CEH Preperation test

What does the -oX flag do in an Nmap scan?


What would you enter, if you wanted to perform a stealth scan using Nmap?


The Payment Card Industry Data Security Standard (PCI DSS) contains six different categories of control bjectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance.Which of the following requirements would best fit under the objective, “Implement strong access control measures”?


You are a security officer of a company. You had an alert from IDS that indicates that one PC on your Intranet is connected to a blacklisted IP address (C2 Server) on the Internet. The IP address was blacklisted just before the alert. You are staring an investigation to roughly analyze the severity of the situation. Which of the following is appropriate to analyze?


Log monitoring tools performing behavioral analysis have alerted several suspicious logins on a Linux server occurring during non-business hours. After further examination of all login activities, it is noticed that none of the logins have occurred during typical work hours. A Linux administrator who is investigating this problem realizes the system time on the Linux server is wrong by more than twelve hours. What protocol used on Linux servers to synchronize the time has stopped working?


Chandler works as a pen-tester in an IT-firm in New York. As a part of detecting viruses in the systems, he uses a detection method where the anti-virus executes the malicious codes on a virtual machine to simulate CPU and memory activities. Which type of virus detection method did Chandler use in this context?


Which of the following cryptography attack is an understatement for the extraction of cryptographic secrets (e.g. the password to an encrypted file) from a person by a coercion or torture?


Which of the following antennas is commonly used in communications for a frequency band MHz to VHF and UHF?


Vlady works in a fishing company where the majority of the employees have very little understanding of IT let alone IT Security. Several information security issues that Vlady often found includes, employees sharing password, writing his/her password on a post it note and stick it to his/her desk, leaving the computer unlocked, didn’t log out from emails or other social media accounts, and etc. After discussing with his boss, Vlady decided to make some changes to improve the security environment in his company. The first thing that Vlady wanted to do is to make the employees understand the importance of keeping confidential information, such as password, a secret and they should not share it with other persons. Which of the following steps should be the first thing that Vlady should do to make the employees in his company understand to importance of keeping confidential information a secret?


Which of the below hashing functions are not recommended for use?


If an attacker uses the command SELECT*FROM user WHERE name = `x’ AND userid IS NULL; –`; which type of SQL injection attack is the attacker performing?


Security Policy is a definition of what it means to be secure for a system, organization or other entity. For Information Technologies, there are sub-policies like Computer Security Policy, Information Protection Policy, Information Security Policy, network Security Policy, Physical Security Policy, Remote Access Policy, and User Account Policy. What is the main theme of the sub-policies for Information Technologies?


You perform a scan of your company’s network and discover that TCP port 123 is open. What services by default run on TCP port 123?


Steve, a scientist who works in a governmental security agency, developed a technological solution to identify people based on walking patterns and implemented this approach to a physical control access. A camera captures people walking and identifies the individuals using Steve’s approach. After that, people must approximate their RFID badges. Both the identifications are required to open the door. In this case, we can say:


Assume a business-crucial web-site of some company that is used to sell handsets to the customers worldwide. All the developed components are reviewed by the security team on a monthly basis. In order to drive business further, the website developers decided to add some 3rd party marketing tools on it. The tools are written in JavaScript and can track the customer’s activity on the site. These tools are located on the servers of the marketing company. What is the main security risk associated with this scenario?


Which of the following is considered as one of the most reliable forms of TCP scanning?


Which of the following act requires employer’s standard national numbers to identify them on standard transactions?


Code injection is a form of attack in which a malicious user:


Based on the below log, which of the following sentences are true? Mar 1, 2016, 7:33:28 AM 54373 22 tcp_ip


Darius is analysing IDS logs. During the investigation, he noticed that there was nothing suspicious found and an alert was triggered on normal web application traffic. He can mark this alert as:


On performing a risk assessment, you need to determine the potential impacts when some of the critical business process of the company interrupt its service. What is the name of the process by which you can determine those critical business?


Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet?


Which component of IPsec performs protocol-level functions that are required to encrypt and decrypt the packets?


Which of the following attacks exploits web age vulnerabilities that allow an attacker to force an unsuspecting user’s browser to send malicious requests they did not intend?


Which of the following DoS tools is used to attack target web applications by starvation of available sessions on the web server? The tool keeps sessions at halt using never-ending POST transmissions and sending an arbitrarily large content-length header value.


Which is the first step followed by Vulnerability Scanners for scanning a network?


You are attempting to run an Nmap port scan on a web server. Which of the following commands would result in a scan of common ports with the least amount of noise in order to evade IDS? – Pn p- 65535-T5 O T0 –host-timeout 99-T1


Some clients of TPNQM SA were redirected to a malicious site when they tried to access the TPNQM main site. Bob, a system administrator at TPNQM SA, found that they were victims of DNS Cache Poisoning. What should Bob recommend to deal with such a threat?


DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switches leverages the DHCP snooping database to help prevent man-in-the-middle attacks?


You are the Network Admin, and you get a compliant that some of the websites are no longer accessible. You try to ping the servers and find them to be reachable. Then you type the IP address and then you try on the browser, and find it to be accessible. But they are not accessible when you try using the URL. What may be the problem?


You are looking for SQL injection vulnerability by sending a special character to web applications. Which of the following is the most useful for quick validation?


The collection of potentially actionable, overt, and publicly available information is known as


Which of the following Secure Hashing Algorithm (SHA) produces a 160-bit digest from a message with a maximum length of (2640) bits and resembles the MD5 algorithm?


The security administrator of ABC needs to permit Internet traffic in the host and UDP traffic in the host He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access to the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happening in the network?


You are working as a Security Analyst in a company XYZ that owns the whole subnet range .0.0.0/8 and While monitoring the data, you find a high number of outbound connections. You see that IP’s owned by XYZ (Internal) and private IP’s are communicating to a Single Public IP. Therefore, the Internal IP’s are sending data to the Public IP. After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised. What kind of attack does the above scenario depict?


What is the main security service a cryptographic hash provides?


An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed?


Which protocol is used for setting up secure channels between two devices, typically in VPNs?


Which of the following provides a security professional with most information about the system’s security posture?


When a security analyst prepares for the formal security assessment – what of the following should be done in order to determine inconsistencies in the secure assets database and verify that system is compliant to the minimum security baseline?


Which of the following program infects the system boot sector and the executable files at the same time?


What is the minimum number of network connections in a multi homed firewall?


You are monitoring the network of your organizations. You notice that: Which of the following solution will you suggest?


From the following table, identify the wrong answer in terms of Range (ft).


Which of the following is the best countermeasure to encrypting ransomwares?


Sam is working as s pen-tester in an organization in Houston. He performs penetration testing on IDS in order to find the different ways an attacker uses to evade the IDS. Sam sends a large amount of packets to the target IDS that generates alerts, which enable Sam to hide the real traffic. What type of method is Sam using to evade IDS?


Which of the following steps for risk assessment methodology refers to vulnerability identification?


Nedved is an IT Security Manager of a bank in his country. One day. he found out that there is a security breach to his company’s email server based on analysis of a suspicious connection from the email server to an unknown IP Address. What is the first thing that Nedved needs to do before contacting the incident response team?


What type of analysis is performed when an attacker has partial knowledge of inner-workings of the application?


Trinity needs to scan all hosts on a /16 network for TCP port 445 only. What is the fastest way she can accomplish this with Nmap? Stealth is not a concern. -Pn


What is the least important information when you analyze a public IP address in a security alert?


