Browse all practice questions for the Certified Ethical Hacker Version 11 (CEHv11) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified Ethical Hacker Version 11 (CEHv11) Practice Test 2026 - Free CEHv11 Practice Questions and Study Guide course image
All questions

These questions are part of the practice quiz. Start practicing

  • Hybrid Attack uses dictionary words plus other methods to crack passwords.
  • Which tool provides Data Hiding and Watermarking to detect unauthorized file copying?
  • Which tool is used to detect listening ports to find information about the nature of services running on the target machine?
  • Which tool is commonly used to wipe out all the logs from a Windows system during a compromise?
  • Which term describes the state of infrastructure and information well-being to keep theft, tampering, disruption of information and services kept tolerable and low?
  • Which attack modifies a cookie’s contents to bypass security mechanisms?
  • Which term refers to software designed to perform malicious actions such as theft or fraud?
  • Which method places malware-laden advertisements into legitimate online advertising channels?
  • Which concept functions as a component of intelligence-driven defense for identifying and preventing malicious intrusion activities and helps security professionals understand adversaries' tactics, techniques, and procedures ahead of time?
  • Which malware rewrites the USB firmware with malicious code that directly interacts with the operating system and installs malicious payload on the target machine?
  • Which tool is used to gather a list of words from a target site to create a password wordlist?
  • Which spyware copies itself to a USB device and operates without user notification?
  • Which term covers the methods and tools used by attackers to perform a specific attack?
  • Which term describes the act of replaying previously captured transmissions to spoof communications?
  • Which tool is described as a metadata extraction tool?
  • Which domain controller stores extra information across the entire organization and enables cross-domain object lookup, using port 3268?
  • Which resource aggregates phishing URLs and domain data to help defenders identify malicious content?
  • Which term describes techniques that ensure the program is not running under the debugger?
  • Which statement best describes a bucket in cloud storage terms?
  • Which UNIX tool allows a user to execute commands with the privileges of another user, often root?
  • Which technique provides information about the locations and types of servers?
  • Which term describes the adversary collecting as much data as possible, including sensitive employee and customer data, business tactics, and financial information, for exfiltration or destruction?
  • Which command returns a list of unique words from the target URL?
  • Which tool generates file hashes using algorithms such as MD5, SHA-1, CRC32, and various SHA-2 variants?
  • Which DNS attack involves altering the DNS resolver cache to redirect DNS queries to malicious sites?
  • Which file pattern commonly reveals SonicWall Global VPN Client configuration that may contain sensitive data?
  • In Wireshark, which display filter tokens are used to specify IP addresses and TCP ports?
  • Which exploitation vector focuses on exploiting widely used third-party applications, such as Adobe Reader or Flash, to gain access to remote systems?
  • Which MIB manages TCP/IP-based Internet using a simple architecture and system?
  • Which Trojan is described as a Windows-targeted rootkit delivered via Trickler named DoubleFantasy?
  • What is the Metasploit Framework primarily described as?
  • Which Trojan type can bypass a firewall and operate in reverse using a web-based interface on port 80?
  • Which term describes software and hardware designed to detect or cause changes in industrial operations through direct monitoring and/or controlling of industrial physical devices?
  • Which hping3 command is used to collect the initial sequence number?
  • What term describes a system that checks every packet entering the network for anomalies and incorrect data?
  • Which SNMP operation is used by the manager to request information from an SNMP agent?
  • Which tool allows extraction of secret files directly from audio CD tracks?
  • Which tool is described as scanning for rootkits by examining processes, threads, modules, services, files, MBR, ADSs, registry keys, and inline hooking?
  • Which command is shown for performing a reverse DNS lookup with dnsrecon on a specific IP range?
  • Which layer stores production data in a structured form and is typically backed by databases like MS SQL Server or MySQL?
  • Which command scans all the nearby wireless networks?
  • Which attack is described as generating stego objects from a known message to identify the embedding algorithm?
  • Which protocol enables clients to share files between computers in a network?
  • Which tool is a free utility that provides details about Windows executable files?
  • Which technique is used to compress malware into a smaller footprint and pack it to evade detection?
  • Which cloud-based service provides immediate global visibility into IT vulnerabilities and helps monitor changes to prevent breaches?
  • Which overflow occurs when an application writes more data to a buffer than allocated?
  • Which MIB monitors network traffic between DHCP servers and remote hosts?
  • An unsupervised self-learning system is used to define what the normal network looks like, and then uses this to backtrack and report any deviations or anomalies in real-time. Which approach is this?
  • Which spyware monitors all web pages accessed by users, often in their absence?
  • Which term describes techniques used to prevent dynamic analysis by fingerprinting the emulated system environment?
  • Which SNMP operation is described as being used by an SNMP agent to inform the pre-configured SNMP manager of a certain event?
  • Sniffs traffic over a network or a part of the network. Which term matches this description?
  • What describes blocking execution of malicious applications on a system or network?
  • SSDP scanning is primarily used for discovering devices on a network by multicast messaging for which protocol family?
  • This is an easy approach in which a payload is transferred bitwise over an established session between two systems. Which field is used?
  • Which port and protocol are commonly associated with DNS services?
  • What term describes a network that forwards your information through multiple proxies to reach the destination?
  • Which deployment refers to monitoring a single host for suspicious activity?
  • Used to gather information about IoT devices, such as manufacturer details, geographical location, IP address, hostname, and open ports. Which tools fit this description?
  • Which term best describes attackers exploiting vulnerabilities in cloud technologies to target cloud storage systems and gain access to users' data?
  • What is the Microsoft web server application for Windows that supports HTTP, HTTPS, FTP, FTPS, SMTP, and NNTP?
  • Which security component is capable of inspecting content beyond headers?
  • What command line is used to identify the IPv6 capabilities of a device?
  • Which term denotes malicious software that damages or disables computer systems and gives control to the attacker?
  • A security solution which filters data packets?
  • Which malware remains inactive until a financial transaction occurs and can modify registry entries on startup?
  • Which term describes a computer system designed and configured to protect network resources from attacks?
  • What is the term for malware that provides attackers with full control by bypassing authentication and security measures?
  • Which attack uses a ping with oversized or malformed packets to crash or destabilize the target system?
  • Which environment is designed for securely testing code by restricting its execution?
  • BeRoot is best described as which type of security tool?
  • Which free software provides an open network to defend your system against traffic analysis and state security monitoring?
  • Which tool provides encrypted data transport over the network and resembles Netcat functionality?
  • Which term describes spyware installed without user knowledge that piggybacks onto other applications to spread?
  • Which platform is described as offering threat detection, incident response, and compliance management across cloud, on‑premises, and hybrid environments?
  • Which command line tool is used for viewing open ports and connections to detect trojans?
  • Which tool is used for comprehensive remote administration to execute commands across hosts?
  • Horizontal Privilege Escalation refers to:
  • This patch to klibc provides run-init on modern Ubuntu systems.
  • Which attack donates the attacker's own session ID to the target user?
  • Which property does a digital signature primarily provide to prove authorship and prevent denial of authorship?
  • In this technique, you initially send a packet (ping request) to a legitimate host and wait for a reply.
  • What is the web application attack that injects client-side script into web pages viewed by other users?
  • Which service is described as providing comprehensive DDoS protection offerings from an ISP or DDoS service?
  • Which keylogger transmits logs over a local Wi-Fi network and can be accessed over TCP/IP?
  • Which approach collects and analyzes information that affects the security of an application to identify threats and mitigation strategies?
  • Which tool is used for open-source intelligence gathering to enumerate LinkedIn employees?
  • Which acronym expands to Lightweight Directory Access Protocol?
  • Displays a list of users who are logged on to remote machines or machines on local network.
  • Which IDS evasion technique involves sending unusual Unicode characters to confuse detection systems?
  • What Metasploit command is used to gain administrative-level privileges and dump password hashes?
  • Which term describes attackers locating unsecured wireless networks while moving in vehicles?
  • Which action would an attacker take to ensure logs cannot be used for prosecution by removing traces?
  • An in-built Windows command-line tool that can be used to securely delete data by overwriting it to avoid their recovery in the future.
  • Which tool is described as a system optimization, privacy, and cleaning utility that can erase browsing traces?
  • Which Metasploit component establishes a communication channel between the framework and the victim host, enabling file upload/download, screenshots, and password hash collection?
  • Which attack allows an attacker to manipulate hidden fields to change data stored in them, such as altering prices during checkout?
  • Black Hole Filtering is effective in preventing IP spoofing at which network level?
  • Which tools are cited for deep and dark web searching, including Tor Browser, ExoneraTor, and OnionLand Search engine?
  • Which technique involves manipulating or spoofing tokens to impersonate other users in order to escalate privileges?
  • Which term corresponds to the Push (PSH) flag?
  • Which protocol is the successor to SSL?
  • It is an SIEM tool that can automatically collect all the event logs from all the systems present in the network.
  • Which tools are used to discover and identify previously unknown vulnerabilities in a system?
  • Which tool is commonly used as a post-exploitation payload enabling command execution and log wiping?
  • Which term describes using multiple search engines to produce results from the Internet?
  • Which Google advanced search operator restricts results to a specific domain?
  • Which term describes an attack where packets and authentication tokens are captured using a sniffer?
  • Which assessment approach involves the auditor selecting different strategies for each machine or component?
  • Which protocol mirrors XML-RPC but uses JSON for data serialization?
  • Which tool is a Blackjacking tool?
  • Which service is associated with TCP port 139?
  • Which honeypots are described as capturing attack patterns and threat actors' TTPs toward database attacks?
  • Which protocol uses UDP port 500 to establish IPsec security associations and exchange keys for VPNs?
  • Which term describes the speed of biometric data processing after input is provided?
  • Which technique enables better load management by balancing loads across multiple servers to mitigate DDoS and maintain performance?
  • Which type of scanning checks for known weaknesses to determine if a system is exploitable?
  • Which option lists a specific warning sign of an APT attack?
  • Which protocol is considered the modern successor for securing communications in transit?
  • Which type breaches web browser security by injecting client-side scripts into a web page?
  • Which tool retrieves information about network devices via WMI, SNMP, HTTP, SSH, and PowerShell?
  • Which Trojan family uses vulnerable service protocols such as VNC, HTTP/HTTPS, and ICMP to attack the victim's machine?
  • Which zone is uncontrolled and lies outside the boundaries of an organization?
  • Which policy defines the acceptable use of system resources?
  • What term describes collecting sensitive information from someone else’s trash, including items like bills or notes?
  • Which acronym stands for User Datagram Protocol?
  • Which design pattern describes software components that expose specific functionality as services to other applications?
  • Which operator would you use to locate documents whose URL contains the word 'login'?
  • Which software is described as PC-user activity-monitoring software running secretly in the background?
  • Which hardware keystroke capture device is commonly referred to as KeyGrabber?
  • Which cryptographic algorithm uses the product of two large prime numbers?
  • Which DNS record maps an IP address to a hostname?
  • Which policy defines the resources being protected and the rules that control access to them?
  • Which malware component compresses the malware file and uses packing techniques to conceal its code and data?
  • Sublist3r can utilize multiple search engines for subdomain discovery.
  • Which attack targets peer-to-peer networks by exploiting Direct Connect protocol bugs, initiating a DDoS without bots?
  • Which command displays the NetBIOS name cache and their resolved IP addresses?
  • Which cloud model is operated for a single organization?
  • Covering tracks on the network might involve techniques such as reverse HTTP shells, reverse ICMP tunnels, DNS tunneling, and TCP parameters. Which term describes this action?
  • In a MAC flooding attack, the CAM table is overwhelmed. Which statement best describes the result?
  • Which script takes a file to splat over run-init during ramdisk assembly and calls update-initramfs?
  • Which party can conduct independent assessment of cloud service controls and provide an opinion thereon?
  • Which command identifies IoT devices using insecure HTTP ports?
  • Which PC system utility erases unnecessary files and data, cleans the Windows registry, automatically fixes system errors, and optimizes your system?
  • What term describes turning off event auditing on the target system?
  • Which tool is used to trap adversaries by emulating a legitimate website?
  • Which tool can hide a message in a selected image from the photo library or camera?
  • An attack that injects HTML code via vulnerable form inputs to change the appearance or information presented to users.
  • Which term describes an attack performed when the attacker is in close physical proximity to the target?
  • Which DNS poisoning scenario involves infecting John's machine with a Trojan to change his DNS IP address to the attacker's?
  • Which tool is described as a high-performance, cross-platform secured SOCKS5 proxy that helps attackers surf privately and securely?
  • Exposing internal objects such as files or database records to users via direct references can lead to which vulnerability?
  • Which protocol uses port 119 for Usenet?
  • Which type of analysis involves executing malware code to observe its interactions with the host and resultant impact on the system?
  • Which technique involves using decoy IP addresses to mislead IDS while probing a target?
  • In the hacking lifecycle, what is the activity called when an attacker attempts to obtain higher privileges to perform protected operations?
  • Which command lists wireless interfaces and configuration on a system?
  • Which messages are typically used in single sign-on protocols and are often Base64-encoded?
  • Which honeypot type is described as emulating a real production network and prompting attackers to invest effort while providing alerts?
  • Which term describes an attack that uses a sniffer to capture traffic and then replay it to spoof communications?
  • Which attack involves searching for and exploiting operating system vulnerabilities to gain access?
  • What is the primary purpose of RESTful APIs?
  • Which honeypots trap malware campaigns and emulate vulnerabilities such as outdated APIs and SMBv1 protocols?
  • Which command-line utility displays a list of computers in a specified workgroup or shared resources available on a specified computer?
  • Which MIB monitors and manages host resources?
  • What does the -p option specify in hping3 command syntax?
  • Which category includes examples like sender's email address and attachments used in email communications?
  • Which protocol is used for Internet telephony for voice and video calls?
  • DNS poisoning is also known as which attack?
  • Which tool helps identify security leaks in a Wi-Fi network and detects intruders?
  • Which testing approach is defined by testers not knowing the internal architecture of the system under test?
  • Which proxy app uses Tor to encrypt Internet traffic and bounces through a series of computers to create a truly private Internet connection?
  • Which port is used for LDAP?
  • Which category of DoS attacks targets infrastructure resources like connection state tables in devices such as load balancers and firewalls?
  • Which tool allows password-protected reading of a hidden message within a photo?
  • Which term refers to legally intercepting data communications between endpoints for surveillance?
  • Which system detects and prevents unauthorized wireless devices and rogue access points?
  • An adversary can create and configure multiple domains pointing to the same host, allowing rapid switching between domains to avoid detection.
  • Which ICMP technique queries the subnet mask from the target?
  • Which firewall combines the features of packet filtering, circuit-level gateways, and application-level firewalls, filtering at the network layer and evaluating contents at the application layer?
  • Which operator provides information Google has about a specific page?
  • Which device sits at the border of a network to enforce access control and monitor traffic?
  • What is the purpose described when an attacker uses an IoT device as a backdoor to gain access to an organization's network without infecting an end system protected by IDS/IPS, firewall, and antivirus?
  • Which concept restricts unauthorized users from gaining access to assets by granting only the minimum privileges necessary?
  • Which timing attack is carried out by measuring the approximate time the server takes to process a POST request to deduce the existence of a username?
  • Which field indicates how many hops a packet may traverse before it is discarded by a router?
  • Which tool is a robust network threat detection engine capable of real-time intrusion detection, inline intrusion prevention, network security monitoring, and offline pcap processing?
  • What is the tool used to add additional information to Traceroute's results?
  • Which acronym stands for Simple Network Management Protocol?
  • What term describes adversaries who create multiple points of entry to maintain access?
  • Which assessment determines the vulnerabilities in the organization's wireless networks?
  • Which port is commonly used by the Network Time Protocol (NTP)?
  • If an attacker bypasses authentication due to flaws in access control, this represents which vulnerability?
  • Which tool is used to create rainbow tables?
  • Which tunneling approach leverages the HTTP protocol to allow internet access through restricted networks by encapsulating traffic in HTTP requests?
  • Which detection method identifies a web shell by analyzing server access, error logs, suspicious strings that indicate encoding, user agent strings, and other methods?
  • Which technology provides authentication of DNS traffic?
  • Which honeypots specifically target spammers who abuse resources like open mail relays and open proxies, consisting of mail servers that accept emails from any source?
  • Which SQL injection technique relies on observing the application's response to infer information rather than retrieving data directly?
  • Which command determines the route data takes to reach a destination?
  • Which utility provides encrypted communication over the network similar to netcat?
  • Which option provides a framework for attackers to construct Trojan horses and customize them to their needs?
  • Which Google search pattern would locate pages that have a login page title and a specific utility name in the text?
  • Which scenario is an example of an IDOR vulnerability?
  • Which Go-based directory scanner enumerates hidden files and directories, DNS subdomains, and virtual hosts on a target?
  • Which protocol allows a user's workstation to access mail from a mailbox server?
  • Which data resource leverages a database of 120 million business records and analytics to deliver a sales intelligence solution that helps focus on the right prospects?
  • During which Kill Chain stage is a backdoor installed to gain remote access?
  • Which tool hides any file in any other file?
  • Which category is described as faster than Asymmetric, AES, DES, RC4?
  • Which software scans a computer and detects and removes keystroke logger software?
  • Which tool is described as a data extraction utility that extracts emails and meta tags from web pages?
  • Which acronym stands for a protocol suite used to secure IP communications by providing confidentiality, integrity, and authentication?
  • Which detection technique is described as identifying changes in the statistical properties of traffic over time (change-point detection)?
  • The attacker has access to the stego-object and the steganography tool or algorithm used to hide the message.
  • Which is an on-demand delivery of IT capabilities where infrastructure and applications are provided as a metered service over a network?
  • Which attack tries all possible upper and lower case combinations of a word in the input dictionary?
  • Which type of indicators are obtained from data extracted from a security incident, such as hash values and regular expressions?
  • Which term describes the risk that remains after countermeasures have been deployed?
  • Which assessment uses a network scanner to identify hosts, services, and vulnerabilities?
  • Which phase focuses on removing the root cause of the incident and closing all attack vectors to prevent recurrence?
  • Which tool is a high-performance, cross-platform secured SOCKS5 proxy?
  • Which term describes the process of collecting and analyzing information about threats and adversaries to enable informed decisions against cyber-attacks?
  • Which service would you query to determine if a user's IP is on known blacklists?
  • Which DNS record provides for domain name aliases within your zone?
  • Which term describes malware that can replicate itself to spread across a network?
  • A vulnerability which enables attackers to add their own files on a server via a web browser. Such vulnerability arises when an application adds files without proper validation of inputs, thereby enabling the attacker to modify the input and embed path traversal characters.
  • Which technique is described as enumerating key elements in the computer system and comparing them to a baseline dataset that is generated without relying on common APIs, with discrepancies indicating rootkit presence?
  • A technique used to encrypt plaintext by writing it onto a sheet of paper through a pierced (or stenciled) sheet of paper, cardboard, or any other similar material.
  • Which environment uses a switch that maintains a MAC address table and forwards packets to the correct destination?
  • Which technique hides information with the help of signs or symbols embedded in the data to change its appearance to a predetermined meaning?
  • In Sublist3r, which flag specifies a comma-separated list of search engines to use?
  • Which term describes an attack that is not detected by the IDS, resulting in no alert?
  • What program invites ethical hackers to find vulnerabilities for rewards?
  • Which option is used to create user-specified Trojans via selection from a variety of available options?
  • Which approach permits access only to approved URLs?
  • What type of malware tricks users into visiting infected websites or downloading malicious software?
  • Which service uses port 25 by default?
  • Which SNMP operation is described as being used by the SNMP manager to modify the value of a parameter within an SNMP agent's MIB?
  • Which term describes warfare that can include the shutdown of systems, data errors, theft of information, theft of services, system monitoring, false messaging, and access to data?
  • Which tool can hide a secret file within an innocuous image, video, or music file?
  • Which CVSS metric is most influenced by an organization’s security controls and network environment?
  • Which method is used to analyze RAM dumps to detect rootkits?
  • Which script takes command-line arguments and places them into the section used by Horse Pill?
  • What is the process called when the hash of a document is encrypted with the signer's private key?
  • With the -F, -P, and -U options, what kind of probe scan is performed and on which port?
  • What privacy feature do meta search engines typically offer?
  • Which tool is commonly used for cracking WEP and WPA-PSK wireless networks?
  • What term refers to a coordinated network of infected machines used to carry out attacks?
  • Which term describes computer code delivered as an e-mail attachment that, when activated, destroys specific files and propagates to the address book?
  • What term best describes identifying the common methods or techniques used by attackers to breach networks to improve defenses?
  • Which attack sends HTTP requests with complete headers but an incomplete message body, causing the server to wait for the rest of the data?
  • What is Machine.config described as?
  • SamSam ransomware relies on which encryption key algorithm?
  • Which technique floods a target by transmitting multiple HTTP requests from a single HTTP session within one packet?
  • Which Google search operator displays the cached copy of a webpage?
  • Which term describes the component of malware that performs its intended action after exploitation?
  • What is the practice of hiding a covert message within an overt message called?
  • Which attack involves presenting a Kerberos ticket to access services on other systems?
  • Which Windows-focused virus is identified by the designation Win32/Simile?
  • Which type of indicators are useful for identifying indications of intrusion, such as malicious IP addresses, virus signatures, MD5 hash, and domain names, and are used to identify specific behavior related to malicious activities?
  • A web application responds to a URL parameter with an ID that points to a sensitive resource; this is an example of which vulnerability?
  • Which tool is used to discover hidden ADSs and clean them completely from your system, with advanced auto analysis and online threat verification?
  • Which security feature blocks execution in a non-executable memory location?
  • What term describes someone who manipulates telecommunications systems to make free calls?
  • A vulnerability residing in a bare-metal cloud server that enables attackers to implant a malicious backdoor in its firmware to bypass security and monitor user activity.
  • Which non-interactive command-line tool is used to retrieve files via HTTP, HTTPS, and FTP and can be scripted?
  • Which malware type can bypass standard system authentication or security mechanisms without detection?
  • Which filesystem stores a file with two data streams, called NTFS data streams, along with the file attributes?
  • Which Google search operator would you use to ensure all terms appear in the title?
  • Which operator presents information that Google has about a particular web page?
  • Which of the following is an example of Public Key (Asymmetric) systems?
  • Which technique involves shutting down the infected system and booting from an alternative trusted media to find traces of the rootkit?
  • What is the effect of the query intitle:asterisk.management.portal web-access?
  • Which component is used to manage user accounts and passwords in hashed format?
  • Which policy focuses on corporate email usage?
  • Which hping3 command performs a FIN, PUSH and URG scan on port 80?
  • Which activity is used to detect bugs and irregularities in the developed web applications?
  • Which term describes malware that hijacks a user session by stealing cookies?
  • Which technique uses a stolen or forged hash to gain access without decrypting the password?
  • Which spyware category monitors email communications and forwards them?
  • A preparatory phase that defines policies and standards, clarifies the scope, and prioritizes critical assets to create a baseline for vulnerability management is known as what?
  • What is the primary way a WAF helps prevent web application attacks?
  • Which query would locate a Linksys VoIP router configuration page?
  • Which tool is an OS X-based SSH tunneling software?
  • Which attack method exploits websites that construct LDAP statements from user-supplied input?
  • Which HTTP method is used to submit data to a web server as part of a request?
  • Which term is defined as gathering information about threats from online sources?
  • The DNS record that points to a domain's mail server is:
  • Which term refers to the component that stores the complete set of rules to identify a packet and determines the action to be performed?
  • EquationDrug Rootkit is commonly installed by what method?
