Ethical Hacking

This test contains the questions related to the CEH (Certified Ethical Hacker) exam certification. These are useful for other exams like UGC/NET, GATE etc.

20 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Which of the following is/are correct statement (s) about effects of Hacking Attacks?

  1. Hacking attacks can have detrimental effects on the victim.
  2. The Malware infects desktop computers can reveal administrator credentials or FTP credentials.
  3. Vulnerabilities in the server operating system can provide a hacker access to the files that make up the web site.
  4. All of the above
  5. Only (1) and (3) are correct
Question 2 Multiple Choice (Single Answer)

Which of the following is/are applicable for the 'Scanning phase' of hacking?

  1. It involves gathering information regarding a potential target without the targeted individual or company’s knowledge.
  2. It involves probing the network to discover individual hosts, IP addresses and services on the network.
  3. In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
  4. It involves taking the information discovered during reconnaissance and using it to examine the network.
  5. Both (3) and (4)
Question 3 Multiple Choice (Single Answer)

Which of the following is/are applicable for the 'Reconnaissance phase' of hacking?

  1. It involves gathering information regarding a potential target without the targeted individual or company’s knowledge.
  2. It involves probing the network to discover individual hosts, IP addresses and services on the network.
  3. It involves taking the information discovered during reconnaissance and using it to examine the network.
  4. In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
  5. Both (1) and (2)
Question 4 Multiple Choice (Single Answer)

Which of the following is/are applicable for 'Enumeration' in Ethical Hacking?

  1. It is the process to gather the information about a target machine by actively connecting to it.
  2. This process is used to check and identify the user's specific details.
  3. This process is used to establish null sessions and connections.
  4. All of the above
  5. Only (1) and (2)
Question 5 Multiple Choice (Single Answer)

Which of the following is/are applicable for the 'Maintaining Access phase' of hacking?

  1. It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
  2. It involves probing the network to discover individual hosts, IP addresses and services on the network.
  3. In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
  4. It involves taking the information discovered during reconnaissance and using it to examine the network.
  5. Both (3) and (4)
Question 6 Multiple Choice (Single Answer)

Which of the following is/are applicable for the 'Gaining Access phase' of hacking?

  1. In this phase, once a hacker has gained access, they want to keep that access for future exploitation and attacks.
  2. It involves taking the information discovered during reconnaissance and using it to examine the network.
  3. It involves gathering information regarding a potential target without the targeted individual’s or company’s knowledge.
  4. In this phase, the vulnerabilities discovered during the reconnaissance and scanning phase are now exploited to gain access.
  5. None of the above
Question 7 Multiple Choice (Single Answer)

Which of the following is/are applicable about Vulnerability Research in Ethical Hacking?

  1. It is the process by which security flaws in technology are identified.
  2. It involves reverse engineering process.
  3. Any technology vendor can use vulnerability research services.
  4. All of the above
  5. Both (1) and (3)
Question 8 Multiple Choice (Single Answer)

Which of the following is / are not the Application level attacks in ethical hacking?

  1. The attacks on Voice over IP (VoIP).
  2. The attacks on the mail server and web apps.
  3. Several protocol attacks.
  4. Exploiting specific network protocol implementations.
  5. Both (3) and (4)
Question 9 Multiple Choice (Single Answer)

Which of the following is/are applicable about the Port Scanning in Ethical Hacking?

  1. Port Scanning is used to find out the vulnerabilities in the services listing on a port.
  2. In this scanning, the associate resources find out the parts of the target organisation.
  3. This scanning involves connecting with TCP and UDP ports on a system.
  4. The most common and popular tool is Nmap in Port scanning.
  5. All of the above
Question 10 Multiple Choice (Single Answer)

Which of the following is/are incorrect about 'Covering Tracks' in hacking?