A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer’s software and hardware without the owner’s permission. Their intention can either be to simply gain knowledge or to illegally make changes. Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?


Insecure direct object reference is a type of vulnerability where the application does not verify if the user is authorized to access the internal object via its name or key. Suppose a malicious user Rob tries to get access to the account of a benign user Ned. Which of the following requests best illustrates an attempt to exploit an insecure direct object reference vulnerability?


Identify the web application attack where the attackers exploit vulnerabilities in dynamically generated web pages to inject client-side script into web pages viewed by other users.


DNS cache snooping is a process of determining if the specified resource address is present in the DNS cache records. It may be useful during the examination of the network to determine what software update resources are used, thus discovering what software is installed. What command is used to determine if the entry is present in DNS cache? update.antivirus.com


What network security concept requires multiple layers of security controls to be placed throughout an IT infrastructure, which improves the security posture of an organization to defend against malicious attacks or potential vulnerabilities? What kind of Web application vulnerability likely exists in their software?


An attacker scans a host with the below command. Which three flags are set? (Choose three.) #nmap sX host.domain.com


When tuning security alerts, what is the best approach?


Firewalls are the software or hardware systems that are able to control and monitor the traffic coming in and out the target network based on pre-defined set of rules. Which of the following types of firewalls can protect against SQL injection attacks?


What is the purpose of a demilitarized zone on a network?


Which one of the following Google advanced search operators allows an attacker to restrict the results to those websites in the given domain?


Bob, your senior colleague, has sent you a mail regarding a deal with one of the clients. You are requested to accept the offer and you oblige. After 2 days. Bob denies that he had ever sent a mail. What do you want to “”know”” to prove yourself that it was Bob who had send a mail?


How is the public key distributed in an orderly, controlled fashion so that the users can be sure of the sender’s identity?


Alice encrypts her data using her public key PK and stores the encrypted data in the cloud. Which of the following attack scenarios will compromise the privacy of her data? resists Andrew’s attempt to access the stored data


Why containers are less secure that virtual machines?


What is one of the advantages of using both symmetric and asymmetric cryptography in SSL/TLS? negotiate keys for use with symmetric cryptography. encryption instead.


Developers at your company are creating a web application which will be available for use by anyone on the Internet, The developers have taken the approach of implementing a Three-Tier Architecture for the web application. The developers are now asking you which network should the Presentation Tier (front- end web server) be placed in?


Which of the following types of jailbreaking allows user-level access but does not allow iboot-level access?


An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections. When users accessed any page, the applet ran and exploited many machines. Which one of the following tools the hacker probably used to inject HTML code?


Email is transmitted across the Internet using the Simple Mail Transport Protocol. SMTP does not encrypt email, leaving the information in the message vulnerable to being read by an unauthorized person. SMTP can upgrade a connection between two mail servers to use TLS. Email transmitted by SMTP over TLS is encrypted. What is the name of the command used by SMTP to transmit email over TLS?


You need a tool that can do network intrusion prevention and intrusion detection, function as a network sniffer, and record network activity, what tool would you most likely select?


Why should the security analyst disable/remove unnecessary ISAPI filters?


You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement? internal network


A virus that attempts to install itself inside the file it is infecting is called?


In which of the following password protection technique, random strings of characters are added to the password before calculating their hashes?


The network team has well-established procedures to follow for creating new rules on the firewall. This includes having approval from a manager prior to implementing any new rules. While reviewing the firewall configuration, you notice a recently implemented rule but cannot locate manager approval for it. What would be a good step to have in the procedures for a situation like this? soon as possible.


Identify the UDP port that Network Time Protocol (NTP) uses as its primary means of communication?


Bob, a network administrator at BigUniversity, realized that some students are connecting their notebooks in the wired network to have Internet access. In the university campus, there are many Ethernet ports available for professors and authorized visitors but not for students. He identified this when the IDS alerted for malware activities in the network. What should Bob do to avoid this problem?


If you want only to scan fewer ports than the default scan using Nmap tool, which option would you use?


What does the option * indicate?


In the field of cryptanalysis, what is meant by a “rubber-hose” attack?


Which of the following is an adaptive SQL Injection testing technique used to discover coding errors by inputting massive amounts of random data and observing the changes in the output?


Company XYZ has asked you to assess the security of their perimeter email gateway. From your office in New York, you craft a specially formatted email message and send it across the Internet to an employee of Company XYZ. The employee of Company XYZ is aware of your test. Your email message looks like this: From: jim_miller@companyxyz.com To: michelle_saunders@companyxyz.com Subject: Test message Date: 4/3/2017 14:37 The employee of Company XYZ receives your email message. This proves that Company XYZ’s email gateway doesn’t prevent what?


A pen tester is configuring a Windows laptop for a test. In setting up Wireshark, what river and library are required to allow the NIC to work in promiscuous mode?


These hackers have limited or no training and know how to use only basic techniques or tools. What kind of hackers are we talking about?


Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS?


Darius is analysing logs from IDS. He want to understand what have triggered one alert and verify if it’s true positive or false positive. Looking at the logs he copy and paste basic details like below: source IP: source port: 80 destination IP: destination port: 63221 What is the most proper answer.


A company’s policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Using Wire shark to examine the captured traffic, which command can be used as a display filter to find unencrypted file transfers?


Your business has decided to add credit card numbers to the data it backs up to tape. Which of the following represents the best practice your business should observe?


When conducting a penetration test, it is crucial to use all means to get all available information about the target network. One of the ways to do that is by sniffing the network. Which of the following cannot be performed by the passive network sniffing?


Cross-site request forgery involves:


Analyst is investigating proxy logs and found out that one of the internal user visited website storing suspicious Java scripts. After opening one of them, he noticed that it is very hard to understand the code and that all codes differ from the typical Java script. What is the name of this technique to hide the code and extend analysis time?


During the process of encryption and decryption, what keys are shared? During the process of encryption and decryption, what keys are shared?


Bob, a system administrator at TPNQM SA, concluded one day that a DMZ is not needed if he properly configures the firewall to allow access just to servers/ports, which can have direct internet access, and block the access to workstations. Bob also concluded that DMZ makes sense just when a stateful firewall is available, which is not the case of TPNQM SA. In this context, what can you say? one


Which of the following Bluetooth hacking techniques does an attacker use to send messages to users without the recipient’s consent, similar to email spamming?


You are a Penetration Tester and are assigned to scan a server. You need to use a scanning technique wherein the TCP Header is split into many packets so that it becomes difficult to detect what the packets are meant for. Which of the below scanning technique will you use?


A hacker named Jack is trying to compromise a bank’s computer system. He needs to know the operating system of that computer to launch further attacks. What process would help him?


In which of the following cryptography attack methods, the attacker makes a series of interactive queries, choosing subsequent plaintexts based on the information from the previous encryptions?


In Wireshark, the packet bytes panes show the data of the current packet in which format?


What type of vulnerability/attack is it when the malicious person forces the user’s browser to send an authenticated request to a server?


Which Nmap option would you use if you were not concerned about being detected and wanted to perform a very fast scan?


Bob finished a C programming course and created a small C application to monitor the network traffic and produce alerts when any origin sends “many” IP packets, based on the average number of packets sent by all origins and using some thresholds. In concept, the solution developed by Bob is actually:


A circuit level gateway works at which of the following layers of the OSI Model? protocol link


The use of technologies like IPSec can help guarantee the following: authenticity, integrity, confidentiality and


Which of the following processes evaluates the adherence of an organization to its stated security policy?


