Ethical Hacking Online Quiz

Comprehensive quiz covering ethical hacking fundamentals including reconnaissance, scanning, enumeration, various attack types (DDoS, XSS, phishing), security tools (Nmap, Wireshark), malware, penetration testing methodologies, and the CIA triad.

62 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Nslookup can be used to gather information regarding which of the following?

  1. Host names and IP addresses
  2. Whois information
  3. DNS server locations
  4. Name server types and operating systems
Question 2 Multiple Choice (Single Answer)

What is the first phase of hacking?

  1. Attack
  2. Maintaining access
  3. Gaining access
  4. Reconnaissance
Question 3 Multiple Choice (Single Answer)

Performing a shoulder surfing in order to check other’s password is ____________ ethical practice.

  1. a good
  2. not so good
  3. very good social engineering practice
  4. a bad
Question 4 Multiple Choice (Single Answer)

Which method of hacking will record all your keystrokes?

  1. Keyhijacking
  2. Keyjacking
  3. Keylogging
  4. Keyboard monitoring
Question 5 Multiple Choice (Single Answer)

Which of the following is known as Malicious software?

  1. Illegalware
  2. Badware
  3. Malware
  4. Maliciousware
Question 6 Multiple Choice (Single Answer)

Firewalls are used to protect against _________.

  1. data driven attacks
  2. fire attacks
  3. virus attacks
  4. unauthorised access
Question 7 Multiple Choice (Single Answer)

Bots is a _______________

  1. Program to send mails automatically
  2. Program to monitor logins
  3. Program to specific tasks on a network
  4. Program to check virus
Question 8 Multiple Choice (Single Answer)

IPS defines as

  1. Intrusion Prevention System
  2. Intrusion Precaution System
  3. Intrusion Preservation System
  4. Intrusion Provision System
Question 9 Multiple Choice (Single Answer)

Known bugs can be solved or removed by __________________ develop by the vendors of the application.

  1. removing the application
  2. changing the software
  3. installing security patches
  4. installing database patches
Question 10 Multiple Choice (Single Answer)

Wireshark is a ____________ tool.

  1. network protocol analysis
  2. network connection security
  3. connection analysis
  4. defending malicious packet-filtering
Question 11 Multiple Choice (Single Answer)

Enumeration is part of what phase of ethical hacking?

  1. Reconnaissance
  2. Maintaining Access
  3. Gaining Access
  4. Scanning
Question 12 Multiple Choice (Single Answer)

Why would a hacker use a proxy server?

  1. To create a stronger connection with the target.
  2. To create a ghost server on the network.
  3. To obtain a remote access connection.
  4. To hide malicious activity on the network.
Question 13 Multiple Choice (Single Answer)

Which Nmap scan is does not completely open a TCP connection?

  1. SYN stealth scan
  2. TCP connect
  3. XMAS tree scan
  4. ACK scan
Question 14 Multiple Choice (Single Answer)

A scan that checks a system for known vulnerabilities.

  1. Vulnerability
  2. Availability
  3. Security Triad
  4. Vulnerability Scan
Question 15 Multiple Choice (Single Answer)

Which among the following is a password recovery tool for Microsoft Operating Systems?

  1. Metasploit
  2. Cain and abel
  3. NMAP
  4. Angry IP Scanner
Question 16 Multiple Choice (Single Answer)

What is fullform of NMAP?

  1. Network Mapping
  2. Network Management
  3. Network Mapper
  4. Network Monitoring
Question 17 Multiple Choice (Single Answer)

In which testing the results vary from test to test?

  1. Automated
  2. Manual
  3. Complex
  4. Dual
Question 18 Multiple Choice (Single Answer)

Among the following which type of testing is more efficient and fast?

  1. Manual
  2. Complex
  3. Automated
  4. Dual
Question 19 Multiple Choice (Single Answer)

Among the following which type of testing is exhaustive and time taking?

  1. Manual
  2. Complex
  3. Dual
  4. Automated
Question 20 Multiple Choice (Single Answer)

Which type of penetration testing requires expert engineers ?

  1. Automated
  2. Manual
  3. Complex
  4. Dual
Question 21 Multiple Choice (Single Answer)

Which type of penetration testing even a learner can run?

