Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Page 1

Total questions: 150

Worksheet time: 1hrs 15mins

Name
Class
Date
1.

Which statement best distinguishes ethical hackers from malicious hackers?

a)

They use similar tools but aim to identify and reduce risks

b)

They avoid using hacker tools to prevent legal issues

c)

They exploit weaknesses for personal gain and fame

d)

They only work on physical systems, not computer networks

2.

What is the primary purpose of penetration testing conducted by ethical hackers?

a)

To extract confidential data for testing backups

b)

To identify security risks so countermeasures can be applied

c)

To ensure hackers cannot access the Internet

d)

To replace existing security teams with automated tools

3.

According to the material, what misconception about hackers is highlighted?

a)

Hackers focus on hardware faults rather than software

b)

Hackers instantly obtain passwords by typing a few commands

c)

Hackers only attack when paid by companies

d)

Hackers are mostly unskilled but numerous

4.

Why should security professionals learn the same tools used by hackers?

a)

To legally attack competitors for market advantage

b)

To understand and defend against malicious techniques

c)

To remove the need for network monitoring teams

d)

To simplify software development lifecycles

5.

What is the initial goal of the first chapter described in the material?

a)

To mandate legal procedures for cybercrime prosecution

b)

To introduce the world of hackers and define terminology

c)

To provide in-depth exploit code for attacks

d)

To teach cryptography proofs in mathematics

6.

What best describes the realm of hackers and how they operate, as perceived by most professionals?

a)

Only relevant to outdated legacy systems

b)

Defined entirely by physical security practices

c)

Well documented and widely understood by everyone

d)

Unknown to most computer and security professionals

7.

Which term is commonly used as a shortened name for penetration testing?

a)

Pen testing

b)

Risk scanning

c)

Threat mapping

d)

Code auditing

8.

What ethical stance is emphasized for those guided through the hacking process in the book?

a)

Act as a good guy focusing on defense

b)

Exploit systems first to learn faster

c)

Prioritize speed over safety in assessments

d)

Ignore legal considerations while testing

9.

Which activity is incorrectly associated with ethical hacking in the material?

a)

Learning attacker techniques to build defenses

b)

Using tools to find vulnerabilities in networks

c)

Conducting assessments to mitigate identified risks

d)

Hacking for profit by selling stolen credentials

10.

What outcome is expected after identifying risks and vulnerabilities during a pen test?

a)

The network is shut down to prevent future attacks

b)

All user data is anonymized for compliance only

c)

The system is left unchanged to observe attackers

d)

A countermeasure is implemented to reduce the risk

11.

Which action best differentiates an ethical hacker from a malicious hacker during a penetration test?

a)

Operating without explicit client permission

b)

Gaining prior authorization from data owners

c)

Exploiting systems for personal financial gain

d)

Avoiding documentation to remain stealthy

12.

What is the primary goal of using the same tools as malicious hackers in ethical hacking?

a)

Create zero-day exploits for higher bounties

b)

Bypass enterprise monitoring permanently

c)

Identify weaknesses to apply fixes or patches

d)

Demonstrate tool superiority to clients

13.

Which legal consideration is emphasized for ethical hackers before using hacking techniques?

a)

Encrypting all traffic with proprietary algorithms

b)

Only following the client company policy document

c)

Complying with state, national, and international laws

d)

Consulting social media for jurisdictional advice

14.

Why must ethical hackers act in a professional manner during penetration tests?

a)

To ensure tests are undetectable by defenders

b)

To reduce tool licensing costs for the project

c)

To guarantee zero vulnerabilities are reported

d)

To gain client trust and avoid harming systems

15.

Which statement best describes the ongoing nature of ethical hacking work?

a)

It repeats only when attackers change motivation

b)

It ends once the first vulnerability is discovered

c)

It continues as new weaknesses and patches emerge

d)

It pauses until regulators certify each fix

16.

Which role most commonly performs ethical hacking according to the passage?

a)

Product managers coordinating releases

b)

Finance auditors with data analytics skills

c)

Security professionals or penetration testers

d)

Help desk technicians with basic scripting

17.

Which step comes immediately after discovering a security weakness in ethical hacking practice?

a)

Erase evidence to preserve confidentiality

b)

Apply or recommend the necessary mitigation

c)

Notify attackers of the new opportunity

d)

Sell the exploit to software vendors

18.

