Ethical Hacker Methodology Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Methodology flashcards as text
After gaining a low-privileged shell, a tester exploits a misconfiguration to become root. What is this step called?
Answer: Privilege escalation
Privilege escalation raises an attacker's permissions from a low-level account to administrator or root.
Which classification describes a hacker who tests systems without permission but discloses flaws to the owner without malicious intent?
Answer: Gray hat
A gray hat acts without authorization but generally without malicious intent, reporting issues afterward.
A client only wants the tester to assess externally facing web applications. Where is this restriction defined?
Answer: In the scope of the engagement
The scope defines exactly which systems and assets are authorized for testing.
What is the purpose of obtaining a proof of concept (PoC) during exploitation?
Answer: To demonstrate that a vulnerability is genuinely exploitable
A PoC demonstrates that a discovered vulnerability can actually be exploited, validating the risk.
Which phase would include using tools like Maltego to map relationships between people, domains, and infrastructure?
Answer: Reconnaissance
Maltego is an OSINT tool used during reconnaissance to map relationships among entities.
What ethical principle requires that a tester stop and notify the client immediately upon discovering an active breach by a real attacker?
Answer: Duty to report critical findings promptly
Ethical hackers must promptly report critical findings such as evidence of an active compromise.
Why does an ethical hacker restore systems to their original state at the end of an engagement?
Answer: To remove test artifacts, accounts, and changes made during testing
Cleanup removes any accounts, tools, and changes introduced so the environment is left as it was found.