โ† All Certified Ethical Hacker Flashcard Decks

Certified Ethical Hacker MCQ Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Ethical Hacker MCQ flashcards as text
  1. Which type of SQL injection relies on observing the response time of the database to infer data?

    Answer: Time-based blind SQL injection

    Time-based blind injection uses delay functions to infer true/false conditions from response times.

  2. What is the main goal of a session hijacking attack?

    Answer: Take over an authenticated user's session

    Session hijacking steals or predicts a valid session token to impersonate a legitimate user.

  3. Which wireless attack involves setting up a fraudulent access point that mimics a legitimate one?

    Answer: Evil twin

    An evil twin is a rogue AP impersonating a trusted network to capture user credentials.

  4. What does the term 'privilege escalation' refer to?

    Answer: Gaining higher access rights than originally granted

    Privilege escalation exploits flaws to obtain elevated permissions beyond the initial access level.

  5. Which hashing algorithm is considered cryptographically broken and should not be used for security?

    Answer: MD5

    MD5 is vulnerable to collision attacks and is unsuitable for security-sensitive hashing.

  6. In a penetration test, what document defines the scope and legal authorization for the engagement?

    Answer: Rules of Engagement

    The Rules of Engagement specify the scope, limitations, and authorization for testing.

  7. What technique encodes a malicious payload to evade signature-based intrusion detection systems?

    Answer: Obfuscation

    Obfuscation alters the payload's appearance to bypass signature detection while preserving function.