SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CEH: Certified Ethical Hacker
Start Test
Study First
Subjects
:
certifications
,
ceh
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A trusted entity that issues and revokes public key certificates. In a network - a CA is a trusted entity that issues - manages - and revokes security credentials and public keys for message encryption and/or authentication. Within a public key infra
Certificate Authority (CA)
INFOSEC Assessment Methodology (IAM)
Transport Layer Security (TLS)
Confidentiality
2. A method of network traffic filtering that monitors the entire communications process - including the originator of the session and from which direction it started.
Administratively Prohibited
Trusted Computer Base (TCB)
risk transference
stateful packet filtering
3. The rate at which a biometric system will incorrectly identify an unauthorized individual and allow them access (see false negative).
Vulnerability
False Acceptance Rate (FAR)
--randomize_hosts -O OS fingerprinting
Dumpster Diving
4. An attack where the hacker positions himself between the client and the server - to intercept (and sometimes alter) data traveling between the two.
session splicing
Man-in-the-middle attack
Daisy Chaining
Digital Watermarking
5. Any kind of connection that allows you to see all traffic passing by. Generally used in reference to a NIDS (network-based IDS) to monitor all traffic.
SSH
HTTP
NOP
network tap
6. A virus designed to infect the master boot record.
Man-in-the-middle attack
Active Fingerprinting
Defines legal email marketing
Master boot record infector
7. Sneaky scan timing
serialize scans & 15 sec wait
File Allocation Table (FAT)
parameter tampering
serial scan & 300 sec wait
8. The process of using easily accessible DNS records to map a target network's internal hosts.
scope creep
null session
Service Set Identifier (SSID)
DNS enumeration
9. Injecting traffic into the network to identify the operating system of a device.
Boot Sector Virus
secure channel
Open System Interconnection (OSI) Reference Model
Active Fingerprinting
10. Process of breaking a packet into smaller units when it is being transmitted over a network medium that's unable to support a transmission unit the original size of the packet.
flood
fragmentation
HIDS
intranet
11. A technology where you advertise one IP address externally and data packets are rerouted to the appropriate IP address inside your network by a device providing translation services. In this way - IP addresses of machines on your internal network are
null session
Network Address Translation (NAT)
encryption
Packet Internet Groper (ping)
12. don't ping
Warm Site
Mantrap
-P0
replay attack
13. A computer virus that infects and spreads in multiple ways.
proxy server
Multipartite virus
802.11
DNS
14. An e-mail protection method using a secret message or image that can be referenced on any official communication with the site; if an e-mail is received without the image or message - the recipient knows it is not legitimate.
Antivirus (AV) software
R
Sign in Seal
Kerberos
15. A NAT method in which multiple internal hosts - using private IP addressing - can be mapped through a single public IP address using the session IDs and port numbers. An internal global IP address can support in excess of 65 -000 concurrent TCP and U
Countermeasures
heuristic scanning
Reconnaissance - Scanning - Gaining Access - Maintaining Access - Covering Tracks
Port Address Translation (PAT)
16. An agreement between the penetration tester and the client detailing the activities the tester is permitted to perform.
Black Hat
Written Authorization
Due Diligence
Information Technology (IT) infrastructure
17. A business - government agency - or educational institution that provides access to the Internet.
Internet service provider (ISP)
enumeration
Authentication
null session
18. A protocol that uses a private key to encrypt data before transmitting confidential documents over the Internet; widely used on e-commerce - banking - and other sites requiring privacy.
Hacks with permission
Secure Sockets Layer (SSL)
rule-based access control
Hypertext Transfer Protocol Secure (HTTPS)
19. CAN-SPAM
private key
public key infrastructure (PKI)
-PI
Defines legal email marketing
20. A standard that provides best-practice recommendations on information security management for use by those responsible for initiating - implementing - or maintaining Information Security Management Systems (ISMS). Information security is defined with
Level III assessment
ISO 17799
SMB
Contingency Plan
21. A network traffic management technique designed to allow applications to specify the route a packet will take to a destination - regardless of what the route tables between the two systems say.
Community String
Access Control List (ACL)
network tap
source routing
22. A device set up to send a response on behalf of an end node to the requesting host. Proxies are generally used to obfuscate the host from the Internet.
Asymmetric Algorithm
proxy server
U P F
Warm Site
23. Start of Authority record. This record identifies the primary name server for the zone. The SOA record contains the host name of the server responsible for all DNS records within the namespace - as well as the basic properties of the domain.
GET
Malicious code
SOA record
route
24. A small Trojan program that listens on port 777.
Tini
packet filtering
infrastructure mode
segment
25. A communications channel that is being used for a purpose it was not intended for - usually to transfer information secretly.
