Ethical Hacking
This test contains the questions related to the CEH (Certified Ethical Hacker) exam certification. These are useful for other exams like UGC/NET, GATE etc.
Questions
Which of the following is/are correct statement (s) about effects of Hacking Attacks?
- Hacking attacks can have detrimental effects on the victim.
- The Malware infects desktop computers can reveal administrator credentials or FTP credentials.
- Vulnerabilities in the server operating system can provide a hacker access to the files that make up the web site.
- All of the above
- Only (1) and (3) are correct
Which of the following is/are applicable for the 'Scanning phase' of hacking?
- It involves gathering information regarding a potential target without the targeted individual or company’s knowledge.
- It involves probing the network to discover individual hosts, IP addresses and services on the network.
- In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
- It involves taking the information discovered during reconnaissance and using it to examine the network.
- Both (3) and (4)
Which of the following is/are applicable for the 'Reconnaissance phase' of hacking?
- It involves gathering information regarding a potential target without the targeted individual or company’s knowledge.
- It involves probing the network to discover individual hosts, IP addresses and services on the network.
- It involves taking the information discovered during reconnaissance and using it to examine the network.
- In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
- Both (1) and (2)
Which of the following is/are applicable for 'Enumeration' in Ethical Hacking?
- It is the process to gather the information about a target machine by actively connecting to it.
- This process is used to check and identify the user's specific details.
- This process is used to establish null sessions and connections.
- All of the above
- Only (1) and (2)
Which of the following is/are applicable for the 'Maintaining Access phase' of hacking?
- It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
- It involves probing the network to discover individual hosts, IP addresses and services on the network.
- In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
- It involves taking the information discovered during reconnaissance and using it to examine the network.
- Both (3) and (4)
Which of the following is/are applicable for the 'Gaining Access phase' of hacking?
- In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
- It involves taking the information discovered during reconnaissance and using it to examine the network.
- It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
- In this phase, the vulnerabilities discovered during the reconnaissance and scanning phase are now exploited to gain access.
- None of the above
Which of the following is/are applicable about Vulnerability Research in Ethical Hacking?
- It is the process by which security flaws in technology are identified.
- It involves reverse engineering process.
- Any technology vendor can use vulnerability research services.
- All of the above
- Both (1) and (3)
Which of the following is / are not the Application level attacks in ethical hacking?
- The attacks on Voice over IP (VoIP).
- The attacks on the mail server and web apps.
- Several protocol attacks.
- Exploiting specific network protocol implementations.
- Both (3) and (4)
Which of the following is/are applicable about the Port Scanning in Ethical Hacking?
- Port Scanning is used to find out the vulnerabilities in the services listing on a port.
- In this scanning, the associate resources find out the parts of the target organisation.
- This scanning involves connecting with TCP and UDP ports on a system.
- The most common and popular tool is Nmap in Port scanning.
- All of the above
Which of the following is/are incorrect about 'Covering Tracks' in hacking?
- In this process, the hackers cover their tracks to avoid detection by security personnel.
- In this process, the hackers remove all traces of the attack, such as log files or intrusion detection system (IDS) alarms.
- In this process, once the hacker owns the system, they can use it as a base to launch additional attacks.
- The steganography, the use of tunneling protocols and altering log files are the example of such processes.
- Both (2) and (3)
Which of the following is/are the scenarios of Computer hacking?
- Hacking is a breach of computer security.
- Hackers may even delete sensitive information on gaining access to it.
- Identity theft is another important consequence of computer hacking.
- It can lead to theft of critical business information.
- All of the above
Which of the following is/are the Network infrastructure attacks in Ethical Hacking?
- The attacks on Voice over IP (VoIP).
- Exploiting specific network protocol implementations.
- Installing a network analyzer on a network and capturing every packet.
- Flooding a network with multiple requests.
- Both (3) and (4)
Which of the following is/are the Operating System level attacks in ethical hacking?
- The attacks on Voice over IP (VoIP).
- Exploiting specific network protocol implementations.
- Attacking built-in authentication systems.
- Breaking file system security.
- Option (2), (3) and (4)
Which of the following are the causes to apply Penetration test in Ethical Hacking?
- To determe the feasibility of a particular set of attack vectors.
- Penetration tester identifies all level vulnerabilities for a successful exploit.
- Assessing the magnitude of potential business and operational impacts of successful attacks.
- All of the above
- Both (1) and (2)
Which of the following is/are correct about IP spoofing attack in hacking?
- The attack may be directed to a specific computer addressed as though it is from that same computer.
- In this attack, the hackers may be able to break through other friendly but less secure networks and get access to your network using this method.
- This attack may cause the IP address location ambiguity.
- All of the above
- Both (1) and (3)
Which of the following is called Password cracking attack in hacking?
- In this attack, the attacker uses the authentication to track the session information.
- In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
- This is an attack where DNS information is falsified.
- This attack may cause unauthorized access in the system.
- Both (1) and (4)
Which of the following is known as Server spoofing in hacking?
- In this attack, the attacker uses the LANMAN authentication to get information about the credentials of the network packets.
- By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
- In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
- Both (1) and (2)
- None of the above
Which of the following is called Session hijacking attack?
- In this attack, the attacker uses the authentication to track the session information.
- In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
- This is an attack where DNS information is falsified.
- By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
- None of the above
Which of the following is/are applicable for Ping broadcast attack in hacking?
- In this attack, a ping request packet is sent to a broadcast network address where there are many hosts.
- The source address is shown in the packet to be the IP address of the computer to be attacked.
- This attack may cause some network delay with lot of ping traffic.
- All of the above
- Both (1) and (2)
Which of the following is/are applicable for Teardrop attack in hacking?
- In this attack, a ping request packet is sent to a broadcast network address where there are many hosts.
- In this attack, one packet in the network may cause the overlappings in the existing packet.
- This attack may cause an unexpected error condition to occur on the victim host.
- All of the above
- Both (2) and (3)