What permission is highlighted as critical before accessing a computer system for testing?

a)

Implicit consent from network users

b)

Verbal agreement with system admins

c)

Written approval from data owners

d)

Assumed approval after contract signing

19.

Which phrase best captures the purpose of ethical hacking as described?

a)

Collecting data for competitive advantage

b)

Disrupting services to measure resilience

c)

Strengthening security by proactive testing

d)

Compromising systems to showcase skill

20.

Which misconception is directly addressed when the author says, “That’s an oxymoron”?

a)

Hacking only targets small business networks

b)

Hacking tools are obsolete in enterprises

c)

Hacking requires advanced mathematics

d)

Hacking can never be lawful or ethical

21.

Which term describes a hacker who uses skills for destructive purposes such as spreading malware or launching DoS attacks?

a)

Security administrator role

b)

Penetration tester only

c)

White‑hat ethical hacker

d)

Cracker or malicious hacker

22.

What primary goal distinguishes a white‑hat hacker from a black‑hat hacker?

a)

Defending systems with permission

b)

Earning bounties without consent

c)

Destroying data for notoriety

d)

Evading detection at all times

23.

Which action is critical before any ethical hacking activity?

a)

Collecting password dumps

b)

Running automated exploits

c)

Using anonymous networks

d)

Obtaining explicit authorization

24.

Black‑hat hackers are best characterized by which behavior?

a)

Auditing configurations routinely

b)

Violating system integrity with intent

c)

Reporting vulnerabilities responsibly

d)

Testing defenses under contract

25.

Gray‑hat hackers are most accurately described as individuals who

a)

Never cause policy violations

b)

May act ethically or not, situationally

c)

Are defensive analysts only

d)

Always operate with written consent

26.

Which outcome is commonly associated with black‑hat intrusions after gaining access?

a)

Training staff on procedures

b)

Hardening systems and patching

c)

Documenting risks for stakeholders

d)

Destroying data and denying service

27.

Why are white‑hat hackers prime candidates for security certification exams?

a)

They work without formal rules

b)

They know tools and countermeasures

c)

They avoid learning exploit chains

d)

They focus on social popularity

28.

In professional terminology, another name for a cracker is a

a)

Malicious hacker

b)

Network auditor

c)

Bug bounty tester

d)

Blue team leader

29.

Which practice most clearly violates ethical hacking principles?

a)

Exploiting a flaw without consent

b)

Coordinated vulnerability disclosure

c)

Writing a risk assessment report

d)

Running tests in a lab sandbox

30.

A former gray‑hat becomes a security professional and now uses skills ethically. Which hat category do they fit?

a)

Black hat category now

b)

Remain gray hat only

c)

Unclassifiable category

d)

White hat category now

31.

Which statement best characterizes gray-hat hackers?

a)

They explore systems without intent to harm

b)

They never disclose security weaknesses publicly

c)

They only perform work with prior permission

d)

They always act maliciously for personal gain

32.

What primarily differentiates white hats from gray hats in terms of ethics?

a)

Use of social engineering techniques

b)

Explicit permission before testing systems

c)

Access to advanced zero-day exploits

d)

Technical skill level and certifications

33.

Why might some people view certain gray-hat actions as a 'courtesy'?

a)

They replace vulnerable hardware for free

b)

They break in and then explain how to fix holes

c)

They donate funds to secure infrastructure

d)

They inform law enforcement before testing

34.

Which scenario exemplifies gray-hat behavior described in the material?

a)

Deploying ransomware to force security upgrades

b)

Finding a flaw and notifying the bank to fix it

c)

Exploiting a bank service and selling data

d)

Pen-testing a client network under contract

35.

What legal risk do unsolicited security audits (tiger team) pose for gray hats?

a)

They could breach non-disclosure agreements

b)

They can be sued for patent infringement

c)

They may face charges for unauthorized access

d)

They risk violating export encryption laws

36.

Why do many companies respond negatively to self-proclaimed ethical hackers offering fixes 'for a price'?

a)

It breaches mandatory union rules for consultants

b)

It implies ownership transfer of sensitive data

c)

It resembles extortion after unauthorized access

d)

It violates environmental compliance standards

37.

From a curiosity standpoint, what motivates some gray hats?

a)

Interest in tools rather than causing damage

b)

Profit from selling stolen credentials

c)

Desire to publish exploit code for fame

d)

Goal of shutting down competitor networks

38.

