Mixed Deck — All Certified Ethical Hacker Topics Flashcards
100 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All Certified Ethical Hacker Topics flashcards as text
After compromising one host, a tester uses it to attack deeper internal systems. What is this called?
Answer: Pivoting
Pivoting uses a compromised host as a stepping stone to reach other internal systems.
Which Google search operator is used to search for specific file types hosted on a target website?
Answer: filetype:
The 'filetype:' Google dork operator restricts results to specific file extensions (e.g., PDF, XLS, DOC) which may expose sensitive documents.
A polymorphic virus evades antivirus primarily by doing what on each infection?
Answer: Changing its decryption routine/code signature
Polymorphic viruses mutate their code or decryption routine each time to alter their signature.
What distinguishes an IPS from an IDS?
Answer: An IPS can actively block or drop malicious traffic
An IPS is inline and can actively block or drop malicious traffic, while an IDS only detects and alerts.
You work as a Security Analyst for a retail organization. In securing the company's network, you set up a firewall and an IDS. However, hackers are able to attack the network. After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed. What type of alert is the IDS giving?
Answer: False Negative
A false negative occurs when a security system, such as an Intrusion Detection System (IDS), fails to detect an actual attack or malicious activity. In this scenario, hackers successfully attacked the network, but the misconfigured IDS did not trigger an alarm, allowing the breach to go unnoticed. This is a critical failure as it means a real threat was missed, compromising the network's security.
An attacker enumerates valid usernames by observing different error messages. This is a flaw in:
Answer: Username enumeration / verbose feedback
Distinct responses for valid vs invalid users leak account existence (username enumeration).
What is the key size used by the AES algorithm in its strongest standard configuration?
Answer: 256 bits
AES supports 128, 192, and 256-bit keys, with 256-bit being the strongest.
Which protocol does a ping sweep typically use to identify live hosts?
Answer: ICMP echo request
A ping sweep sends ICMP echo requests across a range to find responsive hosts.
Which of these is an example of active reconnaissance?
Answer: Performing a port scan against the target
Port scanning directly interacts with the target, making it active reconnaissance.
A web shell uploaded through an unrestricted file upload allows an attacker to:
Answer: Execute commands on the server
A web shell provides remote command execution on the compromised server.
What is a 'zero-day vulnerability'?
Answer: A previously unknown vulnerability with no available patch
A zero-day vulnerability is a security flaw that is unknown to the vendor and has no available patch, making it particularly dangerous and valuable to attackers.
Why must an ethical hacker document every action and finding during an engagement?
Answer: For reproducibility, reporting, and legal accountability
Thorough documentation supports reproducible results, clear reporting, and legal accountability.
Which tool is commonly used to bind a Trojan to a legitimate executable so it runs alongside the original program?
Answer: Wrapper (binder)
A wrapper or binder joins a Trojan to a legitimate executable so both run together.
An attacker sets up a rogue AP with the same SSID as a legitimate corporate network to lure clients. What is this called?
Answer: Evil twin
An evil twin mimics a legitimate AP's SSID to trick users into connecting through the attacker.
In a man-in-the-middle attack on key exchange, what does the attacker do?
Answer: Intercepts and relays communication while impersonating both parties
The attacker secretly relays and possibly alters messages between two parties who think they communicate directly.
Which algorithm is an example of asymmetric (public-key) cryptography?
Answer: RSA
RSA is a widely used asymmetric algorithm based on factoring large prime numbers.
Which of the following is the most important step for the ethical hacker to perform during the pre-assessment?
Answer: Obtain written permission to hack
The most crucial step for an ethical hacker is to obtain explicit, written permission from the target organization before commencing any hacking activities. Without written authorization, any penetration testing or security assessment, even if intended for good, could be considered illegal and lead to severe legal consequences. This step ensures the legality, ethical conduct, and clear scope of the engagement.
What ethical principle requires that a tester stop and notify the client immediately upon discovering an active breach by a real attacker?
Answer: Duty to report critical findings promptly
Ethical hackers must promptly report critical findings such as evidence of an active compromise.
Which phase would include using tools like Maltego to map relationships between people, domains, and infrastructure?
Answer: Reconnaissance
Maltego is an OSINT tool used during reconnaissance to map relationships among entities.
What is the purpose of privilege escalation after gaining initial access?
Answer: Gain higher-level permissions
Privilege escalation elevates an attacker's access from a low-privilege account to admin/root.