SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CEH: Certified Ethical Hacker
Start Test
Study First
Subjects
:
certifications
,
ceh
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. 18 U.S.C. 1030
Replacing numbers in a url to access other files
Fraud and related activity in connection with computers
pattern matching
gray hat
2. An outdated symmetric cipher encryption algorithm - previously U.S. government-approved and used by business and civilian government agencies. DES is no longer considered secure due to the ease with which the entire keyspace can be attempted using mo
polymorphic virus
piggybacking
Data Encryption Standard (DES)
Mandatory access control (MAC)
3. The act or actions of a hacker to put forward a cause or a political agenda - to affect some societal change - or to shed light on something he feels to be political injustice. These activities are usually illegal in nature.
-p <port ranges>
Secure Sockets Layer (SSL)
hacktivism
iris scanner
4. A nonnumerical - subjective risk evaluation. Used with qualitative assessment (an evaluation of risk that results in ratings of none - low - medium - and high for the probability.)
hot site
qualitative analysis
Boot Sector Virus
Replacing numbers in a url to access other files
5. Vulnerability Scanning
HIDS
human-based social engineering
The automated process of proactively identifying vulnerabilities of computing systems present in a network
honeypot
6. Policy stating what users of a system can and cannot do with the organization's assets.
symmetric algorithm
Acceptable Use Policy (AUP)
security breach or security incident
Zombie
7. An approach to restricting system access to authorized users in which roles are created for various job functions. The permissions to perform certain operations are assigned to specific roles. Members of staff (or other system users) are assigned par
Reconnaissance - Scanning - Gaining Access - Maintaining Access - Covering Tracks
TACACS
Wi-Fi
role-based access control
8. An application that monitors a computer or network to identify - and prevent - malware. AV is usually signature-based - and can take multiple actions on defined malware files/activity.
Asynchronous
session hijacking
-PP
Antivirus (AV) software
9. The concept of having more than one person required to complete a task
separation of duties
Fraud and related activity in connection with computers
Data Encryption Standard (DES)
rogue access point
10. An organized collection of data.
XOR Operation
Database
port knocking
identity theft
11. A network administration command-line tool available for many operating systems for querying the Domain Name System (DNS) to obtain domain name or IP address mappings or any other specific DNS record.
Data Link layer
enumeration
nslookup
-p <port ranges>
12. A method of evaluating the security of a computer system or network by simulating an attack from a malicious source.
penetration testing
Daisy Chaining
Google hacking
Zero Subnet
13. An inspection of a place where a company or individual proposes to work - to gather the necessary information for a design or risk assessment.
Information Technology (IT) security architecture and framework
site survey
-oA
POP 3
14. The security property that data is not modified in an unauthorized and undetected manner. Also - the principle and measures taken to ensure that data received is in the exact same condition and state as when it was originally transmitted.
Antivirus (AV) software
Finding a directory listing and gaining access to a parent or root file for access to other files
integrity
polymorphic virus
15. A program or piece of code inserted into a system - usually covertly - with the intent of compromising the confidentiality - integrity - or availability of the victim's data - applications - or operating system. Malware consists of viruses - worms -
session hijacking
Man-in-the-middle attack
Malware
-PT
16. A skilled hacker that straddles the line between white hat (hacking only with permission and within guidelines) and black hat (malicious hacking for personal gain). Gray hats sometime perform illegal acts to exploit technology with the intent of achi
gray hat
Virus Hoax
serialize scans & 15 sec wait
-sO
17. A routing protocol developed to be used within a single organization.
Interior Gateway Protocol (IGP)
identity theft
Cold Site
Defines legal email marketing
18. A value assigned to uniquely identify a single wide area network (WAN) in wireless LANs. SSIDs are broadcast by default - and are sent in the header of every packet. SSIDs provide no encryption or security.
Defense in Depth
SOA record
Electronic Code Book (ECB)
Service Set Identifier (SSID)
19. A utility that traces a packet from your computer to an Internet host - showing how many hops the packet takes to reach the host and how long the packet requires to complete the hop.
Tiger Team
Traceroute
FreeBSD
Authentication
20. A unit of information formatted according to specific protocols that allows precise transmittal of data from one network node to another. Also called a datagram or data packet - a packet contains a header (container) and a payload (contents). Any IP
Methodology
spyware
The automated process of proactively identifying vulnerabilities of computing systems present in a network
packet
21. Version Detection Scan
Domain Name System (DNS) lookup
Active Attack
-sV
script kiddie
22. A one-way mathematical function that generates a fixedlength numerical string (hash) from a given data input. MD5 and SHA-1 are hashing algorithms.
SMB
hashing algorithm
Asymmetric
public key
23. Port 389
Bluesnarfing
LDAP
Baseline
Covert Channel
24. Security identifier. The method by which Windows identifies user - group - and computer accounts for rights and permissions.