What consequence transforms a gray hat’s good intentions into unethical behavior?

a)

Refusing to accept payment for work

b)

Lacking the correct permission to test

c)

Disclosing bugs to vendors immediately

d)

Using open-source tools for scanning

39.

How might victims perceive unsolicited vulnerability reports from gray hats?

a)

As helpful guidance with clear liability waivers

b)

As routine maintenance approved by policy

c)

As guaranteed compliance evidence for audits

d)

As potential legal issues requiring police action

40.

Which balanced interpretation reflects the debate around gray-hat hacking?

a)

It is harmless entertainment without impact

b)

It can be helpful yet legally problematic

c)

It is ethical only when data is destroyed

d)

It is always purely criminal activity

41.

Which term refers to testing the security of a system or network by simulating intruder actions?

a)

Red teaming, full spectrum

b)

Penetration test, or pen test

c)

Forensic incident analysis

d)

Security awareness program

42.

What primarily distinguishes an ethical hacker from a malicious hacker during a test?

a)

Use of completely different tools

b)

Authorization and reporting obligations

c)

Superior technical brilliance

d)

Working only on offline systems

43.

According to the passage, what is a common myth about hackers breaking into systems?

a)

It only happens through physical access

b)

It needs expensive proprietary tools

c)

It depends on social etiquette skills

d)

It requires a mysterious leap of brilliance

44.

What do ethical hackers commonly rely on to breach target systems during testing?

a)

Persistence and well-known tricks

b)

Pure hardware fault injection

c)

Quantum encryption attacks

d)

Random chance and luck

45.

When hired, what is one of the first things an ethical hacker asks an organization?

a)

What needs protection and from whom

b)

If backups can be ignored

c)

Which brand of laptop to use

d)

Whether to skip log collection

46.

What is the main purpose of a pen test report?

a)

Compile potential risks and findings

b)

Market the tester's services

c)

Replace the organization’s policies

d)

Provide user training materials

47.

Which activity is critical for presenting findings in a pen test report?

a)

Encrypting all endpoint drives

b)

Taking screenshots or saving logs

c)

Erasing temporary tool traces

d)

Disabling antivirus permanently

48.

Which of the following lists the four basic elements of security mentioned?

a)

Confidentiality, Authenticity, Integrity, Availability

b)

Confidentiality, Accountability, Integrity, Auditability

c)

Privacy, Authenticity, Integrity, Resilience

d)

Secrecy, Attribution, Accuracy, Redundancy

49.

In practice, how does a pen test typically proceed?

a)

Using the same tools as attackers

b)

Bypassing documentation entirely

c)

Only testing physical perimeters

d)

Inventing new zero-day exploits

50.

Why is building a penetration test plan useful for an organization?

a)

To satisfy vendor hardware quotas

b)

To align tests with data and risks

c)

To eliminate patch management

d)

To avoid any need for evidence

51.

Which security element is the primary target in a denial-of-service (DoS) attack?

a)

Authentication of connected devices

b)

Availability of systems and networks

c)

Integrity of stored information

d)

Confidentiality of user credentials

52.

The main purpose of a DoS attack is to

a)

Exhaust system resources or bandwidth

b)

Alter cipher text to change meaning

c)

Steal password hashes in transit

d)

Bypass MAC filtering on routers

53.

Information theft of data traveling in cleartext across trusted networks primarily compromises

a)

Confidentiality of communications

b)

Availability of network services

c)

Non-repudiation of messages

d)

Integrity of stored backups

54.

Why are bit-flipping attacks categorized as integrity attacks?

a)

They expose plaintext credentials during transit

b)

They impersonate devices to join the network

c)

They overwhelm services to deny access to users

d)

They tamper with cipher text causing predictable changes

55.

In a bit-flipping attack, the attacker’s action primarily involves

a)

Capturing cleartext traffic to read sensitive data

b)

Cloning a station’s MAC address to gain access

c)

Flooding a target with packets to consume bandwidth

d)

Modifying cipher text to alter the plain text predictably

56.

Applying a bit-flipping attack to digitally signed messages can enable an attacker to

a)

Recover the secret signing key from the signature

b)

Encrypt plaintext with a stronger cipher algorithm

c)

Change the meaning of a signed statement without detection

d)

Replay the same message to cause DoS conditions

57.