Destination Unreachable
Baseline
Covert Channel
promiscuous mode
26. The use of deceptive computer-based means to trick individuals into disclosing sensitive personal information
hot site
phishing
impersonation
Bluesnarfing
27. Baseband LAN specification developed by Xerox Corporation - Intel - and Digital Equipment Corporation. One of the least expensive - most widely deployed networking standards; uses the CSMA/CD method of media access control.
-PP
-PT
Ethernet
node
28. The directory service created by Microsoft for use on itsnetworks. Provides a variety of network services using Lightweight Directory Access Protocol (LDAP) - Kerberos-based authentication - and single sign-on for user access to network-based resourc
Active Directory (AD)
Destination Unreachable
Anonymizer
MD5
29. A self-replicating malicious program that attempts installation beneath antivirus software by directly intercepting the interrupt handlers of the operating system to evade detection.
Virus Hoax
Tunneling Virus
Information Technology (IT) infrastructure
Bluesnarfing
30. Idlescan
Ethical Hacker
-sI
encapsulation
Bastion host
31. Actions - devices - procedures - techniques - or other measures intended to reduce the vulnerability of an information system.
Countermeasures
Community String
qualitative analysis
Internet Protocol (IP)
32. A communications protocol used for browsing the Internet.
Hypertext Transfer Protocol (HTTP)
signature scanning
scope creep
Virus Hoax
33. An application that monitors a computer or network to identify - and prevent - malware. AV is usually signature-based - and can take multiple actions on defined malware files/activity.
Antivirus (AV) software
Level II assessment
Fraud and related activity in connection with computers
Hypertext Transfer Protocol (HTTP)
34. Port 22
signature scanning
Backdoor
Level II assessment
SSH
35. A value used to control cryptographic operations - such as decryption -encryption - signature generation - and signature verification.
A S
Cryptographic Key
Bug
security controls
36. An attacker who breaks into computer systems with malicious intent - without the owner's knowledge or permission.
Malware
Confidentiality
Client
Black Hat
37. A software or hardware application or device that captures user keystrokes.
keylogger
Blowfish
Corrective Controls
network interface card (NIC)
38. The process of embedding information into a digital signal in a way that makes it difficult to remove.
identity theft
Daisy Chaining
Digital Watermarking
risk transference
39. One or more locations from which control is exercised over a computer - television broadcast - or telecommunications network.
SID
network operations center (NOC)
ping sweep
Service Set Identifier (SSID)
40. SYN Ping
Audit Trail
gateway
Rijndael
-PS
41. A group of people - gathered together by a business entity - working to address a specific problem or goal.
Zero Subnet
-PT
Tiger Team
Discretionary Access Control (DAC)
42. Cracking Tools
Electronic serial number
John the Ripper - LOphtcrack - Ophtcrack - Cain and Abel
-sL
802.11
43. A term representing the responsibility managers and their organizations have to provide information security to ensure the type of control - the cost of control - and the deployment of control are appropriate for the system being managed.
John the Ripper - LOphtcrack - Ophtcrack - Cain and Abel
Contingency Plan
Due Care
replay attack
44. Content Addressable Memory table. Holds all the MAC-address-to-port mappings on a switch.
Algorithm
Password Authentication Protocol (PAP)
Discretionary Access Control (DAC)
CAM table
45. A method of password cracking whereby all possible options are systematically enumerated until a match is found. These attacks try every password (or authentication option) - one after another - until successful. Bruteforce attacks take a long time t
Zone transfer
Brute-Force Password Attack
Defines legal email marketing
Wide Area Network (WAN)
46. A method used to prevent IDS detection by dividing the request into multiple parts that are sent in different packets
session splicing
Blowfish
Cache
net use \[target ip]IPC$ '' /user:''
47. A cyber attacker who acts without permission from - and gives prior notice to - the resource owner. Also known as a malicious hacker.
Cracker
Virus
parallel scan
ISO 17799
48. Created by the U.S. Federal Communications Commission to uniquely identify mobile devices; often represented as an 11-digit decimal number or eight-digit hexadecimal number.
War Driving
Electronic serial number
non-repudiation
Overwhelm CAM table to convert switch to hub mode
49. A programming principle whereby the last piece of data added to the stack is the first piece of data taken off.
Threat
Last In First Out (LIFO)
Buffer
Warm Site
50. The science or study of protecting information - whether in transit or at rest - by using techniques to render the information unusable to anyone who does not possess the means to decrypt it.
Warm Site
null session
Bastion host
Cryptography