The precaution of prohibiting employees from bringing personal computing devices into a facility is what type of security control?


Which of the following tools will scan a network to perform vulnerability checks and compliance auditing?


On a Linux device, which of the following commands will start the Nessus client in the background so that the Nessus server can be configured?


From the two screenshots below, which of the following is occurring?


Which tool would be used to collect wireless packet data?


An attacker has been successfully modifying the purchase price of items purchased on the company’s web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the Intrusion Detection System (IDS) logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the purchase price?


A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm’s public facing web servers. The engineer decides to start by using netcat to port 80. The engineer receives this output: Which of the following is an example of what the engineer performed?


An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces. Which of the following is the most likely reason for lack ofmanagement or control packets?


Which of the following is a preventive control?


Which of the following problems can be solved by using Wireshark?


How can a rootkit bypass Windows 7 operating system’s kernel mode, code signing policy?


After gaining access to the password hashes used to protect access to a web based application, knowledge of which cryptographic algorithms would be useful to gain access to the application?


Which of the following open source tools would be the best choice to scan a network for potential targets?


Which of the following examples best represents a logical or technical control?


Which property ensures that a hash function will not produce the same hashed value for two different messages?


What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?


What are the three types of authentication?


Which of the following is an application that requires a host application for replication?


The network administrator for a company is setting up a website with e-commerce capabilities. Packet sniffing is ac oncern because credit card information will be sent electronically over the Internet. Customers visiting the site will need to encrypt the data with HTTPS. Which type of certificate is used to encrypt and decrypt the data?


A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version installed. Considering the NMAP result below, which of the following is likely to be installed on the target machine by the OS?


Which of the following resources does NMAP need to be used as a basic vulnerability scanner covering several vectors like SMB, HTTP and FTP?


A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?


Which of the following techniques will identify if computer files have been changed?


A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT department had a dial-out modem installed. Which security policy must the security analyst check to see if dial-out modems are allowed?


A security consultant decides to use multiple layers of anti-virus defense, such as end user desktop anti-virus and E-mail gateway. This approach can be used to mitigate which kind of attack?


When utilizing technical assessment methods to assess the security posture of a network, which of the following techniques would be most effective in determining whether end-user security training would be beneficial?


WPA2 uses AES for wireless data encryption at which of the following encryption levels?


Which type of access control is used on a router or firewall to limit network activity?


A pentester gains access to a Windows application server and needs to determine the settings of the built-in Windows firewall. Which command would be used?


What is a successful method for protecting a router from potential smurf attacks?


Which type of scan is used on the eye to measure the layer of blood vessels?


An attacker uses a communication channel within an operating system that is neither designed nor intended to transfer information. What is the name of the communications channel?


A person approaches a network administrator and wants advice on how to send encrypted email from home. The end user does not want to have to pay for any license fees or manage server services. Which of the following is the most secure encryption protocol that the network administrator should recommend?


A developer for a company is tasked with creating a program that will allow customers to update their billing and shipping information. The billing address field used is limited to 50 characters. What pseudo code would the developer use to avoid a buffer overflow attack on the billing address field?


Which of the following is a hashing algorithm?


Which protocol and port number might be needed in order to send log messages to a log analysis tool that resides behind a firewall?


Low humidity in a data center can cause which of the following problems?


During a wireless penetration test, a tester detects an access point using WPA2 encryption. Which of the following attacks should be used to obtain the key? obtain the key.


A security engineer has been asked to deploy a secure remote access solution that will allow employees to connect to the company’s internal network. Which of the following can be implemented to minimize the opportunity for the man-inthe- middle attack to occur?


At a Windows Server command prompt, which command could be used to list the running services?


What is the main disadvantage of the scripting languages as opposed to compiled programming languages?


The following is part of a log file taken from the machine on the network with the IP address .168.1.106: What type of activity has been logged?


A hacker, who posed as a heating and air conditioning specialist, was able to install a sniffer program in a switched environment network. Which attack could the hacker use to sniff all of the packets in the network?


Which of the following can the administrator do to verify that a tape backup can be recovered in its entirety?


While conducting a penetration test, the tester determines that there is a firewall between the tester’s machine and the target machine. The firewall is only monitoring TCP handshaking of packets at the session layer of the OSI model. Which type of firewall is the tester trying to traverse?


Smart cards use which protocol to transfer the certificate in a secure manner?


A security consultant is trying to bid on a large contract that involves penetration testing and reporting. The company accepting bids wants proof of work so the consultant prints out several audits that have been performed. Which of the following is likely to occur as a result?


A botnet can be managed through which of the following?


What is the outcome of the comm”nc -l -p 2222 | nc 1234″?


Which results will be returned with the following Google search query? site:target.com -site:Marketing.target. com accounting the word accounting


The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities?


A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee’s new responsibilities is to manage the implementation of an RFID card access system to a new server room on campus. The server room will house student enrollment information that is securely backed up to an off-site location. During a meeting with an outside consultant, the Chief Security Officer explains that he is concerned that the existing security controls have not been designed properly. Currently, the Network Administrator is responsible for approving and issuing RFID card access to the server room, as well as reviewing the electronic access logs on a weekly basis. Which of the following is an issue with the situation?


Which type of intrusion detection system can monitor and alert on attacks, but cannot stop them?


Which of the following techniques does a vulnerability scanner use in order to detect a vulnerability on a target service?


Which of the following lists are valid data-gathering activities associated with a risk assessment?


A tester has been using the msadc.pl attack script to execute arbitrary commands on a Windows NT4 web server. While it is effective, the tester finds it tedious to perform extended functions. On further research, the tester come across a perl script that runs the following msadc functions: Which exploit is indicated by this script?


Which set of access control solutions implements two-factor authentication?


A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company`s building dressed like an electrician and waits in the lobby for an employee to pass through the main access gate, then the consultant follows the employee behind to get into the restricted area. Which type of attack did the consultant perform?


Which of the following describes the characteristics of a Boot Sector Virus?


When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?


A hacker is attempting to use nslookup to query Domain Name Service (DNS). The hacker uses the nslookup interactive mode for the search. Which command should the hacker type into the command shell to request the appropriate records?


While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. What specific octet within the subnet does the technician see?


How can telnet be used to fingerprint a web server?


One advantage of an application-level firewall is the ability to


Which of the following is used to indicate a single-line comment in structured query language (SQL)?


When using Wireshark to acquire packet capture on a network, which device would enable the capture of all traffic on the wire?


What technique is used to perform a Connection Stream Parameter Pollution (CSPP) attack?


In the software security development life cycle process, threat modeling occurs in which phase?


What is the main reason the use of a stored biometric is vulnerable to an attack? biometric.


A company has publicly hosted web applications and an internal Intranet protected by a firewall. Which technique will help protect against enumeration?


If the final set of security controls does not eliminate all risk in a system, what could be done next?


A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?


Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?


Which of the following types of firewall inspects only header information in network traffic?


A company has five different subnets:,,, and How can NMAP be used to scan these adjacent Class C networks?


Which of the following is an example of an asymmetric encryption implementation?


A company is using Windows Server 2003 for its Active Directory (AD). What is the most efficient way to crack the passwords for the AD users?


