Ethical Hacking Online Quiz
Comprehensive quiz covering ethical hacking fundamentals including reconnaissance, scanning, enumeration, various attack types (DDoS, XSS, phishing), security tools (Nmap, Wireshark), malware, penetration testing methodologies, and the CIA triad.
Questions
Nslookup can be used to gather information regarding which of the following?
- Host names and IP addresses
- Whois information
- DNS server locations
- Name server types and operating systems
What is the first phase of hacking?
- Attack
- Maintaining access
- Gaining access
- Reconnaissance
Performing a shoulder surfing in order to check other’s password is ____________ ethical practice.
- a good
- not so good
- very good social engineering practice
- a bad
Which method of hacking will record all your keystrokes?
- Keyhijacking
- Keyjacking
- Keylogging
- Keyboard monitoring
Which of the following is known as Malicious software?
- Illegalware
- Badware
- Malware
- Maliciousware
Firewalls are used to protect against _________.
- data driven attacks
- fire attacks
- virus attacks
- unauthorised access
Bots is a _______________
- Program to send mails automatically
- Program to monitor logins
- Program to specific tasks on a network
- Program to check virus
IPS defines as
- Intrusion Prevention System
- Intrusion Precaution System
- Intrusion Preservation System
- Intrusion Provision System
Known bugs can be solved or removed by __________________ develop by the vendors of the application.
- removing the application
- changing the software
- installing security patches
- installing database patches
Wireshark is a ____________ tool.
- network protocol analysis
- network connection security
- connection analysis
- defending malicious packet-filtering
Enumeration is part of what phase of ethical hacking?
- Reconnaissance
- Maintaining Access
- Gaining Access
- Scanning
Why would a hacker use a proxy server?
- To create a stronger connection with the target.
- To create a ghost server on the network.
- To obtain a remote access connection.
- To hide malicious activity on the network.
Which Nmap scan is does not completely open a TCP connection?
- SYN stealth scan
- TCP connect
- XMAS tree scan
- ACK scan
A scan that checks a system for known vulnerabilities.
- Vulnerability
- Availability
- Security Triad
- Vulnerability Scan
Which among the following is a password recovery tool for Microsoft Operating Systems?
- Metasploit
- Cain and abel
- NMAP
- Angry IP Scanner
What is fullform of NMAP?
- Network Mapping
- Network Management
- Network Mapper
- Network Monitoring
In which testing the results vary from test to test?
- Automated
- Manual
- Complex
- Dual
Among the following which type of testing is more efficient and fast?
- Manual
- Complex
- Automated
- Dual
Among the following which type of testing is exhaustive and time taking?
- Manual
- Complex
- Dual
- Automated
Which type of penetration testing requires expert engineers ?
- Automated
- Manual
- Complex
- Dual
Which type of penetration testing even a learner can run?
- Automated
- Manual
- Complex
- Dual
In which testing programming Knowledge is required to carry out testing?
- System Testing
- Unit Testing
- White box testing
- Black box testing
What is full form of NDA?
- Non-Disclosure Agreement
- Non –Divisible Agreement
- Non-Distributed Agreement
- Never Disclose Agreement
Anyone who is familiar with penetration testing can perform ______ test.
- Ribbon
- Pen
- System
- Audit
Hackers who help in finding bugs and vulnerabilities in a system & don’t intend to crack a system are termed as ________
- Black Hat hackers
- White Hat Hackers
- Grey Hat Hackers
- Red Hat Hackers
What is the primary goal of an Ethical Hacker ?
- Avoiding detection
- Testing security controls
- Resolving security vulnerabilities
- Determining return on investment for security measures
What type of attack tries to guess password by trying common words
- Dictionary attack
- Brute force attack
- Man in the middle attack
- Smurf attack
Victims of phishing are mostly ___________________
- Tech enthusiast
- Professional computer engineers
- Lack of computer knowledge
- Lack of management skill
DDoS stands for _________________
- Direct Distribution of Server
- Distributed Denial of Service
- Direct Distribution of Service
- Distributed Denial of Server
XSS stands for _________________
- Crack Site Scripting
- Cross Site Server
- Cross Site Scripting
- Crack Server Scripting
A _________ attack has the potential to infect the members of the targeted victim group.
