SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CEH: Certified Ethical Hacker
Start Test
Study First
Subjects
:
certifications
,
ceh
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A step-by-step method of solving a problem. In computing security - an algorithm is a set of mathematical rules (logic) for the process of encryption and decryption
network operations center (NOC)
Algorithm
Network Basic Input/Output System (NetBIOS)
-sL
2. The steps taken to gather evidence and information on the targets you wish to attack.
Countermeasures
Transmission Control Protocol (TCP)
reconnaissance
Asymmetric
3. Also known as the dot-dot-slash attack. Using directory traversal - the attacker attempts to access restricted directories and execute commands outside intended web server directories by using the URL to redirect to an unintended folder location.
Banner Grabbing
Network Basic Input/Output System (NetBIOS)
Cryptographic Key
Directory Traversal
4. A hybrid of the HTTP and SSL/TLS protocols that provides encrypted communication and secure identification of a web server.
self encrypting
Third Party
SAM
Hypertext Transfer Protocol Secure (HTTPS)
5. ICMP Type/Code 0-0
intrusion prevention system (IPS)
spyware
Echo Reply
Internet Protocol Security (IPSec) architecture
6. Formal description and evaluation of the vulnerabilities in an information system
patch
Buffer Overflow
Vulnerability Assessment
parallel scan
7. An organized collection of data.
No previous knowledge of the network
Database
White Box Testing
hardware keystroke logger
8. A social-engineering effort in which the attacker pretends to be an employee - a valid user - or even an executive to elicit information or access.
-sU
impersonation
spyware
Rijndael
9. A file system used by the Mac OS.
red team
Authorization
Information Technology (IT) asset valuation
Hierarchical File System (HFS)
10. The process of a system providing a fully qualified domain name (FQDN) to a local name server - for resolution to its corresponding IP address.
Challenge Handshake Authentication Protocol (CHAP)
Domain Name System (DNS) lookup
Written Authorization
Packet Internet Groper (ping)
11. Phases of an attack
false negative
NT LAN Manager (NTLM)
Reconnaissance - Scanning - Gaining Access - Maintaining Access - Covering Tracks
A procedure for identifying active hosts on a network.
12. A cyber attacker who acts without permission from - and gives prior notice to - the resource owner. Also known as a malicious hacker.
Wide Area Network (WAN)
quantitative risk assessment
Cracker
Demilitarized Zone (DMZ)
13. Monitoring of telephone or Internet conversations - typically by covert means.
Institute of Electrical and Electronics Engineers (IEEE)
Wiretapping
Self Replicating
proxy server
14. nmap
Fiber Distributed Data Interface (FDDI)
No previous knowledge of the network
-p <port ranges>
Buffer
15. Hashing algorithm that results in a 128-bit output.
Timestamping
MD5
-oN
service level agreements (SLAs)
16. The process of recording activity on a system for monitoring and later review.
Cold Site
spam
Vulnerability Assessment
Auditing
17. A method of external testing whereby several systems or resources are used together to effect an attack.
private network address
Daisy Chaining
404EE
rootkit
18. A technology where you advertise one IP address externally and data packets are rerouted to the appropriate IP address inside your network by a device providing translation services. In this way - IP addresses of machines on your internal network are
Buffer Overflow
Network Address Translation (NAT)
Fiber Distributed Data Interface (FDDI)
Database
19. The set of all hardware - firmware - and/or software components critical to IT security. Bugs or vulnerabilities occurring inside the TCB might jeopardize the security properties of the entire system.
Trusted Computer Base (TCB)
Console Port
Serial Line Internet Protocol (SLIP)
iris scanner
20. A trusted entity that issues and revokes public key certificates. In a network - a CA is a trusted entity that issues - manages - and revokes security credentials and public keys for message encryption and/or authentication. Within a public key infra
Cracker
Certificate Authority (CA)
Exposure Factor
Zombie
21. The means by which a recipient of a message can ensure the identity of the sender and that neither party can deny having sent or received the message. The most common method is through digital certificates.
Information Technology (IT) security architecture and framework
non-repudiation
John the Ripper - LOphtcrack - Ophtcrack - Cain and Abel
key exchange protocol
22. A three-step process computers execute to negotiate a connection with one another. The three steps are SYN - SYN/ACK - ACK.