  • Which term refers to incident response services for any user, company, agency, or organization in partnership with the Department of Homeland Security?
  • Which term best describes the assurance that a message originated from the claimed sender and was not altered in transit?
  • If you are segmenting a network and place a buffer zone between internal networks and the internet, what is that zone called?
  • Which term stores the address of the next data element to be stored onto the stack?
  • Which protocol is a TCP/IP-based protocol used for exchanging management information between devices on a network?
  • Which scan would be used to determine if a host responds to ICMP ECHO requests, indicating possible firewall filtering?
  • Which tool provides complete Whois records from registrars for a dataset?
  • Which component injects exploits or malicious code into other running processes to alter execution and hinder removal?
  • Which technique enumerates key elements in the computer system such as system files, processes, and registry keys and compares them to a baseline dataset that is generated without relying on common APIs, with discrepancies indicating rootkit presence?
  • In an hping3 command, which option is used to spoof the source IP address?
  • The infected machine looks for new vulnerable machines in its own local network
  • Which Google dork operator restricts results to pages within a specific domain?
  • What attack takes over a valid TCP communication session between two computers?
  • What term describes a method of requesting DNS mapping?
  • Which term refers to government-authorized interception of communications for surveillance?
  • Which protocol provides NetBIOS name resolution and is commonly referred to by the acronym NBNS?
  • Attackers create fraudulent websites that appear legitimate; when visited, they scan the victim's plugins for vulnerabilities to exploit in the browser memory. This technique is called what?
  • What term describes the splitting of a probe packet into several smaller packets during transmission?
  • Which port is used for IMAP?
  • Which approach targets discovering and identifying vulnerabilities that are not yet known to security staff?
  • In data mining, dimensionality reduction reduces the number of random variables under consideration by obtaining a smaller set of variables.
  • Which service explores archived versions of websites via an Internet Archive Wayback Machine to gather information on an organization's pages since creation?
  • Which attack produces a spoofed session by including multiple SYN and ACK packets with RST or FIN, without a full handshake?
  • Which term refers to Internet-connected computers that are compromised by malware and used to perform attacks under control of a attacker via a command and control server?
  • The malware type that infects legitimate software and relies on existing system protocols to perform malicious activities is called what?
  • Which option best describes a hardware keylogger that does not rely on software and records keystrokes locally?
  • Which vector targets office applications via spearphishing with links to malicious files?
  • Which type is used to hide messages in ASCII text by adding whitespaces at the end of lines?
  • Which rootkit hides in hardware devices or platform firmware that are not inspected for code integrity?
  • Which technique involves sending emails that appear to be from legitimate sites to steal credentials?
  • Which mechanism ensures that the traffic inside the network follows an optimized path to enhance network performance?
  • What term describes an application that can serve as an intermediary for connecting with other computers?
  • Which Metasploit module generates a no-operation instruction used for padding out buffers?
  • What process involves reading and recording data to establish a signature or baseline for files and system sectors?
  • Which attack involves injecting HTML into a web page through vulnerable inputs to alter content?
  • Which resource includes details of the latest vulnerabilities present in OSs, devices, and applications?
  • Which Android app is commonly used for security analysis in wireless networks and can capture credentials from social media platforms?
  • Which open-source tool is described as used to create worms that can infect drives, files, show messages, and disable antivirus software?
  • Which term denotes a legal channel for transferring data securely within a company network?
  • Which DNS poisoning tool assists in spoofing the DNS query packet of a certain IP address or a group of hosts in the network?
  • What is the term for unauthorized changes made to the content of a single web page or an entire website, changing its visual appearance?
  • Which attack type involves sending a reset (RST) packet with an invalid checksum to confuse security appliances?
  • Which spyware copies spyware files from a USB device onto the hard disk without any request or notification and runs in hidden mode?
  • Which policy defines the account creation process, authority, and rights and responsibility of the user accounts?
  • Which tool enumerates running processes with detailed information like process IDs?
  • Which phase is the virus replicating itself and attaching to a .exe file in the system?
  • Which tool is used to analyze packet capture files?
  • Which processor vulnerability allows attackers to exploit speculative execution to read restricted data across security boundaries?
  • What utility is used to clear Windows event logs for system, application, and security?
  • Which term refers to the stage where the attacker creates or selects a malicious payload for unauthorized access using an exploit and backdoor?
  • Which type converts sensitive information into user-definable free speech such as a play?
  • Displays a list of users who are logged on to hosts on the local network.
  • Which technique involves replacing the MAC address of a compromised machine in the ARP cache of the server to divert traffic?
  • What does GHDB stand for?
  • What tool is used to encrypt and tunnel all traffic from a local machine to a remote machine to avoid detection by perimeter security controls?
  • CxSAST is used for which type of security testing?
  • Which software monitors and displays Win32 API calls made by applications?
  • Which term describes an attack that uses the same procedure as a replay attack, along with reverse engineering of the protocol to capture the original signal?
  • A scenario where an attacker poisons a shared cache by returning malicious content for a targeted URL.
  • Recon-ng is best described as what?
  • FISMA is the U.S. law that requires what?
  • A vulnerability where privileged functions are accessible without proper authorization checks is known as:
  • Which is the long-form option to enable port scanning in Sublist3r?
  • If attackers gain access to the API or etcd, what information can they easily retrieve from the mounted volumes?
  • Which tool is an open source intelligence gathering framework that helps security professionals in performing automated footprinting and reconnaissance, OSINT research, and intelligence gathering?
  • Which type of attack is used to directly modify protection policies, delete existing policies, add new policies, and modify applications, system data, and resources?
  • Which item is described as an executable file format used on Windows OS to store the information that a Windows system requires to manage the executable code?
  • Which term describes malware delivered by e-mail attachments that can propagate to other systems?
  • In IoT, which layer is responsible for delivering applications to different users?
  • A Trojan horse is used to intercept and manipulate calls between a browser and its security mechanisms or libraries.
  • Which type of malware exploits vulnerabilities in network communication protocols such as SMB to deliver malicious payloads?
  • Which port corresponds to IMAP?
  • Which category comprises software installed remotely via network or email and stores logs on the hard drive, sending them to an attacker via email?
  • Acquiring administrative privileges is known as what?
  • Which web proxy tool is widely used for intercepting and modifying web traffic during security testing?
  • Which technique utilizes 1-bit steganography by modifying the cover so that the transmission of a '1' changes statistical characteristics?
  • Which detection method identifies signs of a hidden web shell by analyzing server logs and traffic for encoding and unusual user agents?
  • Which service provides registration information for domain names?
  • Which tool is a desktop OS designed for advanced security and privacy, mitigating common attack vectors while maintaining usability?
  • Which hping3 command performs an ACK scan on port 80?
  • Which tool is commonly used to search for geotagged information on social networks?
  • Which directory search pattern is used to find a directory index that might reveal VPN server keys?
  • The attacker first finds a legitimate account with limited privileges, then logs in as that user, and gradually escalates privileges to access protected resources.
  • Which type hides any kind of file with any extension inside a carrying video file?
  • Which mobile app is described as scanning and providing complete network information such as IP address, MAC address, device vendor, and ISP location for Android and iOS?
  • Which malware type infects the firmware residing on network cards and hard disks to deliver the malicious payload?
  • Which attack breaks down a passphrase into fingerprints comprising single and multi-character components?
  • Which tool is used to reconstruct firmware images for embedded devices?
  • Which solution is described as an automated dynamic testing solution that discovers configuration issues as well as identifies and prioritizes security vulnerabilities in running applications?
  • Which tool focuses on uninstalling software and removing leftover traces from a system?
  • Which term refers to a network design that uses a screening firewall and a DMZ to expose limited services?
  • Which type uses natural language or text to conceal data?
  • Which term describes a centralized login mechanism allowing access to multiple systems using one credential?
  • Which concept describes spoofing a MAC address to impersonate another device on the local network?
  • Which protocol provides centralized authentication, authorization, and accounting for network access control?
  • Which command is used to perform a DNS lookup for a domain's A record?
  • Which technique differs from full page overlays by only masking or modifying selected page controls to mislead the user?
  • Provides information related to the TTPs used by threat actors (attackers) to perform attacks. Provides day-to-day operational support by helping analysts assess various security incidents related to events, investigations, and other activities. It also guides the high-level executives of the organizations in making strategic business decisions.
  • In IoT architecture, which layer handles device management and information management?
  • Which software is described as monitoring everything users do on a computer in total secrecy?
  • Which product is described as a network monitoring solution capable of monitoring IT infrastructure using SNMP, WMI, and SSH?
  • Which testing approach involves testing a web application using manually designed data, customized code, and browser extension tools such as SecApps to detect vulnerabilities focusing on business logic?
  • Which term describes the process of recognizing, measuring, and classifying security vulnerabilities in a computer system, network, and communications?
  • Which tool would you use to mirror websites for offline access?
  • An attack that uses the cryptanalytic time-memory trade-off technique, which requires less time than other techniques, creates a table of all the possible passwords and their respective hash values in advance. What is this attack called?
  • What term describes the process of monitoring and capturing all data packets passing through a network to observe sensitive information such as Telnet passwords, email traffic, and DNS traffic?
  • Which attack category uses drive-by compromise to target web browsers?
  • What term is used for flooding a target by masking multiple HTTP requests within a single HTTP packet?
  • Which attack type exhausts a target's maximum concurrent connections by using incomplete HTTP requests?
  • Which scan involves sending UDP packets and observing a UDP response to infer host activity?
  • Which term describes capturing passwords by monitoring data packets in transit?
  • Which port is used by Network Time Protocol?
  • Which statement best describes the CAM table's function on a switch?
  • What is the phase called when an adversary, after penetrating the network, gathers information such as local user context, hostname, IP addresses, remote systems, and active programs?
  • Which command-line tool can delete the data and prevent recovery of that data in the future?
  • Which technique helps an attacker increase anonymity by routing traffic through multiple proxies?
  • Which method uses user-controlled values to influence LDAP statements and access directory data?
  • Which command collects the number of time samples from several time sources?
  • Which service allows locating objects from any domain using a cross-domain catalog?
  • What type of software allows a hacker to gain near total control of a computer while hiding its presence from the user and standard detection methods?
  • Which technique hides a malicious page behind a legitimate page and can cause click events to drop through?
  • Which Trojan uses web interfaces and port 80 to gain access and is described as an HTTP tunnel that works in reverse direction?
  • Which LDAP administration tool works with LDAP servers such as Active Directory, Novell Directory Services, and Netscape/iPlanet?
  • Tools used to perform a reverse image search. Which set is correct?
  • Which attack impersonates a legitimate DHCP server and offers IP addresses to clients acting as a default gateway?
  • Which layer includes the functional logic of the web application, which is implemented using technologies such as .NET, Java, and middleware?
  • What provides the best protection against data compromise in the event of physical theft of the device?
  • Which Trojan is a utility for editing Windows resources such as .exe, .dll, .res, .rc, and .dcr extensions?
  • Which term indicates the number of host systems involved in the attack?
  • Which assessment type conducts security evaluation without obtaining any credentials?
  • Which MIB contains object types for workstation and server services?
  • Which product is described as an application for people on the move that monitors app permissions and sorts them by privacy-risk level?
  • Which set of tools is used for reverse image searching to identify the source of an image?
  • What does ARP stand for?
  • Which technique best describes the goal of session hijacking by intercepting and impersonating one party in the connection?
  • Port 9100 is commonly used by which printing mechanism?
  • Which tool is specifically designed to silently copy files from USB devices?
  • Which tool can enumerate all devices on the network and save a list of known devices with a custom name?
  • Which type of malware uses files to gain an initial entry into the target machine by exploiting executables, Flash, Java, and documents?
  • Which Windows service enforces IPsec policies for all network communications initiated from the system?
  • Which item is described as a package addressing a critical defect in a live environment and fixing a single issue?
  • Used for analyzing, reverse engineering and extracting data from the firmware image.
  • Which concept emulates only a limited number of services and generates an error if the attacker performs an action outside its emulation?
  • Which protocol uses UDP port 123 for clock synchronization in networks?
  • Which rootkit technique locates and patches the system memory to hide from detection?
  • The process of identifying, gathering, analyzing, verifying, and using information about your competitors from resources such as the Internet is known as what?
  • Which service provides a name-resolution service for NetBIOS names?
  • What is the primary purpose of a container image in deployment?
  • Which tool would you use to perform automated scanning and manual testing to find web application vulnerabilities?
  • What term describes the numeric name given to an object that uniquely identifies it in the MIB hierarchy?
  • Which practice ensures that no single individual has full control by distributing duties?
  • Which exploitation vector targets common office applications such as Microsoft Office via spearphishing with links to malicious files?
  • Which type embeds hidden messages in a digital sound format?
  • Which service is associated with TCP port 21, typically used for control?
  • Which term describes a large-scale denial-of-service attack conducted via many compromised hosts to overwhelm a target?
  • Name the network authentication protocol that provides strong authentication for client/server applications through secret-key cryptography.
  • Which detection approach uses a database of anomalies and flags deviations from normal traffic, contrasting with signature detection?
  • Which attack class targets weaknesses in the XML parser to cause DoS or logical errors in web service processing?
  • Which command puts the wireless card in monitor mode?
  • Which term describes standalone malicious programs that replicate, execute, and spread across network connections independently?
  • ICMP tunneling commonly uses which ICMP message types to carry payload?
  • An attack is performed on a network or single computer by an entrusted individual who has authorized access.
  • Which statement best differentiates the deep web from the dark web?
  • Which password cracking technique uses a word list to guess passwords, trying each word in the list?
  • Which statement best describes OAuth?
  • Which threat involves competitors unlawfully gathering data to undermine a target's market position?
  • Which Trojan category is designed to form a botnet for carrying out DDoS attacks?
  • Which type of keylogger logs web form inputs by monitoring the submit event during form submission?
  • Which host discovery option sends IP packets with the IP header set to a specific protocol number for discovery?
  • Which vulnerability arises when error messages reveal details about the application, enabling attackers to identify vulnerabilities?
  • Which technique embeds information by altering the transform-domain content, such as image coefficients?
  • Which assessment relies on vulnerability scanning tools such as Nessus, Qualys, or GFI LanGuard to automate checks?
  • Which DNS record maps an IP address to a hostname and is used most often for DNS lookups?
  • What is an obfuscator in IDS evasion?
  • Which term maintains the source index for string operations?
  • Which description matches the payload that attempts to update an existing record?
  • When the attacker’s own system disseminates the toolkit to the target at the moment of breach, this is known as which propagation method?
  • What term describes a collection of computers and peripherals connected as one entity?
  • Which vulnerability involves injecting carriage return and line feed characters into user input to trick the server into treating the input as a new object?
  • Which policy focuses on password hygiene necessary for protecting organizational resources?
  • Which fileless malware operates in memory and can steal keystrokes and credentials?
  • Which vulnerability occurs when a web application forwards a user to another resource without proper validation, potentially bypassing access controls?
  • Which term refers to software that downloads additional malicious files from the Internet to a compromised system?
  • Which security feature prevents a user from accidentally executing a potentially malicious program?
  • Which attack creates a fake session by sending multiple SYN and multiple ACK packets along with one or more RST or FIN packets?
  • Encryption Flooding Unicode Characters is associated with which security concept?
  • Which term corresponds to the PSH flag?
  • Which term describes publishing personal information found in public databases and social media?
  • Which attack vector focuses on stealing data from a victim's machine without their knowledge?
  • Which of the following tools is used to find URLs of AWS S3 buckets?
  • Which memory area is used for static memory allocation and stores variables in Last-In-First-Out (LIFO) order?
  • Which tool is described as a vulnerability scanner used to scan web servers?
  • Which concept describes the security context used by a process or thread, typically represented by a token?
  • Which technique helps network administrators develop new filtering techniques and update load balancing and throttling countermeasures?
  • Which tool is used to monitor the target IT infrastructure to discover devices connected to the Internet along with their details such as the operating system used, IP address, protocols used, and geography?
  • What term describes setting up routers to throttle incoming traffic levels to a safe amount for the server?
  • The payload blah'; DROP TABLE Creditcard; -- is an example of which SQL action?
  • Which tool is described as a 'virus maker' that allows attackers to assemble Trojans from presets?
  • What is the term used to describe a decoy system that is designed to lure attackers and study their methods?
  • Which method makes changes to digital carriers to embed information foreign to the native carriers?
  • What attack is commonly used to gain unauthorized access to a database?
  • What is a described characteristic of Tor Browser in this material?
  • Which password recovery tool captures passwords stored by major web browsers and passes them to the credential enumerator module?
  • What term describes a program that captures data from information packets traveling on networks to identify confidential data?
  • Which technology would you use to monitor networks and alert on intrusions?
  • Which rootkit replaces the original boot loader with the one controlled by a remote attacker?
  • Which protocol suite provides data security by using Encapsulating Security Payload (ESP), Authentication Header (AH), and Internet Key Exchange (IKE) to secure communication between VPN endpoints?
  • Which honeypots are high-interaction and primarily deployed by research institutes, governments, or military organizations to gain detailed knowledge about intruders?
  • An attack where an attacker runs a virtual machine on the same physical host as the victim to exploit shared resources to steal data such as cryptographic keys is called?
  • Which security product provides protection against Trojans, viruses, spyware, ransomware, phishing, and dangerous websites, and also securely stores passwords and backs up media and files?
  • Which attack is used when the attacker wants to detect the hiding technique given both the message and stego-medium?
  • Which activity is a risk assessment approach that analyzes security of an application by capturing, organizing, and analyzing information that affects its security?
  • Which category includes examples like URLs, domain names, and IP addresses used for network activity?
  • What is the wrapper program used to create a self-extracting package that can automatically install embedded setup files and Trojans?
  • This script takes the file to splat over run-init while assembling ramdisks as a command-line argument. It then calls update-initramfs and splats over the run-init as the ramdisks are being assembled.
  • Spike templates are used to define which aspect of overflow testing?
  • Which term describes an MITM attack that allows the attacker to monitor, record, and alter or inject data into traffic?
  • Which tool is a 32-bit assembler-level analyzing debugger for Windows and can attach to running programs and log arguments?
  • Exploiting unsanitized or unvalidated inputs to application logs.
  • Attackers exploit legitimate system packages installed in the system, such as Word and JavaScript, to run the malware. This is best described as using which category?
  • Which technique helps identify the true source of an attack and take necessary steps to block further attacks?
  • Which policy provides guidelines for implementing strong password protection on organizational resources?
  • Which attack is described as using a single input dictionary to build chains of combined words?
  • Which vulnerability involves maliciously crafted serialized data that, when deserialized, can execute code or alter behavior?
  • Which assessment is used to test database systems such as MySQL, MSSQL, Oracle, and PostgreSQL for injection vulnerabilities?
  • Which malware rewrites the boot record with malicious code, which, when executed, gains access and installs the malicious payload?
  • An attacker pretends to be another user or machine to gain access. Instead of taking over an existing active session, the attacker initiates a new session using the victim's stolen credentials.
  • Which term describes the patterns of activities and methods associated with specific threat actors or groups?
  • Which web server fingerprinting tool identifies servers based on HTTP characteristics even when the banner is obfuscated?
  • Which file is described as providing a mechanism for securing information by changing machine-level settings?
  • Which approach limits the impact of DDoS attacks by denying traffic with spoofed addresses?
  • Which term is best described as extracting information from a victim through disarming conversations tailored to the victim's interests?
  • What security mechanism is a challenge-response test used by web applications to determine if the responder is a human?
  • Which component generates randomized decryption routines to bolster polymorphism?
  • What term describes dividing data into groups based on similarity, ignoring class information?
  • What misconfiguration allows attackers to view server contents via a web directory index?
  • Which term describes attacker actions to stay undetected on an IoT device by clearing logs, updating firmware, and using backdoors and Trojans?
  • Which command is used to test TCP timestamp handling by a firewall on a specific host?
  • Which category involves observing network traffic without modifying it?
  • Which online tools are used to search for both geotagged and non-geotagged information about the target on social media sites?
  • Which exploitation vector targets web browsers through spearphishing links and drive-by compromises?
  • Which honeypots involve fake email addresses distributed across the open Internet and dark web to lure threat actors into malicious activities?
  • Which term refers to techniques used to prevent analysis by debuggers during reverse engineering?
  • Which tool is described as capable of discovering shared folders and retrieving network device information via multiple protocols including WMI, SNMP, HTTP, SSH, and PowerShell?
  • What is the process of taking organized and careful steps when reacting to a security incident or cyberattack?
  • Which REST constraint requires resources to be identified by unique URIs and manipulated using a uniform set of HTTP methods?
  • This is a ramdisk-based containerizing rootkit that resides inside initrd and uses a mount and PID namespace before the actual init starts.
  • Which tool is used to break complex passwords, recover encryption keys, and unlock documents in a production environment?
  • Which term refers to extracting information such as IP addresses, protocols, open ports, and device details in IoT networks?
  • Which Trojan can be embedded as a macro in an MS Word document and covertly creates registry keys and processes, then connects to multiple malicious C2 servers?
  • Tools used to reverse a video or convert a video into text and other formats to extract critical information about the target. Which option lists these tools?
  • Which practice involves intercepting and modifying the data exchanged between a browser extension and its server?
  • Which Windows feature caches executable metadata to speed up application launches?
  • What is the term for the unintentional downloading of software via the Internet by visiting a compromised website that exploits browser flaws?
  • Which protocol assigns IP addresses and other information to computers to enable communication on a network?
  • What term is used for invisible writing with colorless liquids that can later be made visible by lighting or heating?
  • Mimikatz is a tool that can extract plaintext passwords, hashes, PINs, and Kerberos tickets from memory.
  • Which security tool is described as centralizing threat detection, investigation, and response to help security analysts prioritize threats?
  • Which policy determines who may install new resources on the network and how changes are documented?
  • BeEF is described as which type of testing framework?
  • Which protocol is a secure remote management protocol intended as a replacement for Telnet?
  • Which concept describes trading memory for time in cryptanalytic cracking methods?
  • Which tool shows files opened remotely?
  • also known as a one-click attack or session riding, is an attack in which the attacker exploits the victim's active session with a trusted site to perform malicious activities such as item purchases and the modification or retrieval of account information.
  • Which term is a wrapper program to create self-extracting packages including embedded Trojans?
  • Which term describes a fixed-size output produced by a hash function that is used to verify data integrity?
  • Which directory is cited as storing plist files used for high-privilege execution?
  • Which port does the Internet Printing Protocol (IPP) listen on by default?
  • Which switch port is configured to receive a copy of every packet for monitoring and analysis?
  • Which tool provides a listing of all device drivers currently loaded in the system?
  • Which term denotes that APT campaigns are composed of multiple phases, such as reconnaissance and exfiltration?
  • Which type of keylogger operates within a malware hypervisor on the host operating system?
  • In Bash, which file typically stores the command history?
  • Which published standard provides an open framework for communicating the characteristics and impacts of IT vulnerabilities?
  • Which term helps an attacker identify IoT devices with weak configurations such as hidden exploits, firmware bugs, weak settings and passwords, and poorly encrypted communications?
  • In an SCTP COOKIE ECHO scan, the absence of a response from a port typically indicates which state?
  • Attackers search for unsecured Wi-Fi networks in moving vehicles with laptops or PDAs to access data on those devices. This is known as ...
  • Which mechanism specifies a list of allowed application components to execute in a system to prevent unauthorized execution?
  • Which spyware tracks phone location points and emails them to a specified address?
  • What is the primary purpose of the IPsec Policy Agent?
  • Which Windows command queries the DNS name servers and retrieves information about the target host addresses, name servers, mail exchanges, etc.?