MAC address spoofing is best described as an attack on

a)

Availability of wireless spectrum resources

b)

Authentication mechanisms in network access

c)

Integrity of files stored on backup tapes

d)

Confidentiality of encrypted payload contents

58.

Which scenario most closely illustrates a confidentiality breach described?

a)

Passwords sent in cleartext across a trusted LAN

b)

A server crash from a UDP flood on port 80

c)

A changed cipher text altering a payment amount

d)

A rogue laptop cloning a MAC to join Wi‑Fi

59.

Which outcome is a realistic risk of DoS attacks highlighted in the material?

a)

Multiple victims beyond the target system controls

b)

Exposure of private keys used for signatures

c)

Unauthorized reading of encrypted messages

d)

Silent alteration of database tuples

60.

Why can MAC address spoofing defeat network controls like MAC filtering?

a)

It corrupts ARP tables to erase device entries

b)

It decrypts traffic to reveal access credentials

c)

It forces routers to drop all unauthorized traffic

d)

It allows an intruder to assume a legitimate station’s identity

61.

Which quality is emphasized as essential for ethical hackers due to the long payoff time of many attacks?

a)

Creativity and improvisation only

b)

Patience, persistence, perseverance

c)

Charisma and team motivation

d)

Rapid decision-making speed

62.

Why is in-depth knowledge of targeted platforms like Windows, Unix, and Linux important for ethical hackers?

a)

It guarantees faster incident response

b)

It improves general coding style

c)

It reduces hardware costs significantly

d)

It enables testing on relevant systems

63.

In some organizations, an ethical hacker may serve on a “tiger team.” What is the primary purpose of this team?

a)

Testing systems to find vulnerabilities

b)

Maintaining daily network operations

c)

Designing new security policies

d)

Training staff on basic computing

64.

Which skill set is listed as useful for performing ethical hacking and vulnerability testing?

a)

Office productivity software

b)

Web programming and databases

c)

Graphics design and UX

d)

Digital marketing analytics

65.

What does the term “threat” most accurately refer to in security analysis?

a)

A patched vulnerability on a host

b)

An environment or situation risking breach

c)

A user with minimal privileges

d)

A backup copy of critical data

66.

Which statement best distinguishes ethical hackers from malicious hackers, according to the terminology section?

a)

Malicious hackers pose threats using techniques

b)

Malicious hackers only test with permission

c)

Ethical hackers never write code

d)

Ethical hackers ignore vulnerabilities

67.

What is an exploit in the context of computer security?

a)

A defensive firewall configuration

b)

A software piece leveraging a vulnerability

c)

A compliance reporting template

d)

A user education program for phishing

68.

Why are many exploits implemented as small strings of code executed on a system?

a)

Small code avoids antivirus scanning

b)

Small code efficiently exposes vulnerabilities

c)

Small code simplifies user training

d)

Small code guarantees persistence

69.

Which misconception is addressed regarding the need to create exploits to be an ethical hacker?

a)

You must always develop custom malware

b)

You need advanced math for all tests

c)

You must avoid using any tools available

d)

You do not need to write exploits to practice

70.

Which scenario best illustrates prioritizing threats during a security analysis?

a)

Cataloging all patches released this year

b)

Focusing first on high-impact, likely risks

c)

Rebooting servers every maintenance window

d)

Writing a new policy draft for later

71.

Which term describes a defined method used to breach an IT system by targeting a vulnerability?

a)

Patch procedure for risk mitigation

b)

Exploit used to trigger a weakness

c)

Audit script for compliance checks

d)

Protocol enforcing secure defaults

72.

What best defines a vulnerability in the context of system security?

a)

A user policy for account access

b)

An intentional security backdoor

c)

A bug or design flaw enabling faults

d)

A normal reboot causing downtime

73.

What is the primary goal when ethical hackers test high‑value Targets of Evaluation (TOEs)?

a)

To encrypt all user files by default

b)

To replace legacy systems immediately

c)

To detect vulnerabilities and patch them

d)

To exfiltrate data for benchmarking

74.

In security terminology, what does TOE stand for?

a)

Test of Exploitation

b)

Target of Evaluation

c)

Threat Operations Engine

d)

Tool for Ethical testing

75.

