Vulnerability Assessment and Exploitation Flashcards
6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Vulnerability Assessment and Exploitation flashcards as text
Which automated exploitation framework is most commonly referenced in CEH for developing and testing exploits?
Answer: Metasploit Framework
The Metasploit Framework is the most widely used open-source exploitation framework, providing tools for exploit development, delivery, and post-exploitation.
What is 'privilege escalation' in the context of exploitation?
Answer: Increasing the attacker's level of access beyond the initial compromise
Privilege escalation involves leveraging vulnerabilities or misconfigurations to gain higher-level permissions (e.g., from a standard user to administrator or root).
Which technique is used to exploit a vulnerability in a client application by luring a victim to visit a malicious webpage?
Answer: Client-Side Exploitation
Client-side exploitation targets vulnerabilities in browsers, plugins, or document readers by tricking the user into visiting a malicious page or opening a malicious file.
What is the CEH term for a vulnerability database that lists publicly known security flaws with a standardized identifier?
Answer: CVE (Common Vulnerabilities and Exposures)
The CVE (Common Vulnerabilities and Exposures) database provides standardized identifiers (e.g., CVE-2021-44228) for publicly known cybersecurity vulnerabilities.
What is a 'false positive' in the context of vulnerability scanning?
Answer: A vulnerability reported by the scanner that does not actually exist
A false positive occurs when a vulnerability scanner incorrectly identifies a non-vulnerable system as vulnerable, requiring manual verification to confirm real findings.
Which exploitation countermeasure randomizes the memory layout of a process to prevent attackers from predicting where to redirect code execution?
Answer: ASLR (Address Space Layout Randomization)
ASLR randomizes the base addresses of the stack, heap, and libraries each time a process runs, making it difficult for attackers to reliably target specific memory addresses.