  • Which tactic involves gathering information by initiating a conversation and tailoring questions to the victim's responses?
  • Which SMTP command is used to verify the actual delivery addresses of recipients?
  • In certificate-based authentication, which entity issues digital certificates to bind public keys to identities?
  • What is a cluster scanner described as in the material?
  • Which term describes identifying IoT devices with weak configurations through vulnerability scanning?
  • Which platform provides content-enabled workflow solutions designed for professionals in the legal, risk management, corporate, government, law enforcement, accounting, and academic markets and maintains an electronic database of information related to legal and public records?
  • Port 1080/TCP is commonly used by which proxy protocol?
  • Which device is described as rapidly mitigating large attacks without increasing latency and supports unicast and anycast?
  • Which mechanism uses HTTP headers to pin a server's public key to mitigate fraudulent certificates?
  • Which statement best describes A10 Thunder TPS?
  • Which option lists the toolset described as tracking most shared content and content trends on social media (BuzzSumo, Google Trend, Hashatit and Ubersuggest)?
  • Which attack damages the reliability of an intermediate web cache by swapping cached content for a URL with infected content?
  • What term describes an alarm that correctly indicates an actual attack?
  • Which attack is carried out by trusted individuals who have physical access to critical assets?
  • Which term refers to a registry listing all available web services?
  • A directory that stores files and is accessible to all containers in a pod.
  • Which tool encodes secret messages into innocent-looking spam emails with a password and other gimmicks?
  • What technique uses NTFS streams to hide malicious files on the target system?
  • Which attack involves an attacker gaining access to the communication channel to intercept data between the victim and the server?
  • Which term refers to monitoring network traffic to identify security vulnerabilities and diagnose problems, often included in network forensics discussions?
  • Which technique adds a random string to a password before hashing?
  • Which term describes exploiting information and loopholes in an access control system to gain entry?
  • Which operator finds information for a specific location?
  • Which type of steganography involves hiding one or more files in a folder by moving the file physically while maintaining association to the original folder for recovery?
  • In Sublist3r, which flag scans found subdomains against specific TCP ports?
  • Which term describes techniques used to detect possible goat files by heuristic rules?
  • What type of device appears as a USB drive and sits between the keyboard and USB port to capture keystrokes?
  • Which traceroute variant is described as providing network route tracing with performance tests, DNS, Whois, and network resolution?
  • Which attack involves tricking the server by injecting new lines into response headers along with arbitrary code?
  • Which utility is commonly used to identify and manage programs that run automatically at Windows startup?
  • Which protocol for IPsec uses the Diffie-Hellman algorithm to derive a master key and a unique session key?
  • Which technique describes compromising a system to gain a remote shell and pivot through the compromised system to access other vulnerable systems in the network?
  • Which Linux command queries DNS name servers to retrieve information about a target host addresses, name servers, mail exchanges, etc?
  • Which tool kills processes by name or process ID?
  • Which term describes a network device that protects resources by filtering traffic at the network's gateway?
  • Which MIB is described as managing TCP/IP-based Internet using a simple architecture and system?
  • Fraudsters impersonate executives from financial institutions and rely on persuasive talking to obtain sensitive information. Which technique is this?
  • What does issuing the -9 flag on Hping cause it to do with respect to HTTP traffic?
  • Which rootkit type replaces the original OS kernel and device driver codes?
  • Which technique is used to bypass IDS/firewalls by manipulating port numbers to evade rules?
  • Which scan sends an empty TCP ACK packet to the target directly?
  • Which term is commonly used to describe using Google search operators to gather sensitive information?
  • Which Burp Suite tool tests the randomness of session tokens?
  • Attackers trick victims into clicking malicious links that execute macros automatically to inject a malicious payload into the process memory.
  • In this technique, the attacker places an attack toolkit on their own system, and a copy of the attack toolkit is transferred to a newly discovered vulnerable system. The attack tools installed on the attacking machine use some special methods to accept a connection from the compromised system and then transfer a file containing the attack tools to it.
  • Which detection method differs from signature recognition and relies on a database of anomalies detected when traffic deviates from normal tolerance?
  • Which virus attacks the File Allocation Table (FAT) to destroy the index, making files unrecoverable?
  • Which term describes the layer that includes sensors and edge devices connecting to cloud services?
  • Which operator restricts results to documents containing a keyword in the URL (not necessarily all keywords)?
  • Which tool rewrites iptables rules as part of its honeynet capabilities?
  • Which practice evaluates the current security posture by identifying gaps between desired and actual controls?
  • Which REST constraint indicates that responses can be cached to improve API performance?
  • Vulnerabilities that manifest when an application integrates user-controllable values into a string that the code interpreter dynamically validates.
  • Which DNS poisoning scenario manipulates a user's proxy settings to redirect to a malicious site controlled by the attacker?
  • What is described as a vulnerability that occurs when an application accepts more data than the allocated buffer?
  • Which Kill Chain stage involves delivering the payload to the victim via email attachments, malicious links, vulnerable web applications, or USB drives?
  • What term describes programs that exploit kernel vulnerabilities to execute arbitrary commands with higher privileges?
  • Which of the following is an automatic system that detects intrusions and can take actions to prevent them, typically deployed behind firewalls?
  • Which term describes software that secretly records information about users without their knowledge?
  • Which online services are listed as examples of DNS lookup resources?
  • Acquiring access to another account's files is an example of which concept?
  • Which term describes the set of systems used in industry to monitor and control processes, including SCADA and PLC components?
  • This vulnerability leads to overwriting links to dynamic memory allocation (dynamic object pointers), heap headers, heap-based data, virtual function tables, etc. Attackers use this to take control of the program's execution.
  • Which assessment assesses distributed organization assets, such as client and server applications, simultaneously through appropriate synchronization techniques?
  • Which tool is described as capable of multi-hash password cracking across multiple algorithms such as MD4, MD5, and SHA-512?
  • Which tool is used for local network discovery, port scanning, and banner grabbing for protocols such as ssh, telnet, http, https, ftp, smb?
  • Which cloud model describes shared infrastructure used by a specific community with common concerns?
  • Which technology detects runtime attacks and provides visibility into vulnerabilities in real-time apps?
  • Which component is commonly used to deflect logic bombs and Trojans?
  • Evaluates the performance of the implemented risk management strategies.
  • Which protocol uses UDP port 69 for file transfer?
  • Which command demonstrates a TCP traceroute?
  • Breaks the availability of essential services.
  • Which Windows password cracker is based on rainbow tables and has a GUI across multiple OS?
  • Split DNS is used to maintain what for external and internal networks?
  • Which firewall examines all incoming requests against known vulnerabilities and only allows requests that are deemed genuine to pass?
  • Which DNS record identifies the primary name server for the zone?
  • Which technique is used to control the rate of outbound or inbound traffic to mitigate DDoS?
  • Which type hides information by embedding data in signs or symbols to convey predetermined meaning?
  • Which DNS record contains the Start of Authority data for a zone?
  • Which technique creates a shell within a website to gain remote access to server functionalities?
  • Which term represents the overall governance framework for information security, including policies and guidelines?
  • Which open-source Python-driven tool is aimed at penetration testing around social engineering?
  • Which tools are used to collect publicly available email addresses of the target organization for social engineering and brute-force attacks?
  • Which component is responsible for producing mutation variants of the virus to evade detection?
  • Which term refers to the total number of hosts involved in an attack?
  • Which technology enables packaging and running software in isolated environments that share the host OS kernel?
  • Which scan detects when a port is open after completing the three-way TCP handshake?
  • Which attack involves reading cookies on a victim's machine to learn user behavior or exfiltrate data?
  • Which term describes an attack that floods a target with nonlegitimate service requests to exhaust resources and make services unavailable?
  • Who is a person or organization that provides cloud services to consumers?
  • Which action involves sending custom network packets to scan a target beyond a firewall?
  • Which filtering technique scans the headers of IP packets leaving a network to ensure unauthorized or malicious traffic never leaves the internal network?
  • Which of the following is an example of an IDOR vulnerability?
  • Which term describes a packet crafting tool that helps security professionals assess the network?
  • Which term refers to a software design problem involving insufficient input validation?
  • It compares a snapshot of the file system, boot records, or memory with a known trusted baseline.
  • Which LLMNR/NBNS/mDNS Spoofing Detection Toolkit detects name service spoofing?
  • What term describes when an intrusion detection system correctly classifies normal activity as acceptable?
  • Which testing technique sends a large amount of data to a target to provoke a buffer overflow and identify the EIP location?
  • Which tool provides competitive intelligence to monitor brand and trademark use, affiliate compliance, and competitive advertisers across paid search, organic search, local search, social media, mobile, and shopping engines worldwide?
  • When passwords are stored with weak hashing algorithms, attackers can obtain the original passwords from the database. This vulnerability is called:
  • Which concept describes routing traffic through a sequence of proxies to obscure origin?
  • Which packet capture library is commonly used on Linux?
  • Which term uniquely identifies each node on a network?
  • Which command retrieves email account information for a specified email address?
  • Which attack employs precomputed hashes to crack passwords faster by using rainbow tables?
  • On gaining access to the target system, an adversary can use the command-line interface to interact with the system, browse files, read and modify file content, create new accounts, connect to remote systems, and download and install malicious code.
  • Which set of documents defines the basic security requirements and rules to protect an organization's systems?
  • Which IPsec protocol provides integrity and data origin authentication with optional anti-replay?
  • Which testing approach evaluates a running application from the outside without access to source code?
  • Which attack involves eavesdropping on cookies to analyze users' surfing habits and potentially sell them or use them against the user?
  • Which technique allows tunneling a backdoor shell in the data portion of ICMP Echo packets?
  • Which process is used in sheep farming, whereby sheep are dipped in chemical solutions to make them parasite-free?
  • What is the process of conducting security assessment and performance analysis of an application and generating timely reports on its security levels and threat exposures?
  • Which virus type combines the approaches of file infectors and boot record infectors and attempts to attack both the boot sector and the executable or program files?
  • Pass the Ticket Attack allows attackers to sign in using the victim's Kerberos ticket on other computers.
  • Terabit DDoS Protection System (DPS) focuses on maintaining service availability by doing what?
  • Which tool provides strategy research capabilities for consumer markets and publishes reports on industries, consumers, and demographics?
  • Which tool assists attackers in automatically or manually listing IPv4/IPv6 addresses, hostnames, domain names, and URLs?
  • Which antivirus solution is described as using behavioral detection to monitor active applications and block suspicious activity, including blocking malicious websites masquerading as legitimate sites?
  • The term describing ongoing actions taken to reduce vulnerability risk by applying patches and configuration changes is called what?
  • Which technique would be used to masquerade as a trusted host to gain unauthorized access to a network?
  • Which tool is described as a metadata extraction tool?
  • In DNS, which record maps an IP address back to a hostname in reverse DNS?
  • Which AAA server protocol is commonly used with 802.1x authentication?
  • Which port is commonly used by Windows file sharing (SMB) over TCP?
  • Which controls must security professionals use to analyze and detect insider threats?
  • Which manipulation technique is associated with redirecting traffic to an attacker's computer as per the material?
  • Which term refers to the discrete technical steps that constitute an APT and differentiate it from other cyberattacks?
  • Which attack adds and modifies tags in the Ethernet frame to allow traffic flow through any VLAN?
  • What is the term for transferring a copy of the DNS zone file from the primary DNS server to a secondary DNS server?
  • Which network-monitoring tool captures all data transmitted over a network and provides a wide range of analysis statistics, including forensics, advanced protocol analysis, in-depth packet decoding, and automatic expert diagnosis?
  • Which Windows tool is commonly used for DNS queries and resolving domain names to IP addresses?
  • Which policy provides maximum security by blocking all services, only enabling safe/necessary services and logging all activity?
  • Which attack is performed by supplying an unvalidated input or by injecting files into a web application?
  • The DNS record that allows you to alias both services to the same record (IP address).
  • A well-defined level of information security that includes policies, processes, procedures, standards and guidelines.
  • Which tool provides accurate capture of USB4 and Thunderbolt 3 protocols for fast debugging and problem-solving?
  • What is the general term for converting data into a symbolic form to hide its meaning?
  • What is the security feature that validates ARP packets in a network?
  • Which of the following tools is used to identify and download documents for metadata extraction in a corporate context?
  • What is the name of the technique that hides target controls with opaque overlays which are removed briefly to register a click?
  • Which tool is marketed as a rainbow-table-based Windows password cracker with a graphical user interface?
  • Which tool is used to track visitors, monitor sales, and show conversion rates with the company's website?
  • Which hping3 command performs a SYN scan on ports 50 to 60?
  • Which tool dumps Windows event log records for analysis?
  • A Watering Hole Attack targets which of the following by compromising a site frequently visited by the intended victims?
  • Which vendor offers the SEC EDGAR database service on the web with links to SEC documents?
  • Which monitoring tool shows real-time file system, registry, and process/thread activity?
  • The process of reducing and maintaining risk at an acceptable level by means of a well-defined and actively employed security program.
  • Which scan relies on analyzing the TTL field value of RST packets in response to ACK probes?
  • What term describes tools that give attackers remote control over the victim's system?
  • can change the proxy settings in the user's browser to send all sessions through an attacker's machine.
  • What attack method involves sending emails with malicious attachments or content to many recipients to trick them into executing malware?
  • What vulnerability occurs when an attacker can impersonate a user due to weak or predictable session identifiers?
  • Which tool helps an attacker identify the topology of a target network and trace the path to the target host, revealing the positions of firewalls, IDS, routers, and other access control devices?
  • Which zone would typically host security-sensitive management interfaces and critical administrative services?
  • Which Android-based proxy tool supports HTTP/SOCKS4/SOCKS5 proxy and user authentication?
  • Which Kill Chain stage establishes two-way communication between the victim and an adversary-controlled server and may use encryption to hide the channel?
  • Which phishing variant targets high-profile executives or celebrities with access to valuable information?
  • An attacker captures the hash of a password and compares it with the precomputed hash table. If a match is found, the password is cracked. What is this process called?
  • Sublist3r syntax: which option specifies the target domain?
  • Which program takes snapshots or screenshots of the computer on which it is installed?
  • Which term refers to a text or image condensed into a single dot using a reverse microscope to avoid detection?
  • What term describes attackers who publish malicious apps in major app stores to steal user credentials?
  • DDoS Protector is described as what in the material?
  • Which category system is widely used as a baseline for weakness identification, mitigation, and prevention?
  • Which attack is described as implanting a backdoor in firmware of a bare-metal cloud server to bypass security?
  • Which attack targets the TCP state table by sending a flood of SYN packets with spoofed addresses to deplete resources?
  • Which term describes corporate espionage aimed at undermining a target's market position by stealing information?
  • Which operator lists web pages that have links to the specified web page?
  • Which tool is described as a PHP/Python-based script that helps in scanning and discovering php/cgi/perl/asp/aspx shells and maintains a web shells signature database?
  • Which tool helps to track website updates and automatic changes?
  • Which file extension is associated with SonicWall Global VPN Client files that may contain sensitive login information?
  • Which SQL injection example illustrates an end-of-line comment technique?
  • Which network scanner is listed in the material?
  • Which scenario best illustrates a webhook's typical usage?
  • Which virus type hides from antivirus by concealing the original file size or presenting a copy of itself elsewhere while the infected file remains?
  • Which vulnerability involves modifying input to embed path traversal sequences to reach restricted directories?
  • Which cryptographic concept uses keys that can be distributed openly and are used for encryption and decryption?
  • Which term refers to malware that can reproduce itself to spread to other computers?
  • What term describes malware that secretly gathers information about users without their knowledge?
  • Which tool is used to detect and exploit REST API vulnerabilities and can be integrated into CI/CD?
  • Which technique hides content in a carrier medium visible to everyone.
  • Which tool helps identify and fingerprint WAF protections protecting a website?
  • Which term refers to information warfare which involves the attacks against the opponent's ICT assets?
  • Which scan relies on analyzing the WINDOW field value of RST packets in response to ACK probes?
  • Which type of malware infects Microsoft Office files by exploiting macros?
  • Which web vulnerability scanner has session splicing capabilities?
  • Web application vulnerabilities that allow untrusted data to be interpreted and executed as part of a command or query.
  • Which assessment type identifies the operating system on a host and tests it for known deficiencies, and also searches for common applications and services?
  • What term refers to tools to perform user-directed spidering?
  • Which tool is described as a live OS that can run from a DVD, USB, or SD card, allows attackers to use the Internet anonymously, and leaves no trace on the computer?
  • ARP packets are used to discover all active devices in the IPv4 range even when their presence is hidden by restrictive firewalls. What is this technique called?
  • Which tool is commonly used to scan for executables prone to DLL hijacking?
  • Which term describes the network of IP-addressed devices that can sense and transmit data?
  • Which tool provides real-time visibility and expert analysis of each part of the target network and can analyze, drill down, and fix performance bottlenecks across multiple network segments?
  • Which assessment focuses on testing databases such as MySQL, MSSQL, Oracle, and PostgreSQL for data exposure or injection-type vulnerabilities?
  • Which REST constraint describes the separation of concerns between client and server, allowing independent evolution?
  • Gaining control over an HTTP user session by obtaining the session IDs is called?
  • Which attack embeds malicious JavaScript that captures session tokens in the background?
  • Which online tool is used to monitor mentions of an organization's name across the internet?
  • Which service provides an anti-abuse API to determine blacklist status of IP/domain/email?
  • Which tool is described as a network monitoring platform that can gather data via SNMP, WMI, and SSH?
  • Which attack uses a grammatically correct SOAP document containing infinite processing loops to exhaust XML parser and CPU resources?
  • Which keylogger is a hardware device placed between the keyboard and the computer, requiring no software, and records keystrokes?
  • An attack vector is a flaw within a client's application cloud which can enable attackers to access other client's data.
  • Which attack uses a single input dictionary to build chains of combined words?
  • Which utility identifies users currently logged on locally or via network shares?
  • Which protocol is used for unencrypted remote login on port 23?
  • PowerShell transcript logs and Windows Event logs can be checked to identify malicious hosts; the user agent string and IP addresses can also be used for this purpose.
  • An XML parser misconfiguration allows an attacker to abuse external entities and access restricted resources. This attack is called:
  • Which malware inserts itself into a file or executable and spreads to other systems?
  • Which DNS record contains host information such as CPU type and operating system?
  • What is the term for software that monitors, records, and forwards all incoming and outgoing emails?
  • Which tool is used to deploy honeypots and create virtual machines under GNU license?
  • Which technology abstracts hardware resources to enable multiple operating systems to run on a single machine?
  • What is the term for collecting information by searching physical trash for sensitive data?
  • Which layer handles HTTP requests from clients and serves web pages using servers such as IIS or Apache?
  • Which tool provides a lookup database for default passwords, credentials, and ports?
  • Which term represents the numeric identifier that uniquely identifies an object in the MIB hierarchy?
  • Which type of malware masquerades as legitimate software but opens a backdoor for attackers?
  • Which term describes software designed to be controlled remotely to perform tasks automatically?
  • Which service offers IAM services including SSO, MFA, IGA and intelligence collection?
  • Which tool reconstructs the malicious firmware from the legitimate firmware, enabling deconstruction and reconstruction of firmware images for various embedded devices?
  • The DNS record that points to the host's IP address and is commonly used for IPv4 is:
  • Which Kerberos credential type enables forging TGTs for any account within a domain?
  • Name a tool designed to exploit weaknesses in DHCP and other protocols, used for testing networks?
  • Which tool provides a robust network threat detection engine with IDS, IPS, and NSM features and supports offline pcap processing?
  • Which tool is described as a tool for comparing websites (traffic) by using Alexa, Compete, and Technorati?
  • A honeypot that emulates a limited set of services and triggers errors for unexpected actions is best described as which type?
  • What is the name of the tool used to implement ACK tunneling?
  • Which feature within OmniPeek provides targeted visualization and search capabilities?
  • Which scanning technique relies on the Simple Service Discovery Protocol (SSDP) to interact with devices using multicast addresses?
  • Which security mechanism provides an additional factor beyond password to verify identity?
  • Which mechanism binds a client’s TLS session to a public key certificate to mitigate MITM attacks?
  • What is the primary function of spider honeypots?
  • Which attack uses multiple sources to overwhelm a target with traffic?
  • Which firewall type works as a proxy server and filters connections for specific services and protocols when acting as a proxy?
  • The scenario where an authorized person unintentionally or intentionally allows an unauthorized person to pass through a secure door is called what?
  • Which protocol uses an asymmetric key pair to deliver the shared session key?
  • Which tactic involves an authorized person allowing an unauthorized individual to pass through a secure door, for example by saying they forgot their ID badge?
  • Which technique uses a wider bandwidth and code synchronization to recover data from spread-spectrum signals?
  • Security professionals can identify this behavior by checking logs for process IDs, processes with arbitrary letters and numbers, and malicious files downloaded from the Internet.
  • Which virus type remains permanently in memory during an entire work session, even after the target host's program is executed and terminated?
  • Which cloud model describes a dynamic, multi-vendor environment where workloads are spread across several clouds and managed via a single interface?
  • OpenVAS is a vulnerability scanner used to identify vulnerabilities in what?
  • An adversary modifies the content of the HTTP user agent field to communicate with the compromised system and to carry further attacks.
  • Which virus type blocks access to target machines or provides victims with limited access to the system?
  • An attacker takes advantage of the DNS recursive method of DNS redirection. What attack term describes this?
  • Which term describes attempts to cause users on a network to flood each other with data, making the traffic appear as if everyone is attacking everyone and masking the hacker's identity?
  • Which honeypots are also called email traps and attract fake and malicious emails from adversaries to inform administrators and warn employees?
  • What Windows object represents the security context of a process or thread?
  • The attacker performs password cracking without communicating with the authorizing party.
  • Which tool is specifically designed to protect malware from reverse engineering or analysis?
  • Which tool is described as capable of flooding a target by sending an HTTP POST flood from mobile devices?
  • Which software can detect and remove spyware, adware, Trojan horses, rogue security software, computer worms, rootkits, parasites, and other potentially harmful software applications?
  • What is the process of reverse engineering a specific piece of malware to determine its origin, functionality, and potential impact called?
  • Which term describes safeguards, separation of duties, and privilege assignments to minimize risks to critical assets?
  • DroidSheep is a tool used for session hijacking on which platform?
  • Which terms describe the encryption protocols intended to protect wireless network traffic?
  • Which stage is primarily focused on gathering information and identifying weak points before launching an attack?
  • Which pattern is used to locate SSL VPN service information pages containing remediation guidance?
  • A technique used to hide the message within a large amount of useless data.
  • Which Kill Chain stage describes the attacker gaining access to confidential data, disrupting services, or destroying operational capability after compromising the network?
  • Which tool hides secret data in WAV/FLAC, can extract from audio CD tracks, and encrypt secret files?
  • Which term refers to a login mechanism that intentionally allows access after certain failure conditions, potentially weakening authentication security?
  • Which method uses hardware designed to capture keystrokes directly from input pathways and typically requires physical access?
  • Which attack is browser-based and uses a malicious extension or code to manipulate security checks?
  • Weak encryption or improper storage can let attackers steal or modify highly sensitive data such as credit card numbers or SSNs. This is known as:
  • Most susceptible to buffer overflows
  • Which tool is vendor-agnostic and supports many firewall brands for log analytics and bandwidth reporting?
  • What term describes using a tool to locate the original source and details of an image, such as photographs or profile pictures?
  • Which Trojan hides its data by masquerading as ICMP_ECHO traffic and tunnels data within ICMP packets?