Which statement best distinguishes a remote exploit from a local exploit?

a)

Remote changes hardware; local changes software

b)

Remote is internal; local is always external

c)

Remote is over a network; local requires access

d)

Remote needs prior access; local does not

76.

Which scenario exemplifies a remote attack?

a)

An employee uses an unlocked admin console

b)

A worm sends payloads across the internet

c)

A contractor installs a keylogger physically

d)

A technician boots from a USB on site

77.

Why are information security policies based on “need to know” and “least privilege” critical for preventing local exploits?

a)

They remove all software vulnerabilities

b)

They block all external traffic forever

c)

They minimize access an insider can abuse

d)

They guarantee perfect network isolation

78.

Which group most commonly perpetrates local attacks inside organizations?

a)

Random internet users

b)

Employees or trusted insiders

c)

Unaffiliated open‑source coders

d)

Third‑party ISPs abroad

79.

Ethical hackers use tools to locate systems vulnerable to exploits primarily to:

a)

Plan and perform data exfiltration

b)

Prevent attacks by remediation

c)

Sell discovered bugs to bidders

d)

Confuse attackers with honeypots

80.

Which misconception about hackers is corrected by the material?

a)

Most attacks are external remote hacks

b)

Most attacks always need zero‑days

c)

Most attacks are harmless pranks

d)

Most attacks are blocked by firewalls

81.

Which phase of ethical hacking focuses on gathering information about a target without their knowledge?

a)

Active reconnaissance activities

b)

Passive reconnaissance activities

c)

Privilege escalation activities

d)

Covering tracks activities

82.

In the five-phase model of hacking, which phase typically comes immediately after reconnaissance?

a)

Covering tracks phase

b)

Gaining access phase

c)

Scanning phase

d)

Maintaining access phase

83.

What is the primary goal of the scanning phase in the hacking process?

a)

Establish persistence mechanisms

b)

Collect legal disclosures

c)

Probe systems to find openings

d)

Hide evidence of prior activities

84.

Which phase involves obtaining entry into the target system after identifying vulnerabilities?

a)

Gaining access phase

b)

Reconnaissance phase

c)

Covering tracks phase

d)

Maintaining access phase

85.

Maintaining access most directly aims to achieve which outcome?

a)

Immediate data exfiltration only

b)

One-time password compromise

c)

Complete log erasure first

d)

Long-term foothold in systems

86.

Covering tracks commonly includes which type of action?

a)

Deleting or altering logs

b)

Adding new administrator users

c)

Patching all discovered flaws

d)

Running exhaustive port scans

87.

Why do ethical hackers follow a process similar to malicious hackers when testing security?

a)

To reduce system performance overhead

b)

To realistically assess vulnerabilities

c)

To benchmark user interface design

d)

To perfectly imitate malware behavior

88.

Which statement best differentiates passive from active reconnaissance?

a)

Passive uses phishing emails; active collects OSINT only

b)

Passive uses external data sources; active interacts directly

c)

Passive requires vulnerability scans; active uses public records

d)

Passive changes target settings; active avoids any contact

89.

According to the five phases shown in the figure, which is the correct order for the last two phases?

a)

Gaining access then reconnaissance

b)

Scanning then covering tracks

c)

Maintaining access then covering tracks

d)

Covering tracks then maintaining access

90.

During an ethical assessment, what is the most appropriate reason to limit information disclosure based on “need to know”?

a)

It ensures perfect anonymity online

b)

It prevents all phishing attempts

c)

It accelerates vulnerability scanning

d)

It minimizes privilege escalation risks

91.

Which statement best describes passive reconnaissance in ethical hacking?

a)

Probing hosts and services to elicit responses

b)

Exploiting vulnerabilities to gain system access

c)

Monitoring publicly available data without interaction

d)

Modifying packets to bypass security controls

92.

In the context of reconnaissance, information gathering using open Internet searches is considered

a)

Vulnerability exploitation phase

b)

Privilege escalation procedure

c)

Active intrusion testing technique

d)

Passive information-gathering activity

93.

Which practice is commonly cited as a passive information-gathering technique alongside social engineering?

a)

Port knocking on perimeter firewalls

b)

Dumpster diving for discarded records

c)

Running credential brute-force tools

d)

Crafting spear-phishing payloads

94.

Why is sniffing network traffic attractive to many ethical hackers at the beginning?

a)

It requires specialized hardware investments

b)

It guarantees undetectable access to hosts

c)

It reveals encrypted payloads by default

d)

It exposes visible flows and destinations of traffic

95.

