Test your basic knowledge |

CEH: Certified Ethical Hacker

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A device or service designed to obfuscate traffic between a client and the Internet. Generally used to make activity on the Internet as untraceable as possible.






2. A documented process for a procedure designed to be consistent - repeatable - and accountable.






3. A measurable - physical characteristic used to recognize the identity - or verify the claimed identity - of an applicant. Facial images - fingerprints - and handwriting samples are all examples of biometrics.






4. The science or study of protecting information - whether in transit or at rest - by using techniques to render the information unusable to anyone who does not possess the means to decrypt it.






5. Sending unsolicited messages over Bluetooth to Bluetooth-enabled devices such as mobile phones - PDAs - or laptop computers.






6. ICMP Timestamp






7. Vulnerability Scanning






8. The act of secretly listening to the private conversations of others without their consent. This can also be done over telephone lines (wiretapping) - e-mail - instant messaging - and other methods of communication considered private






9. ICMP Type/Code 3-13






10. Used to find the domain name associated with an IP address; the opposite of a DNS lookup.






11. PI and PT Ping






12. An extensible mechanism for e-mail. A variety of MIME types exist for sending content such as audio - binary - or video using the Simple Mail Transfer Protocol (SMTP).






13. An attack that combines a brute-force attack with a dictionary attack.






14. A group of penetration testers that assess the security of an organization - which is often unaware of the existence of the team or the exact assignment.






15. The condition of a resource being ready for use and accessible by authorized users.






16. The means by which a recipient of a message can ensure the identity of the sender and that neither party can deny having sent or received the message. The most common method is through digital certificates.






17. A software license agreement; a contract between the 'licensor' and purchaser establishing the right to use the software.






18. Port 53






19. A well-known and studied phenomenon of human nature - whereby a single trait influences the perception of other traits.






20. A software program for remotely controlling a Microsoft Windows computer system over a network. Generally considered malware.






21. Shifting responsibility from one party to another






22. A host designed to collect data on suspicious activity.






23. A portion of memory used to temporarily store output or input data.






24. An evaluation consisting of a document review - interviews - and demonstrations. No hands-on testing is performed.






25. Port 389






26. Occurs when authorized users accumulate excess privileges on a system due to moving from position to position.






27. Hex 10






28. Hex 29






29. The act of using numerous electronic serial numbers on a cell phone until a valid number is located.






30. A security protocol used in IEEE 802.11i to replace WEP without the requirement to replace legacy hardware.






31. IP Protocol Scan






32. The process of a system providing a fully qualified domain name (FQDN) to a local name server - for resolution to its corresponding IP address.






33. A list of IP addresses and corresponding MAC addresses stored on a local computer.






34. A method in cryptography by which cryptographic keys are exchanged between users - allowing use of a cryptographic algorithm (for example - the Diffie-Hellman key exchange).






35. A program designed to browse websites in an automated - methodical manner. Sometimes these programs are used to harvest information from websites - such as e-mail addresses.






36. The process of systematically testing each port on a firewall to map rules and determine accessible ports.






37. A computer network confined to a relatively small area - such as a single building or campus - in which devices connect through high-frequency radio waves using IEEE standard 802.11.






38. A free and popular version of the Unix operating system.






39. A computer file system architecture used in Windows - OS/2 - and most memory cards.






40. Window Scan






41. One or more locations from which control is exercised over a computer - television broadcast - or telecommunications network.






42. A function that is easy to compute in one direction - yet believed to be difficult to compute in the opposite direction (finding its inverse) without special information - called the 'trapdoor.' Widely used in cryptography.






43. Sending packets or requests to another system to gain information to be used to identify weaknesses and protect the system from attacks.






44. Xmas Tree scan






45. FIN Scan






46. An anonymous connection to an administrative share (IPC$) on a Windows machine. Null sessions allow for enumeration of Windows machines - among other attacks.






47. Content Addressable Memory table. Holds all the MAC-address-to-port mappings on a switch.






48. Any circumstance or event with the potential to adversely impact organizationaloperations - organizational assets - or individuals through an information system via unauthorized access - destruction - disclosure - modification of information - and/or






49. The act of checking some sequence of tokens for the presence of the constituents of some pattern.






50. An Internet Protocol Security (IPSec) header used to verify that the contents of a packet have not been modified while the packet was in transit.