  • In which assessment does the ethical hacker manually evaluate vulnerabilities, ranking, and scoring?
  • Which malware family is described as a backdoor that can bypass standard authentication or security measures?
  • Which is the final step in the seven-step Cyber Kill Chain?
  • A UDP scan on port 80 checks for what?
  • Which term best describes the objective of an APT attack, such as obtaining sensitive information or achieving political goals?
  • Which service offers virtualization of container engines, management of containers, applications and clusters through a web portal or API?
  • Which term describes a method to deploy and hide Trojans in a covert protocol?
  • Which RAT is described as having powerful data-stealing capabilities?
  • Which tool is used to audit an organization's security for phishing attacks using methods such as Entice to Click, Credential Harvesting, Send Attachment, Training, Vishing, and Smishing?
  • Which Trojan category uses vulnerable service protocols to attack the victim's machine?
  • What encoding is used to represent unusual characters so that they can be safely used within an HTML document?
  • Which type of messages are commonly Base64-encoded in web authentication flows and can be decoded to reveal their contents?
  • Which tool is described as producing a hash value for files using multiple algorithms including MD5 and SHA-256?
  • What is a self-replicating program that copies itself by attaching to other executable code and runs without user consent?
  • Which pair of IPsec services correspond to integrity/origin authentication and confidentiality?
  • A WAF primarily inspects which type of traffic to detect web application attacks?
  • Which database is described as maintaining a CVE database containing details of the latest vulnerabilities?
  • Which of the following is not typically categorized as a password cracker?
  • Which encoding uses the hex value of characters to transmit binary data, often used in data representations?
  • Which intrusion category is suggested by short or incomplete logs, unusually slow system performance, missing logs or incorrect permissions, modifications to system software, unusual displays, gaps in accounting, system crashes, and unfamiliar processes?
  • Which technique can be used by an adversary as a tool for automating data exfiltration and launching further attacks?
  • Which virus actively alters and corrupts service call interruptions?
  • Which of the following attacks is a type that a WAF such as dotDefender is designed to mitigate?
  • Which protocol uses UDP port 69 for file transfer?
  • What term describes an alarm when no actual attack is in progress?
  • What is the name of the attack that uses a transparent frame to overlay content and trick a user into interacting with a hidden element?
  • Which flag enables the TCP timestamp option in hping3?
  • Which symptom could indicate an SQL injection vulnerability has been exploited?
  • Which framework is developed for securing cyberspace based on the concept of military kill chains?
  • What tool is used to observe and analyze the network traffic generated by malware?
  • Identify the network scanner app for iOS that scans LAN, Wi-Fi networks, websites, and open ports, discovering network devices.
  • Which statement best describes the difference between Network-Based IDS and Host-Based IDS?
  • Which tool is an enumeration tool for NetBIOS and SMB protocols?
  • Which tool bypasses the HTTP proxy to access blocked services such as email and instant messaging?
  • Which term describes how long the attacker remains undetected in the target network?
  • Which type hides one OS in another?
  • Which register stores the address of the next data element to be stored onto the stack?
  • Which technique distributes web server load across multiple servers to increase reliability?
  • A network of computers infected with a virus and used to carry out security breaches is called what?
  • Which software hides itself on a target phone to monitor and log activity such as Internet use, texts, and calls?
  • Which capability describes remotely installing applications, running programs, and updating files on Windows machines across a network?
  • In REST, which principle ensures the server does not retain session information between requests, while the client stores session state?
  • Active Session Hijacking is described as:
  • Which analysis method involves executing the malware to observe its behavior on the host system?
  • What term defines the weakness or flaw in a system that can be exploited?
  • Which technique uses ARP-based strategies to detect sniffers by manipulating the ARP cache?
  • Which acronym stands for Remote Procedure Call?
  • Which Trojan family provides remote control of a command shell on a victim's machine?
  • Which NirSoft utility is designed to recover all network passwords stored on the system for the current user, and can also recover passwords stored on external drives?
  • Which ransomware attacks victims through email campaigns, with ransom notes directing victims to contact the actors via email and pay in bitcoins for decryption?
  • In the Kill Chain, which stage includes spreading the infection to other end systems in the network after initial compromise?
  • Which practice is used to map out potential threats by considering attacker goals, system architecture, and data flow?
  • Which operator lists web pages that are similar to the specified web page?
  • Which tool would you use to identify and download documents for metadata extraction in a corporate context?
  • AS-REP Roasting is the process of cracking which Kerberos artifact to recover the user's password?
  • Which resource focuses on collecting CVEs and cybersecurity incidents?
  • What process computes the hash value for a binary to help identify and track files across a network?
  • Which tool is described as extracting names and email addresses from Outlook to enable phishing campaigns?
  • Which tool is a network traffic sniffer app with SSL decryption using MITM techniques, capable of capturing and decrypting SSL traffic and displaying packets in hex or text?
  • Which firewall focuses on the application layer and uses proxies to filter traffic, restricting traffic to services supported by the proxy?
  • Which attack specifically exhausts DHCP addresses by overwhelming the DHCP server with requests?
  • Which assessment starts by building an inventory of protocols on the machine, then detects ports attached to services, and finally selects vulnerabilities to test?
  • Which term refers to methods attackers use to deploy and hide malicious Trojans in an undetectable protocol?
  • Which keylogger category replaces the existing I/O driver with embedded keylogging functionality and sends keystrokes via the Internet?
  • Which technique do antivirus products use to execute suspicious code in a controlled environment to detect encrypted and polymorphic viruses?
  • Which malware type captures a target's sensitive data such as IDs and passwords from a web browser form or page?
  • In the seven-step Cyber Kill Chain, which is the second step?
  • Which protocol allows a client to access and manipulate electronic mail messages on a server?
  • Which attack targets directory services by manipulating LDAP statements constructed from user input?
  • What is a patch?
  • Which term refers to the monitoring of telephone or Internet conversations by a third party with covert intentions?
  • Which command delivers network route tracing with performance tests, DNS, Whois, and network resolution to investigate network issues?
  • Which term describes injecting client-side scripts into web pages viewed by other users?
  • What is the term for data attached to a file but not stored within the file itself on an NTFS system?
  • Which protocol is used for accessing and maintaining distributed directory information services over an IP network?
  • Which tool changes account passwords?
  • What is a container image?
  • An attacker uses cloud file synchronization services like Google Drive or Dropbox to enable data compromise, command and control, exfiltration, and remote access. What is this attack called?
  • Which system monitors all network traffic, ideal for observing sensitive network segments?
  • Which term describes a mechanism to enable a program on a client to execute a function on a remote server?
  • What is the tool used to discover the router on the path to a target host or firewall location?
  • Which protection and auditing tool detects ransomware attacks coming from the network and stops them?
  • Which Trojan is described as a financial fraudulent malware that targets POS and payment equipment such as credit card and debit card readers?
  • Which of the following is described as an open source intelligence gathering framework used for automated footprinting and OSINT research?
  • The infected machine probes IP addresses randomly from the target network IP range and checks for vulnerabilities
  • Which sniffing technique uses MAC flooding to sniff the packets by forging ARP packets with the target MAC address as the source and the attacker's MAC address as the destination?
  • Which indicators are found by performing an analysis of the infected system within the organizational network, including filenames, file hashes, registry keys, DLLs, and mutex?
  • Which file name launches the Computer Management Console?
  • Which local security database stores user accounts on a Windows machine?
  • Which policy defines the sensitivity levels of information?
  • Static malware analysis is also known as which term?
  • In hping3, which option switches to UDP mode?
  • Which term is described as an advanced security mechanism for username-and-password-based login models?
  • Which type of attack exhausts resources in network infrastructure devices by consuming connection state tables on devices like load balancers, firewalls, and application servers?
  • Which tool is described as a network stress and DoS/DDoS application capable of attacking up to 256 URLs simultaneously?
  • Which category includes artifacts found on the host such as filenames, file hashes, registry keys, DLLs, and mutex?
  • What technique allows attackers to inject malicious code directly from the Windows registry through a legitimate system process, bypassing UAC and other controls?
  • Which OWASP vulnerability category is commonly listed as top item on the OWASP Top Ten?
  • What does the Reverse IP Domain Check tool help you determine?
  • Which layer includes cloud services, a B2B layer that holds all the commercial transactions, and a database server that supplies production data in a structured form?
  • Which Sublist3r option enables verbose output?
  • Which description best matches automated testing in web application security testing?
  • Which AWS hacking tool includes automated scripts for reconnaissance, escalating privileges, maintaining access, and clearing tracks?
  • The tool set described as 'Professional Toolset' for DNS tasks is:
  • Which tool allows a user to control and manage remote systems from the command line?
  • Which URL pattern is commonly used to locate FortiGate SSL-VPN login portals?
  • Which assessment type involves obtaining credentials of all machines in the network to perform the assessment?
  • Which term describes the overall goals of an APT that may include political or strategic aims rather than pure profit?
  • What term describes the time it takes to be accepted or rejected after a person provides identification and authentication information?
  • Which detection method involves monitoring network traffic for malicious file transfers, file integrity monitoring, and event logs to identify data staging?
  • Which application programming interface provides online web services to client-side applications for retrieving and updating data from multiple sources?
  • Which type is described as hiding content on the web by placing it behind other web objects?
  • Which term describes recognizing, measuring, and classifying security vulnerabilities in a system?
  • Which term best describes a system that queries multiple search engines and aggregates results?
  • Which tool can be used to establish a VPN using the SSH TCP/IP tunneling feature or provide a secure file depository via SFTP?
  • Which tool is used for link analysis and graph-based investigations?
  • Which keyword is used to locate VPN SSL login portals that provide access to many organizations VPN services?
  • What is the name of the attack where an attacker compromises a DNS server and changes its mapping to redirect requests to a rogue DNS server?
  • Port 631 is assigned to which printing protocol by default?
  • Which DNS enumeration technique queries the DNS server for a specific cached DNS record?
  • Which assessment type commonly uses tools like Nessus or Qualys as part of its process?
  • Which Google search command returns sites that contain the search terms in the page title?
  • Which file lists the directories and files that the website owner wants to hide from web crawlers?
  • What indicates the receipt of a packet in TCP communications?
  • Which WebApp Security Scanner is described as searching for vulnerabilities such as SQL injection and XSS?
  • What category covers adversaries creating and configuring multiple domains that point to the same host to switch between domains and evade detection?
  • What risk arises from misconfigured CORS?
  • Which protocol is used to mount file systems on a remote host over a network, enabling interaction as if mounted locally?
  • Which scan type involves sending an SCTP COOKIE ECHO chunk to the target, resulting in no response when the port is open?
  • Which Sublist3r option is used to write results to a file?
  • Which term describes malware that uses obfuscated or layered code to mislead disassembly and analysis?
  • Which attack creates a new alphabet from 2- to 3-character syllables derived from passwords to match against the password database?
  • Which tool is used to create customized viruses and offers many built-in options to create a virus?
  • Which protocol enables running a payload on a remote Windows system to modify services and the registry for lateral movement?
  • Which scan sends ACK probe packets to multiple ports and analyzes the TTL value of the RST packets received?
  • Attackers exploit pre-installed Windows tools to install and run malicious code; what category is this?
  • Which SMTP command is used to define the recipients of a message?
  • In which phase does the attacker wait for the victim to log in to the target web server using the trap session ID and then take over the session?
  • What is a side-channel attack that retrieves sensitive information by measuring the response time of the server?
  • Which term describes an anti-analysis technique that prevents disassembly tools from listing program instructions correctly?
  • Which layer contains code that reads data from the browser and returns the results (e.g., IIS Web Server, Apache Web Server)?
  • Which technique uses voice technology such as the telephone system or VoIP to obtain personal or financial information?
  • Which scanner can simultaneously perform two or more scans on different machines in the network?
  • Which device verifies that packets belong to an established session?
  • Architectural style for web services using HTTP semantics.
  • Which DNS record identifies the e-mail servers within your domain?
  • Which rootkit replaces regular application binaries with a fake Trojan or modifies the behavior of existing applications by injecting malicious code?
  • Which directory stores plist files that execute with user privileges?
  • In the referenced model, which layer provides the connection between endpoints?
  • Which hardware keylogger is a device that captures keystrokes from a PS/2 or USB keyboard?
  • In this type of attack, a hacker alters the content of the web page by using HTML code and by identifying the form fields that lack valid constraints?
  • Which specific attack floods a target with spoofed UDP packets directed at random ports with a large source IP range?
  • Which term describes a safe, encrypted tunnel over a public network for secure communication between endpoints?
  • Which term describes threat intelligence that provides information about the resources an attacker uses to perform an attack, such as command and control channels and tools?
  • Which term refers to a practice that manipulates search engine results to promote harmful software?
  • Which term refers to clues, artifacts, and forensic data that indicate a potential intrusion?
  • Which scan is described as being performed quickly by scanning thousands of ports per second on a fast network not obstructed by a firewall?
  • Which post-exploitation tool is used to check common misconfigurations to escalate privileges?
  • Which tool is used for gathering email account information from public sources and checks if an email was leaked using the haveibeenpwned.com API?
  • Which term describes the act of deserializing malicious serialized content along with injected code, compromising the system?
  • Common software vulnerabilities that happen due to coding errors that allow attackers to gain access to the target system are known as what?
  • Which product is described as a framework of services and tools offering vulnerability scanning and vulnerability management?
  • Which process involves reducing and maintaining risk at an acceptable level?
  • Which tool audits and validates the behavior of security devices by generating standard application traffic or attack traffic between two virtual machines?
  • Which approach can accelerate tests and provide repeatable results but cannot replace manual testing entirely?
  • Which propagation method uses a central source to manage the transfer of tools to compromised hosts?
  • Which spyware type captures web form data submitted via browsers?
  • Which online service is named for discovering subdomains?
  • Which term describes phishing targeted at high-profile executives to obtain confidential information?
  • Which term is used to describe where information about threats is collected from online sources?
  • Which detection method identifies DNS tunneling by analyzing DNS requests, DNS payloads, unspecified domains, and the destination of DNS requests?
  • Which malware family is described as targeting POS devices and payment equipment to skim card data?
  • Which service offers insights into competitors' search, affiliate, display, and social marketing strategies and metrics to improve marketing campaigns?
  • Which utility lists information about a system?
  • Which system detects intrusions by matching traffic against a database of known attack signatures?
  • Which device blocks DDoS attacks with multi-layered protection?
  • Which web shell variant is described as a PHP-based web shell that allows attackers to monitor running processes and execute remote commands to download, upload, erase or edit files?
  • A website as well as a paid subscription-based publication that publishes industry reports.
  • The technique used for recovering passwords from hashes using the unused processing power of machines across the network is known as what?
  • Which web security policy protects HTTPS websites against MITM attacks by enforcing secure connections?
  • Which keylogger is installed with one-time physical access to the target machine and then logs keystrokes retrievable via Bluetooth?
  • Which network sniffer utility shows the DNS queries sent on your system?
  • Which attack method relies on encoding payloads so the shellcode is rewritten on each delivery to avoid pattern matching?
  • Which web server technology is developed by Microsoft for Windows?
  • Which inter-process communication mechanism is used in Windows to enable legitimate communication between running processes by exchanging messages through a pipe?
  • Which term collectively refers to attacks such as Bluesnarfing and Bluejacking?
  • Which term refers to ensuring that information remains confidential and integral during processing and storage, among other aspects?
  • Which command demonstrates scanning a range of ports using the -8 option?
  • Which tool is used to manage Windows audit policy settings?
  • Which tool focuses on monitoring brand and trademark usage across paid and organic search, local search, and social channels worldwide?
  • Which flood attack collects a list of pages or images and appears to be going through these pages, but secretly floods the target?
  • Which type of attacks involves stealing data and personal identities?
  • Which term describes the specialized Whois service that stores only the registrar's Whois server name?
  • SPECTER refers to which IDS-related concept?
  • Which policy forbids everything, with no internet connection or severely limited internet usage?
  • Heartbleed is a notable vulnerability in the OpenSSL library. Which of the following is the name given to this flaw?
  • A web-based communication protocol that enables interactions between applications on different platforms via XML and HTTP; SOAP-based APIs can generate, recover, modify, and erase logs.
  • Which rootkit replaces the original OS kernel and device driver codes?
  • What malware is capable of changing the system's DNS server settings and gives attackers control of the DNS server used on the victim's system?
  • What term refers to the utilization of information and communication technologies (ICT) for a competitive advantage over an opponent?
  • Which server/client-based honeypot application captures the rootkits and other malicious malware that hijacks the read() system call?
  • Which scanner resides on a single machine but can scan several machines on the same network?
  • Which tool is described as an information gathering tool for a website or IP address?
  • Which attack presumes that the message and the stego-medium are available, enabling detection of the technique used to hide the message?
  • The DNS record that points to a host's IP address is:
  • the attacking host itself transfers the attack toolkit to a newly discovered vulnerable system, exactly at the time it breaks into that system.
  • Which name refers to a tool that enumerates Google Cloud storage buckets and checks privileges?
  • Which assessment would evaluate the internal network by examining hosts, services, and vulnerabilities from within the organization?
  • Which of the following is a suite of command-line utilities used to control and manage remote Windows systems?
  • Which act is a legal framework aimed at protecting investors and improving corporate governance?
  • Which virus stores itself with the same filename as the target program file, potentially masquerading as the legitimate program?
  • Which term describes the act of publishing an individual's publicly available information online?
  • Which item is the Push (PSH) TCP flag?
  • This type of steganography hides the message in the carrier another file.
  • Which type of web page would typically host Cisco ASA login interfaces?
  • Which technique allows you to change (spoof) the MAC address of your NIC instantly?
  • Which form of social engineering involves leaving a physical device, such as a USB flash drive containing malicious files, in a location where people can find it?
  • Which OSINT tool is described as performing name server lookup?
  • Which term describes the phase of gathering information about a network and the organization, such as IP ranges and employees, prior to attack?
  • Which rootkit type acts as a hypervisor and modifies the boot sequence to load the host OS as a virtual machine?
  • What term describes a procedure used for identifying active hosts, open ports, and unnecessary services enabled on particular hosts?
  • Which statement about Sublist3r's search engine usage is true?
  • Which attack starts with a SYN while the real connection is not yet established and uses an invalid TCP checksum?
  • What tool is used to silently copy files from USB devices?
  • Which term stores the address of the next instruction to be executed?
  • Which virus is identified by the family name Win32/Simile that targets Windows systems?
  • Which honeypot type is described as deployed inside the production network and captures only a limited amount of information about the adversaries?
  • Which Trojan starts a VNC server daemon on the infected system, allowing the attacker to connect with a VNC viewer?
  • What term describes artifacts and indicators that indicate a potential intrusion?
  • Which policy defines the terms and conditions of granting special access to system resources?
  • Which spyware logs printer activity and sends the log file to a specified email address over the Internet?
  • Which tool diagnoses Wi-Fi/Internet issues and can perform ping, traceroute, port scanning, Whois, DNS lookup?
  • What is the process of recovering passwords using techniques such as brute-forcing, guessing, and social engineering?
  • Port 1813/TCP, UDP is used for which RADIUS service?
  • Which of the following is commonly used to detect changes on a website and alert when content changes?
  • Which host discovery technique probes multiple ports to determine if they are online and to detect firewall behavior?
  • This TCP-related concept is used by attackers to distribute the payload and to create covert channels.
  • Which tool can hide data within a cover file (e.g., images) and watermark images with an invisible signature to detect unauthorized copying?
  • Which mechanism uses setuid and setgid bits to allow executables to run with elevated privileges?
  • Which technology allows HTTP-based tunnels to bypass proxies and potentially provide protection against spyware and identity theft?
  • Which Kill Chain stage is performed to collect as much information about the target as possible before attacking?
  • Which GUI tool is used for viewing ports and connections to detect trojans?
  • Which term describes a category of malware intended to perform harmful actions on a target system?
  • Which set of FTP-oriented tools is used to retrieve critical files and directories about the target from FTP servers?
  • Which technique involves decompiling browser extensions to inspect their behavior?
  • Which tool is described as an open-source anonymizer software that tunnels network traffic through a secure proxy by configuring Windows proxy settings automatically?
  • Which security feature restricts IP traffic on untrusted Layer 2 ports by filtering traffic based on the DHCP snooping binding database?
  • Vulnerabilities that include untrusted data interpreted and executed as commands.
  • Which family of attacks exhausts the target's bandwidth by consuming large amounts of traffic, either inside the target network or on the link to the Internet?
  • A disgruntled or terminated employee who steals data by introducing malware is an example of which insider type?
  • What is the term for the basic technique that checks a range of IPs to identify live hosts?
  • Which technique involves injecting an authentic-looking reset (RST) packet using a spoofed source address and predicting the acknowledgment number?
  • Which port is associated with NetBIOS name service?
  • Which technique helps determine if an IP or service is a source of threat?
  • Which types of confidential information are commonly associated with on-the-dark-web data?
  • Which kit exploits outdated software versions to distribute ransomware such as Cerber?
  • Which analysis method helps detect new or unknown viruses that are typically variants of an existing virus family?
  • What is the default authentication scheme that performs authentication using a challenge/response strategy?
  • What is the term for capturing the initial system state for comparison during malware analysis?
  • Which term denotes a person or organization that uses cloud computing services?
  • Which infrastructure is designed to verify and authenticate the identity of individuals?
  • A message warning of a non-existent computer virus threat that spreads through social engineering is known as what?
  • Which protocol maps IP network addresses to MAC addresses on a data link layer?
  • Which simple utility scans your computer for applications that are either susceptible to dylib hijacking or have been hijacked?
  • Which statement best describes scope in OAuth?
  • What is the term for a malware component that camouflages payloads to impede the normal operation of targeted systems?
  • What term describes a collection of computer software that detects and analyzes malicious code threats such as viruses, worms, and Trojans?
  • Which set of tools are listed as DNS lookup resources?
  • Which resource would best assist a sales team in identifying the right prospects using a large business records database?
  • the user hides the information in image files of different formats, such as .PNG, .JPG, and .BMP.
  • Active sniffing on a switched LAN typically involves what action?
  • Which command identifies wireless card?
  • Which query would locate the Asterisk web management portal?
  • Which hijacking method involves predicting the sequence numbers that a victim host sends to create a connection that appears to originate from the host, or a blind spoof?
  • The DNS record that indicates authority for a domain is:
  • Which attack path describes a sequence where an attacker first gains legitimate low-privilege account and escalates privileges?
  • Which tool is described as a free software that defends against traffic analysis by providing an open network?
  • What term describes the basic functional code of malware that results in security breaches?
  • What type of program allows manipulation of the fundamental binary data that makes up a computer file?
  • Which term describes the phase of attacking opponents ICT assets?
  • Which term describes hiding data within DNS requests to evade security controls?
  • Which rootkit is described as trojanized and masquerades as cracked software to infect systems and perform data exfiltration?
  • Which technique is used to hide malicious files and activities using rootkits and steganography?
  • Which technique encodes malicious content or data of other programs within DNS queries and replies?
  • Which tool would you use to compare websites' traffic using third-party metrics?
  • Which type of attack does not require technical knowledge to crack the password?
  • Which vulnerability arises when untrusted input is embedded in code or queries?
  • Which tool is designed to detect both known and unknown threats on mobile devices by analyzing device behavior?
  • Which tool includes a script that performs the basic enumeration of any open port?
  • Which tool is open-source vulnerability scanner used widely?
  • Which technique uses digital objects developed specifically to cover secret communication?
  • An insider who uses technical knowledge to identify network weaknesses and sells confidential information is best described as a ...
  • Which phase involves installing malicious programs like Trojans or rootkits to grant remote system access and enable remote execution?