Which risk is most associated with using sniffing tools on a network?

a)

They anonymize the operator’s machine

b)

They display only metadata but never content

c)

They may reveal usernames and passwords

d)

They inherently block suspicious connections

96.

Active reconnaissance differs from passive reconnaissance primarily because it

a)

Avoids touching target systems entirely

b)

Uses social networks to profile employees

c)

Probes hosts and services to elicit replies

d)

Relies only on physical surveillance methods

97.

The phrase rattling the doorknobs most closely refers to which activity?

a)

Hijacking established TCP sessions

b)

Bypassing multi-factor authentication flows

c)

Lightly probing network services for responses

d)

Encrypting stolen data before exfiltration

98.

Why does active reconnaissance increase the chance of detection compared to passive reconnaissance?

a)

It cannot be linked to operator identifiers

b)

It exclusively uses out-of-band data sources

c)

It always requires insider credentials

d)

It generates traffic traceable to the scanning system

99.

A realistic security concern when administrators first use sniffing tools is that they

a)

Learn that encryption makes monitoring impossible

b)

Find that all passwords are always hashed in transit

c)

Confirm that hidden networks never leak any data

d)

Realize how much sensitive data traverses in cleartext

100.

Both passive and active reconnaissance can ultimately lead to the discovery of

a)

Valuable details about systems and services

b)

Network segmentation diagrams only

c)

Unrelated marketing analytics data

d)

User interface design patterns only

101.

During the scanning phase of an ethical hacking engagement, the primary purpose of using tools like port scanners and network mappers is to

a)

install software on the target hosts remotely

b)

conceal the attacker’s presence within systems

c)

examine the network using gathered reconnaissance data

d)

exploit discovered vulnerabilities immediately

102.

Which tool category is most directly used to identify open communication endpoints on a host during scanning?

a)

ICMP scanners

b)

Vulnerability scanners

c)

Dialers

d)

Port scanners

103.

ICMP scanners and ping sweeps are primarily used to

a)

perform denial-of-service pretests

b)

capture credentials from unencrypted sessions

c)

map application dependencies across servers

d)

discover live hosts and basic reachability

104.

Simple Network Management Protocol (SNMP) sweepers are used in scanning mainly to

a)

perform stack-based buffer overflow tests

b)

brute-force SSH passwords on routers

c)

enumerate network devices and basic details

d)

inject configuration changes into switches

105.

Which item is typically a target of information gathering during scanning?

a)

Database table schemas

b)

User accounts on systems

c)

Encryption keys in memory

d)

Firmware source code

106.

In the overall process, scanning follows reconnaissance because it

a)

needs prior information to focus the examination

b)

immediately exploits weaknesses without context

c)

requires physical access before network checks

d)

replaces all recon steps with automated probes

107.

Which statement best describes the transition from scanning to gaining access?

a)

Gaining access uses exposed weaknesses to penetrate

b)

Scanning fixes vulnerabilities before exploitation

c)

Gaining access only occurs on offline systems

d)

Reconnaissance replaces scanning in later stages

108.

A hacking attack during the gaining access phase can be delivered via

a)

only the public Internet connection

b)

either LAN, wireless, or local access paths

c)

exclusively mobile cellular networks

d)

air-gapped systems without any contact

109.

Which example aligns with the gaining access phase rather than scanning?

a)

Mapping hosts with a network mapper

b)

Launching a stack-based buffer overflow

c)

Running a ping sweep across subnets

d)

Identifying OS versions with banners

110.

Session hijacking in this context most appropriately fits as

a)

an exploitation technique in gaining access

b)

a scanning method to list active sessions

c)

a post-exploitation data exfiltration stage

d)

a defensive countermeasure for networks

111.

In the context of hacking phases, what is the primary goal of maintaining access after initial compromise?

a)

To immediately exfiltrate every available dataset

b)

To notify administrators of the intrusion for forensics

c)

To patch the system against all vulnerabilities

d)

To keep control for future exploitation and attacks

112.

When hackers harden a compromised system to secure their exclusive access, which technique aligns with this behavior?

a)

Isolating the host from every network segment

b)

Upgrading the operating system and firmware

c)

Disabling all user accounts and backups

d)

Installing backdoors, rootkits, and Trojans

113.