What is the best defense against privilege escalation vulnerability?


A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank’s DNS servers, reading news articles online about the bank, watching what times the bank employees come into work and leave from work, searching the bank’s job postings (paying special attention to IT related jobs), and visiting the local dumpster for the bank’s corporate office. What phase of the penetration test is the tester currently in?


Which security control role does encryption meet?


In order to show improvement of security over time, what must be developed?


Which type of antenna is used in wireless communication?


How is sniffing broadly categorized?


Fingerprinting VPN firewalls is possible with which of the following tools?


Which tool can be used to silently copy files from USB devices?


Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. Which of the following is the correct bit size of the Diffie-Hellman (DH) group 5?


A newly discovered flaw in a software application would be considered which kind of security vulnerability?


What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?


Which type of scan measures a person’s external features through a digital video camera?


Which of the following is a strong post designed to stop a car?


An NMAP scan of a server shows port 25 is open. What risk could this pose?


To send a PGP encrypted message, which piece of information from the recipient must the sender have before encrypting the message?


Which of the following conditions must be given to allow a tester to exploit a Cross-Site Request Forgery (CSRF) vulnerable web application?


Which technical characteristic do Ethereal/Wireshark, TCPDump, and Snort have in common?


A hacker is attempting to see which IP addresses are currently active on a network. Which NMAP switch would the hacker use?


Which of the following does proper basic configuration of snort as a network intrusion detection system require?


A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the tester consider using?


A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: The engineer wants to configure remote desktop access from a fixed IP on the remote network to a remote desktop server in the DMZ. Which rule would best fit this requirement?


What results will the following command yield: ‘NMAP -sS -O -p 123053’?


During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this response, which type of packet inspection is the firewall conducting?


How does an operating system protect the passwords used for account logins?


John the Ripper is a technical assessment tool used to test the weakness of which of the following?


What is the name of the international standard that establishes a baseline level of confidence in the security functionality of IT products by providing a set of requirements for evaluation?


How can rainbow tables be defeated?


Bluetooth uses which digital modulation technique to exchange information between paired devices?


Which command lets a tester enumerate alive systems in a class C network via ICMP using native Windows tools?


An NMAP scan of a server shows port 69 is open. What risk could this pose?


Which of the following business challenges could be solved by using a vulnerability scanner? quit. policies.


Which command line switch would be used in NMAP to perform operating system detection?


Which of the following cryptography attack methods is usually performed without the use of a computer?


A network administrator received an administrative alert at 3:00 a.m. from the intrusion detection system. The alert was generated because a large number of packets were coming into the network over ports 20 and 21. During analysis, there were no signs of attack on the FTP servers. How should the administrator classify this situation?


What is the main difference between a “Normal” SQL Injection and a “Blind” SQL Injection vulnerability? code injection.


Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?


During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?


Which of the following programming languages is most vulnerable to buffer overflow attacks?


Passive reconnaissance involves collecting information through which of the following?


Which of the following is a detective control?


The following is a sample of output from a penetration tester’s machine targeting a machine with the IP address .168.1.106: What is most likely taking place?


A hacker searches in Google for filetype:pcf to find Cisco VPN config files. Those files may contain connectivity passwords that can be decoded with which of the following?


An engineer is learning to write exploits in C++ and is using the exploit tool Backtrack. The engineer wants to compile the newest C++ exploit and name it calc.exe. Which command would the engineer use to accomplish this? hackersExploit.cpp -o calc.exe


Which tool is used to automate SQL injections and exploit a database by forcing a given web application to connect to another database controlled by a hacker?


A company has hired a security administrator to maintain and administer Linux and Windows-based systems. Written in the nightly report file is the following: Firewall log files are at the expected value MB. The current time is 12am. Exactly two hours later the size has decreased considerably. Another hour goes by and the log files have shrunk in size again. Which of the following actions should the security administrator take?


Pentest results indicate that voice over IP traffic is traversing a network. Which of the following tools will decode a packet capture and extract the voice conversations?


Which of the following scanning tools is specifically designed to find potential exploits in Microsoft Windows products?


Which solution can be used to emulate computer services, such as mail and ftp, and to capture information related to logins or actions?


When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator’s computer to update the router configuration. What type of an alert is this?


A security engineer is attempting to map a company’s internal network. The engineer enters in the following NMAP command: NMAP n sS P0 p 80 ***.***.**.** What type of scan is this?


Which of the following is considered an acceptable option when managing a risk?


ICMP ping and ping sweeps are used to check for active systems and to check


A recently hired network security associate at a local bank was given the responsibility to perform daily scans of the internal network to look for unauthorized devices. The employee decides to write a script that will scan the network for unauthorized devices every morning at 5:00 am. Which of the following programming languages would most likely be used?


During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to exploit this vulnerability?


One way to defeat a multi-level security solution is to leak data via


What is the correct PCAP filter to capture all TCP traffic going to or from host on port 25?


A penetration tester is hired to do a risk assessment of a company’s DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems. What kind of test is being performed?


Which of the following items of a computer system will an anti-virus program scan for viruses?


Which of the following is an example of two factor authentication?


Which statement is TRUE regarding network firewalls preventing Web Application attacks?


What is the broadcast address for the subnet


A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?


Which of the following programs is usually targeted at Microsoft Office products?


Which of the following is a client-server tool utilized to evade firewall inspection?


Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run?


What information should an IT system analysis provide to the risk assessor?


A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. The analyst will use the Blackjacking attack method to demonstrate how an attacker could circumvent perimeter defenses and gain access to the corporate network. What tool should the analyst use to perform a Blackjacking attack?


Which of the statements concerning proxy firewalls is correct? client.


Least privilege is a security concept that requires that a user is


Which of the following parameters enables NMAP’s operating system detection feature?


A security analyst in an insurance company is assigned to test a new web application that will be used by clients to help them choose and apply for an insurance plan. The analyst discovers that the application is developed in ASP scripting language and it uses MSSQL as a database backend. The analyst locates the application’s search form and introduces the following code in the search input field: When the analyst submits the form, the browser returns a pop-up window that says “Vulnerable”. Which web applications vulnerability did the analyst discover?


Which of the following is a symmetric cryptographic standard?


Which of the following is a hardware requirement that either an IDS/IPS system or a proxy server must have in order to properly function?


Which system consists of a publicly available set of databases that contain domain name registration contact information?


Which of the following settings enables Nessus to detect when it is sending too many packets and the network pipe is approaching capacity?


What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?


A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new document that allowed the forms to be completed, the student decides to write a script that pulls passwords from a list of commonly used passwords to try against the secured PDF until the correct password is found or the list is exhausted. Which cryptography attack is the student attempting?


Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drawn based on these scan results? server. firewall. with a TTL error.


While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting malicious input?


A security policy will be more accepted by employees if it is consistent and has the support of


What is the main advantage that a network-based IDS/IPS system has over a host-based solution?


A security administrator notices that the log file of the company’s webserver contains suspicious entries: Based on source code analysis, the analyst concludes that the login.php script is vulnerable to


Which of the following identifies the three modes in which Snort can be configured to run?


When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?


A pentester is using Metasploit to exploit an FTP server and pivot to a LAN. How will the pentester pivot using Metasploit?


A covert channel is a channel that


A hacker was able to sniff packets on a company’s wireless network. The following information was discovered: Using the Exlcusive OR, what was the original message?


What statement is true regarding LM hashes?


