SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CEH: Certified Ethical Hacker
Start Test
Study First
Subjects
:
certifications
,
ceh
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A situation in which an IDS or other sensor triggers on an event as an intrusion attempt - when it was actually legitimate traffic.
false negative
POST
quality of service (QoS)
Internet service provider (ISP)
2. A routing protocol developed to be used within a single organization.
Detective Controls
Domain Name System (DNS) lookup
Interior Gateway Protocol (IGP)
TACACS
3. A command used in HTTP and FTP to retrieve a file from a server.
Secure Multipurpose Mail Extension (S/MIME)
Finger
Acknowledgment (ACK)
GET
4. An attack that combines a brute-force attack with a dictionary attack.
hybrid attack
port scanning
Hacks without permission
Data Link layer
5. A value assigned to uniquely identify a single wide area network (WAN) in wireless LANs. SSIDs are broadcast by default - and are sent in the header of every packet. SSIDs provide no encryption or security.
Service Set Identifier (SSID)
Digital Certificate
sidejacking
Media Access Control (MAC)
6. A device providing temporary - on-demand - point-to-point network access to users.
Access Creep
DNS
Target Of Engagement (TOE)
network access server
7. A set of rules defined by a system administrator that indicates whether access is allowed or denied to resource objects.
rule-based access control
Hypertext Transfer Protocol (HTTP)
remote access
CNAME record
8. A host designed to collect data on suspicious activity.
honeypot
Zone transfer
suicide hacker
Domain Name System (DNS) lookup
9. The monetary loss that can be expected for an asset due to risk over a one-year period. ALE is the product of the annual rate of occurrence (ARO) and the single loss expectancy (SLE). It is mathematically expressed as ALE = ARO
Application-Level Attacks
Annualized Loss Expectancy (ALE)
Domain Name System (DNS)
Vulnerability
10. Layer 7 of the OSI reference model. The Application layer provides services to applications - which allow them access to the network. Protocols such as FTP and SMTP reside here.
logic bomb
Application Layer
symmetric algorithm
Data Link layer
11. A protocol used to pass control and error messages between nodes on the Internet.
Pretty Good Privacy (PGP)
encryption
Internet Control Message Protocol (ICMP)
Secure Multipurpose Mail Extension (S/MIME)
12. Weakness in an information system - system security procedures - internal controls - or implementation that could be exploited or triggered by a threat source.
Vulnerability
routed protocol
Audit Trail
Time Bomb
13. A fully qualified domain name consists of a host and domain name - including a top-level domain such as .com - .net - .mil - .edu -and so on.
fully qualified domain name (FQDN)
Routing Protocol
-sP
risk
14. In regard to hash algorithms - this occurs when two or more distinct inputs produce the same output.
Collision
Authentication Header (AH)
Hacks with permission
Sign in Seal
15. Aggressive scan timing
parallel scan & 300 sec timeout & 1.25 sec/probe
reconnaissance
quantitative risk assessment
FTP
16. The process of transforming ciphertext into plaintext through the use of a cryptographic algorithm.
Macro virus
Internet Protocol (IP)
Decryption
Fast Ethernet
17. Injecting traffic into the network to identify the operating system of a device.
heuristic scanning
Active Fingerprinting
Level III assessment
Crossover Error Rate (CER)
18. A symmetric key cipher where plaintext bits are combined with a pseudo-random cipher bit stream (keystream) - typically by an exclusive-or (XOR) operation. In a stream cipher the plaintext digits are encrypted one at a time - and the transformation o
Auditing
signature scanning
stream cipher
Bluesnarfing
19. The condition of a resource being ready for use and accessible by authorized users.
Internet service provider (ISP)
S
War Driving
Availability
20. An unknown deficiency in software or some other product that results in a security vulnerability being identified.
security defect
Unicode
Network Basic Input/Output System (NetBIOS)
Asymmetric
21. In penetration testing - this is a method of testing the security of a system or subnet without any previous knowledge of the device or network. Designed to simulate an attack by an outside intruder (usually from the Internet).
human-based social engineering
Tini
Local Administrator
Black Box Testing
22. A wireless LAN security standard developed by IEEE. Requires Temporal Key Integrity Protocol (TKIP) and Advanced Encryption Standard (AES).
spyware
Fiber Distributed Data Interface (FDDI)
Unicode
802.11 i
23. A proprietary - open - wireless technology used for transferring data from fixed and mobile devices over short distances.