A system that has been owned by a hacker and used to launch further attacks is often referred to as what?

a)

Honeypot host

b)

Air-gapped server

c)

Beacon node

d)

Zombie system

114.

Which action best represents the covering tracks phase of an intrusion?

a)

Brute-forcing remote desktop passwords

b)

Escalating privileges to kernel level

c)

Scanning subnets for open ports

d)

Removing log evidence to avoid detection

115.

Which example is specifically cited as a method to conceal activity during covering tracks?

a)

Encrypting disks using full-disk encryption

b)

Compressing logs with archival utilities

c)

Hashing data with SHA-256 digests

d)

Steganography to hide data within files

116.

What is the common purpose of using tunneling protocols in the post-compromise phase?

a)

To replace the need for encryption entirely

b)

To permanently disable intrusion detection

c)

To speed up file transfers across networks

d)

To bypass detection by routing traffic covertly

117.

Trojan horses, backdoors, and rootkits are collectively categorized as what?

a)

Standard operating system services

b)

Forensic tools used by responders

c)

Patches for vulnerability mitigation

d)

Malware installed after exploitation

118.

Which statement best distinguishes buffer overflows and SQL injection in intrusion contexts?

a)

Both are methods to gain access, often against application servers

b)

Both are post-exploitation tools for persistence on endpoints

c)

Only SQL injection affects compiled binaries at runtime

d)

Only buffer overflows target databases through query strings

119.

Which artifact is most likely targeted for alteration to evade detection following an attack?

a)

Timezone configuration settings

b)

Wallpaper preferences for users

c)

Printer spooler default options

d)

System log files capturing events

120.

Which scenario most accurately illustrates the term owning a system in hacker terminology?

a)

An attacker gains control and can use the system at will

b)

A phishing email is sent but no one clicks it

c)

A vulnerability is scanned but no exploit is executed

d)

A temporary DoS prevents users from logging in

121.

Most hacking tools exploit weaknesses in which four general areas listed here?

a)

Operating systems, applications, shrink-wrap code, misconfigurations

b)

Hardware drivers, databases, cloud services, encryption keys

c)

Firewalls, antivirus, user training, mobile devices

d)

Authentication, authorization, accounting, auditing

122.

Why can default operating system settings create security risks?

a)

They may remain unpatched and expose vulnerabilities

b)

They always disable network connectivity by design

c)

They require purchasing third-party security tools

d)

They enforce complex passwords for all users

123.

A primary reason applications contain exploitable vulnerabilities is that development is often

a)

Compliance-led with slow release cycles

b)

Feature-driven under tight deadlines

c)

Security-driven with extended testing

d)

Regression-focused with no new features

124.

Shrink-wrap code can be risky because off-the-shelf programs may

a)

Remove all macros by default

b)

Prohibit internal scripting entirely

c)

Include features users are unaware of

d)

Run only in isolated sandboxes

125.

Which example illustrates shrink-wrap code being exploited?

a)

Firmware updates disabling debug ports

b)

Encrypted backups stored offsite securely

c)

Macros in Microsoft Word executing programs

d)

Two-factor authentication on VPNs enabled

126.

Misconfigurations increase risk primarily by

a)

Rewriting core operating system kernels

b)

Eliminating all user permissions entirely

c)

Blocking patch installation permanently

d)

Leaving systems at lowest security settings

127.

In an initial client discussion, an ethical hacker should ask about

a)

Preferred laptop brand for the assessment team

b)

Marketing campaigns scheduled next quarter

c)

Exact employee salaries for payroll audits

d)

Specific areas like wireless or social engineering

128.

The purpose of customizing a penetration test based on client concerns is to

a)

Guarantee zero false positives always

b)

Reduce the scope to save time only

c)

Align tests to the client's needs

d)

Avoid testing multiple attack vectors

129.

Remote network hacking in a penetration test primarily simulates

a)

A vendor replacing network hardware

b)

A user upgrading software offline

c)

A developer fixing code defects locally

d)

An intruder attacking over the Internet

130.

Security audits should generally attempt to access data from

a)

Only cloud-hosted applications

b)

Only external perimeter networks

c)

All common entry methods listed

d)

Only physical on-site systems

131.