When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?


Which vital role does the U.S. Computer Security Incident Response Team (CSIRT) provide? the Department of Homeland Security decommissions old Internet infrastructure sectors Department, as well as private sectors


Which of the following describes a component of Public Key Infrastructure (PKI) where a copy of a private key is stored to provide third-party access and to facilitate recovery operations?


A certified ethical hacker (CEH) is approached by a friend who believes her husband is cheating. She offers to pay to break into her husband’s email account in order to find proof so she can take him to court. What is the ethical response?


An ethical hacker for a large security research firm performs penetration tests, vulnerability tests, and risk assessments. A friend recently started a company and asks the hacker to perform a penetration test and vulnerability assessment of the new company as a favor. What should the hacker’s next step be before starting work on this job? gathering. to attack.


A computer technician is using a new version of a word processing software package when it is discovered that a special sequence of characters causes the entire computer to crash. The technician researches the bug and discovers that no one else experienced the problem. What is the appropriate next step?


Which of the following guidelines or standards is associated with the credit card industry?


If an e-commerce site was put into a live environment and the programmers failed to remove the secret entry point that was used during the application development, what is this secret entry point known as?


The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following?


How can a policy help improve an employee’s security awareness? benefits of security terminating employees consultative help line managers know employee strengths


The Open Web Application Security Project (OWASP) testing methodology addresses the need to secure web applications by providing which one of the following services?


Which element of Public Key Infrastructure (PKI) verifies the applicant?


When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is


Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/IP specifications?


Which of the following is a common Service Oriented Architecture (SOA) vulnerability?


Which of the following is an advantage of utilizing security testing methodologies to conduct a security audit?


To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settings?


Some passwords are stored using specialized encryption algorithms known as hashes. Why is this an appropriate method?


For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using a digital signature, the message digest is encrypted with which key?


Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest?


SOAP services use which technology to format information?


Which security strategy requires using several, varying methods to protect IT systems against attacks?


Which of the following is a characteristic of Public Key Infrastructure (PKI)?


If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may be using TCP. Which other option could the tester use to get a response from a host using TCP?


Which of the following descriptions is true about a static NAT?


Which of the following defines the role of a root Certificate Authority (CA) in a Public Key Infrastructure (PKI)?


Which of the following processes of PKI (Public Key Infrastructure) ensures that a trust relationship exists and that a certificate is still valid for specific operations?


A consultant has been hired by the V.P. of a large financial organization to assess the company’s security posture. During the security testing, the consultant comes across child pornography on the V.P.’s computer. What is the consultant’s obligation to the financial organization?


Which of the following levels of algorithms does Public Key Infrastructure (PKI) use?


An attacker has captured a target file that is encrypted with public key cryptography. Which of the attacks below is likely to be used to crack the target file?


Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design, and implementation?


Which initial procedure should an ethical hacker perform after being brought into an organization?


Which of the following is a primary service of the U.S. Computer Security Incident Response Team (CSIRT)? reporting computer security incidents worldwide. information on individuals travelling abroad. individuals and multi-national corporations. individual’s property or company’s asset.


In the OSI model, where does PPTP encryption take place?


While testing the company’s web applications, a tester attempts to insert the following test script into the search area on the company’s web site: Afterwards, when the tester presses the search button, a pop-up box appears on the screen with the text: “Testing Testing Testing”. Which vulnerability has been detected in the web application?


A technician is resolving an issue where a computer is unable to connect to the Internet using a wireless access point. The computer is able to transfer files locally to other machines, but cannot successfully reach the Internet. When the technician examines the IP address and default gateway they are both on the Which of the following has occurred?


Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion?


Which NMAP feature can a tester implement or adjust while scanning for open ports to avoid detection by the network’s IDS?


Which of the following is optimized for confidential communications, such as bidirectional voice and video?


Employees in a company are no longer able to access Internet web sites on their computers. The network administrator is able to successfully ping IP address of web servers on the Internet and is able to open web sites by using an IP address in place of the URL. The administrator runs the nslookup command for www.eccouncil.org and receives an error message stating there is no response from the server. What should the administrator do next?


A Certificate Authority (CA) generates a key pair that will be used for encryption and decryption of email. The integrity of the encrypted email is dependent on the security of which of the following?


The intrusion detection system at a software development company suddenly generates multiple alerts regarding attacks against the company’s external webserver, VPN concentrator, and DNS servers. What should the security team do to determine which alerts to check first?


Which of the following network attacks takes advantage of weaknesses in the fragment reassembly functionality of the TCP/IP protocol stack?


Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?


How do employers protect assets with security policies pertaining to employee surveillance activities? trustworthiness. employees. employee keystrokes. and consequences.


Company A and Company B have just merged and each has its own Public Key Infrastructure (PKI). What must the Certificate Authorities (CAs) establish so that the private PKIs for Company A and Company B trust one another and each private PKI can validate digital certificates from the other company?


An attacker sniffs encrypted traffic from the network and is subsequently able to decrypt it. The attacker can now use which cryptanalytic technique to attempt to discover the encryption key?


Which United States legislation mandates that the Chief Executive Officer (CEO) and the Chief Financial Officer (CFO) must sign statements verifying the completeness and accuracy of financial reports?


An IT security engineer notices that the company’s web server is currently being hacked. What should the engineer do next?


Which statement best describes a server type under an N-tier architecture?


Which of the following items is unique to the N-tier architecture method of designing software applications?


International Organization for Standardization (ISO) standard 27002 provides guidance for compliance by outlining


What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?


What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data? than the message.


Which of the following can take an arbitrary length of input and produce a message digest output bit?


Which type of security document is written with specific step-by-step details?


Advanced encryption standard is an algorithm used for which of the following?


A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take?


Which of the following tools would be the best choice for achieving compliance with PCI Requirement 11?


A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the best remediation against this type of attack?


Which of the following is an example of IP spoofing?


When setting up a wireless network, an administrator enters a pre-shared key for security. Which of the following is true?


Which cipher encrypts the plain text digit (bit or byte) one by one?


This international organization regulates billions of transactions daily and provides security guidelines to protect personally identifiable information (PII). These security controls provide a baseline and prevent low-level hackers sometimes known as script kiddies from causing a data breach. Which of the following organizations is being described?


Which of the following is the least-likely physical characteristic to be used in biometric control that supports a large company?


You are performing information gathering for an important penetration test. You have found pdf, doc, and images in your objective. You decide to extract metadata from these files and analyze it. What tool will help you with the task?


You’ve just been hired to perform a pen test on an organization that has been subjected to a large-scale attack. The CIO is concerned with mitigating threats and vulnerabilities to totally eliminate risk. What is one of the first things you should do when given the job? levels.


Perspective clients want to see sample reports from previous penetration tests. What should you do next?


Which of the following is a component of a risk assessment?


You have successfully gained access to your client’s internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Microsoft Windows workstations have file sharing enabled. Which port would you see listening on these Windows machines in the network?


You have successfully gained access to a linux server and would like to ensure that the succeeding outgoing traffic from this server will not be caught by a Network Based Intrusion Detection Systems (NIDS). What is the best way to evade the NIDS?


What is a “Collision attack” in cryptography?


When you are collecting information to perform a data analysis, Google commands are very useful to find sensitive information and files. These files may contain information about passwords, system functions, or documentation. What command will help you to search files using Google as a search engine?


