System Hacking and Malware Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Hacking and Malware flashcards as text
An attacker wants to maintain persistent access to a compromised Windows host across reboots. Which location is commonly abused for autostart persistence?
Answer: The Run registry key
The HKLM/HKCU Run registry keys execute programs automatically at startup, enabling persistence.
Which attack precomputes hashes for many possible passwords to speed up cracking but is defeated by salting?
Answer: Rainbow table attack
Rainbow tables use precomputed hash chains, which salting defeats by making each hash unique.
A keylogger implemented as a small hardware device inserted between the keyboard and the computer is which type?
Answer: Hardware keylogger
A physical device placed inline with the keyboard cable is a hardware keylogger.
Which technique uses legitimate system tools already present on a host (like PowerShell or WMI) to avoid dropping detectable malware files?
Answer: Living off the land (LOLBins)
Living-off-the-land attacks abuse built-in trusted binaries to operate without dropping new files.
During post-exploitation, an attacker dumps credentials from the LSASS process memory on Windows. Which tool is most associated with this?
Answer: Mimikatz
Mimikatz extracts credentials, hashes, and tickets from LSASS memory.
Which malware analysis approach examines a binary's strings, imports, and disassembly WITHOUT executing it?
Answer: Static analysis
Static analysis inspects a file's contents and code without running it.
An attacker escalates from a standard user to SYSTEM by exploiting a service running as SYSTEM with a writable executable path. This is an example of what?
Answer: Vertical privilege escalation
Gaining higher privileges (user to SYSTEM) is vertical privilege escalation.