  • Which type of malware is characterized by embedding itself inside the host file it infects?
  • What type of attack involves intercepting and monitoring network traffic and data flow on the target network and does not tamper with the data?
  • Which command-line protocol is used to securely manage network devices, typically as an alternative to Telnet?
  • The payload example that attempts to modify an existing row demonstrates which SQL operation?
  • Which tool is an open-source anonymizer software that tunnels traffic through a secure proxy and automatically configures Windows proxy settings?
  • An unsupervised self-learning system is used to define what the normal network looks like, and then uses this to detect deviations. Which category does this belong to?
  • Which technique manipulates DNS resolution to redirect a victim to a fraudulent site?
  • Which term refers to the assurance that the integrity, availability, confidentiality and authenticity of information and information systems are protected during usage, processing, storage, and transmission of information?
  • Which tool is used to implement ACK tunneling?
  • Redirects packets from a target host on the LAN intended for another host on the LAN by forging ARP replies?
  • What SNMP concept refers to the process of creating a list of the user's accounts and devices on a target computer?
  • What port range is associated with a SYN scan mentioned in the material?
  • Script-based injection uses scripts embedded in documents as email attachments; which option describes this approach?
  • Which category of malware triggers based on a time-based condition, such as a calendar date?
  • Which library is primarily used for packet capture on Windows?
  • What term describes the organizational approach followed by threat actors to launch their attack?
  • NetNTLM responses are used in which authentication protocol?
  • What is the default protocol used by hping before flags are applied?
  • Which term refers to using search operators to locate sensitive information that helps attackers identify targets?
  • Which technique uses a stolen or forged hash to gain access without decrypting the password?
  • Which virus type is commonly associated with attacking both boot sectors and program files, representing a hybrid infection strategy?
  • Which technique is a type of man-in-the-middle attack used to hijack HTTPS sessions?
  • Which shellcode evasion method encodes the payload and uses a decoder to rewrite the shellcode on every transmission?
  • Which database is the U.S. government repository that provides CVE details and vulnerability scores?
  • What term describes a repository containing a collection of notes or messages submitted by users over the Internet?
  • Which technique involves creating pages that imitate a bank to steal credentials?
  • Which type hides data by embedding it into a video file?
  • Which system classifies software weaknesses and is widely used by the community as a baseline for vulnerability identification?
  • GFI LanGuard is described as what?
  • Which term describes the act of spoofing the NIC's MAC address to impersonate another device?
  • What action involves manipulating or erasing logs to cover up unauthorized access?
  • OSSIM stands for Open Source Security Information and Event Management. Which option presents this correctly?
  • Performed by attackers to identify the passwords, API tokens and endpoints, vulnerable services running, backdoor accounts, configuration files in use, private keys, stored data, etc.
  • What term refers to components of Windows that allow external applications to access information such as file systems, threads, and registry?
  • Which rootkit type is described as substituting or injecting code into the kernel to conceal attacker activity?
  • Which technique relies on computers and Internet systems to carry out targeted actions?
  • Which category of attacks aims to exhaust the target's bandwidth, causing traffic blockage?
  • Which IoT malware became famous for turning devices into a botnet to attack external targets?
  • Which finding involves extracting FTP/SFTP credentials from a plaintext file opened in Sublime Text?
  • Which port/service matches TCP port 21?
  • Which protocol is used to update or upgrade software and firmware on remote networked devices and uses UDP port 69?
  • Which component is used to decrypt the virus code after it has started executing, typically following a control takeover?
  • Which keylogger type logs keystrokes by altering memory tables within the browser or system and can bypass security controls?
  • Which command uses the --email option to fetch words and email addresses from the target website?
  • Which attack includes multiple methods to target a service at the application layer and beyond?
  • An attacker disables Windows functionality such as last access timestamp, hibernation, virtual memory, system restore points, etc. to cover tracks. Which action is described?
  • Which term defines the use of information systems against the virtual personas of individuals or groups?
  • Which type of malware acts as a potent backdoor specifically targeting the root or operating system?
  • Which mechanism is used to maintain a session state in the stateless HTTP protocol?
  • Which tool is used to capture and interactively browse the traffic on a network?
  • Which ARP-based technique is used to discover active devices on an IPv4 network?
  • Which attack type exploits the second stage of the TCP three-way handshake by sending numerous SYN-ACK packets to exhaust server resources?
  • Which attack involves manipulating parameters exchanged between client and server to modify application data such as user credentials, permissions, and product prices?
  • Which type of malware rewrites the boot sector to gain control upon system startup?
  • Which of the following is widely used as an exploit database/resource for security testing?
  • Which tool is described as a multi-platform disassembler and debugger that explores binary programs?
  • Which ICMP method queries the target for a timestamp to obtain time information?
  • What term describes the technique of altering DNS mappings to redirect requests to a rogue server?
  • What term describes infrastructure that adversaries use to communicate with compromised systems through an encrypted channel?
  • Which NirSoft utility is used to recover passwords stored by browsers such as Internet Explorer, Firefox, Chrome, Safari, and Opera?
  • Which technology operates at the Internet Protocol layer to secure IP communications by providing confidentiality, integrity, and authentication?
  • Which tool is described as a program designed to identify and prevent malicious Trojans or malware from infecting computer systems?
  • Which statement best describes the redirect_uri in OAuth?
  • Which term describes the process of studying the changes that have taken place across a system or machine after a series of actions or incidents?
  • An attack that exploits the victim's active session by predefining or controlling the session ID used during authentication is known as what?
  • Which term describes the overarching practice of identifying the patterns and techniques used by attackers to breach networks?
  • Which firewall checks incoming requests for vulnerabilities but does not actively reject potential attacks?
  • Which tool is described as the command to put the wireless card in monitor mode?
  • Which DNS record is described in the material as mapping an IP address to a hostname and is used most often for DNS lookups?
  • What is the term for a category of network threats where the attacker gains unauthorized access and remains inside the network undetected for a long period?
  • Which tool can attack up to 256 target URLs simultaneously?
  • Which tool obtains detailed information on the kernel, which can be used to escalate privileges on the target system?
  • Security professionals can find unspecified domains by checking the data feeds generated by those domains, which can also reveal malicious files and unsolicited communication.
  • Which tool is described as a dedicated test solution for validating converged network service deployments in a lab environment?
  • It provides interface details and service implementation details.
  • Which technology has replaced the conventional PSTN in many corporate and home environments?
  • Nikto is a vulnerability scanner for what?
  • Which term describes an attack that overwhelms a target's network capacity to prevent legitimate access?
  • Which tool is used to identify SIP devices and PBX servers on a target network?
  • To detect hidden or background software installs performed by malware, which tool is used?
  • Which server platform on Windows supports multiple protocols including HTTP, HTTPS, FTP, FTPS, SMTP, and NNTP?
  • Which type of detection focuses on anomalies in the protocol layer to identify flaws in a TCP/IP deployment?
  • Which attack involves many hosts flooding a target with requests to overwhelm it?
  • Which term is a software application that can be remotely controlled to execute predefined tasks?
  • Which platform is described as a competitive keyword research tool that can provide Google keywords and AdWords for any site, along with a competitor list?
  • Which hping3 option initiates a flood of packets to overwhelm the target?
  • What term describes the use of radio-electronic and cryptographic techniques to degrade communication?
  • Which term is used for viruses that can secure intellectual property against emulation-assisted reverse engineering?
  • Which tool is described as a DNS proxy on Android to access IP addresses that are beyond the firewalls?
  • Which technology acts as a gateway for communication and integrates different applications using the web?
  • The attacker performs password cracking by directly communicating with the victim's machine.
  • Which keylogger can be accessed remotely over TCP/IP after installation?
  • Which term refers to a huge network of compromised devices used to perform distributed denial-of-service attacks?
  • Which term refers to the formal guidelines and rules governing security across the organization?
  • What is the term for two inputs producing the same hash?
  • Which practice would best defend against sniffing by encrypting communications end-to-end?
  • Which term best describes malware that forms a network of compromised hosts under centralized control?
  • Which Android mobile application is described as identifying the active host in the range of possible addresses in a network?
  • Which MIB is for the Windows Internet Name Service (WINS)?
  • Which technique describes hiding the secret message in a legitimate carrier message designed in a pattern unclear to the average reader?
  • Which virus is activated in response to a specific event, such as launching an application or a specific date/time?
  • Which keylogger is described as a forged Windows device driver that records keystrokes and is undetectable by standard tools?
  • Which program is described as a fake Android antivirus application?
  • Which weakness involves replacing original binaries with malicious binaries to escalate privileges by manipulating how binaries are launched?
  • Which type of attack is commonly used to disrupt services and can be launched via IoT devices?
  • AnDOSid is commonly used to generate TCP SYN, UDP, and ICMP traffic to test firewall rules, IDS signatures, and router ACLs. Which option matches this use?
  • Which web service testing tool supports multiple protocols such as SOAP, REST, HTTP, JMS, AMF, and JDBC for probing and injection testing?
  • Which tool is described as a PHP/Python-based script that helps in scanning and discovering php/cgi shells and has a web shells signature database?
  • FOR loop is described as an online tool to search default passwords.
  • Which tool is a Web Reconnaissance framework with independent modules and database interaction?
  • Which term refers to the point where the attacker obtains access to the operating system or application?
  • Which tool is described as a "website traffic monitoring tool"?
  • Which ransomware is linked to the GOLD LOWELL threat group and targets unpatched servers?
  • Which tool terminates a remote process by name or process ID?
  • A forensic examiner finds a file in the root directory used to store RAM contents during hibernation. Which file is this?
  • Which CVSS metric represents vulnerabilities based on a particular environment or implementation?
  • Which timing-based attack uses the browser to send crafted requests from the user's browser via JavaScript?
  • Which is an offline browser utility that downloads a website to a local directory and reconstructs directories and files?
  • Which device is designed to capture USB4 and Thunderbolt 3 protocol traffic for debugging?
  • Which Kill Chain stage triggers when the adversary's malicious code exploits a vulnerability after the initial weapon is transmitted?
  • The adversary analyzes collected data to identify vulnerabilities and techniques to exploit and gain unauthorized access, creating or selecting a deliverable malicious payload using an exploit and a backdoor. What is this stage called?
  • Obfuscating refers to which activity?
  • What is placed on the top of one physical server and host operating system, and share the operating system kernel binaries and libraries, thereby reducing the need for reproducing the OS?
  • Which banner grabbing approach is less likely to alert the target because it does not initiate extra probes?
  • Which term refers to an intermediary server placed between the user and a website to browse anonymously and protect privacy?
  • Which operator returns results that contain all search keywords in the page title?
  • Which shell script checks for vulnerability against various 'speculative execution' CVEs?
  • It uses information obtained from an infected machine to find new vulnerable machines
  • Which Linux-based tool can be used to change Windows user passwords or activate disabled accounts?
  • Which approach involves the attacker posing as an authority figure and the target seeking guidance before divulging information?
  • Which honeypot application captures rootkits by intercepting the read() system call?
  • In Sublist3r, which flag sets the number of threads for subbrute bruteforce?
  • Which security product is described as essential for antivirus protection, exploit prevention, firewall implementation, and web control communication between systems?
  • Which virus category is known for corrupting the file system by manipulating the FAT structure?
  • Terabit DDoS Protection System (DPS) is designed to protect key network services by doing what before outages?
  • Which tool supports multi-hash algorithms and multi-device password cracking?
  • Which technique obfuscates malicious traffic by carrying it within common protocols in legitimate traffic?
  • Which type of malware uses firmware on hardware components to compromise devices?
  • Which Trojan is described as a small HTTP server embedded inside a program and can be bundled with legitimate software?
  • Which term describes security vulnerabilities due to insecure or misconfigured servers or apps?
  • Which term describes a malicious piece of code or script that is developed using server-side languages and then installed on a target server?
  • Which tool can be used to identify the target's operating system by observing TTL values in the results?
  • Which tool is used to identify the real IP address of load balancers behind a proxy?
  • Which register stores the address of the next instruction to be executed?
  • Which macOS persistence mechanism can be installed to run at boot by loading a plist via launchd/launchctl?
  • Which tool can map network topology and display OSI Layer 2 and Layer 3 topology data while tracking network changes?
  • OSRFramework includes applications related to which capabilities?
  • Which tactic involves sending mass messages with the expectation that recipients forward the message to others?
  • Which attack is a large-scale, coordinated assault on availability launched from many compromised machines over the Internet?
  • Which port is SNMPTRAP?
  • Attackers exploit weaknesses in authentication or session management to impersonate users. This vulnerability is known as?
  • During which phase are actual attacks on security controls performed?
  • Which term refers to security threats that target weaknesses in web applications to steal credentials or personal data?
  • Which tool is used for load-balancing detection by header analysis rather than broad web technology discovery?
  • An insider who bypasses general security procedures due to a lack of security awareness is known as a ...
  • Which command enumerates users on LinkedIn?
  • HIPAA primarily governs the protection of what type of data?
  • Which term denotes the process of evaluating malware threats through systematic analysis?
  • In this type of steganography, a certain language is used that can be understood by the particular group of people to whom it is addressed, while being meaningless to others.
  • Which tool is commonly used to analyze trends and identify popular content across social media?
  • Which activity is described as performing automated collection, validation, indexing, acceptance, and forwarding of submissions by companies and others who are required by law to file with the U.S. Securities and Exchange Commission (SEC)?
  • Which policy governs the management and monitoring of firewall devices within the organization?
  • Which tool is a parallelized login cracker capable of attacking numerous protocols?
  • Which Windows-based honeypot intrusion detection system attracts attackers by simulating vulnerable services?
  • Which Trojan category is known for disabling security software like firewalls or IDS, enabling the attacker to proceed with subsequent steps?
  • In machine learning, which broad category encompasses both the tasks of classification and regression?
  • Which debugger is described as a 32-bit Windows debugger ideal when source code is unavailable?
  • What architectural style defines a web service as a communication medium between systems on the web, using standard HTTP methods to operate on resources?
  • Port 443 is used for which service?
  • Which directory serves as the top-level root for the server's configuration, error, executable, and log files?
  • Which Windows protocol enables running a payload on a remote system to interact with WinRM for lateral movement?
  • Which threat category includes risks arising from trusted insiders who misuse their access?
  • IKE is the main key management protocol in IPsec that negotiates and establishes security associations and keys.
  • Which repository hosts publicly available exploits and proofs-of-concept?
  • Which command obtains the NetBIOS name table of a remote computer?
  • Which method involves dropping packets when a server is under heavy load and may require a requester to solve a difficult puzzle before continuing?
  • Which attack type involves multiple intermediary machines to contribute to a DDoS attack and is typically spoofed?
  • Which keylogger type attaches to the PS/2 or USB interface and does not require software to function?
  • Which REST constraint allows intermediaries to provide shared services such as caching without the client needing to know about the final server?
  • Which utility displays a list of all device drivers currently loaded in the system?
  • What is the name of the standardized list of common software vulnerabilities and exposures?
  • Which activity involves monitoring network traffic without injecting or altering any packets?
  • In cybersecurity frameworks, what does the acronym TTPs stand for?
  • Which honeypots are primarily deployed by research institutes, governments, or military organizations to gain detailed knowledge about intruders' actions?
  • Which app designed for iPhone and iPad allows attackers to browse websites smoothly and anonymously?
  • Which mode on a NIC allows capture of all traffic on the network, not just traffic addressed to it?
  • Which ransomware targets Linux devices with AES encryption on QNAP NAS?
  • Which tool is described as a program or automated script that browses websites in a methodical manner to collect employee names and email addresses, used for footprinting and social engineering?
  • Which routing protocol helps a host discover the IP addresses of active routers on its subnet by listening to router advertisements and solicitations?
  • Kiuwan, Veracode, Flawfinder, Splint, and BOVSTT are examples of what type of tools?
  • Which technique involves leaving a USB drive in a public area hoping someone will plug it into their computer?
  • Which term stands for the publicly available list of vulnerability identifiers used in advisories?
  • In Cisco VPN client configurations, which field is stored as enc_GroupPwd and is encrypted but can be cracked easily?
  • What term refers to protecting information by converting it into an unreadable form?
  • Which Bluetooth attack is specifically associated with unauthorized data access to a device?
  • Which file lists the directories and files to be hidden from web crawlers?
  • Which port is associated with NetBIOS name service?
  • Which hardware device captures keystrokes and stores them in its memory for later retrieval?
  • Which technique involves connecting a rogue switch to manipulate STP to intercept traffic?
  • Which flood attack uses randomly generated GET requests within a valid page range to appear legitimate and exhaust resources?
  • What term lists the open ports and services on a target computer by sending a sequence of messages?
  • The attacker performs probability analysis to test whether the stego object and original data are the same or not.
  • Which tool is a text extractor that can extract text from any file?
  • DNS commonly uses which transport protocols?
  • What is the primary purpose of a honeypot in security testing?
  • What technique places an executable in a path so that the application will execute it in place of the legitimate target?
  • Which tools are used to search for people belonging to the target organization?
  • Which tactic describes scanning the number of hosts in the target network in a random order to reach targets beyond a firewall?
  • Which tool is used to perform AS-REP roasting attacks?
  • Which IPsec protocol provides confidentiality in addition to AH's services?
  • Which tool acts as a poisoner for LLMNR, NBT-NS, and MDNS to capture credentials?
  • Which protocol is described as a reliable, message-oriented transport layer protocol?
  • Which keylogger observes typed content across emails, chats, and applications and can trace Internet activity, often invisible across the network?
  • Which Windows command is commonly used to enumerate shared resources on the network?
  • Which resource provides a database of default passwords and credentials?
  • The -1 flag in hping3 is used to send what type of packet?
  • Which vulnerability is described as the most common and is mainly caused by human error?
  • Which tool is commonly used to perform password cracking across multiple protocols including IPv6 support?
  • Which port is used by NetBIOS datagram service?
  • Which term describes viruses that rewrite their entire code during each infection, making each copy unique?
  • Which flood attack pretends to be navigating pages by issuing new GET requests from a valid page range?
  • Which assessment type observes vulnerabilities through the Internet using external routers, firewalls, or web servers?
  • Which virus type hides from antivirus by masking the original size of the file or temporarily placing a copy of itself on another drive, thus replacing the infected file with the uninfected file stored on the hard drive?
  • Which standalone application allows remote attackers to use the victim's computer as a proxy to connect to the target machine?
  • Which scan type sends TCP probe packets with a TCP flag (FIN, URG, PSH) set or with no flags?
  • Which technique uses precomputed hash tables to speed password cracking?
  • Which assessment would you use to verify vulnerability discovery across client and server applications with synchronized scanning?
  • Which protocol suite provides interoperability-based security for IP communications at the network layer?
  • Which option is used to perform a SYN scan in hping3?
  • Which technique involves injecting into the memory of a running process to propagate and re-inject (as described with local shellcode injection, remote thread injection, and process hollowing)?
  • Which DNS poisoning scenario uses a Trojan to modify a user's proxy settings to redirect to the attacker’s site?
  • Which term describes testing where the tester has full visibility into the application architecture and source code?
  • Which utility focuses on capturing and analyzing DNS queries generated by applications?
  • An attacker tricks a user into interacting with a legitimate web server using an explicit session ID value. What is this attack called?
  • Imperva Incapsula DDoS Protection is positioned to defend which kind of entities?
  • In a shared Ethernet environment, which statement describes how frames not addressed to a machine are handled?
  • Which zone is described as secured with strict policies?
  • Provides a means to identify a resource. It is a global identifier for Internet resources accessed remotely or locally.
  • Which attack uses a chi-square statistical test to determine embedding by examining frequency changes?
  • Which term refers to the preparatory phase where an attacker seeks to gather information about a target prior to launching an attack?
  • Which tool is described as providing information related to patent and trademark registration?
  • Which term is used to prevent dynamic analysis by fingerprinting the emulated environment, potentially protecting IP?
  • Which term refers to a channel used for legitimate data transfer within an organization?
  • Which search query locates the Cisco SPA504G Configuration Utility for IP phones?
  • Which tool is primarily used to perform AS-REP roasting against Active Directory accounts?
  • The attacker analyzes the embedded algorithm used to detect distinguishing statistical changes along with the length of the embedded data.
  • Which attack involves flooding the target with TCP or UDP fragments to prevent proper reassembly and degrade performance?
  • Which Trojan can bypass firewalls and operate in reverse, using web-based interfaces on port 80, spawning a child program at a predetermined time?
  • This technique compares characteristics of all system processes and executable files with a database of known rootkit fingerprints.
  • Which attack is described as an active sniffing technique used to steal and manipulate sensitive data?
  • Which router feature protects TCP servers from a TCP SYN-flooding attack?
  • It is a logic defect that leads to significant consequences in the authentication process.
  • Which vulnerability involves configuring a hostPath volume to retrieve sensitive information from the node?
  • Which technique involves manipulating access tokens to impersonate other users and escalate privileges?
  • Which type embeds the content in audio and graphical data?
  • Which honeypots are used to obtain in-depth information about intruder actions and attack methods to improve security mechanisms?
  • Which wireless tool is commonly used to detect and locate rogue access points and perform wireless network discovery?
  • Selects and implements appropriate controls for the identified risks.
  • Which option sends IP packets with a specific protocol number in the IP header for discovery?
  • After fileless malware infects a target, attackers use the system to move laterally and infect other connected systems. What is this technique called?
  • Which payload type involves sending extremely large data to exhaust system resources and disrupt service availability?
  • Which tool is described as a command-line oriented network scanning and packet crafting tool that supports ICMP, TCP, UDP, and raw-IP protocols?
  • Which product is known as the Refog Mac Keylogger?
  • Attackers use tools to identify subdomains related to the target bucket.
  • Port 515 is commonly associated with which printing service?
  • Which Google dork could be used to locate Excel files on a target site containing usernames, passwords, and emails?
  • Which tool allows real-time social network content search with analytics data?
  • The tool that extracts DNS information, DNS lookups, and Whois lookups is:
  • Which attack manipulates parameters exchanged between client and server to modify application data?
  • Which term stores the address of the first data element stored onto the stack?
  • Which tool allows an attacker to create custom network packets and helps security professionals assess the network?
  • Which intrusion detection approach uses models of potential intrusions and compares them with incoming events to detect misuse?
  • Which class of DoS attacks exploits vulnerabilities in application layer protocols or applications, often by opening and holding many connections?
  • Which header field controls how many routers a packet can pass through before being discarded?
  • Which vulnerability occurs when scripts do not validate untrusted input, enabling code injection via frames across browsers?
  • What action involves modifying or deleting logs to remove evidence of intrusion?
  • Which web service footprints a web server and gathers information such as server name, server type, operating systems, and applications running?
  • Helps in detecting hidden and background installations performed by malware.
  • Which DDoS attack uses a highly repetitive, periodic train of packets delivered every 10 minutes?
  • Which attack vector lures victims via email or a link to trigger remote code execution and obtain privileges equal to those of authorized users?
  • Which term describes allowing the sender to partially or completely specify the route a packet takes through the network?
  • Aircrack-ng is a tool used for what purpose in wireless security?
  • Which tool hides secret messages inside a photo and allows decoding with the same app, possibly with a password?
  • What does the process of fragmentation in network probes involve?
  • Which port number is used by the Line Printer Daemon (LPD) protocol?
  • Which tool can decrypt SSL/TLS traffic using MITM and display packets in hex or text?
  • Which term best defines the Dark Web or Darknet?
  • Which tool enumerates the DNSSEC zone and obtains results on the DNS record files?
  • Which keylogger operates at the device driver level and can intercept all keyboard input?
