Certified Ethical Hacker MCQ Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Ethical Hacker MCQ flashcards as text
Which type of SQL injection relies on observing the response time of the database to infer data?
Answer: Time-based blind SQL injection
Time-based blind injection uses delay functions to infer true/false conditions from response times.
What is the main goal of a session hijacking attack?
Answer: Take over an authenticated user's session
Session hijacking steals or predicts a valid session token to impersonate a legitimate user.
Which wireless attack involves setting up a fraudulent access point that mimics a legitimate one?
Answer: Evil twin
An evil twin is a rogue AP impersonating a trusted network to capture user credentials.
What does the term 'privilege escalation' refer to?
Answer: Gaining higher access rights than originally granted
Privilege escalation exploits flaws to obtain elevated permissions beyond the initial access level.
Which hashing algorithm is considered cryptographically broken and should not be used for security?
Answer: MD5
MD5 is vulnerable to collision attacks and is unsuitable for security-sensitive hashing.
In a penetration test, what document defines the scope and legal authorization for the engagement?
Answer: Rules of Engagement
The Rules of Engagement specify the scope, limitations, and authorization for testing.
What technique encodes a malicious payload to evade signature-based intrusion detection systems?
Answer: Obfuscation
Obfuscation alters the payload's appearance to bypass signature detection while preserving function.