NEW
Font size
WorksheetsMock Test - Ethical Hacking
Total questions: 70
Worksheet time: 35mins
What is ethical hacking?
Unauthorized access to computer systems for financial gain
The authorized practice of bypassing system security to identify potential data breaches and threats
Creating malicious software to disrupt networks
Stealing sensitive information from organizations
Which Malaysian law covers unauthorized access to computer systems?
Communications and Multimedia Act 1998
Computer Crimes Act 1997
Personal Data Protection Act 2010
Malaysian Copyright Act
What does OSINT stand for?
Online Security Intelligence Testing
Offensive System Integrity Networking
Open-Source Intelligence
Operational Security Integration Network
During reconnaissance, what should ethical hackers prioritize first?
Active port scanning
Passive footprinting using public sources
Network exploitation
System compromise
Which of the following is a passive reconnaissance technique?
Ping sweep
Port scanning
Google dorking
Banner grabbing
What does WHOIS database provide?
Real-time network traffic information
Domain registration information and registrant details
Active malware signatures
Firewall configuration data
Which tool is used for automated email and subdomain enumeration?
Nmap
theHarvester
Masscan
Wireshark
What is a DNS zone transfer vulnerability?
Slow network response during DNS queries
Misconfigured DNS allowing complete zone file transfer without authentication
DNS cache poisoning attack
DNSSEC signature verification failure
What does WEP stand for in wireless networks?
Wired Equivalent Privacy
Wireless Encryption Protocol
Web Enhanced Protection
Windows Ethernet Protocol
Which wireless encryption standard is completely broken and should never be used?
WPA2
WPA3
WEP
802.1X
What is the primary goal of a denial-of-service (DoS) attack?
Steal sensitive data
Make network resources unavailable to legitimate users
Gain unauthorized access
Modify system files
What does DDoS stand for?
Direct Denial of Service
Distributed Denial of Service
Double Defense of Systems
Data Disruption of Services
Which TCP connection state indicates a service is running and accepting connections?
CLOSED
FILTERED
OPEN
LISTENING
What is the TCP three-way handshake?
SYN-SYN-ACK
SYN-SYN-ACK-ACK
ACK-ACK-ACK
SYN-ACK-FIN
Which Nmap scan type is the stealthiest and requires root privileges?
TCP Connect scan
SYN scan
UDP scan
ACK scan
What is ARP poisoning?
Adding poison to network packets
Sending forged ARP replies to corrupt target's ARP cache
DNS resolution failure
DHCP server misconfiguration
Which encryption algorithm is the current industry standard for symmetric encryption?
DES
3DES
AES
RC4
What is the primary purpose of hashing?
Encrypt data for confidentiality
Verify data integrity
Compress file size
Authenticate users
Which hash algorithm is broken and should not be used?
SHA-256
SHA-512
MD5
SHA-3
What does SQL injection exploit?
Network bandwidth limitations
Unsanitized user input in SQL queries
Firewall rules
Encryption algorithms
What is the primary difference between passive and active footprinting?
Passive is illegal; active is legal
Passive leaves no traces; active generates network traffic
Passive is slower than active
Active uses only public sources
Which OSINT tool provides visual relationship mapping and automated data gathering?
theHarvester
Maltego
Shodan
Netcraft
What is a DNS zone transfer (AXFR) attack's primary benefit to attackers?
Identify active DNS servers
Obtain complete list of subdomains and internal hostnames
Bypass firewall rules
Encrypt network traffic
Which of the following reveals hidden directories and sensitive files?
Passive DNS enumeration
Google dorking (advanced search operators)
Banner grabbing
MAC address filtering
What is the KRACK attack vulnerability in wireless networks?
Brute force attack on WPA-PSK
Key Reinstallation Attack exploiting WPA2 4-way handshake
Rogue access point creation
WEP IV exhaustion
How many bits does WPA2 use for encryption key derivation?
56 bits
104 bits
128 bits
256 bits
What is the first step in a typical penetration testing engagement?
Port scanning
Obtaining written authorization and defining scope
System exploitation
Report writing
Which enumeration technique specifically targets Windows NetBIOS names?
SNMP enumeration
NBTscan
NFS enumeration
LDAP enumeration
What information can be extracted from HTTP response headers?