  1. Automated
  2. Manual
  3. Complex
  4. Dual
Question 22 Multiple Choice (Single Answer)

In which testing programming Knowledge is required to carry out testing?

  1. System Testing
  2. Unit Testing
  3. White box testing
  4. Black box testing
Question 23 Multiple Choice (Single Answer)

What is full form of NDA?

  1. Non-Disclosure Agreement
  2. Non –Divisible Agreement
  3. Non-Distributed Agreement
  4. Never Disclose Agreement
Question 24 Multiple Choice (Single Answer)

Anyone who is familiar with penetration testing can perform ______ test.

  1. Ribbon
  2. Pen
  3. System
  4. Audit
Question 25 Multiple Choice (Single Answer)

Hackers who help in finding bugs and vulnerabilities in a system & don’t intend to crack a system are termed as ________

  1. Black Hat hackers
  2. White Hat Hackers
  3. Grey Hat Hackers
  4. Red Hat Hackers
Question 26 Multiple Choice (Single Answer)

What is the primary goal of an Ethical Hacker ?

  1. Avoiding detection
  2. Testing security controls
  3. Resolving security vulnerabilities
  4. Determining return on investment for security measures
Question 27 Multiple Choice (Single Answer)

What type of attack tries to guess password by trying common words

  1. Dictionary attack
  2. Brute force attack
  3. Man in the middle attack
  4. Smurf attack
Question 28 Multiple Choice (Single Answer)

Victims of phishing are mostly ___________________

  1. Tech enthusiast
  2. Professional computer engineers
  3. Lack of computer knowledge
  4. Lack of management skill
Question 29 Multiple Choice (Single Answer)

DDoS stands for _________________

  1. Direct Distribution of Server
  2. Distributed Denial of Service
  3. Direct Distribution of Service
  4. Distributed Denial of Server
Question 30 Multiple Choice (Single Answer)

XSS stands for _________________

  1. Crack Site Scripting
  2. Cross Site Server
  3. Cross Site Scripting
  4. Crack Server Scripting
Question 31 Multiple Choice (Single Answer)

A _________ attack has the potential to infect the members of the targeted victim group.

  1. Passive
  2. Active
  3. Waterhole
  4. DOS
Question 32 Multiple Choice (Single Answer)

Path or means by an attacker gains access to an information system to perform malicious activities is known as _______

  1. Attack vector
  2. Array
  3. Sql injection
  4. Worm
Question 33 Multiple Choice (Single Answer)

Which of the following is the best countermeasure to session hijacking?

  1. Port filtering firewall
  2. Encryption
  3. Session monitoring
  4. Strong passwords
Question 34 Multiple Choice (Single Answer)

What is the first phase of a DDoS attack?

  1. Intrusion
  2. Attack
  3. DoS
  4. Finding a target system
Question 35 Multiple Choice (Single Answer)

What is sniffing?

  1. Sending corrupted data on the network to trick a system
  2. Capturing and deciphering traffic on a network
  3. Corrupting the ARP cache on a target system
  4. Performing a password-cracking attack
Question 36 Multiple Choice (Single Answer)

A __________ is a way to access a computer or device without authentication

  1. Rootkit
  2. Ransomware
  3. Backdoor
  4. Trojan
Question 37 Multiple Choice (Single Answer)

A ________ is software that gives a malicious user "root access," or total control over a computer

  1. keylogger
  2. Ransomware
  3. Rootkit
  4. Spyware
Question 38 Multiple Choice (Single Answer)

__________ is a type of malware that locks a computer or hijacks a user's files until it is paid

  1. Ransomware
  2. Keylogger
  3. Trojan
  4. Stenographer
Question 39 Multiple Choice (Single Answer)

_________ a method of flooding the Internet with copies of the same message.

  1. Adware
  2. Spyware
  3. Malware
  4. spam
Question 40 Multiple Choice (Single Answer)

_________ displays ads on your computer.

  1. Adware
  2. Spyware
  3. Malware
  4. Virus
Question 41 Multiple Choice (Single Answer)

________ is the process of recognizing a user’s identity

  1. Authentication
  2. Authorization
  3. entry
  4. observation
Question 42 Multiple Choice (Single Answer)

__________ means the data is always available and accessible to the right people at the right time.

  1. Confidentiality
  2. Integrity
  3. Availability
  4. authenticity
Question 43 Multiple Choice (Single Answer)

__________ means the data in transit/rest is not modified and is accurate.

  1. Confidentiality
  2. Integrity
  3. Availability
  4. authenticity
Question 44 Multiple Choice (Single Answer)

Ensures that data or an information system is accessed by only an authorized person.