- Passive
- Active
- Waterhole
- DOS
Path or means by an attacker gains access to an information system to perform malicious activities is known as _______
- Attack vector
- Array
- Sql injection
- Worm
Which of the following is the best countermeasure to session hijacking?
- Port filtering firewall
- Encryption
- Session monitoring
- Strong passwords
What is the first phase of a DDoS attack?
- Intrusion
- Attack
- DoS
- Finding a target system
What is sniffing?
- Sending corrupted data on the network to trick a system
- Capturing and deciphering traffic on a network
- Corrupting the ARP cache on a target system
- Performing a password-cracking attack
A __________ is a way to access a computer or device without authentication
- Rootkit
- Ransomware
- Backdoor
- Trojan
A ________ is software that gives a malicious user "root access," or total control over a computer
- keylogger
- Ransomware
- Rootkit
- Spyware
__________ is a type of malware that locks a computer or hijacks a user's files until it is paid
- Ransomware
- Keylogger
- Trojan
- Stenographer
_________ a method of flooding the Internet with copies of the same message.
- Adware
- Spyware
- Malware
- spam
_________ displays ads on your computer.
- Adware
- Spyware
- Malware
- Virus
________ is the process of recognizing a user’s identity
- Authentication
- Authorization
- entry
- observation
__________ means the data is always available and accessible to the right people at the right time.
- Confidentiality
- Integrity
- Availability
- authenticity
__________ means the data in transit/rest is not modified and is accurate.
- Confidentiality
- Integrity
- Availability
- authenticity
Ensures that data or an information system is accessed by only an authorized person.
- Confidentiality
- Integrity
- Availability
- authenticity
_________ attack takes place when one entity pretends to be different entity
- Trojan
- worms
- Masquerade
- ransomeware
Which attack has the potential to cause major damage to an individual’s or organization’s resource
- Passive attack
- Active attack
- Anti attack
- Perfect attack
What is the difference between a backdoor and a Trojan?
- A Trojan usually provides a backdoor for a hacker.
- A backdoor must be installed first.
- A Trojan is not a way to access a system.
- A backdoor is provided only through a virus, not through a Trojan.
What is the process of hiding text within an image called?
- Steganography
- Encryption
- Spyware
- Keystroke logging
What is a null session?
- Connecting to a system with the administrator username and password
- Connecting to a system with the admin username and password
- Connecting to a system with a random username and password
- Connecting to a system with no username and password
What is enumeration?
- Identifying active systems on the network
- Cracking passwords
- Identifying users and machine names
- Identifying routers and firewalls
A packet with all flags set is which type of scan?
- Full Open
- Syn scan
- XMAS
- TCP connect
What are the three types of scanning?
- Port, network, and vulnerability
- Port, network, and services
- Grey, black, and white hat
- Server, client, and network
What is an antivirus?
- A bigger and more dangerous virus
- Software used to duplicate viruses
- Computer software used to prevent, detect and remove malicious software
- A biological agent that reproduces itself inside the cells of living things
The ____________ attack allows an evil page to click on a “victim site” on behalf of the visitor
- Session hijacking
- Masquerading
- SSH
- Clickjacking
A _________ attack allows a malicious actor to intercept, send and receive data
- Brute force
- Man in middle
- Denial of service
- Virus
What port number does FTP use?
- 21
- 25
- 23
- 80
What is it called when a hacker pretends to be a valid user on the system?
- Impersonation
- Third-person authorization
- Help desk
- Valid user
Using pop-up windows to get a user to give out information is which type of social engineering attack?
- Human-based
- Computer-based
- Nontechnical
- Coercive
What is footprinting?
- Measuring the shoe size of an ethical hacker
- Accumulation of data by gathering information on a target
- Scanning a target network to detect operating system types
- Mapping the physical layout of a target’s network
What is the next step to be performed after footprinting?
- Scanning
- Enumeration
- System hacking
- Active information gathering
The security, functionality, and ease of use triangle illustrates which concept?
- As security increases, functionality and ease of use increase.
- As security decreases, functionality and ease of use increase.
- As security decreases, functionality and ease of use decrease.
- Security does not affect functionality and ease of use.
_____________ is the technique used in business organizations and firms to protect IT assets.
- Ethical hacking
- Unethical hacking
- Fixing bugs
- Internal data-breach