โ† All Certified Ethical Hacker Flashcard Decks

System Hacking and Malware Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 System Hacking and Malware flashcards as text
  1. Which type of malware disguises itself as legitimate software to trick users into installing it but does not self-replicate?

    Answer: Trojan horse

    A Trojan horse masquerades as legitimate software and does not self-replicate.

  2. An attacker re-times malicious commands to run during off-hours and routes traffic over port 443 to blend with normal HTTPS. This primarily aims to achieve what?

    Answer: Defense evasion / detection avoidance

    Blending malicious traffic with legitimate HTTPS and off-hours timing is defense evasion.

  3. Which Linux file, if writable by a low-privilege user, could be abused to escalate privileges by adding a malicious cron entry?

    Answer: /etc/crontab

    A writable /etc/crontab lets an attacker schedule commands that run as root.

  4. A polymorphic virus evades antivirus primarily by doing what on each infection?

    Answer: Changing its decryption routine/code signature

    Polymorphic viruses mutate their code or decryption routine each time to alter their signature.

  5. Which technique allows an attacker who compromised one host to use its trust relationships to access additional systems on the network?

    Answer: Lateral movement

    Lateral movement uses a foothold to reach and compromise other systems across the network.

  6. An ethical hacker wants to verify whether a downloaded file matches a known-malicious sample using a unique fingerprint. Which value should they compare?

    Answer: Cryptographic hash (e.g., SHA-256)

    A cryptographic hash such as SHA-256 uniquely fingerprints a file for malware identification.

  7. Which type of backdoor is hidden inside the firmware or boot process and loads before the operating system?

    Answer: Bootkit

    A bootkit infects the boot process or firmware and loads before the OS starts.