Digital Signature
Application Layer
User Datagram Protocol (UDP)
SID
25. A communications channel that is being used for a purpose it was not intended for - usually to transfer information secretly.
Domain Name System (DNS) cache poisoning
CAM table
Audit Trail
Covert Channel
26. Port Scanning
27. A utility that sends an ICMP Echo message to determine if a specific IP address is accessible; if the message receives a reply - the address is reachable.
Packet Internet Groper (ping)
security defect
Corrective Controls
War Chalking
28. A limited-function version of the Internetworking Operating System (IOS) - held in read-only memory in some earlier models of Cisco devices - capable of performing several seldom-needed low-level functions such as loading a new IOS into Flash memory
Master boot record infector
Vulnerability Assessment
Audit Data
RxBoot
29. A limit on the amount of time or number of iterations or transmissions in computer and network technology a packet can experience before it will be discarded.
Time To Live (TTL)
Audit Trail
ping sweep
Event
30. Port 31337
Address Resolution Protocol (ARP) table
Packet Internet Groper (ping)
Back orifice
Black Box Testing
31. ICMP Timestamp
HTTP tunneling
-PP
firewalking
Tiger Team
32. A situation in which an IDS or other sensor triggers on an event as an intrusion attempt - when it was actually legitimate traffic.
promiscuous mode
Traceroute
NetBus
false negative
33. SYN Ping
Covert Channel
-PS
symmetric encryption
SYN attack
34. An Internet routing protocol used to exchange routing information within an autonomous system.
RxBoot
ad hoc mode
Interior Gateway Protocol (IGP)
Bluesnarfing
35. A set of exclusive rights granted by the law of a jurisdiction to the author or creator of an original work - including the right to copy - distribute - and adapt the work.
infrastructure mode
Distributed DoS (DDoS)
Copyright
Self Replicating
36. Attacks on the actual programming code of an application.
Videocipher II Satellite Encryption System
security by obscurity
Acknowledgment (ACK)
Application-Level Attacks
37. The process of using easily accessible DNS records to map a target network's internal hosts.
security breach or security incident
Reconnaissance - Scanning - Gaining Access - Maintaining Access - Covering Tracks
rogue access point
DNS enumeration
38. nmap
Secure Multipurpose Mail Extension (S/MIME)
--randomize_hosts -O OS fingerprinting
SYN attack
Information Technology (IT) asset criticality
39. A set of rules defined to screen network packets based on source address - destination address - or protocol; these rules determine whether the packet will be forwarded or discarded.
Bug
-sF
Tini
Filter
40. A computer security expert who performs security audits and penetration tests against systems or network segments - with the owner's full knowledge and permission - in an effort to increase security.
Domain Name System (DNS)
End User Licensing Agreement (EULA)
Ethical Hacker
Authorization
41. Layer 6 of the OSI reference model. The Presentation layer ensures information sent by the Application layer of the sending system will be readable by the Application layer of the receiving system.
footprinting
802.11
remote access
Presentation layer
42. Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality - integrity - or availability of an information system. A virus - worm - Trojan horse - or other code-based entity that infects a
source routing
Computer-Based Attack
Malicious code
Eavesdropping
43. The result of using a private key to encrypt a hash value for identification purposes within a PKI system. The signature can be decoded by the originator's public key - verifying his identity and providing non-repudiation. A valid digital signature g
Bluejacking
Digital Signature
Auditing
security bulletins
44. Polymorphic Virus
self encrypting
route
hashing algorithm
RxBoot
45. A standard developed to enable routers to exchange messages containing information about routes to reach subnets in the network.
Network Address Translation (NAT)
Routing Protocol
S
suicide hacker
46. Transmitting one protocol encapsulated inside another protocol.
Tunneling
net use \[target ip]IPC$ '' /user:''
Active Directory (AD)
A series of messages sent by someone attempting to break into a computer to learn about the computer's network services.
47. A backup facility with the electrical and physical components of a computer facility - but with no computer equipment in place. The site is ready to receive the necessary replacement computer equipment in the event the user has to move from his main
Man-in-the-middle attack
network operations center (NOC)
Cold Site
Address Resolution Protocol (ARP) table
48. A security tool designed to protect a system or network against attacks by comparing traffic patterns against a list of both known attack signatures and general characteristics of how attacks may be carried out. Threats are rated and protective measu
hash
symmetric algorithm
intrusion prevention system (IPS)
symmetric encryption
49. A Unix-like computer operating system descending from the BSD. Open-BSD includes a number of security features absent or optional in other operating systems.
S
Address Resolution Protocol (ARP)
router
OpenBSD
50. An unknown deficiency in software or some other product that results in a security vulnerability being identified.
Auditing
Dumpster Diving
Malicious code
security defect