System Hacking and Malware Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Hacking and Malware flashcards as text
A Trojan opens TCP port 6667 and beacons to an external server awaiting commands. This indicates the host is part of what?
Answer: A botnet
A compromised host beaconing to a command server for instructions is a bot in a botnet.
Which type of malware encrypts a victim's files and demands payment for the decryption key?
Answer: Ransomware
Ransomware encrypts files and demands payment for the decryption key.
An ethical hacker wants to detect a previously unknown malware sample by observing its runtime behavior in an isolated environment. This is called what?
Answer: Dynamic (sandbox) analysis
Dynamic analysis runs the sample in a sandbox to observe its behavior at runtime.
Which tool is commonly used to bind a Trojan to a legitimate executable so it runs alongside the original program?
Answer: Wrapper (binder)
A wrapper or binder joins a Trojan to a legitimate executable so both run together.
An attacker schedules malicious code to execute only when a specific employee's account is deleted. This is an example of what?
Answer: Logic bomb
A logic bomb executes its payload when a specific condition or trigger is met.
Which Windows feature, when abused, lets attackers store malicious data hidden from normal directory listings on NTFS volumes?
Answer: Alternate Data Streams (ADS)
NTFS Alternate Data Streams can hide data that does not appear in standard directory listings.
What is the primary purpose of a packer when used by malware authors?
Answer: To compress and obfuscate the binary to evade signature detection
Packers compress and obfuscate malware binaries to evade signature-based detection.