  1. In this process, the hackers cover their tracks to avoid detection by security personnel.
  2. In this process, the hackers remove all traces of the attack, such as log files or intrusion detection system (IDS) alarms.
  3. In this process, once the hacker owns the system, they can use it as a base to launch additional attacks.
  4. The steganography, the use of tunneling protocols and altering log files are the example of such processes.
  5. Both (2) and (3)
Question 11 Multiple Choice (Single Answer)

Which of the following is/are the scenarios of Computer hacking?

  1. Hacking is a breach of computer security.
  2. Hackers may even delete sensitive information on gaining access to it.
  3. Identity theft is another important consequence of computer hacking.
  4. It can lead to theft of critical business information.
  5. All of the above
Question 12 Multiple Choice (Single Answer)

Which of the following is/are the Network infrastructure attacks in Ethical Hacking?

  1. The attacks on Voice over IP (VoIP).
  2. Exploiting specific network protocol implementations.
  3. Installing a network analyzer on a network and capturing every packet.
  4. Flooding a network with multiple requests.
  5. Both (3) and (4)
Question 13 Multiple Choice (Single Answer)

Which of the following is/are the Operating System level attacks in ethical hacking?

  1. The attacks on Voice over IP (VoIP).
  2. Exploiting specific network protocol implementations.
  3. Attacking built-in authentication systems.
  4. Breaking file system security.
  5. Option (2), (3) and (4)
Question 14 Multiple Choice (Single Answer)

Which of the following are the causes to apply Penetration test in Ethical Hacking?

  1. To determe the feasibility of a particular set of attack vectors.
  2. Penetration tester identifies all level vulnerabilities for a successful exploit.
  3. Assessing the magnitude of potential business and operational impacts of successful attacks.
  4. All of the above
  5. Both (1) and (2)
Question 15 Multiple Choice (Single Answer)

Which of the following is/are correct about IP spoofing attack in hacking?

  1. The attack may be directed to a specific computer addressed as though it is from that same computer.
  2. In this attack, the hackers may be able to break through other friendly but less secure networks and get access to your network using this method.
  3. This attack may cause the IP address location ambiguity.
  4. All of the above
  5. Both (1) and (3)
Question 16 Multiple Choice (Single Answer)

Which of the following is called Password cracking attack in hacking?

  1. In this attack, the attacker uses the authentication to track the session information.
  2. In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
  3. This is an attack where DNS information is falsified.
  4. This attack may cause unauthorized access in the system.
  5. Both (1) and (4)
Question 17 Multiple Choice (Single Answer)

Which of the following is known as Server spoofing in hacking?

  1. In this attack, the attacker uses the LANMAN authentication to get information about the credentials of the network packets.
  2. By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
  3. In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
  4. Both (1) and (2)
  5. None of the above
Question 18 Multiple Choice (Single Answer)

Which of the following is called Session hijacking attack?

  1. In this attack, the attacker uses the authentication to track the session information.
  2. In this attack, the attacker may fake their IP address so the receiver thinks it is sent from a location that it is not actually from.
  3. This is an attack where DNS information is falsified.
  4. By this attack, the attacker gets the password of a user or administrator on a network and gain unauthorized access.
  5. None of the above
Question 19 Multiple Choice (Single Answer)

Which of the following is/are applicable for Ping broadcast attack in hacking?

  1. In this attack, a ping request packet is sent to a broadcast network address where there are many hosts.
  2. The source address is shown in the packet to be the IP address of the computer to be attacked.
  3. This attack may cause some network delay with lot of ping traffic.
  4. All of the above
  5. Both (1) and (2)
Question 20 Multiple Choice (Single Answer)

Which of the following is/are applicable for Teardrop attack in hacking?

  1. In this attack, a ping request packet is sent to a broadcast network address where there are many hosts.
  2. In this attack, one packet in the network may cause the overlappings in the existing packet.
  3. This attack may cause an unexpected error condition to occur on the victim host.
  4. All of the above
  5. Both (2) and (3)