  • Which assessment tests and analyzes all elements of the web infrastructure for misconfigurations, outdated content, or known vulnerabilities?
  • Used when data classes are not separated, such as when the data is continuous.
  • Which term describes attacks that target the parsing stage of XML in web services to cause DoS or logic errors?
  • Which mechanism is designed to bind a client’s credentials to a TLS session to reduce the risk of MITM?
  • Which tool conceals messages in text files by appending tabs and spaces to the ends of lines?
  • Which tool lets you edit a field by selecting it and changing its value in an edit box?
  • Which policy is described as wide open and only known dangerous services or behaviors are blocked?
  • Which control category is described as Divide responsibilities among multiple employees to restrict the amount of power or influence held by any individual?
  • Which testing approach focuses on finding vulnerabilities by testing a running application from outside with no internal access?
  • Which tool examines Windows hardware and software vulnerability to Meltdown and Spectre attacks?
  • Which tool allows an attacker to track an email and extract information such as sender identity, mail server, sender's IP address, and location?
  • Which category of malware would typically deliver payloads by tricking users into enabling macros in documents?
  • Which publication is a paid resource known for publishing industry reports?
  • Which practice specifically deals with setting the path that a packet follows across the network?
  • Which type is described as hiding content by placing documents inside a folder so they can be recovered later?
  • Which port is commonly used by HP JetDirect printers for raw printing?
  • Which Kill Chain stage describes the attacker controlling the victim's system from a remote location and potentially using it as a launching point for other attacks?
  • Which register stores the address of the first data element stored onto the stack?
  • Which method can change browser proxy settings to route traffic through an attacker?
  • A security attack vector that threatens the performance of a website and hampers its security to steal user credentials, set up a phishing site or acquire private data by targeting web applications.
  • Which layer is described as responsible for moving and processing data between tiers?
  • Which register maintains the source index for various string operations?
  • Which cloud service model provides virtual machines and other hardware abstraction accessible via a service API?
  • Which term best describes the integrated set of industrial control components used to monitor and control processes, such as SCADA, RTU, PLC, and DCS?
  • APTs are tailored to which vulnerabilities?
  • Which technique relies on quickly swapping visible content so as to distract attention during interaction?
  • Which description matches a low-interaction honeypot used to observe attacks against TCP and UDP services, running as a daemon and starting server processes dynamically on requested ports?
  • Which scanning method is described as using a spoofed source address to discover available services?
  • Which policy allows access only to a defined set of URLs?
  • What is considered the foundation of the security infrastructure?
  • Which container vulnerability scanning tool is listed among the following?
  • Which term refers to extracting information such as IP address, protocols used, open ports, device type, geo location, manufacturing number, and manufacturing company?
  • Which method is typically used to discover reachable hosts behind a firewall by sending ICMP Echo requests?
  • Which software component performs protocol-level functions required to encrypt and decrypt IPsec packets?
  • Which scanning method uses ICMP ECHO requests to determine if a host is alive?
  • What name is given to attackers who inject malware into seemingly legitimate websites to trick users into clicking?
  • Which authentication mechanism allows a user to log in once and access multiple systems?
  • Which system is described as a honeypot that presents common Internet services to lure attackers?
  • Unauthorized use of the victim's computer to stealthily mine digital currency.
  • What term describes the technical methods used by an attacker to achieve intermediate results during their attack?
  • Which protocol is used to establish sessions for real-time communications such as voice and video?
  • Which assessment evaluates the network from an outside perspective to identify exploits accessible from the internet?
  • Product-Based Solutions are typically deployed how?
  • Which query finds configuration pages for online VoIP devices while excluding PDFs?
  • Which query would you use to find pages related to a given page?
  • Which platform is commonly described as a comprehensive security operations solution for threat detection, incident response, and compliance across hybrid environments?
  • What feature identifies and limits the MAC addresses of the machines that can access the port, forwarding only the packets with source addresses inside the allowed set?
  • NetPatch Firewall is best described as what kind of system?
  • In cybersecurity, which type of attack involves tampering with data in transit or disrupting communication between systems to bypass security?
  • Which regulation governs the protection of electronic medical data in the United States?
  • Which service footprints a web server by collecting server name, server type, operating systems, and applications running?
  • What term describes how a web application controls which users can create, update, or delete resources?
  • In CVSS, which metric represents the inherent qualities of a vulnerability?
  • Which local file can be edited to redirect DNS resolution to phishing sites?
  • Which DNS record type defines the hostname and port for services, enabling clients to locate specific services within a domain?
  • In e-commerce, what data can be altered via hidden fields to influence checkout pricing and transactions?
  • Which rootkit technique locates and manipulates the 'system' process in kernel memory structures to patch it?
  • Hides the text message by transforming the appearance of the carrier text message, such as by changing font sizes and styles, adding extra spaces as whitespaces in the document, and including different flourishes in letters or handwritten text.
  • Which service type enables code to run in response to events without managing servers?
  • Which scenario describes exposure of FTP/SFTP server credentials on a public code hosting platform?
  • Which RAT is described as having powerful data-stealing capabilities?
  • Which attack exploits cloud file synchronization services to enable data exfiltration and remote access?
  • Which DNS enumeration technique attempts to obtain internal records when the DNS zone is not properly configured?
  • Which cloud service model offers software to subscribers on-demand over the internet?
  • Which keylogger is marketed as Spyrix Keylogger Free and is used for remote PC monitoring while remaining hidden from security software?
  • Which attack involves sending large volumes of ICMP echo request packets to a victim system directly or via reflectors?
  • Which device facilitates separation of duties in a security architecture?
  • Port 1701 UDP is associated with which tunneling protocols?
  • Which policy defines who can have remote access?
  • Which zone acts as a barrier between internal networks and the internet, providing a controlled boundary?
  • Which rootkit replaces the original system calls with fake ones to hide information about the attacker?
  • Which resource provides a centralized database of SEC filings and related information?
  • Which capability allows an attacker to bypass firewall, antivirus, IDS/IPS, and email spam filter?
  • Which technique involves implementing a sequence of modifications to the cover to obtain a stego-object?
  • Horizontal privilege escalation refers to which scenario?
  • Which tool is used to identify the real IP address of load balancers?
  • Which scan uses FIN/ACK probes such that no response indicates Open|Filtered and an RST response indicates a closed port?
  • Which attack focuses on the vulnerabilities introduced by shrink-wrapped libraries and code?
  • Which attack method involves persuading people to reveal confidential information without breaking into systems?
  • A software design problem where unexpected input can be entered into an application is known as what?
  • Which ICMP method queries for the address mask to obtain subnet mask information?
  • Which Nmap option enables extensive detection such as OS detection and version scanning?
  • Evaluation Assurance Level (EAL) is associated with which security evaluation framework?
  • Which tool, listed here, is used to flood the local network with random MAC and IP addresses to facilitate sniffing?
  • Which TCP flag is used to initiate a connection in the TCP three-way handshake?
  • Which interface is used by Windows to enable authentication through various security packages such as NTLM?
  • Which vulnerability occurs when input from a client is not validated before being processed by the application?
  • Which technology commonly uses certificates to establish encrypted communications and verify identities across networks?
  • Which tool would you use to identify startup programs and their load order in Windows?
  • Which technique targets network resources on a VLAN to gain access to traffic in other VLANs?
  • Which term describes security mechanisms that redirect all malicious network traffic to a honeypot after any intrusion attempt is detected?
  • Which operator constrains results to a specific domain in Google searches?
  • Which assessment scans the internal infrastructure to identify exploits and vulnerabilities?
  • Which operator restricts results to documents containing all search keywords in the URL?
  • Which MIB is used for the Windows Internet Name Service (WINS)?
  • Which networking utility is known for reading and writing data across network connections by using TCP/IP and is often used for debugging and exploration?
  • Which practice provides users with only enough access privilege to allow them to perform their assigned tasks?
  • Which type logs and analyzes more complex attacks by simulating a real OS and applications, offering greater realism than low-interaction options?
  • Which term best describes exploiting default configurations in libraries and code that ship with software?
  • Which tool is described as open-source with plugins for different attack types to test web services?
  • refers to any type of data attached to a file, but not in the file on an NTFS system?
  • Which tool is described as capable of logging keystrokes, passwords, and screenshots while remaining hidden from antivirus software?
  • Which tool is used to inspect the dependencies of an executable and understand library relationships?
  • Which service uses port 25 by default?
  • Which tool is used to gather email account information from public sources (IP, hostname, country) and can check leaks via haveibeenpwned API?
  • Which term describes the entity that provides cloud services to customers?
  • Which port is SNMP?
  • Which term describes the characteristic that APT attacks are multiphased with stages like reconnaissance and exfiltration?
  • Which type hides web objects behind other objects and uploads them to a web server?
  • Which tool is commonly used to detect misconfigured services on the target operating system?
  • Which Android app performs passive vulnerability detection based on the fingerprint of installed software versions?
  • Architectural approach for web services using HTTP concepts; not a protocol.
  • Which technology hides internal network topology by separating internal and external IP addressing and acts as a choke point for traffic?
  • Kerberoasting is cracking the TGS to recover the service account password.
  • Which honeypot entry describes running actual vulnerable services on production systems and capturing complete information about an attack vector?
  • Which technology separates IP addresses into two sets to hide the internal network layout and forces connections to go through a choke point?
  • Which term best describes the defender's strategies for protecting ICT assets?
  • Which command is commonly used to troubleshoot NetBIOS name resolution problems on Windows?
  • Which security tool is used by security professionals for threat detection, investigation, and response?
  • What is the purpose of subdomain discovery in cloud bucket targeting?
  • Which assessment approach involves outsourcing security tasks to external auditors and can be hosted inside or outside the network?
  • Which type of threat intelligence helps security teams add indicators to defensive systems such as IDS, IPS, firewalls, and endpoints to detect attacks early?
  • What tools help identify the last saved settings altered by malware in the Windows registry and other configuration areas?
  • Which tool stores the complete Whois information from all registrars for a data set?
  • Which term refers to a person or organization that uses cloud computing services?
  • Which attack floods the server by sending a high volume of SYN-ACK packets in response to client SYNs, attempting to exhaust resources during the handshake?
  • Which tool discovers IKE hosts and can fingerprint them using the retransmission backoff pattern?
  • What access control method uses the client's MAC address to permit access?
  • Which term describes unauthorized access by a user with similar permissions to another user's resources?
  • Which attack involves altering protection policies, deleting existing policies, adding new policies, and modifying application data and resources?
  • Which statement about the response_type parameter in OAuth is true?
  • Which tool is best described as a centralized engine for collecting and analyzing events across a network?
  • Extension of SOAP for security and authentication.
  • Which Trojan type infects a computer by randomly deleting files, folders, and registry entries, often causing OS failure?
  • The showmount utility relies on which protocol family to query NFS exports?
  • What provides the best defense against sniffing by ensuring data confidentiality?
  • Which formula represents the risk equation?
  • Which DNS attack involves injecting forged DNS records into the resolver's cache to redirect queries?
  • Which service category provides penetration testing, authentication, intrusion detection, anti-malware, security incident and event management services?
  • A blind detector is fed with the original or unmodified data to learn the resemblance of original data from multiple perspectives.
  • What term describes a neutral zone between a company’s internal network and an untrusted external network to prevent outsider access to private data?
  • Which tool is commonly used for dynamic analysis of malware and disassembly of binary code when source is unavailable?
  • What term describes a decoy system used to attract attackers and log activity?
  • Which term describes an attacker who interacts with an employee in person to collect sensitive information?
  • Which concept involves concealing the existence of a message rather than its content?
  • Which tool is described as giving the attacker practically complete control over the infected computer?
  • This phase involves maintaining access to the target system, including evading endpoint security devices and establishing ongoing access until data use ends.
  • Which protection tool is primarily used to stop ransomware by monitoring network activity?
  • Which Trojan is associated with capturing a single-use password for online banking transactions?
  • Which port is associated with the Hypertext Transfer Protocol?
  • Which of the following is a tool used to scan and identify vulnerabilities in containers?
  • John the Ripper, Hydra, RainbowCrack, Lophtcrack, and Cain & Abel are examples of what kind of security tools?
  • Which injection occurs when server-side templates are influenced by unsafe user input?
  • Which online reputation tracking tool monitors the web, social media, forums, and blogs for the target brand?
  • Which attack targets client-side components to execute code in the user's context when visiting a malicious page?
  • Which Trojan type is described as downloading additional malware from the Internet onto the compromised host?
  • Which scan sends ACK probe packets and analyzes the WINDOW field value of the RST packets?
  • Which term refers to tools used to remove malware, including rootkits, viruses, Trojans, and worms, from a system?
  • Which tool includes a script that can enumerate open ports?
  • Which tools can help obtain the physical location of a target for social engineering?
  • Which encoding standard is described as a variable-length encoding that expresses each byte in hexadecimal and prefixes with %?
  • If an attacker can access a node in a pod, which vulnerability allows access to all volumes used within the pod?
  • Which tool executes processes remotely?
  • Which service provides information related to patent and trademark registration?
  • What is a hotfix?
  • Which tool is commonly used to flood HTTP requests from mobile devices?
  • Vertical Privilege Escalation refers to:
  • Which firewall operates at the network layer and analyzes each packet using criteria such as source/destination IP, source/destination port, and protocol to decide to drop or forward?
  • Which term refers to a protected network created with a two- or three-homed firewall behind a screening firewall, commonly used to refer to the DMZ?
  • Which method helps identify the source of DoS traffic and allows administrators to recognize the type of DDoS attack or combination used?
  • Which IDS evasion technique involves splitting attack traffic into many small packets so that no single packet triggers the IDS?
  • Which tool enumerates subdomains across multiple sources, commonly used in recon?
  • Which technique hides information in significant parts of the cover image, such as cropping and compression?
  • Which firewall type is capable of applying packet filtering at the network layer and evaluating application-layer contents for allowed sessions?
  • Which Windows file stores thumbnail previews of images and documents?
  • A restricted operating system intended for testing code is called what?
  • A kernel-mode driver component that can be used by an attacker to take control of an OS without alerting security mechanisms.
  • Which term is used to describe a framework for managing digital certificates and public-key cryptography?
  • Which tool allows you to surf anonymously on the Internet without disclosing your IP address?
  • Which shellcode type uses only ASCII characters to bypass input restrictions and IDS signatures?
  • Which Trojan is described as a small HTTP server embedded inside programs and can be wrapped with a genuine program?
  • Which item is described as performing name server lookup?
  • Which scanner can scan networks from any machine on the network?
  • Which port is NFS or IIS?
  • Which virus changes the extensions of files?
  • Which password recovery tool reveals passwords for various email clients and passes them to the credential enumerator module?
  • What is the core process sequence of Tree-Based Assessment?
  • Which term refers to a value derived from a set of data that helps verify data integrity and is used in digital signatures?
  • Which layer is described as moving and processing data between tiers in some network architectures?
  • CeWL command that displays various options to obtain a list of words from the target website yields which result?
  • Kiuwan, Veracode, Flawfinder, Splint, BOVSTT are examples of which category of tools?
  • Which detection technique compares runtime execution paths of all system processes and executable files before and after rootkit infection?
  • Which command-line utility is typically used to request a DNS zone transfer in debugging or security assessments?
  • Which option is used to flood a network to overwhelm IDS capability and generate noise?
  • Which authentication system uses port 88?
  • Shows various layers and the corresponding elements/mechanisms/services that make web applications vulnerable.
  • Which term describes a condition when an intrusion detection system fails to react to an actual attack event?
  • Which online tool is used for discovering subdomains and their IP addresses, including network information and their HTTP servers?
  • Which practice is commonly used by ISPs to prevent spoofed source addresses from entering the network?
  • Which platform aggregates data from multiple sources to estimate traffic, geography, and referral data for a company's websites and mobile apps?
  • Which term describes an attacker’s technique that manipulates the application by injecting code via input fields and comments?
  • Which tool lists all the dependent modules of an executable file and builds hierarchical tree diagrams?
  • What is the AWS service that stores files, folders, and objects via web APIs?
  • Which shell is described as sh-compatible and stores command history in a file called the bash history?
  • Directory service that lists all available services.
  • Which technique involves modifying plist files to execute code at startup and to escalate privileges?
  • Which REST principle emphasizes that clients interact with resources via a uniform interface using standard HTTP methods and URIs?
  • Which banking Trojan masquerades as a mobile junk cleaning and memory-boosting app?
  • Which port is used by the Dynamic Host Configuration Protocol (DHCP) server?
  • Which tool encodes secret messages into innocent-looking spam emails?
  • The assurance that the integrity, availability, confidentiality, and authenticity of information and information systems is protected during usage, processing, storage, and transmission is called what?
  • Which protocol is used to transfer files over a network and for file and printer sharing via NetBIOS?
  • Which open source technology is used for developing, packaging and running applications in containers and provides OS-level virtualization?
  • Which policy is described as having no restrictions on the usage of system resources?
  • This utility can auto-start the location of any startup monitor, display what programs are configured to run during system bootup or login, and show the entries in the order that Windows processes them.
  • Which vulnerability arises from weak transport-layer security that can allow eavesdropping or tampering?
  • Which tactic involves creating a sense of scarcity to push for quick decisions?
  • An attacker constructs forged ARP requests and replies to overload a switch's ARP processing. What is this attack called?
  • What does the -9 option cause Hping to do in relation to HTTP signatures?
  • Which artifact is commonly used to store image thumbnails and is often checked in forensic investigations?
  • Which security platform provides threat detection, incident response, and compliance management across cloud, on‑premises, and hybrid environments?
  • The attacker copies the target's password file and then tries to crack passwords on his own system at a different location.
  • What does AAA stand for in network security?
  • What overarching term refers to hardware and software used to monitor and control industrial operations?
  • This script takes in command-line arguments and puts them into the section mentioned above.
  • In a shared Ethernet environment, what do machines do with frames not addressed to them?
  • Which vulnerability is associated with CPU speculative execution and can allow reading of restricted memory in affected processors?
  • SamSam ransomware is associated with which threat group and exploits unpatched servers present in the target network?
  • Which tool is commonly used for penetration testing, port scanning, and enumeration?
  • Which term describes elevating from a lower privilege level to perform privileged actions on a system?
  • Which memory region is used for dynamic storage during program execution?
  • Which tool is used to develop a backdoor shell and upload it to a target server to gain remote shell access, enabling persistence and spreading backdoors?
  • Which term best describes the collection of systems like SCADA, RTU, PLC, and DCS that monitor and control industrial operations?
  • Which free service analyzes suspicious files and URLs to detect malware?
  • Which term refers to a protected network created with a two- or three-homed firewall behind a screening firewall, commonly associated with the DMZ?
  • Which attack type targets the web servers, application platforms, databases, networks, or frameworks and can lead to illegal system access?
  • Which statement best describes Sublist3r's primary function?
  • Which term is used to identify active hosts, open ports, and unnecessary services on a host?
  • An attacker can embed in a web page a malicious script that does not generate any warning but captures session tokens in the background and sends them to the attacker.
  • Which concept involves continuously identifying threats and monitoring unexpected network changes to prevent breaches?
  • Which tool extracts names and email addresses from the victim's Outlook account to send phishing emails from the compromised account?
  • Which technique tricks a person responsible for making a legitimate delivery into delivering the package to a location other than the intended one?
  • Which attack redirects users to a fraudulent site by corrupting DNS resolution?
  • This attack generates stego objects from a known message using specific steganography tools in order to identify the steganography algorithms.
  • Which Unix/Linux tool that is part of the dsniff collection floods the local network with random MAC and IP addresses to facilitate sniffing?
  • Which attack technique uses fragmentation timing differences between an IDS and the host to bypass detection?
  • What is the effect of flooding a switch's CAM table with random MAC addresses?
  • What term describes the process of verifying a user's identity to grant access?
  • What is the browser-based attack that runs malicious code inside the browser and persists even after closing or navigating away from the malicious web page called?
  • Which form of attack uses Instant Messaging to spread spam and collect credentials, with the user clicking a malicious attachment?
  • Which tool provides hundreds of exploits, an automated exploitation system, and a comprehensive exploit development framework?
  • An insider with access to critical assets who is compromised by an outside threat actor is called a ...
  • The deep web can be accessed using search engines such as Tor Browser and WWW Virtual Library. Which two tools are cited?
  • Which tool used to measure the bounce rate of the target company's website?
  • Which option corresponds to a UDP scan in hping3?
  • Which technique is used to identify modules by using Mona.py within a Windows binary analysis workflow?
  • Automatically monitors what is placed on your system and allows you to uninstall it completely.
  • Which retention method is described as the most secure when stored offsite?
  • Which HTTP header is used to indicate the intent of a SOAP message transmitted over HTTP?
  • Which vulnerability occurs when input from a client is not validated before being processed by web applications and backend servers?
  • What is the reverse process of encoding, allowing encoded data to be interpreted correctly?
  • Which component generates mutation variants by altering the decryption process to evade detection?
  • Which Trojan family runs on Android?
  • Which tool is explicitly described as a vulnerability scanner for web applications?
  • Which term refers to a platform from where services are provided?
  • The art of manipulating people to divulge sensitive information to use it to perform malicious action is known as what?
  • Enter malicious strings in input fields to manipulate the XPath query so that it interferes with the application's logic.
  • Which tool is described as a free tool that provides details about Windows executable files?
  • Which hijacking technique masquerades as a trusted host to conceal the attacker’s identity and gain unauthorized access?
  • Which technique involves sending a pre-connection SYN to probe a server before the full TCP handshake begins?
  • Which tool is commonly used to detect stegano-hidden data in PNG and BMP images?
  • In this technique, the attacker places an attack toolkit on a central source and a copy of the attack toolkit is transferred to a newly discovered vulnerable system. Once the attacker finds a vulnerable machine, they instruct the central source to transfer a copy of the attack toolkit to the newly compromised machine, on which attack tools are automatically installed under management by a scripting mechanism.
  • Which test solution is designed for testing development and deployment of network services for converged infrastructures?
  • Passive Session Hijacking is described as:
  • What term describes intercepting data across the network transport layer to take control of a session?
  • Which statement best describes a webhook?
  • Which tool can encrypt and compress 32-bit executables and .NET apps without affecting their functionality?
  • Which type of malware embeds macros in Office documents to propagate?
  • Which tool is a security application that detects ARP-based attacks?
  • Which item performs name server lookup?
  • The dark web can be accessed using tools such as Tor Browser and ExoneraTor. Which set of tools is cited for this access?
  • Which tool is an open-source framework widely used for conducting social engineering simulations in security testing?
  • Which SNMP operation retrieves the next data item in a table?
  • What term describes a program that records all user keystrokes without the user's knowledge?
  • What approach is commonly used to automatically detect host intrusions by verifying file integrity?
  • Which tool can intercept all requests and responses between the browser and the target web application and reveal information such as the web server and vulnerabilities?
  • Which technique binds a Trojan executable with genuine looking .EXE applications, such as games or office applications?
  • Which name refers to a tool intended to map network topology?
  • Which tool scans and identifies web technologies such as CMS, analytics, and JavaScript libraries on a site?
  • Which tool is capable of detecting various web technologies, including CMS, blogging platforms, analytics packages, and embedded devices?
  • Which Windows utility is commonly used to run a program with the credentials of a different user?
  • Which term describes the degree of uncertainty regarding potential adverse events impacting a system?
  • Used to scale risk by considering the probability, likelihood, and consequence or impact of the risk. What is this concept called?
  • What term describes the identification of the common methods or techniques followed by an adversary to launch attacks to penetrate an organization's network?
  • Which security platform provides threat detection, incident response, and compliance management across cloud, on‑premises, and hybrid environments?
