Ethical Hacker Security Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Security flashcards as text
Which phase of ethical hacking involves actively probing a target to find open ports and live hosts?
Answer: Scanning
Scanning actively probes the target to discover live hosts, open ports, and services.
A penetration tester is given no prior knowledge of the target environment. What type of test is this?
Answer: Black-box
Black-box testing simulates an external attacker with zero internal knowledge of the system.
Which tool is most commonly used for network discovery and port scanning?
Answer: Nmap
Nmap is the standard tool for host discovery, port scanning, and service/version detection.
What does a TCP SYN scan rely on to avoid completing the full handshake?
Answer: Sending RST after SYN-ACK
A SYN scan sends a RST after receiving SYN-ACK, never completing the three-way handshake (half-open scan).
Which document legally authorizes a penetration test and defines its scope?
Answer: Rules of Engagement
The Rules of Engagement document defines scope, timing, and authorized actions for a test.
What is the primary goal of the 'covering tracks' phase for a malicious attacker?
Answer: Hide evidence of intrusion
Covering tracks involves deleting logs and hiding artifacts to evade detection.
Which type of footprinting collects data without directly interacting with the target system?
Answer: Passive footprinting
Passive footprinting gathers information from public sources without touching the target directly.