It is a vulnerability in GNU’s bash shell, discovered in September 4, that gives attackers access to run remote commands on a vulnerable system. The malicious software can take control of an infected machine, launch denial-ofservice attacks to disrupt websites, and scan for other vulnerable devices (including routers). Which of the following vulnerabilities is being described?


The purpose of a __________ is to deny network access to local area networks and other information assets by unauthorized wireless devices.


A common cryptographical tool is the use of XOR. XOR the following binary values: 10110001 00111010


How does the Address Resolution Protocol (ARP) work?


What is the benefit of performing an unannounced Penetration Testing?


You are a Network Security Officer. You have two machines. The first machine ( has snort installed, and the second machine ( has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What wireshark filter will show the connections from the snort machine to kiwi syslog machine?


> NMAP -sn The NMAP command above performs which of the following?


The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE’s Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the transport layer security (TLS) protocols defined in RFC6520. What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy?


env x=`(){ :;};echo exploit` bash -c ‘cat /etc/passwd’ What is the Shellshock bash vulnerability attempting to do on a vulnerable Linux host?


You have successfully compromised a machine on the network and found a server that is alive on the same network. You tried to ping it but you didn’t get any response back. What is happening?


Which of the following is an extremely common IDS evasion technique in the web world?


Which of the following is the BEST way to defend against network sniffing?


During a blackbox pen test you attempt to pass IRC traffic over port 80/TCP from a compromised web enabled host. The traffic gets blocked; however, outbound HTTP traffic is unimpeded. What type of firewall is inspecting outbound traffic?


You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection System. What is the best approach? Systems.


A hacker has successfully infected an internet-facing server which he will then use to send junk mail, take part in coordinated attacks, or host junk email content. Which sort of trojan infects this server?


You have several plain-text firewall logs that you must review to evaluate network traffic. You know that in order to do fast, efficient searches of the logs you must use regular expressions. Which command-line utility are you most likely to use?


When you return to your desk after a lunch break, you notice a strange email in your inbox. The sender is someone you did business with recently, but the subject line has strange characters in it. What should you do?


Which of the following is not a Bluetooth attack?


You’ve gained physical access to a Windows 2008 R2 server which has an accessible disc drive. When you attempt to boot the server and log in, you are unable to guess the password. In your tool kit you have an Ubuntu 9.10 Linux LiveCD. Which Linux based tool has the ability to change any user’s password or to activate disabled Windows accounts?


It is a short-range wireless communication technology intended to replace the cables connecting portable of fixed devices while maintaining high levels of security. It allows mobile phones, computers and other devices to connect and communicate using a short-range wireless connection. Which of the following terms best matches the definition?


As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics of the testing, the associated violations, and essentially protects both the organization’s interest and your liabilities as a tester?


A medium-sized healthcare IT business decides to implement a risk management strategy. Which of the following is NOT one of the five basic responses to risk?


What is the best description of SQL Injection?


This asymmetry cipher is based on factoring the product of two large prime numbers. What cipher is described above?


You are attempting to man-in-the-middle a session. Which protocol will allow you to guess a sequence number?


Which of the following is the successor of SSL?


Which of the following parameters describe LM Hash (see exhibit): Exhibit: 


You are using NMAP to resolve domain names into IP addresses for a ping sweep later. Which of the following commands looks for IP addresses?


When you are getting information about a web server, it is very important to know the HTTP Methods (GET, POST, HEAD, PUT, DELETE, TRACE) that are available because there are two critical methods (PUT and DELETE). PUT can upload a file to the server and DELETE can delete a file from the server. You can detect all these methods (GET, POST, HEAD, PUT, DELETE, TRACE) using NMAP script engine. What nmap script will help you with this task?


This phase will increase the odds of success in later phases of the penetration test. It is also the very first step in Information Gathering, and it will tell you what the “landscape” looks like. What is the most important phase of ethical hacking in which you need to spend a considerable amount of time?


During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?


You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use?


Which of the following is a design pattern based on distinct pieces of software providing application functionality as services to other applications?


The Open Web Application Security Project (OWASP) is the worldwide not-for-profit charitable organization focused on improving the security of software. What item is the primary concern on OWASP’s Top Ten Project Most Critical Web Application Security Risks?


In 2007, this wireless security algorithm was rendered useless by capturing packets and discovering the passkey in a matter of seconds. This security flaw led to a network invasion of TJ Maxx and data theft through a technique known as wardriving. Which Algorithm is this referring to?


Which regulation defines security and privacy controls for Federal information systems and organizations?


When you are testing a web application, it is very useful to employ a proxy tool to save every request and response. You can manually test every request and analyze the response to find vulnerabilities. You can test parameter and headers manually to get more precise results than if using web vulnerability scanners. What proxy tool will help you find web vulnerabilities?


After trying multiple exploits, you’ve gained root access to a Centos 6 server. To ensure you maintain access, what would you do first?


You have compromised a server on a network and successfully opened a shell. You aimed to identify all operating systems running on the network. However, as you attempt to fingerprint all machines in the network using the nmap syntax below, it is not going through. What seems to be wrong?


Which of the following statements is TRUE?


Under the “Post-attack Phase and Activities”, it is the responsibility of the tester to restore the systems to a pretest state. Which of the following activities should not be included in this phase? (see exhibit) Exhibit:


Nation-state threat actors often discover vulnerabilities and hold on to them until they want to launch a sophisticated attack. The Stuxnet attack was an unprecedented style of attack because it used four types of vulnerability. What is this style of attack called?


Your team has won a contract to infiltrate an organization. The company wants to have the attack be as realistic as possible; therefore, they did not provide any information besides the company name. What should be the first step in security testing the client?


This tool is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once enough data packets have been captured. It implements the standard FMS attack along with some optimizations like KoreK attacks, as well as the PTW attack, thus making the attack much faster compared to other WEP cracking tools. Which of the following tools is being described? Aircrack-ng is a complete suite of tools to assess WiFi network security. The default cracking method of Aircrack-ng is PTW, but Aircrack-ng can also use the FMS/KoreK method, which incorporates various statistical attacks to discover the WEP key and uses these in combination with brute forcing. References: http://www.aircrack-ng.org/doku.php?id=aircrack-ng


Which of the following is assured by the use of a hash?


Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?


Which mode of IPSec should you use to assure security and confidentiality of data within the same LAN?


Initiating an attack against targeted businesses and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in malware infection. The attackers run exploits on well-known and trusted sites likely to be visited by their targeted victims. Aside from carefully choosing sites to compromise, these attacks are known to incorporate zero-day exploits that target unpatched vulnerabilities. Thus, the targeted entities are left with little or no defense against these exploits. What type of attack is outlined in the scenario?


A regional bank hires your company to perform a security assessment on their network after a recent data breach. The attacker was able to steal financial data from the bank by compromising only a single server. Based on this information, what should be one of your key recommendations to the bank?


Which of the following is a command line packet analyzer similar to GUI-based Wireshark?


Which of the following is the greatest threat posed by backups?


Which of the following is the structure designed to verify and authenticate the identity of individuals within the enterprise taking part in a data exchange?


What is the process of logging, recording, and resolving events that take place in an organization?


Jimmy is standing outside a secure entrance to a facility. He is pretending to have a tense conversation on his cell phone as an authorized employee badges in. Jimmy, while still on the phone, grabs the door as it begins to close. What just happened?


Using Windows CMD, how would an attacker list all the shares to which the current user context has access?


