โ† All Certified Ethical Hacker Flashcard Decks

System Hacking and Malware Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 System Hacking and Malware flashcards as text
  1. What is privilege escalation and what are the two types?

    Answer: Gaining higher access rights than authorized; vertical (user to admin) and horizontal (accessing another user's resources)

    Privilege escalation exploits vulnerabilities to gain elevated access. Vertical escalation moves from lower to higher privileges (user to root/admin), while horizontal accesses resources of another user with similar privileges.

  2. What is a rootkit and why is it particularly dangerous?

    Answer: Malware that hides deep in the OS to maintain persistent, undetectable access

    Rootkits operate at kernel or firmware level, modifying the OS to hide their presence (hiding files, processes, network connections) from detection tools, providing persistent backdoor access that survives reboots.

  3. What is the difference between a virus, worm, and Trojan?

    Answer: Viruses attach to files and need user action; worms self-replicate across networks; Trojans disguise as legitimate software

    Viruses attach to host files and require user action to spread, worms self-propagate across networks without user interaction, and Trojans appear legitimate but contain hidden malicious functionality.

  4. What is a keylogger and how can it be detected?

    Answer: Software or hardware that records keystrokes; detected through antimalware, process monitoring, and physical inspection

    Keyloggers capture every keystroke typed on a system, either through software (running as a hidden process) or hardware (a device between the keyboard and computer), stealing passwords and sensitive data.

  5. What are common password cracking techniques?

    Answer: Dictionary attacks, brute force, rule-based attacks, rainbow tables, and credential stuffing

    Password cracking employs multiple techniques: dictionary attacks (common words), brute force (all combinations), rule-based (dictionary with modifications), rainbow tables (precomputed hashes), and credential stuffing (reusing leaked credentials).

  6. What is fileless malware and why is it difficult to detect?

    Answer: Malware that operates entirely in memory without writing files to disk, evading traditional file-based scanning

    Fileless malware executes entirely in RAM using legitimate system tools (PowerShell, WMI, macros), leaving no traditional file artifacts on disk, making it invisible to conventional antivirus that scans files.