Ethical Hacker Methodology Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Methodology flashcards as text
During footprinting, which tool would best retrieve domain registration and ownership details?
Answer: WHOIS
WHOIS queries return domain registration, ownership, and contact information.
A tester captures a service's response containing version and OS hints by connecting to an open port. This is called what?
Answer: Banner grabbing
Banner grabbing collects service banners that often reveal software versions and OS details.
Why must an ethical hacker document every action and finding during an engagement?
Answer: For reproducibility, reporting, and legal accountability
Thorough documentation supports reproducible results, clear reporting, and legal accountability.
Which of these is an example of active reconnaissance?
Answer: Performing a port scan against the target
Port scanning directly interacts with the target, making it active reconnaissance.
What is the main purpose of the final reporting phase of a penetration test?
Answer: To deliver findings, risk ratings, and remediation guidance
The reporting phase communicates findings, risk severity, and recommended remediation to the client.
A tester uses the OSINT framework to gather intelligence. What does OSINT stand for?
Answer: Open Source Intelligence
OSINT stands for Open Source Intelligence, gathered from publicly available sources.
Which scanning technique is used specifically to identify live hosts on a network?
Answer: Ping sweep
A ping sweep sends ICMP echo requests across a range to find responsive live hosts.