Bluetooth
Presentation layer
Eavesdropping
The automated process of proactively identifying vulnerabilities of computing systems present in a network
24. A set of related communications protocols operating together as a group to address communication at some or all of the seven layers of the OSI reference model.
protocol stack
Worm
Demilitarized Zone (DMZ)
NT LAN Manager (NTLM)
25. A set of hardware - software - people - policies - and procedures needed to create - manage - distribute - use - store - and revoke digital certificates.
public key infrastructure (PKI)
audit
Time exceeded
Eavesdropping
26. A person or entity indirectly involved in a relationship between two principles.
public key
Overwhelm CAM table to convert switch to hub mode
Vulnerability
Third Party
27. A social-engineering attack that manipulates the victim into calling the attacker for help.
Defines legal email marketing
forwarding
reverse social engineering
Domain Name System (DNS) cache poisoning
28. The act of checking some sequence of tokens for the presence of the constituents of some pattern.
Hypertext Transfer Protocol Secure (HTTPS)
honeypot
pattern matching
R
29. A term trademarked by the Wi-Fi Alliance - used to define a standard for devices to use to connect to a wireless network.
private network address
HIDS
Wi-Fi
local area network (LAN)
30. A systematic process for the assessment of security vulnerabilities.
network interface card (NIC)
INFOSEC Assessment Methodology (IAM)
smart card
Backdoor
31. Hashing algorithm that results in a 128-bit output.
-sX
MD5
protocol stack
public key infrastructure (PKI)
32. The process of systematically testing each port on a firewall to map rules and determine accessible ports.
Tini
firewalking
Cracker
Real application encompassing Trojan
33. Version Detection Scan
Authentication
risk transference
parallel scan & 75 sec timeout & 0.3 sec/probe
-sV
34. A derogatory term used to describe an attacker - usually new to the field - who uses simple - easy-to-follow scripts or programs developed by others to attack computer systems and networks and deface websites.
Backdoor
script kiddie
hacktivism
802.11
35. Incremental Substitution
Replacing numbers in a url to access other files
Buffer Overflow
End User Licensing Agreement (EULA)
Smurf attack
36. All measures and techniques taken to gather information about an intended target. Footprinting can be passive or active.
security incident response team (SIRT)
footprinting
Address Resolution Protocol (ARP)
personal identification number (PIN)
37. A network traffic management technique designed to allow applications to specify the route a packet will take to a destination - regardless of what the route tables between the two systems say.
Crossover Error Rate (CER)
footprinting
source routing
NOP
38. Port 161/162
-PB
S
SNMP
false rejection rate (FRR)
39. A string used for authentication in SNMP. The public community string is used for read-only searches - whereas the private community string is used for read/write. Community strings are transmitted in clear text in SNMPv1. SNMPv3 provides encryption
parallel scan & 300 sec timeout & 1.25 sec/probe
security controls
Replacing numbers in a url to access other files
Community String
40. A group of people - gathered together by a business entity - working to address a specific problem or goal.
Port Address Translation (PAT)
Tiger Team
impersonation
War Dialing
41. A portion of memory used to temporarily store output or input data.
Filter
DNS
Buffer
Interior Gateway Protocol (IGP)
42. Port 53
DNS
Digital Watermarking
personal identification number (PIN)
Level I assessment
43. ACK Scan
Internet Protocol (IP)
File Transfer Protocol (FTP)
-sA
quantitative risk assessment
44. The process of attaching a particular protocol header and trailer to a unit of data before transmission on the network. Occurs at layer 2 of the OSI reference model.
Post Office Protocol 3 (POP3)
encapsulation
Banner Grabbing
Cracker
45. A social-engineering attack using computer resources - such as e-mail or IRC.
Computer-Based Attack
-sA
Whois
CIA triangle
46. The subjective - potential percentage of loss to a specific asset if a specific threat is realized. The exposure factor (EF) is a subjective value the person assessing risk must define.
network operations center (NOC)
Exposure Factor
MD5
scope creep
47. Software or firmware intended to perform an unauthorized process that will have an adverse impact on the confidentiality - integrity - or availability of an information system. A virus - worm - Trojan horse - or other code-based entity that infects a
private network address
Domain Name System (DNS) cache poisoning
Malicious code
rootkit
48. An attack against an authentication protocol in which the attacker intercepts data in transit along the network between the claimant and verifier - but does not alter the data (in other words - eavesdropping).
private network address
Network Basic Input/Output System (NetBIOS)
Brute-Force Password Attack
passive attack
49. A computer process that requests a service from another computer and accepts the server's responses.
Bastion host
Client
-P0
shrink-wrap code attacks
50. ICMP Type/Code 0-0
Competitive Intelligence
XOR Operation
Cold Site
Echo Reply