, mobile devices
Authentication, authorization, accounting, auditing
Why can default operating system settings create security risks?
They may remain unpatched and expose vulnerabilities
They always disable network connectivity by design
They require purchasing third-party security tools
They enforce complex passwords for all users
A primary reason applications contain exploitable vulnerabilities is that development is often
Compliance-led with slow release cycles
Feature-driven under tight deadlines
Security-driven with extended testing
Regression-focused with no new features
Shrink-wrap code can be risky because off-the-shelf programs may
Remove all macros by default
Prohibit internal scripting entirely
Include features users are unaware of
Run only in isolated sandboxes
Which example illustrates shrink-wrap code being exploited?
Firmware updates disabling debug ports
Encrypted backups stored offsite securely
Macros in Microsoft Word executing programs
Two-factor authentication on VPNs enabled
Misconfigurations increase risk primarily by
Rewriting core operating system kernels
Eliminating all user permissions entirely
Blocking patch installation permanently
Leaving systems at lowest security settings
In an initial client discussion, an ethical hacker should ask about
Preferred laptop brand for the assessment team
Marketing campaigns scheduled next quarter
Exact employee salaries for payroll audits
Specific areas like wireless or social engineering
The purpose of customizing a penetration test based on client concerns is to
Guarantee zero false positives always
Reduce the scope to save time only
Align tests to the client's needs
Avoid testing multiple attack vectors
Remote network hacking in a penetration test primarily simulates
A vendor replacing network hardware
A user upgrading software offline
A developer fixing code defects locally
An intruder attacking over the Internet
Security audits should generally attempt to access data from
Only cloud-hosted applications
Only external perimeter networks
All common entry methods listed
Only physical on-site systems
Which statement best describes a remote dial-up network attack in penetration testing?
Simulates repeated dialing to find open modems
Simulates phishing staff for login secrets
Simulates brute forcing wireless passphrases
Simulates scanning firewalls for open ports
What is war dialing primarily used for in security assessments?
Locating open modem lines for intrusion
Sniffing wireless frames for credentials
Harvesting emails through social media
Bypassing physical locks on server rooms
In a local area network (LAN) hack simulation, what prerequisite is typically required?
Physical theft of an executive laptop
Zero-touch exploitation over Internet
Administrator access to cloud apps
Direct access to the internal network
Why have wireless LANs increased the risk surface for organizations?
Users never change default SSIDs anymore
Cables are more expensive than radios
Switches now replace all routers entirely
Radio signals propagate beyond buildings
Which scenario illustrates a WLAN attack advantage over wired LANs?
Attacker must badge into secure server room
Attacker needs to splice into copper wiring
Attacker relies on satellite link outages
Attacker captures traffic from outside premises
What critical risk is associated with stolen equipment such as laptops?
Guaranteed bypass of disk encryption
Inability to join corporate Wi‑Fi networks
Automatic deletion of all local files
Exposure of stored credentials and settings
Which action best mitigates a stolen laptop already joined to the security domain?
Remotely locking the device out of the network
Rebooting the domain controller every hour
Disabling all wireless access points companywide
Publishing the device serial on social media
Which description fits social engineering in a security test?
Exploiting buffer overflows in services
Running automated scans against subnets
Deploying malware via a USB autorun
Using calls or conversations to elicit secrets
A frequent social‑engineering scenario targets which role to extract confidential information?
Facilities staff repairing HVAC units
Help desk personnel answering support calls
Data center movers transporting racks
Finance auditors conducting quarterly reviews
For a Grade 13 cybersecurity assessment, which misconception should be avoided regarding WLAN attacks?
Believing attackers must gain physical building access
Believing attackers may capture radio waves remotely
Believing signals can be intercepted outside walls
Believing growth of WLANs increases attack surface
Which testing type simulates an external attacker with no prior knowledge of the target network?
Black-box testing outside perimeter
Purple-team testing with blue help
White-box testing with admin access
Gray-box testing with partial knowledge
A key disadvantage of black-box testing is that it typically
avoids reconnaissance entirely
reveals all internal credentials
requires more time and effort
guarantees lowest overall cost
Which advantage is most associated with black-box testing in ethical hacking?
Uses complete network maps
Fastest to execute overall
Eliminates scanning activities
Closest to real attacker behavior
White-box testing primarily differs from black-box testing because the tester
has complete internal knowledge
works only from public data
focuses solely on social tricks
tests only physical access
Why is white-box testing generally faster than black-box testing?
It avoids any tool configurations
It bypasses recon and scanning phases
It uses larger test teams always
It never needs attack execution
Security audits often choose white-box testing mainly to
replace all monitoring tools
reduce added time and expense
simulate an outside intruder
ignore insider threat vectors
Gray-box testing aims to evaluate the risks from
purely physical breaches
vendors without devices
unknown internet bots
insiders with partial access
The purpose of gray-box testing is best described as assessing whether insider privileges can
encrypt all server disks
replace perimeter firewalls
disable all endpoint logs
be escalated to higher levels
Which sequence best matches the phases black-box testers must spend significant time on?
Privilege cleanup, asset disposal
Patch testing, change approvals
Reporting, budgeting, staffing
Information gathering, reconnaissance, scanning
Planting a rogue wireless access point after gaining physical access exemplifies a risk because it
prevents any data exfiltration
eliminates social engineering
enables remote LAN access
guarantees lawful monitoring