Client IP addresses
Server type, version, and running applications
User passwords
Database connection strings
What is a NULL session in Windows systems?
A connection that is currently closed
An unauthenticated connection allowing information extraction
An encryption key with all zeros
A network adapter with no IP address
Which attack involves intercepting traffic between two parties without their knowledge?
DoS attack
Man-in-the-Middle (MitM) attack
Dictionary attack
SQL injection
What is ARP's fundamental security weakness?
It uses weak encryption
It lacks authentication mechanism for ARP replies
It doesn't support IPv6
It broadcasts on unnecessary ports
Which network sniffing technique works only on hub-based networks?
Active sniffing
Passive sniffing
Wireless sniffing
Protocol sniffing
What tool can be used for automated SQL injection detection and exploitation?
Nmap
Wireshark
SQLMap
theHarvester
Which OWASP Top 10 vulnerability allows attackers to inject malicious JavaScript?
SQL Injection
Cross-Site Scripting (XSS)
Broken Authentication
Sensitive Data Exposure
What is the primary advantage of WPA3 over WPA2?
Larger block size
Simultaneous Authentication of Equals (SAE) preventing offline dictionary attacks
Faster encryption speed
Support for 40-bit keys
Which file system allows multiple data streams to hide information?
FAT32
NTFS (New Technology File System)
ext4
HFS+
What is privilege escalation?
Increasing network bandwidth
Gaining higher-level permissions than originally granted
Expanding a database
Extending session timeout
What is the primary weakness of RSA encryption?
Small key size
Depends on difficulty of factoring large numbers (vulnerable to quantum computers)
Deterministic output
Weak key derivation
Which cryptographic attack uses pre-computed hash-to-password mappings?
Dictionary attack
Brute force attack
Rainbow table attack
Collision attack
What is a digital signature used for?
Encrypting sensitive data
Proving authenticity, integrity, and non-repudiation
Compressing files
Validating network packets
Which firewall type inspects application layer content?
Packet filtering firewall
Application layer / Proxy firewall
Stateful firewall
Hardware firewall
What is the purpose of a honeypot in network security?
Block malicious traffic
Attract and trap attackers to study their behavior
Encrypt network traffic
Authenticate users
Which IDS detection method is most vulnerable to zero-day exploits?
Anomaly-based detection
Signature-based detection
Behavioral detection
Heuristic detection
What does SIEM stand for?
System Integrity and Event Management
Security Information and Event Management
Secure Internal Email Monitoring
System Infection and Encryption Monitoring
Which organization maintains the OWASP Top 10?
NIST
OWASP (Open Web Application Security Project)
ISO
IEEE
What is the primary protection against SQL injection?
Using complex passwords
Using parameterized queries/prepared statements
Implementing a firewall
Enabling encryption
Which certificate authority validates the authenticity of SSL certificates?
Any organization
Trusted third-party CAs (Verisign, DigiCert, Let's Encrypt, etc.)
The website owner alone
Government agencies only
What is HSTS (HTTP Strict Transport Security)?
A firewall rule
An HTTP header that forces HTTPS connections
An encryption protocol
A password hashing algorithm
Which Malaysian law specifically protects personal data?
Computer Crimes Act 1997
Communications and Multimedia Act 1998
Personal Data Protection Act (PDPA) 2010
Copyright Act 1987
During a penetration test, you discover an unquoted service path vulnerability. Which privilege escalation scenario applies?
Service installed in C:\Program Files\Service\svc.exe (quoted) is vulnerable
Service path C:\Program Files\Dummy Service\svc.exe (unquoted) can be exploited by placing malicious executable in C:*
Only SYSTEM account services are vulnerable
The vulnerability only affects Windows 11
A client's wireless network uses WPA2-PSK with weak password. What attack sequence is most efficient?
Wardrive, identify AP, brute force without capture
Wardrive, de-authenticate client, capture handshake, offline dictionary attack
Flood AP with ARP packets indefinitely
Perform rainbow table lookup directly on WPA2
You capture a PMKID from an Association Request frame. Which advantage does this provide?
Full handshake is required for attack success
PMKID extraction enables faster offline cracking without full 4-way handshake
PMKID cannot be used for password recovery
PMKID is encrypted and impossible to extract
In a network sniffing scenario, the switch employs port isolation. Which technique bypasses this?