Jesse receives an email with an attachment labeled “Court_Notice_21206.zip”. Inside the zip file is a file named “Court_Notice_21206.docx.exe” disguised as a word document. Upon execution, a window appears stating, “This word document is corrupt.” In the background, the file copies itself to Jesse APPDATA\local directory and begins to beacon to a C2 server to download additional malicious binaries. What type of malware has Jesse encountered?


You just set up a security system in your network. In what kind of system would you find the following string of characters used as a rule within its configuration? alert tcp any any -> 21 (msg: “FTP on the network!”;)


It is a kind of malware (malicious software) that criminals install on your computer so they can lock it from a remote location. This malware generates a pop-up window, webpage, or email warning from what looks like an official authority. It explains that your computer has been locked because of possible illegal activities on it and demands payment before you can access your files and programs again. Which of the following terms best matches the definition?


It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of the following terms best matches the definition?


While using your bank’s online servicing you notice the following string in the URL bar: “http://www.MyPersonalBank.com/account?id=368940911028389 &Damount=10980&Camount=21” You observe that if you modify the Damount & Camount values and submit the request, that data on the web page reflect the changes. Which type of vulnerability is present on this site?


An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to “www.MyPersonalBank.com”, that the user is directed to a phishing site. Which file does the attacker need to modify?


An attacker changes the profile information of a particular user (victim) on the target website. The attacker uses this string to update the victim’s profile to a text file and then submit the data to the attacker’s database. What is this type of attack (that can use either HTTP GET or HTTP POST) called?


You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist’s email, and you send her an email changing the source email to her boss’s email( boss@company ). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your malicious links (these links contain malware) and send back the modified pdf, saying that the links don’t work. She reads your email, opens the links, and her machine gets infected. You now have access to the company network. What testing method did you use?


It is a regulation that has a set of guidelines, which should be adhered to by anyone who handles any electronic medical data. These guidelines stipulate that all medical practices must ensure that all necessary measures are in place while saving, accessing, and sharing any electronic medical data to keep patient data secure. Which of the following regulations best matches the description?


You have successfully comprised a server having an IP address .10.0.5. You would like to enumerate all machines in the same network quickly. What is the best nmap command you will use?


Port scanning can be used as part of a technical assessment to determine network vulnerabilities. The TCP XMAS scan is used to identify listening ports on the targeted system. If a scanned port is open, what happens?


The network administrator contacts you and tells you that she noticed the temperature on the internal wireless router increases by more than 20% during weekend hours when the office was closed. She asks you to investigate the issue because she is busy dealing with a big conference and she doesn’t have time to perform the task. What tool can you use to view the network traffic being sent and received by the wireless router?


The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the central processing unit (CPU), rather than passing only the frames that the controller is intended to receive. Which of the following is being described?


Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking. What should you do?


Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?


You are performing a penetration test. You achieved access via a buffer overflow exploit and you proceed to find interesting data, such as files with usernames and passwords. You find a hidden folder that has the administrator’s bank account password and login information for the administrator’s bitcoin account. What should you do?


Look at the following output. What did the hacker accomplish?


Risks = Threats x Vulnerabilities is referred to as the:


A new wireless client is configured to join a 802.11 network. This client uses the same hardware and software as many of the other clients on the network. The client can see the network, but cannot connect. A wireless packet sniffer shows that the Wireless Access Point (WAP) is not responding to the association requests being sent by the wireless client. What is a possible source of this problem?


The “black box testing” methodology enforces which kind of restriction?


While performing online banking using a Web browser, a user receives an email that contains a link to an interesting Web site. When the user clicks on the link, another Web browser session starts and displays a video of cats playing a piano. The next business day, the user receives what looks like an email from his bank, indicating that his bank account has been accessed from a foreign country. The email asks the user to call his bank and verify the authorization of a funds transfer that took place. What Web browser-based security vulnerability was exploited to compromise the user?


Which of the following areas is considered a strength of symmetric key cryptography when compared with asymmetric algorithms?


An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?


Which of the following is a protocol specifically designed for transporting event messages?


Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides different functionality. Collective IPSec does everything except.


Which of the following is designed to identify malicious attempts to penetrate systems?


The “gray box testing” methodology enforces what kind of restriction?


Which of the following tools can be used for passive OS fingerprinting?


Eve stole a file named secret.txt, transferred it to her computer and she just entered these commands: What is she trying to achieve?


What network security concept requires multiple layers of security controls to be placed throughout an IT infrastructure, which improves the security posture of an organization to defend against malicious attacks or potential vulnerabilities?


An IT employee got a call from one of our best customers. The caller wanted to know about the company’s network infrastructure, systems, and team. New opportunities of integration are in sight for both company and customer. What should this employee do? charge.


A network administrator discovers several unknown files in the root directory of his Linux FTP server. One of the files is a tarball, two are shell script files, and the third is a binary file is named “nc.” The FTP server’s access logs show that the anonymous user account logged in to the server, uploaded the files, and extracted the contents of the tarball and ran the script using a function provided by the FTP server’s software. The ps command shows that the nc file is running as process, and the netstat command shows the nc process is listening on a network port. What kind of vulnerability must be present to make this remote attack possible?


What is the way to decide how a packet will move from an untrusted outside host to a protected inside that is behind a firewall, which permits the hacker to determine which ports are open and if the packets can pass through the packetfiltering of the firewall?


The company ABC recently discovered that their new product was released by the opposition before their premiere. They contract an investigator who discovered that the maid threw away papers with confidential information about the new product and the opposition found it in the garbage. What is the name of the technique used by the opposition?


To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following tools would most likely be used in such an audit?


A company’s Web development team has become aware of a certain type of security vulnerability in their Web software. To mitigate the possibility of this vulnerability being exploited, the team wants to modify the software requirements to disallow users from entering HTML as input into their Web application. What kind of Web application vulnerability likely exists in their software?


Craig received a report of all the computers on the network that showed all the missing patches and weak passwords. What type of software generated this report?


Cryptography is the practice and study of techniques for secure communication in the presence of third parties (called adversaries.) More generally, it is about constructing and analyzing protocols that overcome the influence of adversaries and that are related to various aspects in information security such as data confidentiality, data integrity, authentication, and non-repudiation. Modern cryptography intersects the disciplines of mathematics, computer science, and electrical engineering. Applications of cryptography include ATM cards, computer passwords, and electronic commerce. Basic example to understand how cryptography works is given below: Which of the following choices is true about cryptography? keys for both encryption of plaintext and decryption of ciphertext. shared session key and to achieve a communication way. encrypt.


The establishment of a TCP connection involves a negotiation called 3 way handshake. What type of message sends the client to the server in order to begin this negotiation?


What is the most common method to exploit the “Bash Bug” or “ShellShock” vulnerability? to a vulnerable Web server


PGP, SSL, and IKE are all examples of which type of cryptography?


An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their job. The attacker gains access to the DNS server and redirects the direction www.google.com to his own IP address. Now when the employees of the office want to go to Google they are being redirected to the attacker machine. What is the name of this kind of attack?


An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of many of the logged events do not match up. What is the most likely cause?


Websites and web portals that provide web services commonly use the Simple Object Access Protocol SOAP. Which of the following is an incorrect definition or characteristics in the protocol?


The chance of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. Calculate the SLE, ARO, and ALE. Assume the EF = 1 (100%). What is the closest approximate cost of this replacement and recovery operation per year?