Which statement best describes a remote dial-up network attack in penetration testing?

a)

Simulates repeated dialing to find open modems

b)

Simulates phishing staff for login secrets

c)

Simulates brute forcing wireless passphrases

d)

Simulates scanning firewalls for open ports

132.

What is war dialing primarily used for in security assessments?

a)

Locating open modem lines for intrusion

b)

Sniffing wireless frames for credentials

c)

Harvesting emails through social media

d)

Bypassing physical locks on server rooms

133.

In a local area network (LAN) hack simulation, what prerequisite is typically required?

a)

Physical theft of an executive laptop

b)

Zero-touch exploitation over Internet

c)

Administrator access to cloud apps

d)

Direct access to the internal network

134.

Why have wireless LANs increased the risk surface for organizations?

a)

Users never change default SSIDs anymore

b)

Cables are more expensive than radios

c)

Switches now replace all routers entirely

d)

Radio signals propagate beyond buildings

135.

Which scenario illustrates a WLAN attack advantage over wired LANs?

a)

Attacker must badge into secure server room

b)

Attacker needs to splice into copper wiring

c)

Attacker relies on satellite link outages

d)

Attacker captures traffic from outside premises

136.

What critical risk is associated with stolen equipment such as laptops?

a)

Guaranteed bypass of disk encryption

b)

Inability to join corporate Wi‑Fi networks

c)

Automatic deletion of all local files

d)

Exposure of stored credentials and settings

137.

Which action best mitigates a stolen laptop already joined to the security domain?

a)

Remotely locking the device out of the network

b)

Rebooting the domain controller every hour

c)

Disabling all wireless access points companywide

d)

Publishing the device serial on social media

138.

Which description fits social engineering in a security test?

a)

Exploiting buffer overflows in services

b)

Running automated scans against subnets

c)

Deploying malware via a USB autorun

d)

Using calls or conversations to elicit secrets

139.

A frequent social‑engineering scenario targets which role to extract confidential information?

a)

Facilities staff repairing HVAC units

b)

Help desk personnel answering support calls

c)

Data center movers transporting racks

d)

Finance auditors conducting quarterly reviews

140.

For a Grade 13 cybersecurity assessment, which misconception should be avoided regarding WLAN attacks?

a)

Believing attackers must gain physical building access

b)

Believing attackers may capture radio waves remotely

c)

Believing signals can be intercepted outside walls

d)

Believing growth of WLANs increases attack surface

141.

Which testing type simulates an external attacker with no prior knowledge of the target network?

a)

Black-box testing outside perimeter

b)

Purple-team testing with blue help

c)

White-box testing with admin access

d)

Gray-box testing with partial knowledge

142.

A key disadvantage of black-box testing is that it typically

a)

avoids reconnaissance entirely

b)

reveals all internal credentials

c)

requires more time and effort

d)

guarantees lowest overall cost

143.

Which advantage is most associated with black-box testing in ethical hacking?

a)

Uses complete network maps

b)

Fastest to execute overall

c)

Eliminates scanning activities

d)

Closest to real attacker behavior

144.

White-box testing primarily differs from black-box testing because the tester

a)

has complete internal knowledge

b)

works only from public data

c)

focuses solely on social tricks

d)

tests only physical access

145.

Why is white-box testing generally faster than black-box testing?

a)

It avoids any tool configurations

b)

It bypasses recon and scanning phases

c)

It uses larger test teams always

d)

It never needs attack execution

146.

Security audits often choose white-box testing mainly to

a)

replace all monitoring tools

b)

reduce added time and expense

c)

simulate an outside intruder

d)

ignore insider threat vectors

147.

Gray-box testing aims to evaluate the risks from

a)

purely physical breaches

b)

vendors without devices

c)

unknown internet bots

d)

insiders with partial access

148.

The purpose of gray-box testing is best described as assessing whether insider privileges can

a)

encrypt all server disks

b)

replace perimeter firewalls

c)

disable all endpoint logs

d)

be escalated to higher levels

149.

Which sequence best matches the phases black-box testers must spend significant time on?

a)

Privilege cleanup, asset disposal

b)

Patch testing, change approvals

c)

Reporting, budgeting, staffing

d)

Information gathering, reconnaissance, scanning

150.

Planting a rogue wireless access point after gaining physical access exemplifies a risk because it

a)

prevents any data exfiltration

b)

eliminates social engineering

c)

enables remote LAN access

d)

guarantees lawful monitoring