  1. Confidentiality
  2. Integrity
  3. Availability
  4. authenticity
Question 45 Multiple Choice (Single Answer)

_________ attack takes place when one entity pretends to be different entity

  1. Trojan
  2. worms
  3. Masquerade
  4. ransomeware
Question 46 Multiple Choice (Single Answer)

Which attack has the potential to cause major damage to an individual’s or organization’s resource

  1. Passive attack
  2. Active attack
  3. Anti attack
  4. Perfect attack
Question 47 Multiple Choice (Single Answer)

What is the difference between a backdoor and a Trojan?

  1. A Trojan usually provides a backdoor for a hacker.
  2. A backdoor must be installed first.
  3. A Trojan is not a way to access a system.
  4. A backdoor is provided only through a virus, not through a Trojan.
Question 48 Multiple Choice (Single Answer)

What is the process of hiding text within an image called?

  1. Steganography
  2. Encryption
  3. Spyware
  4. Keystroke logging
Question 49 Multiple Choice (Single Answer)

What is a null session?

  1. Connecting to a system with the administrator username and password
  2. Connecting to a system with the admin username and password
  3. Connecting to a system with a random username and password
  4. Connecting to a system with no username and password
Question 50 Multiple Choice (Single Answer)

What is enumeration?

  1. Identifying active systems on the network
  2. Cracking passwords
  3. Identifying users and machine names
  4. Identifying routers and firewalls
Question 51 Multiple Choice (Single Answer)

A packet with all flags set is which type of scan?

  1. Full Open
  2. Syn scan
  3. XMAS
  4. TCP connect
Question 52 Multiple Choice (Single Answer)

What are the three types of scanning?

  1. Port, network, and vulnerability
  2. Port, network, and services
  3. Grey, black, and white hat
  4. Server, client, and network
Question 53 Multiple Choice (Single Answer)

What is an antivirus?

  1. A bigger and more dangerous virus
  2. Software used to duplicate viruses
  3. Computer software used to prevent, detect and remove malicious software
  4. A biological agent that reproduces itself inside the cells of living things
Question 54 Multiple Choice (Single Answer)

The ____________ attack allows an evil page to click on a “victim site” on behalf of the visitor

  1. Session hijacking
  2. Masquerading
  3. SSH
  4. Clickjacking
Question 55 Multiple Choice (Single Answer)

A _________ attack allows a malicious actor to intercept, send and receive data

  1. Brute force
  2. Man in middle
  3. Denial of service
  4. Virus
Question 56 Multiple Choice (Single Answer)

What port number does FTP use?

  1. 21
  2. 25
  3. 23
  4. 80
Question 57 Multiple Choice (Single Answer)

What is it called when a hacker pretends to be a valid user on the system?

  1. Impersonation
  2. Third-person authorization
  3. Help desk
  4. Valid user
Question 58 Multiple Choice (Single Answer)

Using pop-up windows to get a user to give out information is which type of social engineering attack?

  1. Human-based
  2. Computer-based
  3. Nontechnical
  4. Coercive
Question 59 Multiple Choice (Single Answer)

What is footprinting?

  1. Measuring the shoe size of an ethical hacker
  2. Accumulation of data by gathering information on a target
  3. Scanning a target network to detect operating system types
  4. Mapping the physical layout of a target’s network
Question 60 Multiple Choice (Single Answer)

What is the next step to be performed after footprinting?

  1. Scanning
  2. Enumeration
  3. System hacking
  4. Active information gathering
Question 61 Multiple Choice (Single Answer)

The security, functionality, and ease of use triangle illustrates which concept?

  1. As security increases, functionality and ease of use increase.
  2. As security decreases, functionality and ease of use increase.
  3. As security decreases, functionality and ease of use decrease.
  4. Security does not affect functionality and ease of use.
Question 62 Multiple Choice (Single Answer)

_____________ is the technique used in business organizations and firms to protect IT assets.

  1. Ethical hacking
  2. Unethical hacking
  3. Fixing bugs
  4. Internal data-breach