In Risk Management, how is the term “likelihood” related to the concept of “threat?”


What is the difference between the AES and RSA algorithms? encrypt data. encrypt data.


If executives are found liable for not properly protecting their company’s assets and information systems, what type of law would apply in this situation?


In cryptanalysis and computer security, ‘pass the hash’ is a hacking technique that allows an attacker to authenticate to a remote server/service by using the underlying NTLM and/or LanMan hash of a user’s password, instead of requiring the associated plaintext password as is normally the case. Metasploit Framework has a module for this technique: psexec. The psexec module is often used by penetration testers to obtain access to a given system that you already know the credentials for. It was written by sysinternals and has been integrated within the framework. Often as penetration testers, successfully gain access to a system through some exploit, use meterpreter to grab the passwords or other methods like fgdump, pwdump, or cachedump and then utilize rainbowtables to crack those hash values. Which of the following is true hash type and sort order that is using in the psexec module’s ‘smbpass’?


An attacker gains access to a Web server’s database and displays the contents of the table that holds all of the names, passwords, and other user information. The attacker did this by entering information into the Web site’s user login page that the software’s designers did not expect to be entered. This is an example of what kind of software design problem?


In both pharming and phishing attacks an attacker can create websites that look similar to legitimate sites with the intent of collecting personal identifiable information from its victims. What is the difference between pharming and phishing attacks? exploiting vulnerabilities in DNS. In a phishing attack an attacker provides the victim with a URL that is either misspelled or looks similar to the actual websites domain name. exploiting vulnerabilities in DNS. In a pharming attack an attacker provides the victim with a URL that is either misspelled or looks very similar to the actual websites domain name.


What two conditions must a digital signature meet?


Which protocol is used for setting up secured channels between two devices, typically in VPNs?


You are an Ethical Hacker who is auditing the ABC company. When you verify the NOC one of the machines has 2 connections, one wired and the other wireless. When you verify the configuration of this Windows system you find two static routes. route add mask route add mask What is the main purpose of those static routes? indicates that the traffic will be rerouted. static route indicates that all the traffic that is not internal must go to an external gateway.


Seth is starting a penetration test from inside the network. He hasn’t been given any information about the network. What type of test is he conducting?


Rebecca commonly sees an error on her Windows system that states that a Data Execution Prevention (DEP) error has taken place. Which of the following is most likely taking place?


Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, smallsized packets to the target computer, making it very difficult for an IDS to detect the attack signatures. Which tool can be used to perform session splicing attacks?


Due to a slowdown of normal network operations, IT department decided to monitor internet traffic for all of the employees. From a legal stand point, what would be troublesome to take this kind of measure?


A large mobile telephony and data network operator has a data that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup? should be performed. measures. systems exist.


Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?


Which method of password cracking takes the most time and effort?


You are the Systems Administrator for a large corporate organization. You need to monitor all network traffic on your local network for suspicious activities and receive notifications when an attack is occurring. Which tool would allow you to accomplish this goal?


By using a smart card and pin, you are using a two-factor authentication that satisfies


Which of the following security operations is used for determining the attack surface of an organization?


Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?


If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used?


Emil uses nmap to scan two hosts using this command. nmap -sS -T4 -O He receives this output: What is his conclusion?


What is the correct process for the TCP three-way handshake connection establishment and connection termination?


The company ABC recently contracted a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. What of the following options can be useful to ensure the integrity of the data? can compare both to be sure it is the same document.


You want to do an ICMP scan on a remote computer using hping2. What is the proper syntax?


Which of the following is a passive wireless packet analyzer that works on Linux-based systems?


Which of the following incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an organization?


The network in ABC company is using the network address with mask In the network the servers are in the addresses, and An attacker is trying to find those servers but he cannot see them in his scanning. The command he is using is: nmap Why he cannot see the servers? range.


Which of the following statements regarding ethical hacking is incorrect?


An attacker is using nmap to do a ping sweep and a port scanning in a subnet addresses. In which order should he perform these steps? echo requests.


_________ is a set of extensions to DNS that provide to DNS clients (resolvers) origin authentication of DNS data to reduce the threat of DNS poisoning, spoofing, and similar attacks types.


Sophia travels a lot and worries that her laptop containing confidential documents might be stolen. What is the best protection that will work for her?


What does a firewall check to prevent particular ports and applications from getting packets into an organization?


Which tier in the N-tier application architecture is responsible for moving and processing data between the tiers?


Bob learned that his username and password for a popular game has been compromised. He contacts the company and resets all the information. The company suggests he use two-factor authentication, which option below offers that?


An attacker tries to do banner grabbing on a remote web server and executes the following command. Service detection performed. Please report any incorrect results at http://nmap.org/submit/. Nmap done: 1 IP address (1 host up) scanned in 6.42 seconds What did the hacker accomplish?


Which Intrusion Detection System is best applicable for large environments where critical assets on the network need extra security and is ideal for observing sensitive network segments?


Which of the following is considered the best way to protect Personally Identifiable Information (PII) from Web application vulnerabilities?


What mechanism in Windows prevents a user from accidentally executing a potentially malicious batch (.bat) or PowerShell (.ps1) script?


Sid is a judge for a programming contest. Before the code reaches him it goes through a restricted OS and is tested there. If it passes, then it moves onto Sid. What is this middle step called?


Attempting an injection attack on a web server based on responses to True/False questions is called which of the following?


When purchasing a biometric system, one of the considerations that should be reviewed is the processing speed. Which of the following best describes what it is meant by processing? and authentication information.


A penetration test was done at a company. After the test, a report was written and given to the company’s IT authorities. A section from the report is shown below: According to the section from the report, which of the following choice is true?


An attacker attaches a rogue router in a network. He wants to redirect traffic to a LAN attached to his router as part of a man-in-the-middle attack. What measure on behalf of the legitimate admin can mitigate this attack?


Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications and unpatched security flaws in a computer system?


A company’s security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate?


Scenario: What is the name of the attack which is mentioned in the scenario?


Which of these options is the most secure procedure for storing backup tapes?


In order to have an anonymous Internet surf, which of the following is best choice?


What is correct about digital signatures? original document encrypted with the private key of the signing party. document content.


Which of the following programming languages is most susceptible to buffer overflow attacks, due to its lack of a builtin- bounds checking mechanism? Output: Segmentation fault


Which of the following Nmap commands will produce the following output? Output:


Todd has been asked by the security officer to purchase a counter-based authentication system. Which of the following best describes this type of system?


What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?


What is the role of test automation in security testing? manual testing completely. inconsistencies.


Which of the following is a low-tech way of gaining unauthorized access to systems?


In many states sending spam is illegal. Thus, the spammers have techniques to try and ensure that no one knows they sent the spam out to thousands of users at a time. Which of the following best describes what spammers use to hide the origin of these types of e-mails? domain name. occasionally.


Which Metasploit Framework tool can help penetration tester for evading Anti-virus Systems?


The “white box testing” methodology enforces what kind of restriction?


Which of the following types of firewalls ensures that the packets are part of the established session?


You’re doing an internal security audit and you want to find out what ports are open on all the servers. What is the best way to find out?


Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?


Which of the following is one of the most effective ways to prevent Cross-site Scripting (XSS) flaws in software applications?


An Internet Service Provider (ISP) has a need to authenticate users connecting using analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network. Which AAA protocol is most likely able to handle this requirement?