  • Which tool is used to track website traffic and analyze visitor behavior?
  • Which defined process identifies, analyzes, prioritizes, and resolves security incidents to restore normal service and prevent recurrence?
  • In Windows domains, which directory service is commonly associated with Kerberos authentication?
  • Which statement best captures the role of a WAF in relation to other security devices?
  • Which tool is used to identify open S3 buckets and retrieve their content?
  • What term describes malware used to infect a large number of computers to form a botnet controlled via C&C?
  • Which Nmap option outputs results in XML format?
  • Which scanning method is explicitly named INIT Scan?
  • Port 3389/TCP is used by which remote desktop protocol?
  • Which policy defines the access, management, and monitoring of firewalls in an organization?
  • DDoS prevention offerings from ISPs surgically remove DDoS attacks while letting legitimate traffic flow. What is the primary benefit?
  • Which tool dumps password hashes from NT SAM database?
  • Which attack uses a predefined set of rules to mutate or generate password guesses from common words?
  • Which model is described as a dynamic heterogeneous environment that aggregates workloads across multiple cloud vendors and is managed via a single proprietary interface?
  • Which scan describes a method that can send a spoofed source address to identify available services?
  • WinPcap is primarily used on which platform?
  • Which detection category would monitor PowerShell transcript logs and Windows Event logs to identify malicious hosts?
  • Which character encoding system is used for worldwide interchange of text, processing, and display?
  • What is the name of the phishing tool that reveals the victim's IP address and browser information to attackers?
  • Which command determines where the NTP server obtains the time from and follows the chain of NTP servers back to its primary time source?
  • Which wireless detection tool is commonly used for discovering and profiling wireless networks?
  • Which acronym stands for Network File System?
  • Which technique limits the impact by denying traffic with spoofed addresses?
  • Which technique is used to access resources on other systems in the target network via the compromised system, with requests appearing to originate from the initially compromised host?
  • Which tactic involves forwarding messages to obtain free gifts or prizes?
  • Which assessment concentrates on identifying exploitable weaknesses that are accessible from the internet to compromise an organization's perimeter?
  • What term describes an entity or event with the potential to adversely impact a system?
  • A campaign that uses trusted online advertising networks to deliver malware to users through ads?
  • Which type of scanner interacts only with the real machine it resides on and reports to that same machine after scanning?
  • What is the reverse process of serialization, whereby object data is recreated from the serialized data?
  • Which tool automatically extracts specific information from web pages, including targeted contact data and meta tags for promotion and research?
  • Sequencer is a tool in which security testing platform?
  • Cloud infrastructure is operated for a single organization only.
  • Which port is used by the Simple Network Management Protocol (SNMP)?
  • What is the client_id?
  • What term describes pretending to be a legitimate or authorized person to trick targets into revealing information?
  • Which keylogger injects malicious JavaScript into web pages to capture keystroke events such as onKeyUp and onKeyDown?
  • Which term denotes a large network of compromised devices used to execute coordinated attacks?
  • What term describes attackers exploiting pre-installed tools on Windows to install and run malicious code?
  • Which open source orchestration platform developed by Google manages containerized applications and microservices, enabling deployment patterns and failover?
  • Which term describes an ongoing, covert cyber-attack campaign designed to persist within a target network and exfiltrate data over time?
  • Which memory area is dynamically allocated at runtime during program execution and stores program data?
  • Which spyware is used to monitor a user’s web browsing in the absence of the user?
  • Which Android tool is described as a mobile network packet sniffer for rooted Android devices, capable of capturing traffic across Wi-Fi, 3G, and LTE?
  • Which description best describes the Google Hacking Database (GHDB)?
  • Which assessment type focuses on thorough analysis of a web application's configurations and known vulnerabilities?
  • Which term describes a gateway technology used to connect and integrate multiple web applications?
  • Which port is HTTPS?
  • Which attacks occur when a cookie is sent from the client side to the server?
  • Which DDoS category combines volumetric, protocol, and application-layer attacks to disrupt services?
  • Which concept provides storage on a separate machine or disk after the original disk becomes full and is case-sensitive, used to provide object-level security?
  • What tool is a network logon cracker that supports many services including IPv6 and RFC 4013?
  • Which term refers to a traffic-filtering feature in routers to protect TCP servers from a SYN-flooding attack?
  • Which service offers identity and access management including SSO and MFA as a service?
  • DNS tunneling is primarily used to transmit data covertly within what kind of traffic?
  • Golden Tickets enable creation of TGTs for any account in Active Directory.
  • Which spyware is designed to monitor and record a variety of sounds on the computer, saving them in a hidden file for later retrieval?
  • Which tool is a non-interactive downloader that can fetch files via HTTP, HTTPS, and FTP, suitable for scripting?
  • Which term denotes the time from initial vulnerability assessment to gaining and maintaining access?
  • XML-based language that describes and traces web services.
  • Which term refers to using propaganda or terror to demoralize one's adversary in battle?
  • Which phase involves the attacker obtaining a legitimate session ID by establishing a connection with the target web server?
  • Which technique can be used by attackers to escalate privileges, install backdoors, and disable Windows Defender by manipulating application behavior?
  • Which term describes the use of information systems against the virtual personas of individuals or groups?
  • Which statement best describes ZoneAlarm Free Firewall 2019?
  • Which software is described as PC-user activity-monitoring software that runs secretly in the background and logs all users?
  • What cloud model combines two or more clouds that remain unique entities but are bound together to provide the benefits of multiple deployment models?
  • The technique used to inject malicious code into the memory of a running process to propagate and re-inject into other legitimate system processes is known as what?
  • What is the process of applying fixes on vulnerable systems in order to reduce impact and severity of vulnerabilities called?
  • Which security testing tool is commonly used as a web debugging proxy to inspect HTTP(S) traffic?
  • Which software collects traffic data, converts it into a usable format, and presents it via a web-based interface for monitoring network traffic?
  • Which method is specifically associated with embedding data within common image file formats such as PNG, JPG, and BMP?
  • Which file is described as not containing the passwords themselves?
  • Which tool, described as a DNS poisoning utility, helps spoof DNS query packets for a target IP address or group of hosts?
  • Which tool performs banner-grabbing, status code enumeration, and header ordering analysis to fingerprint a web server?
  • Which attack involves attackers posing as technical support and requesting credentials in exchange for a service?
  • EDI stands for which term?
  • Which tool is a Windows-based honeypot intrusion detection system designed to attract and detect hackers by simulating vulnerable services?
  • Which search result is associated with locating Cisco ASA login web pages?
  • An attacker first collects a list of potentially vulnerable machines and then scans them to find vulnerable machines
  • Which Trojan type is primarily associated with defacing websites by altering HTML content?
  • Which method relies on actively crafting TCP packets to elicit banners from the target's IP stack?
  • Which statement best describes scope in OAuth?
  • What is the term for malicious code that hides inside a seemingly harmless program or data and can later damage a system?
  • The PE format mentions less familiar executable types such as SCR (Screensavers), CPL (Control Panel Applets), SYS, MSSTYLES, BPL, and DPL. Which of the following is a less familiar type?
  • Which IPsec domain defines the payload formats, exchange types, and naming conventions for security information such as algorithms or policies?
  • Which term corresponds to the concept of multiple infected IoT devices?
  • What term refers to a software- or hardware-based system located at the network gateway that protects the resources of a private network from unauthorized access?
  • Which SMTP command displays the actual delivery addresses of aliases and mailing lists?
  • Which port is LDAP?
  • Which detection approach relies on cross-view verification to reveal rootkit activity by comparing different representations of data?
  • Used to define the test sample to identify its class.
  • Which software blocks attackers and detects attempts to modify your computer's settings, record your activities, hook into your PC's sensitive processes, or inject malicious code?
  • Which attack uses a flood of fragmented packets to prevent proper reassembly and reduce throughput?
  • What software is essential for detecting viruses?
  • In the IoT architectural model, which layer is associated with connecting endpoints?
  • Which exploitation framework is commonly used to obtain an active session with a target host?
  • The place where the provider loads service descriptions.
  • Which platform is used to deliver exploits and payloads such as Trojans, spyware, backdoors, bots, and buffer overflow scripts?
  • In which DNS poisoning scenario is a Trojan on a host used to change that host's DNS resolver settings to point to the attacker's server?
  • An application feature that helps designers to auto-generate the content of the web page without manual involvement.
  • Which type of malware restricts access to files and demands payment to remove restrictions?
  • ICMP scanning is a category that primarily uses which protocol?
  • What is the name of a UEFI rootkit that is widely used by attackers to inject malware and automatically execute when the system starts up?
  • Which component of Nmap allows automation of a wide variety of tasks by using scripts?
  • Which scanning technique involves resetting the TCP connection before completion of the three-way handshake, creating a half-open connection?
  • Which term describes the process of capturing the system state at the start of malware analysis?
  • Which term describes the points in the network from which entry attempts originate?
  • The tool that identifies a visitor's geographic location using IP address is:
  • What is a web debugging proxy that logs HTTP(S) traffic and can decrypt HTTPS to test web applications?
  • Which technique uses voice-based channels to harvest information by impersonating legitimate entities?
  • Which tool is used to perform layer-7 DDoS attacks on web infrastructure?
  • Uses algorithms that input a set of labeled training data to attempt to learn the differences between the given labels. Supervised learning is further divided into two subcategories, namely, classification and regression. Which term describes this approach?
  • Which sniffing tool provides a graphical console for high-speed packet analysis and is integrated with Riverbed AirPcap adapters to analyze and troubleshoot 802.11 wireless networks?
  • Which service provides a platform for developing, running and managing application functionality for microservices?
  • Which identifier uniquely references an internet resource and can be used in both remote and local contexts?
  • Which Trojan type is primarily associated with defacing websites by altering HTML content?
  • Which attack is also known as a spoofed attack, using intermediary machines to reflect DDoS traffic toward a target?
  • Which technique involves poisoning LLMNR/NBT-NS to capture credentials on a network?
  • Intercepts IP addresses, MAC addresses, and VLANs connected to the switch in a network?
  • Which assessment determines possible network security attacks that could occur on the organization's system?
  • Which malware technique involves moving the MBR and duplicating itself to the original MBR location?
  • Which MIB is described as monitoring and managing host resources?
  • Which term refers to the phase when the attacker tries to retain his or her ownership of the system?
  • Which tools are used to extract and analyze the log files generated by malware on a host?
  • CORS stands for which of the following?
  • Which type of malware uses USB firmware changes to directly interact with the operating system?
  • Which assessment is used to sniff network traffic to discover active systems, network services, applications, and vulnerabilities?
  • Which port is BGP?
  • Which tool is used to validate users?
  • Which CVSS metric is most likely to change over time due to exploit availability or remediation?
  • Which technique can be used to determine if an IP or service is a threat source within a security framework?
  • Which attack involves taking a legitimate mobile game and adding malware before uploading to a third-party app store?
  • Which keylogger replaces the existing I/O driver with embedded logging and sends the keystrokes to a destination via the Internet?
  • Which virus is described as targeting the File Allocation Table on FAT file systems to disrupt file access?
  • An attacker targets weaknesses by using crafted input to traverse server directories beyond the root?
  • Which tool is described as enabling real-time visibility and expert analysis of the target network, with the ability to analyze and fix bottlenecks across segments?
  • Which device is described as a node with multiple NICs that connects to two or more networks, increasing the efficiency and reliability of an IP network?
  • Which term describes malicious programs that specifically target IoT networks and often use a botnet to attack external machines?
  • Which protocol secures VPN connections by encapsulating IP packets and providing encryption and authentication?
  • What is the primary purpose of OS fingerprinting during target enumeration?
  • Which encoding uses the hex value of every character to represent binary data for transmission?
  • Which tool provides secure remote login capabilities to Windows workstations and servers by encrypting data during transmission?
  • The Trickler-delivered Trojan named DoubleFantasy is associated with which broader family?
  • Which tool is used to manipulate the binary data that makes up a computer file?
  • Which spyware is designed for video surveillance, secretly monitoring and recording webcams and video IM conversations?
  • Which method uses a perforated or stencil sheet of paper to encrypt plaintext into a hidden message?
  • Which web service testing tool is open-source and offers plugins for different attack types?
  • Which port is ISAKMP?
  • To obtain the NetBIOS name table of a remote host by IP address, which option is used?
  • Which ISP-level practice prevents spoofed source addresses from Internet traffic?
  • Which term is defined as a virus that terminates and stays resident (TSR) in memory?
  • an attack that hijacks a valid user session. An attacker attempts to lure a user to authenticate himself or herself with a known session ID and then hijacks the user-validated session with the knowledge of the used session ID
  • Which web security testing tool can hijack session IDs in established sessions?
  • An attacker crafts an input string to gain shell access to a web server. What is this attack commonly called?
  • Which DNS record is used to identify the mail exchangers for a domain?
  • What is the term for an attack in which an unauthorized user gains higher privileges on a system, such as obtaining administrator access?
  • Which term describes the process of taking organized and careful steps when reacting to a security incident?
  • Which tool can enumerate SNMP devices and present results in a human-readable format?
  • Which term describes viruses that append their code to the host code without making changes to the latter or relocating the host code?
  • dotDefender is best described as what type of security technology?
  • Which CVSS metric represents features that change during the lifetime of the vulnerability?
  • Which method targets a company employee online by posing as an attractive person to start a fake relationship to obtain confidential information?
  • What is the primary goal of a kernel exploit?
  • Which term describes aggressive SEO techniques used to boost rankings for malware pages?
  • What is the term for risk that remains after vulnerabilities are classified and countermeasures have been deployed?
  • Which attack floods the DHCP server to exhaust IPs, causing a DoS?
  • Which term refers to an area of adjacent memory locations allocated to a program or application to handle its runtime data?
  • In Sublist3r, which flag enables the bruteforce module for subdomain discovery?
  • Which tool restricts access to files, folders, and drivers by locking, hiding, or password-protecting them?
  • Which Metasploit module uploads and downloads files, takes screenshots, and collects password hashes?
  • This technique hides the message in a carrier medium visible to everyone.
  • Which tool is named as a platform used for analyzing web traffic in the provided list?
  • Which Windows IPC mechanism is used to enable legitimate communication between processes by passing messages via a pipe?
  • Which SQL operator allows combining the results of two or more SELECT queries into a single result set?
  • Which term describes allowing only approved software to run on a system to prevent malware execution?
  • What is the dynamic table that stores information such as MAC addresses available on physical ports along with VLAN parameters associated with them?
  • Which program is a fake Android antivirus application?
  • What is the name of the tactic where the attacker fixes a session by injecting a session ID into the victim's browser?
  • Which term describes a form of fraud that uses warnings about malware to coerce a response or action?
  • Which tool allows exploration of archived versions of websites to gather historical information?
  • Which component generates randomized decryption routines?
  • Which term describes the ability of malware to change its identifiable features to evade signature-based detection?
  • In Sublist3r, which flag enables verbose mode to display results in real time?
  • Which tool is used to find the total number of visitors browsing the target website?
  • Which attack uses a user-mode SSPI to obtain the NetNTLM response within the context of the logged-on user?
  • Which technique involves modifying the HTTP user agent field to communicate with a compromised system and to carry forward attacks?
  • Which technique relies on pre-negotiated manipulations to reveal messages written with invisible ink?
  • Which entity manages the use, performance and delivery of cloud services, and maintains relationships between cloud providers and consumers?
  • Path Analyzer Pro is a traceroute and network diagnostic tool that identifies the geographical location of routers, servers, and other IP devices.
  • The port number that is used by default for syslog.
  • Which category refers to unsolicited emails designed to collect financial information?
  • Which encoding is commonly used to safely transmit binary data such as email attachments, using printable ASCII characters?
  • Attackers use rootkits and steganography to hide the malicious files they install on the system.
  • It uses a pseudorandom permutation list of IP addresses to find new vulnerable machines
  • Which term describes an attack in which wireless IoT device communications are jammed by randomly transmitted radio signals?
  • Which command scans the target IP address for an open NFS port (2049) and the NFS services running on it?
  • Also referred to as a whitebox testing, in which the complete system architecture (including its source code) or application/software to be tested is already known to the tester.
  • Which tool lists detailed information about processes?
  • Which virus type transfers all control of the host code to the viral code residing in memory?
  • Which term describes services rendered over a network that is open for public use?
  • Which ensures that an individual cannot deny sending a message and the recipient cannot deny receiving it?
  • Which statement best describes SPAN's function?
  • Which of the following best describes the string 'USER:RID:LM:NTLM'?
  • An attacker can obtain sensitive data like credit card numbers from the database because encryption is weak or improperly implemented. This vulnerability is known as:
  • If an FTP server allows guest login, what risk is most likely?
  • Which protocol allows a client to access and manipulate mail messages on a server?
  • Which protocol is connection-oriented and can carry messages or emails over the Internet?
  • Which resource contains a database of cybersecurity incidents and CVEs?
  • A virus that is set to trigger when important dates are reached is best described as which type?
  • Triggered at managed service providers and their users by spear-phishing with malware to compromise staff or cloud service firm accounts to obtain confidential information?
  • BeEF is best described as what type of testing?
  • What is the term used to describe the activity of discovering which devices are alive on a network?
  • Which command monitors the operations of the NTP daemon ntpd and determines performance?
  • Which attack floods the network with traffic to create noise so the IDS may miss true attack traffic?
  • In Sublist3r, which flag displays the help message and exits?
  • Which describes configuration weaknesses in web infrastructure exploited to launch attacks on web servers such as directory traversal, server intrusion, and data theft?
  • The tool sees TCP data in the same way as that of the application layer. Use this tool to find passwords in a telnet session or to interpret a data stream.
  • Which Android app helps set the proxy on Android devices and can function as a DNS proxy to reach addresses beyond firewalls?
  • Exposure of which configuration file can reveal FTP server settings and anonymous access configurations?
  • Which spyware can monitor webcams and video IM conversations and runs in the background?
  • Which rootkit is described as a hardware or firmware rootkit that can evade code integrity checks?
  • Which technique generates a cover specifically for hiding secret communication?
  • Which term describes the cryptanalytic technique that relies on precomputed tables of hashes to speed password cracking?
  • What protocol synchronizes the clocks of networked computers?
  • Which device sends packets to the destined computer only, rather than broadcasting to all devices on the network?
  • The initial step of the risk management plan. Its main aim is to identify the risks—including the sources, causes, and consequences of the internal and external risks affecting the security of the organization before they cause harm.
  • Which type of virus is programmed to rewrite itself completely each time it infects a new executable file?
  • GUI and command-line modes used to run arbitrary Win32 applications as services (when the service is stopped, the main application window is automatically closed).
  • Which tool automatically discovers and creates a network map of the target network, showing OSI Layer 2 and Layer 3 connections and tracking network changes for inventory management?
  • Security professionals can monitor the activities of an adversary by checking for unusual commands executed in the Batch scripts and PowerShell and by using packet capturing tools.
  • Which type hides messages by embedding in audio and graphical data?
  • 20/TCP is commonly used for which data transfer service?
  • Which Metasploit module encapsulates an exploit to target many platforms with a single exploit?
  • What term refers to the guideline that describes how an attacker performs their attack from beginning to end?
  • In Sublist3r, which flag saves the results to a text file?
  • You can use scripts such as Mona.py to identify modules with which debugger?
  • Which scanning method uses a pseudorandom permutation of IP addresses to determine the order of probes?
  • Which DDoS attack is described as occurring before the target's vulnerabilities are patched or defensive measures are in place?
  • What device interprets traffic passing over a network, captures signals without altering the traffic segment, and is used to monitor network usage?
  • Which policy focuses on information classification by sensitivity levels?
  • Insertion Attack refers to which scenario?
  • What term describes an attack that intercepts traffic between cloud nodes to capture sensitive information?
  • Which attack type involves sending a payload so large that it consumes all system resources, making web services unavailable?
  • What category of tools is used to retrieve information such as domains, IP addresses, DNS records, and network Whois records?
  • Which security evasion tool is designed to conceal the existence of malware and resist reverse engineering?
  • Which approach relies on specialized jargon or language understood by a particular group to conceal information?
  • Which security principle ensures information is only accessible to authorized individuals?
  • Which category is used to send an ICMP error message to a client?
  • Which term describes snooping or eavesdropping to monitor and record traffic?
  • Which of the following Nmap commands performs a full TCP SYN port scan with OS and version detection and outputs XML?
  • Which term describes viruses designed to confuse or trick antivirus systems to prevent detection?
  • Which file on a client can be edited to override DNS results by mapping hostnames to IPs?
  • Which feature is used to mirror traffic to a monitoring device for analysis?
  • Attackers use compromised legitimate websites to infect visitors; the malware then performs malicious activities. What is this attack called?
  • Which vulnerability involves weak transport-layer protection, such as weak ciphers or expired certificates, exposing user data to third parties?
  • Which indicators are used to send malicious data to the target organization or individual, such as the sender's email address, email subject, and attachments or links?
  • Which policy would be most appropriate for an environment with severe restrictions and minimal external connectivity?
  • Which protocol is used for transferring files between clients and servers over a network and is designed for simple, unencrypted file transfer?
  • Which computer spy software enables total secrecy while monitoring everything users do on the computer?
  • Which service uses TCP port 110 for mail retrieval?
  • Which attack involves compromising a specific website likely to be visited by a target organization to distribute malware to visitors?
  • Which of the following tools is used to identify and download documents for metadata extraction in a corporate context?
  • Which command-line tool is commonly used to perform DNS zone transfers during security assessments?
  • Tool is used to detect stegano-hidden data in PNG and BMP image files.
  • Which encryption technique is used by the ransomware eCh0raix?
  • In Windows environments, which technique involves creating a new service or modifying an existing service to escalate privileges or maintain access?
  • This phase assesses the organization's risks and estimates the likelihood and impact of those risks.
  • Which term describes attackers using standard web browsers to walk through the target website functionalities, with traffic monitored by tools that include features of both a web spider and an intercepting proxy?
  • What is the general process of gathering information about systems that are considered to be “alive” and responding on the network?
  • Which attack creates numerous half-open TCP connections by sending initial SYNs and not completing the handshake?
  • Which term describes misuse-detection-style intrusion detection that relies on anomalies rather than signatures?
  • Which Windows component serves as a Windows Application Compatibility Framework to provide compatibility between older and newer Windows versions?
  • Which exploitation vector targets third-party applications such as Adobe Reader and Flash?
  • Which malware remains dormant until the user performs an online financial transaction and edits registry entries at startup?
  • Which vulnerability in OpenSSL allowed attackers to read memory of the server or client process?
  • What is a huge network of compromised systems and can be used by an attacker to launch denial-of-service attacks?
  • Which IPsec component negotiates security associations and exchanges keys?
  • Which concept refers to generating or manually specifying IP addresses of decoys to evade IDS/firewalls?
  • Which cloud service model provides development tools, configuration management, and deployment platforms on-demand to develop custom applications?
  • Which type of attack intercepts communications between two parties to eavesdrop, modify, or impersonate?
  • Which option in Hping creates a scan that uses FIN, PUSH, and URG flags on port 80?
  • Which type hides messages in ASCII text by adding spaces at the end of lines?
  • Which tool is described as a cross-platform, open-source censorship circumvention tool that maps censorship patterns around the world and enables attackers to identify censored links?
  • Which data type is commonly stolen by memory-resident fileless malware when it exfiltrates data?
  • Which threat intelligence type provides day-to-day operational support to assess security incidents and guide executives in making strategic business decisions?
  • Which program is described as a tool that gives the attacker near-complete control over the infected computer?
