Test your basic knowledge |

CEH: Certified Ethical Hacker

Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A step-by-step method of solving a problem. In computing security - an algorithm is a set of mathematical rules (logic) for the process of encryption and decryption






2. The steps taken to gather evidence and information on the targets you wish to attack.






3. Also known as the dot-dot-slash attack. Using directory traversal - the attacker attempts to access restricted directories and execute commands outside intended web server directories by using the URL to redirect to an unintended folder location.






4. A hybrid of the HTTP and SSL/TLS protocols that provides encrypted communication and secure identification of a web server.






5. ICMP Type/Code 0-0






6. Formal description and evaluation of the vulnerabilities in an information system






7. An organized collection of data.






8. A social-engineering effort in which the attacker pretends to be an employee - a valid user - or even an executive to elicit information or access.






9. A file system used by the Mac OS.






10. The process of a system providing a fully qualified domain name (FQDN) to a local name server - for resolution to its corresponding IP address.






11. Phases of an attack






12. A cyber attacker who acts without permission from - and gives prior notice to - the resource owner. Also known as a malicious hacker.






13. Monitoring of telephone or Internet conversations - typically by covert means.






14. nmap






15. Hashing algorithm that results in a 128-bit output.






16. The process of recording activity on a system for monitoring and later review.






17. A method of external testing whereby several systems or resources are used together to effect an attack.






18. A technology where you advertise one IP address externally and data packets are rerouted to the appropriate IP address inside your network by a device providing translation services. In this way - IP addresses of machines on your internal network are






19. The set of all hardware - firmware - and/or software components critical to IT security. Bugs or vulnerabilities occurring inside the TCB might jeopardize the security properties of the entire system.






20. A trusted entity that issues and revokes public key certificates. In a network - a CA is a trusted entity that issues - manages - and revokes security credentials and public keys for message encryption and/or authentication. Within a public key infra






21. The means by which a recipient of a message can ensure the identity of the sender and that neither party can deny having sent or received the message. The most common method is through digital certificates.






22. A three-step process computers execute to negotiate a connection with one another. The three steps are SYN - SYN/ACK - ACK.






23. A physical security attack where the attacker sifts through garbage and recycle bins for information that may be useful on current and future attacks






24. An Application layer protocol for sending electronic mail between servers.






25. In computer security - this is an algorithm that uses separate keys for encryption and decryption.






26. Also known as a public key certificate - this is an electronic file that is used to verify a user's identity - providing non-repudiation throughout the sys-tem. Certificates contain the entity's public key - serial number - version - subject - algori






27. A measurable - physical characteristic used to recognize the identity - or verify the claimed identity - of an applicant. Facial images - fingerprints - and handwriting samples are all examples of biometrics.






28. A VPN tunneling protocol with encryption. PPTP connects two nodes in a VPN by using one TCP port for negotiation and authentication and one IP protocol for data transfer.






29. The contents of a packet. A system attack requires the attacker to deliver a malicious payload that is acted upon and executed by the system.






30. The lack of clocking (imposed time ordering) on a bit stream.






31. Physical socket provided on routers and switches for cable connections between a computer and the router/switch. This connection enables the computer to configure - query - and troubleshoot the router/switch by use of a terminal emulator and a comman






32. The exploitation of a security vulnerability






33. Incremental Substitution






34. A device that receives and sends data packets between two or more networks; the packet headers and a forwarding table provide the router with the information necessary for deciding which interface to use to forward packets.






35. A text file stored within a browser by a web server that maintains information about the connection. Cookies are used to store information to maintain a unique but consistent surfing experience - but can also contain authentication parameters. Cookie






36. Provides data encryption for IEEE 802.11 wireless networks so data can only be decrypted by the intended recipients.






37. Polymorphic Virus






38. A value assigned to uniquely identify a single wide area network (WAN) in wireless LANs. SSIDs are broadcast by default - and are sent in the header of every packet. SSIDs provide no encryption or security.






39. Using conversation or some other interaction between people to gather useful information.






40. Confidentiality - Integrity - and Availability are the three aspects of security and make up the triangle.






41. A denial-of-service attack where the attacker sends a ping to the network's broadcast address from the spoofed IP address of the target. All systems in the subnet then respond to the spoofed address - eventually flooding the device.






42. A protocol used for sending and receiving log information for nodes on a network.






43. A Unix-like computer operating system descending from the BSD. Open-BSD includes a number of security features absent or optional in other operating systems.






44. ex 02






45. A communications protocol used for browsing the Internet.






46. A means of restricting access to system resources based on the sensitivity (as represented by a label) of the information contained in the system resource and the formal authorization (that is - clearance) of users to access information of such sensi






47. The subjective - potential percentage of loss to a specific asset if a specific threat is realized. The exposure factor (EF) is a subjective value the person assessing risk must define.






48. A command that instructs the system processor to do nothing. Many overflow attacks involve stringing several NOP operations together (known as a NOP sled).






49. Recording the time - normally in a log file - when an event happens or when information is created or modified.






50. don't ping