Ethical Hacker Methodology Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Methodology flashcards as text
Which type of penetration test gives the tester full knowledge of the network, including architecture diagrams and source code?
Answer: White-box testing
White-box testing provides the tester with complete internal knowledge of the target.
In a black-box engagement, what does the tester start with?
Answer: Little to no prior knowledge of the target
Black-box testing simulates an outside attacker with no prior internal knowledge.
What is the correct ordered sequence of the CEH hacking phases?
Answer: Recon, Scanning, Gaining access, Maintaining access, Covering tracks
The standard sequence is reconnaissance, scanning, gaining access, maintaining access, then covering tracks.
A tester uses Google search operators like 'site:' and 'filetype:' to find exposed documents. This technique is called what?
Answer: Google dorking
Using advanced search operators to find sensitive exposed data is known as Google dorking.
Which methodology framework is a widely used standard for structuring penetration tests?
Answer: PTES (Penetration Testing Execution Standard)
PTES defines a standard structure for conducting penetration tests across phases.
After compromising one host, a tester uses it to attack deeper internal systems. What is this called?
Answer: Pivoting
Pivoting uses a compromised host as a stepping stone to reach other internal systems.
What distinguishes a vulnerability assessment from a penetration test?
Answer: Vulnerability assessment identifies weaknesses; pentest actively exploits them
A vulnerability assessment identifies and lists weaknesses, while a penetration test attempts to exploit them.