โ† All Certified Ethical Hacker Flashcard Decks

Vulnerability Assessment and Exploitation Flashcards

6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Vulnerability Assessment and Exploitation flashcards as text
  1. Which automated exploitation framework is most commonly referenced in CEH for developing and testing exploits?

    Answer: Metasploit Framework

    The Metasploit Framework is the most widely used open-source exploitation framework, providing tools for exploit development, delivery, and post-exploitation.

  2. What is 'privilege escalation' in the context of exploitation?

    Answer: Increasing the attacker's level of access beyond the initial compromise

    Privilege escalation involves leveraging vulnerabilities or misconfigurations to gain higher-level permissions (e.g., from a standard user to administrator or root).

  3. Which technique is used to exploit a vulnerability in a client application by luring a victim to visit a malicious webpage?

    Answer: Client-Side Exploitation

    Client-side exploitation targets vulnerabilities in browsers, plugins, or document readers by tricking the user into visiting a malicious page or opening a malicious file.

  4. What is the CEH term for a vulnerability database that lists publicly known security flaws with a standardized identifier?

    Answer: CVE (Common Vulnerabilities and Exposures)

    The CVE (Common Vulnerabilities and Exposures) database provides standardized identifiers (e.g., CVE-2021-44228) for publicly known cybersecurity vulnerabilities.

  5. What is a 'false positive' in the context of vulnerability scanning?

    Answer: A vulnerability reported by the scanner that does not actually exist

    A false positive occurs when a vulnerability scanner incorrectly identifies a non-vulnerable system as vulnerable, requiring manual verification to confirm real findings.

  6. Which exploitation countermeasure randomizes the memory layout of a process to prevent attackers from predicting where to redirect code execution?

    Answer: ASLR (Address Space Layout Randomization)

    ASLR randomizes the base addresses of the stack, heap, and libraries each time a process runs, making it difficult for attackers to reliably target specific memory addresses.