Passive sniffing on the switch port
Active sniffing using ARP poisoning or DHCP spoofing
Modifying MAC address filters
Increasing network bandwidth
You identify an application vulnerable to second-order SQL injection. What characteristic defines this?
SQL injection occurs in the first database query
Malicious payload is stored in the database and executed later
The attack requires two separate network connections
It only affects databases with version > 8.0
During DOM-based XSS testing, you identify vulnerable JavaScript code using innerHTML. Which payload type is most effective?
Server-side server-side template injection
Client-side JavaScript payload within DOM context
SQL commands embedded in the HTML
PHP code execution
A Web Application Firewall blocks your SQLi payload with SQL keywords. Which encoding bypass is most likely to succeed?
ROT-13 encoding of the entire query
Comment injection (e.g., uni//on sel//ect) if WAF doesn't handle comments
Hex encoding the protocol headers
Base64 encoding the entire HTTP request
In cryptographic attacks, the birthday attack requires approximately how many attempts to find a hash collision?
2^n (where n = hash bit size)
√(2^n) (square root of 2^n)
n^2
2^(n/2)
You discover a certificate signed with SHA-1 and issued in 2015. What vulnerability exists?
No vulnerability; SHA-1 was secure until 2020
SHA-1 collision attacks practical since 2017 (SHAttered); certificate must be replaced
SHA-1 can only sign documents up to 160 bits
The certificate is automatically revoked by all browsers
A Snort IDS rule uses regex to detect SQL injection. Which evasion technique might bypass it?
Increasing network packet size
Polymorphic payload encoding that produces different regex patterns per attempt
Using IPv6 instead of IPv4
Sending traffic through a VPN
During an HIDS evasion assessment, you use fileless malware techniques. What advantage do these provide?
They consume less disk space
They bypass file-system based detection while maintaining persistence
They automatically uninstall after execution
They require administrator privileges to detect
In a firewall bypass scenario, you use TCP source port 53 (DNS). Why might this succeed?
Port 53 is completely blocked by all firewalls
Port 53 is often allowed outbound for DNS, and firewall may trust it
Port 53 is the default SSH port
DNS port bypasses encryption
You test a certificate validation flaw in a mobile application. Which vulnerability allows MITM attacks despite HTTPS?
All certificates are self-signed
Certificate pinning not implemented; app accepts any valid certificate
TLS 1.0 is enforced
The application doesn't use HTTPS
During KRACK attack simulation against WPA2, what occurs when Message 3 is replayed?
The client ignores the replayed frame
Client reinstalls PTK with same nonce, enabling keystream recovery
The AP automatically upgrades to WPA3
The handshake is terminated immediately
In OAuth 2.0 security testing, you discover a misconfigured redirect_uri. What attack becomes possible?
DDoS attack on authorization server
Authorization code theft via attacker-controlled redirect endpoint
Certificate revocation
Encryption key extraction
You identify a vulnerable SUID binary (owned by root) with a buffer overflow. Why is this critical?
Only the owner can exploit buffer overflows
Any user executing the binary gains root privileges upon successful overflow
SUID binaries cannot be exploited
Buffer overflows only affect network services
During a wireless penetration test, you encounter WPA3 with SAE authentication. What fundamental change does SAE provide?
Larger encryption key size
Differential privacy property preventing offline dictionary attacks
No change from WPA2; just a name change
Mandatory 192-bit encryption for all networks
You discover an application using JWT with 'alg': 'none'. What vulnerability exists?
JWT cannot be used without an algorithm
Algorithm confusion allowing token forgery without signature verification
The application must use RS256 exclusively
No vulnerability; 'none' is secure
In a network penetration test, you identify stateless packet filtering on an access control list. Which bypass technique applies?
Fragmentation always bypasses stateless filters
Crafting return traffic with source port of allowed protocol (e.g., port 80) may bypass
Stateless filters cannot be bypassed
Only source IP spoofing works
You perform adversarial testing on an anomaly-based IDS with false positive rates of 15%. What real-world implication exists?
The IDS is more secure than signature-based IDS
Security team may disable alerts due to alert fatigue, reducing detection effectiveness
False positives prove the IDS is ineffective
15% false positives cannot occur in real networks