Brute-Force Password Attack
Three-Way (TCP) Handshake
human-based social engineering
Sign in Seal
23. A physical security attack where the attacker sifts through garbage and recycle bins for information that may be useful on current and future attacks
-PM
Dumpster Diving
port knocking
File Transfer Protocol (FTP)
24. An Application layer protocol for sending electronic mail between servers.
-PB
asynchronous transmission
Simple Mail Transfer Protocol (SMTP)
Fiber Distributed Data Interface (FDDI)
25. In computer security - this is an algorithm that uses separate keys for encryption and decryption.
Asymmetric Algorithm
Covert Channel
remote procedure call (RPC)
Point-to-Point Protocol (PPP)
26. Also known as a public key certificate - this is an electronic file that is used to verify a user's identity - providing non-repudiation throughout the sys-tem. Certificates contain the entity's public key - serial number - version - subject - algori
Client
operating system attack
-PB
Digital Certificate
27. A measurable - physical characteristic used to recognize the identity - or verify the claimed identity - of an applicant. Facial images - fingerprints - and handwriting samples are all examples of biometrics.
port knocking
Biometrics
Tunneling
spyware
28. A VPN tunneling protocol with encryption. PPTP connects two nodes in a VPN by using one TCP port for negotiation and authentication and one IP protocol for data transfer.
Point-to-Point Tunneling Protocol (PPTP)
File Transfer Protocol (FTP)
Hierarchical File System (HFS)
Level I assessment
29. The contents of a packet. A system attack requires the attacker to deliver a malicious payload that is acted upon and executed by the system.
Tunnel
Banner Grabbing
Assessment
payload
30. The lack of clocking (imposed time ordering) on a bit stream.
Baseline
Trusted Computer Base (TCB)
Post Office Protocol 3 (POP3)
Asynchronous
31. Physical socket provided on routers and switches for cable connections between a computer and the router/switch. This connection enables the computer to configure - query - and troubleshoot the router/switch by use of a terminal emulator and a comman
Simple Network Management Protocol (SNMP)
Echo request
Console Port
separation of duties
32. The exploitation of a security vulnerability
route
Time exceeded
security breach or security incident
DNS enumeration
33. Incremental Substitution
-sL
Replacing numbers in a url to access other files
Daemon
Digital Certificate
34. A device that receives and sends data packets between two or more networks; the packet headers and a forwarding table provide the router with the information necessary for deciding which interface to use to forward packets.
Copyright
Asymmetric Algorithm
router
HIDS
35. A text file stored within a browser by a web server that maintains information about the connection. Cookies are used to store information to maintain a unique but consistent surfing experience - but can also contain authentication parameters. Cookie
Cookie
Availability
Wi-Fi Protected Access (WPA)
Community String
36. Provides data encryption for IEEE 802.11 wireless networks so data can only be decrypted by the intended recipients.
Buffer Overflow
Echo request
MD5
Wi-Fi Protected Access (WPA)
37. Polymorphic Virus
Tunnel
self encrypting
A R
forwarding
38. A value assigned to uniquely identify a single wide area network (WAN) in wireless LANs. SSIDs are broadcast by default - and are sent in the header of every packet. SSIDs provide no encryption or security.
identity theft
Service Set Identifier (SSID)
-sP
piggybacking
39. Using conversation or some other interaction between people to gather useful information.
False Acceptance Rate (FAR)
human-based social engineering
Cryptographic Key
Asymmetric
40. Confidentiality - Integrity - and Availability are the three aspects of security and make up the triangle.
Simple Network Management Protocol (SNMP)
NOP
CIA triangle
-PP
41. A denial-of-service attack where the attacker sends a ping to the network's broadcast address from the spoofed IP address of the target. All systems in the subnet then respond to the spoofed address - eventually flooding the device.
-PT
Smurf attack
RID Resource identifier
Common Internet File System/Server Message Block
42. A protocol used for sending and receiving log information for nodes on a network.
CIA triangle
Finger
Archive
Syslog
43. A Unix-like computer operating system descending from the BSD. Open-BSD includes a number of security features absent or optional in other operating systems.
-PI
OpenBSD
security bulletins
INFOSEC Assessment Methodology (IAM)
44. ex 02
Transport Layer Security (TLS)
S
Simple Network Management Protocol (SNMP)
false rejection rate (FRR)
45. A communications protocol used for browsing the Internet.
payload
Hypertext Transfer Protocol (HTTP)
Cloning
ping sweep
46. A means of restricting access to system resources based on the sensitivity (as represented by a label) of the information contained in the system resource and the formal authorization (that is - clearance) of users to access information of such sensi
Wiretapping
Redundant Array of Independent Disks (RAID)
Mandatory access control (MAC)
Access Control List (ACL)
47. The subjective - potential percentage of loss to a specific asset if a specific threat is realized. The exposure factor (EF) is a subjective value the person assessing risk must define.
Zenmap
Defines legal email marketing
Exposure Factor
Time To Live (TTL)
48. A command that instructs the system processor to do nothing. Many overflow attacks involve stringing several NOP operations together (known as a NOP sled).
NOP
serial scan & 300 sec wait
Warm Site
phishing
49. Recording the time - normally in a log file - when an event happens or when information is created or modified.
Auditing
Timestamping
Internet service provider (ISP)
proxy server
50. don't ping
Tiger Team
local area network (LAN)
Simple Object Access Protocol (SOAP)
-P0