Test your basic knowledge |

CEH: Certified Ethical Hacker

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A trusted entity that issues and revokes public key certificates. In a network - a CA is a trusted entity that issues - manages - and revokes security credentials and public keys for message encryption and/or authentication. Within a public key infra






2. A method of network traffic filtering that monitors the entire communications process - including the originator of the session and from which direction it started.






3. The rate at which a biometric system will incorrectly identify an unauthorized individual and allow them access (see false negative).






4. An attack where the hacker positions himself between the client and the server - to intercept (and sometimes alter) data traveling between the two.






5. Any kind of connection that allows you to see all traffic passing by. Generally used in reference to a NIDS (network-based IDS) to monitor all traffic.






6. A virus designed to infect the master boot record.






7. Sneaky scan timing






8. The process of using easily accessible DNS records to map a target network's internal hosts.






9. Injecting traffic into the network to identify the operating system of a device.






10. Process of breaking a packet into smaller units when it is being transmitted over a network medium that's unable to support a transmission unit the original size of the packet.






11. A technology where you advertise one IP address externally and data packets are rerouted to the appropriate IP address inside your network by a device providing translation services. In this way - IP addresses of machines on your internal network are






12. don't ping






13. A computer virus that infects and spreads in multiple ways.






14. An e-mail protection method using a secret message or image that can be referenced on any official communication with the site; if an e-mail is received without the image or message - the recipient knows it is not legitimate.






15. A NAT method in which multiple internal hosts - using private IP addressing - can be mapped through a single public IP address using the session IDs and port numbers. An internal global IP address can support in excess of 65 -000 concurrent TCP and U






16. An agreement between the penetration tester and the client detailing the activities the tester is permitted to perform.






17. A business - government agency - or educational institution that provides access to the Internet.






18. A protocol that uses a private key to encrypt data before transmitting confidential documents over the Internet; widely used on e-commerce - banking - and other sites requiring privacy.






19. CAN-SPAM






20. A standard that provides best-practice recommendations on information security management for use by those responsible for initiating - implementing - or maintaining Information Security Management Systems (ISMS). Information security is defined with






21. A network traffic management technique designed to allow applications to specify the route a packet will take to a destination - regardless of what the route tables between the two systems say.






22. A device set up to send a response on behalf of an end node to the requesting host. Proxies are generally used to obfuscate the host from the Internet.






23. Start of Authority record. This record identifies the primary name server for the zone. The SOA record contains the host name of the server responsible for all DNS records within the namespace - as well as the basic properties of the domain.






24. A small Trojan program that listens on port 777.






25. A communications channel that is being used for a purpose it was not intended for - usually to transfer information secretly.






26. The use of deceptive computer-based means to trick individuals into disclosing sensitive personal information






27. Baseband LAN specification developed by Xerox Corporation - Intel - and Digital Equipment Corporation. One of the least expensive - most widely deployed networking standards; uses the CSMA/CD method of media access control.






28. The directory service created by Microsoft for use on itsnetworks. Provides a variety of network services using Lightweight Directory Access Protocol (LDAP) - Kerberos-based authentication - and single sign-on for user access to network-based resourc






29. A self-replicating malicious program that attempts installation beneath antivirus software by directly intercepting the interrupt handlers of the operating system to evade detection.






30. Idlescan






31. Actions - devices - procedures - techniques - or other measures intended to reduce the vulnerability of an information system.






32. A communications protocol used for browsing the Internet.






33. An application that monitors a computer or network to identify - and prevent - malware. AV is usually signature-based - and can take multiple actions on defined malware files/activity.






34. Port 22






35. A value used to control cryptographic operations - such as decryption -encryption - signature generation - and signature verification.






36. An attacker who breaks into computer systems with malicious intent - without the owner's knowledge or permission.






37. A software or hardware application or device that captures user keystrokes.






38. The process of embedding information into a digital signal in a way that makes it difficult to remove.






39. One or more locations from which control is exercised over a computer - television broadcast - or telecommunications network.






40. SYN Ping






41. A group of people - gathered together by a business entity - working to address a specific problem or goal.






42. Cracking Tools






43. A term representing the responsibility managers and their organizations have to provide information security to ensure the type of control - the cost of control - and the deployment of control are appropriate for the system being managed.






44. Content Addressable Memory table. Holds all the MAC-address-to-port mappings on a switch.






45. A method of password cracking whereby all possible options are systematically enumerated until a match is found. These attacks try every password (or authentication option) - one after another - until successful. Bruteforce attacks take a long time t






46. A method used to prevent IDS detection by dividing the request into multiple parts that are sent in different packets






47. A cyber attacker who acts without permission from - and gives prior notice to - the resource owner. Also known as a malicious hacker.






48. Created by the U.S. Federal Communications Commission to uniquely identify mobile devices; often represented as an 11-digit decimal number or eight-digit hexadecimal number.






49. A programming principle whereby the last piece of data added to the stack is the first piece of data taken off.






50. The science or study of protecting information - whether in transit or at rest - by using techniques to render the information unusable to anyone who does not possess the means to decrypt it.