  • Which phase involves the attacker injecting the session ID into the victim's browser to fix the session?
  • Attackers analyze the HTML source code to locate URLs to target S3 buckets.
  • The DNS record that defines the mail routing information for a domain is:
  • Which string represents the Pwdump SAM file hash dump format?
  • Which type uses spam emails for secret communication by embedding the secret messages and hiding the embedded data in the spam emails?
  • Which VPN client file type is commonly used to store user profiles, including server addresses and authentication settings?
  • Which technique desynchronizes an IDS from the sequence numbers the kernel honors after a connection is established?
  • Which command extracts email addresses of microsoft.com using the Baidu search engine?
  • In ethical hacking methodologies, which phase covers scoping, rules of engagement, and agreement on attacks?
  • Which tool is described as performing remote process management tasks?
  • Which tool generates traffic based on the average packet rate for network flows and uses header information such as IPs, ports, and protocols?
  • Which Windows deployment feature allows software to install without administrator intervention?
  • During which Kill Chain stage does the attacker download additional malware to maintain access and may install a backdoor?
  • Which tool identifies the geographical location of routers, servers, and other IP devices on the network path?
  • Startpage, eTools.ch and MetaGer are examples of which type of search technology?
  • Which tool proactively scans websites for malware and provides automated alerts and in-depth reporting to enable prompt identification and resolution?
  • If the attacker uses a broad set of techniques and tools to execute a given campaign, this is best described as which term?
  • Which Metasploit module is used to perform arbitrary, one-off actions such as port scanning, denial of service, and fuzzing?
  • Which detection identifies an attack at the initial stage by analyzing the HTTP User-Agent header?
  • What is the name of the script-based tool that enumerates Google Cloud storage buckets and checks access for privilege escalation?
  • Which attack breaks passphrases into fingerprints of varying lengths to crack passwords?
  • Which of the following is NOT listed as one of the seven steps in the Cyber Kill Chain described?
  • Interception and monitoring of network traffic between two cloud nodes is known as?
  • Which firewall type operates at the session layer (or transport layer) and forwards data between networks without verification, blocking inbound packets from the host but allowing traffic to pass through?
  • Which printer usage monitoring software logs all printer activity and can send encrypted logs via email?
  • Which tunneling technique allows attackers to perform various Internet tasks despite firewall restrictions?
  • In SQL injection testing, which designator best describes the intent of the payload blah' AND 1=(SELECT COUNT(*) FROM mytable); --?
  • Which application helps security professionals detect and remove rootkits by scanning processes, threads, modules, services, files, disk sectors (MBR), ADSs, registry keys, driver hooking - SSDT, IDT, and IRP calls, and inline hooks?
  • Which rootkit masquerades as cracked software or legitimate applications to infect systems and perform data exfiltration?
  • Which tool checks web applications for SQL injections, XSS, and other vulnerabilities?
  • Which tool is commonly used to perform dynamic testing of a device's web interface?
  • Which term describes a disassembly-evading technique using specially crafted code or data to produce an incorrect program listing?
  • Which attack constructs a fake session by omitting the initial SYN and using only multiple ACK packets with RST or FIN packets?
  • Which XML editor and development environment is used for modeling, editing, transforming, and debugging XML-related technologies?
  • Which search pattern would find pages containing D-Link VoIP router login portals?
  • Which project provides a general-purpose implementation that uses the time-memory trade-off technique to crack hashes?
  • What is the name of the authentication system that generates secret key encrypted one-time passwords using a counter?
  • Which hping3 command performs a UDP scan on port 80?
  • Which algorithm is based on the difficulty of factoring large integers?
  • Which device has multiple NICs and connects to two or more networks to increase efficiency and reliability of an IP network?
  • Which keylogger type is difficult to write, difficult to detect for user-mode apps, and operates as a keyboard device driver?
  • Which security tool provides a unified platform for threat detection, incident response, and compliance management across cloud, on-premises, and remote locations?
  • Which spyware tracks what children are doing on the computer, both online and offline?
  • The DNS record that points to a host's name server is:
  • Which technique encodes secret information by substituting insignificant bits with the secret message?
  • Provides high-level information regarding cybersecurity posture, threats, details about the financial impact of various cyber activities, attack trends, and the impact of high-level business decisions. It helps organizations identify any similar past incidents, their intentions, and any attributes that might identify the attacking adversaries, why the organization is within the scope of the attack, major attack trends, and how to reduce the risk level.
  • Which type of software hides its presence on a computer while enabling an attacker to gain near-total control?
  • Which tool helps attackers construct Trojan horses and customize them according to their needs?
  • Which query would restrict results to the domain example.com and require 'admin' in the title?
  • Which stores OS and program configuration details such as settings and options?
  • Which technique can help identify the true source of attacks by tracing back to the origin?
  • Which technique enables traffic to flow through any VLAN by manipulating Ethernet frame tags?
  • What is the purpose of sending a flood of SYN packets in a network test?
  • Which firewall type is described as inspecting both network-layer packets and application-layer contents to determine if a session is legitimate?
  • If session timeouts are set to long durations, sessions remain valid longer than intended. This vulnerability is referred to as:
  • Which vulnerability family is associated with speculative execution across processor architectures?
  • Which Trojan creates fake form fields on e-banking pages to collect the target's data?
  • Which technique overlays a legitimate page on top and uses an invisible iframe with a higher z-index?
  • Which technique embeds a backdoor within ICMP Echo messages to enable covert communication?
  • Which tool hides secret files within innocuous media (image, video, or music)?
  • What is the term for a flood of SYN packets used to overwhelm a target?
  • Which specific attack uses spoofed UDP packets to random ports at a high rate from multiple source IPs?
  • What security strategy places several protection layers throughout an information system?
  • What action involves removing system log entries that record an attacker\'s activities?
  • Which command traces the NTP time source back to the primary time source?
  • attackers overwrite parameter values in the connection string to steal user IDs and hijack web credentials.
  • Which attack involves attackers creating apps that mimic popular ones to trick users into downloading?
  • What is the process called for copying DNS zone data from the primary to a secondary DNS server?
  • SQL stands for which language used to manage relational databases?
  • Which term describes the use of physical or chemical methods, such as invisible ink or microdots, to hide the existence of a message?
  • to enable or disable security auditing on local or remote systems, and to adjust the audit criteria for different categories of security events.
  • Which protocol operates on port 80 for web traffic?
  • Which tool can encrypt secret files as part of its features?
  • Which tactic involves taking a legitimate game, repackaging it with malware, and distributing it through third-party stores?
  • Which platform is used for business information that aggregates licensed and free sources and offers alerting and dissemination features?
  • Which tunneling method uses TCP packets with the ACK bit set to carry a backdoor application?
  • What is the primary objective of session hijacking techniques described here?
  • Which command would perform a SYN scan on port 80 toward 10.0.0.25?
  • Which mobile social engineering technique uses SMS to prompt users to take immediate action?
  • Which term describes the action that alerts Snort when a packet matches the rule criteria?
  • Which category of intrusion indicators includes new or unfamiliar files, changes in file permissions, rogue files not on the signed-master list, and missing files?
  • Which virus type modifies its code for each replication to avoid detection?
  • Which IDS category is primarily indicated by repeated probes of services, connections from unusual locations, repeated login attempts, and sudden influxes of log data?
  • Which category of portals is specifically used to access Voice over IP services?
  • An attacker communicates with targeted users via instant messaging to gather personal information such as date of birth?
  • Which protocol is connectionless and provides unreliable service for short messages?
  • In the material, the ARP Method is presented as the social engineering concept used to manipulate information; which term does this correspond to?
  • Which policy outlines the terms for granting special access to system resources?
  • An FTP server that permits anonymous login can lead to what primary risk?
  • Which term is associated with CORE Impact in the material?
  • Spike templates are defined as what?
  • Which statement best describes the main purpose of the Google Hacking Database (GHDB)?
  • What is the file path for the SAM database file on Windows systems?
  • Which term denotes the vulnerability that occurs when input exceeds the buffer and may overwrite adjacent memory?
  • Which attack involves exploiting an application integrated with vulnerable web services to inject a malicious script that discloses and modifies data?
  • Mobiwol NoRoot Firewall primarily enables you to do what on Android devices?
  • What is the act of altering logs to evade legal action?
  • Pre-installed Windows tools like PowerShell and WMI that attackers exploit to install and run malicious code are known as which category?
  • Which detection approach uses a database of known patterns to identify attacks by matching incoming data against signatures?
  • Which attack combines entries from two dictionaries to generate a new wordlist?
  • Which term refers to spoofing a MAC address with the MAC address of a legitimate user on the network?
  • What term describes an application seeking a service?
  • Which tool helps you find all the devices connected to the network, and shows data such as IP addresses, manufacturer names, device names, and MAC addresses?
  • Overwriting the EIP register refers to what capability?
  • Which file stores user account information on Unix-like systems but is said not to contain password data?
  • Which indicators are useful for command and control, malware delivery, identifying the operating system, and other tasks, such as URLs, domain names, and IP addresses?
  • What term describes altering or adding forged DNS records into the DNS resolver cache to redirect DNS queries?
  • Which command illustrates an ICMP traceroute in Windows?
  • Which networking utility reads and writes data across network connections using TCP/IP and is commonly used for debugging and exploration?
  • The material mentions scanning on iOS to determine the identity of all its active machines and Internet devices on the local network. Which operating system is described?
  • Which tool tracks the geographical location of the users visiting the company's website?
  • Which technique is used to detect new or unknown viruses by analyzing behavior rather than signatures?
  • If an attacker modifies log entries to mislead investigators, this is known as what?
  • What sits between the web client and the web server and is used to prevent IP blocking and maintain anonymity?
  • Which term describes an attack that focuses on container storage configurations to facilitate privilege escalation and lateral movement?
  • Which Trojan targets mobile devices, performing actions such as banking credential theft, social networking credential theft, data encryption, and device locking?
  • Which term describes the phase of hacking that involves running targeted applications after gaining access?
  • In the Nmap command shown, which port ranges are scanned?
  • Which concept focuses on layering defenses to bolster security across systems?
  • command to clear all the PowerShell event logs from local or remote computers
  • Which tool is used to perform reverse DNS lookups on a target host?
  • Which term refers to guarantees that data, communications, or documents are genuine?
  • Which term describes BIOS-level firmware capable of capturing keystrokes, requiring physical or admin access?
  • Which tool is used to recover Windows passwords using dictionary, hybrid, rainbow table, and brute-force methods?
  • Which encoding is used to convert a URL into valid ASCII format so it can be safely transmitted over HTTP?
  • To detect a sniffer on a network, identify the system running in promiscuous mode; which method is described as useful for detection?
  • Which tool is primarily used to extract metadata and hidden information from scanned documents?
  • Which timing attack exploits side-channel leaks in the browser to estimate the time taken by the browser to process resources?
  • Which Windows feature caches data about recently used applications to speed up startup and launching?
  • What term refers to all of the strategies/actions used to defend ICT asset attacks?
  • Which search term would you use to locate Cisco VPN login pages?
  • Which policy is primarily concerned with defining access to resources and the protection rules?
  • Which concept provides a structured view of attacker phases to aid defense by identifying and preventing intrusions?
  • Which type of virus infects files executed or interpreted in the system, such as COM, EXE, SYS, OVL, OBJ, PRG, MNU, and BAT files?
  • FOCA is a tool used mainly to find metadata and hidden information in the documents it scans.
  • An access point that masquerades as a legitimate network to intercept wireless communications is known as what?
  • Which term describes transferring your information through a network of Internet-connected computers before passing it on to the website?
  • Which tool detects rogue hosts running Responder on public Wi-Fi networks?
  • Which tool is used to audit security devices by generating traffic between two virtual machines?
  • Which technique uses a 1×1 pixel iframe under the mouse cursor to register clicks on the malicious page?
  • Which scanning technique uses ICMP echo requests to determine which hosts are up?
  • Which term describes sensors, devices, machines, and intelligent edge nodes of various types?
  • What is the term for a hardware/software application that hosts websites and makes them accessible over the Internet?
  • Which tunneling technique uses ICMP echo and reply packets as carriers of TCP payload to covertly access or control a system?
  • WPA2 uses which encryption standard?
  • ISAKMP is best described as which of the following?
  • Which technique involves forging the origin of a message to appear from a trusted source?
  • Which term refers to intercepting network data, including IPs, MACs, and VLANs?
  • Which offline browser utility mirrors a site for offline viewing?
  • Which tool is used for website mirroring to download content from the web to a local computer?
  • Which REST constraint is optional and allows servers to send executable code to clients to extend functionality?
  • In SQL injection payloads, what does the sequence -- typically indicate?
  • Which term describes using a word list and variations to guess passwords?
  • Which term describes the category where attackers gather OS and configuration information to identify exploitable vulnerabilities?
  • Honeynets are networks of honeypots deployed in an isolated environment to determine the adversary's capabilities. Which statement best describes their purpose?
  • Which attack method involves placing a backdoor in a web application to gain remote access?
  • Which free service analyzes suspicious files and URLs for malware, often used to quickly check samples?
  • What describes the service that provides connectivity and transport between cloud consumers and providers?
  • Which attack type requires the attacker to be physically near the target system?
  • Which search pattern is commonly used to locate publicly accessible VPN client configuration files?
  • Which tool allows you to search for content in social networks in real-time and provides deep analytics data?
  • Which method describes attaching a Trojan to a legitimate-looking executable to deceive users?
  • Which technique uses deceptive pop-up windows to lure users into clicking links or downloading malware?
  • Which keylogger uses memory injection to log keystrokes and can bypass UAC in Windows?
  • Port 1812/TCP, UDP is used for which RADIUS service?
  • What term describes the process of capturing network traffic and investigating it to identify malware activity?
  • Which rootkit describes replacing the original boot loader with one controlled by a remote attacker?
  • Which resource tracks the pulse of markets for engaged investors?
  • Which component is used to conceal a malware payload by transforming the code to hinder detection?
  • Which social networking site is specifically mentioned as a target for enumerating employees during OSINT?
  • Which activity involves inferring a target's underlying operating system and software from HTTP responses?
  • A sensor-based technology that directly corrupts technological systems is categorized as which warfare type?
  • Which U.S. government repository of vulnerability management data uses the Security Content Automation Protocol (SCAP)?
  • Which Google search operator allows you to search results based on a file extension?
  • OSRFramework includes applications related to username checking, DNS lookups, information leaks research, deep web search, and regex extraction. This describes which framework?
  • An assessment of the resulted impact on the network is best described as which risk concept?
  • Which attack exploits default configurations and settings of off-the-shelf libraries and code?
  • A process that provides the details of an activity or event that can extract possible attacks in the form of Trojans or worms in the system.
  • Which protocol provides a structured model for messaging, based on XML, for web services?
  • WS-Security role.
  • The probability that a threat-source will exploit a vulnerability.
  • Which scan uses ACK probe packets and then analyzes the TTL and WINDOW fields of the received RST packets to determine if the port is open or closed?
  • Which tool provides reports on industries, consumers, and demographics?
  • Which honeypots deploy fake databases to lure attackers into database-related attacks and identify attack patterns and threat actors?
  • Under the heading Burp Suite and WebScarab, which tool is described as automatically extracting targeted data such as emails, phone numbers, and meta tags from web pages?
  • Computed Hashes. In the context of password cracking, which term best describes hashes that have been generated during the process?
  • LDAP Directory Services is described as storing and organizing information based on its attributes.
  • Which encoding scheme represents binary data using only printable ASCII characters and is commonly used for email attachments and credentials?
  • Which service is commonly used to gather data about hosting providers and SSL certificates, aiding reconnaissance?
  • Which technique involves sending packets with bad or bogus TCP/UDP checksums to bypass certain firewall rule sets?
  • Which tool is a web updates monitoring tool that detects changes on a site?
  • Which protocol is a TCP/IP mail delivery protocol?
  • Which form of malware looks innocent but provides a backdoor for attackers?
  • Ensures appropriate controls are implemented to handle known risks and calculates the chances of a new risk occurring.
  • Which tool helps automate web application security testing and guard the organization's web infrastructure against threats?
  • Evaluation Assurance Level (EAL) is used to rate what?
  • Which file type lets you open, view, and edit a variety of 32-bit Windows executable file types, such as EXE, DLL, and ActiveX Controls?
  • A precomputed table that contains word lists like dictionary files, brute force lists, and their hash values is known as what?
  • What do Application-Layer Vulnerability Assessment Tools primarily test?
  • Which mechanism ensures log file event correlation is accurate across systems?
  • What risk arises when credentials are stored in public code repositories?
  • In social engineering, which tactic is described as creating a feeling of urgency to influence decision-making?
  • Which technique involves identifying and exploiting a mobile channel to gather sensitive information?
  • What is the purpose of rainbow tables in password cracking?
  • Which attack allows the attacker to know the steganography algorithm as well as the original and stego-object and extract the hidden information with the information at hand?
  • What is the primary purpose of cookies in web applications?
  • Which term describes the method of intrusive probing used to gather information such as user lists, routing tables, security flaws, and SNMP data?
  • Which Trojan is a small HTTP server embedded inside any program and can be wrapped with a genuine program (e.g., game chess.exe)?
  • What DNS record type is used to locate Directory Services (LDAP) servers?
  • The attacker compares the stego-object and the cover medium to identify the hidden message.
  • Which term represents security concerns arising from the shared infrastructure and service models where users access computing resources over a network?
  • This approach is quite difficult as it uses a bounce server that receives packets from the victim and sends it to an attacker. Here, one hidden character is relayed by the bounce server per packet.
  • In hping3, which type of scan is performed with the -A option?
  • Which tools are used to extract linked images, scripts, iframes, and URLs from the target website?
  • Which ransomware specifically targets Linux devices with QNAP Network Attached Storages (NAS) by employing AES encryption?
  • Which tool is used to detect load balancing by analyzing the Server and Date headers in responses?
  • Which statement about MAC filtering is true?
  • Which term describes a network intrusion detection system that identifies attacks by comparing traffic to known signatures?
  • Which statement best describes REST's approach to client and server interactions?
  • Which attack exploits vulnerabilities in applications running on an organization's information system to steal or manipulate data or gain unauthorized access?
  • Which service category focuses on container orchestration and management via API or web portal?
  • Which MIB contains object types for workstation and server services?
  • What is the term for a set of requirements, processes, principles and models that determines the structure and behavior of an organization's information systems?
  • Which technique uses advanced Google search operators to identify vulnerable targets?
  • Which attack involves sending partial HTTP requests that leave the server waiting for completion?
  • Port 1812 is used for which service?
  • What is the primary risk associated with publicly exposed VPN client configuration files (.pcf)?
  • Which practice involves performing static analysis on suspicious files to understand their structure without execution?
  • The resource used to determine the network range of the target network is:
  • What protocol in IPsec establishes the required security by combining authentication, key management, and security associations?
  • Which technology provides runtime protection and detects runtime attacks?
  • Which utility dumps event log records?
  • The attacker has access to the stego-object and the steganography tool or algorithm used to hide the message.
  • Which banking Trojan can function as both a Trojan itself and as a downloader/dropper for other banking Trojans and is polymorphic?
  • Which encryption standard for wireless networks was compromised by packet capture-based key cracking?
  • Which tool is used to footprint social networking sites to gather sensitive information about the target, including business strategy and potential clients?
  • Which technique relies on synchronization between sender and receiver to recover data from spread-spectrum signaling?
  • Which DNS zone transfer method is used to copy zone data from a primary server to a secondary server?
  • An ICMP ping scan on the subnet 10.0.1.x is described as what?
  • Which DDoS attack floods the target with a large number of SYN requests containing spoofed source IPs, exhausting half-open connections?
  • Which term denotes the tactic of making a program's behavior harder to understand while preserving function?
  • Which zone is restricted and strictly controls direct access for uncontrolled networks?
  • Syllable Attack is a manual password-cracking algorithm that iterates through a dictionary file.
  • Which standalone term is used to locate login portals that include vpnssl access for companies?
  • Which term describes threat intelligence that provides information about resources an attacker uses to perform an attack, including command and control channels and tools?
  • Which term describes the activity to hide malicious acts?
  • Which REST constraint allows progressive enhancement through intermediary servers such as proxies and gateways?
  • Which Secure Hashing Algorithm produces a 160-bit digest and resembles MD5, with a maximum message length of 2^64 - 1 bits?
  • What is the term for analyzing malware by inspecting the executable code without executing it?
  • Which statement best describes APTs in relation to vulnerabilities?
  • Occurs when users are allowed to insert unsafe inputs into a server-side template.
  • Which term refers to the amount of knowledge, tools, and techniques required to perform an attack?
  • Which attack duplicates the body of a SOAP message during TLS processing and sends it to the server as a legitimate user?
  • Which NetBIOS enumeration tool is described for NetBIOS usage and SMB protocols?
  • Which port is used by Secure Shell (SSH) for secure remote login?
  • Which tool communicates with RPC services and checks misconfigurations on NFS shares?
  • Which tool monitors the total number of pages viewed by the users along with the timestamps and the status of the user on a particular web page (whether the webpage is still active or closed)?
  • Which technique uses network tunneling to hide traffic and evade detection?
  • In the context of DDoS mitigation, which term describes brief, high-volume attack bursts?
  • Which term describes the malicious code that takes advantage of a vulnerability to breach a system?
  • Which integrated tool is used for finding vulnerabilities in web applications and offers automated scanners and manual testing?
  • Which honeypot type emulates a real SSH environment and verifies login attempts against an internal list of fake users?
  • The identified security incidents are analyzed, validated, categorized, and prioritized; the IH&R team further analyzes the compromised device to find incident details such as the type of attack, its severity, target, impact, and method of propagation, and any vulnerabilities it exploited. Which term best describes this activity?
  • The attacker must be connected to the LAN and sniff the DNS request IDs to respond before the legitimate DNS server is known. This attack is called what?
  • Which technique reduces the dimensionality of data by combining features into fewer components?
  • Which type of scanning is used to identify known weaknesses and assess exploitability?
  • Which attack derives a new alphabet from 2- and 3-character syllables of password entries and matches it to the password database?
  • Evasion Attack is best described as which of the following?
  • Silver Tickets are used to call a specific service and access the system that offers the service.
  • Uses port mirroring to monitor all network traffic and records only VoIP traffic by MAC address?
  • Which tool quickly scrapes web data without coding and turns web pages into structured data?
  • Which protocol distributes, inquires into, retrieves, and posts news articles among the ARPA-Internet community?
  • Nessus Professional is described as what type of software?
  • The layer of the online cyberspace that consists of web pages and content hidden and unindexed is the deep web. Which option best describes this?
  • Which service hides the user's IP and allows access to blocked or censored content?
  • Which flood type is described as masking multiple HTTP requests within one packet to remain undetected?
  • Which term describes attackers using the ../ sequence to access restricted directories outside the web server root?
  • Which framework is commonly used to exploit vulnerabilities and gain access to a target system?
  • Which command is used to request changes in the NTP daemon's state after querying it?
  • Which tool is used to retrieve the Security Identifier (SID) for a computer or user?
  • Which service uses port 135 TCP/UDP?
  • Which hping3 command includes a TCP timestamp option to test firewall behavior?
  • Which term best fits the overarching practice of protecting information and information systems?
  • Which DNS record defines the name servers within your namespace?
  • This method also does not require an established connection between the two systems. Here, one hidden character is encapsulated per SYN request and reset packet.
  • Which Trojan class turns the infected machine into a zombie that awaits commands from a DDoS server to overwhelm targets?
  • Which component decrypts the virus code and decrypts it only after taking control of the computer?
  • Which technique uses the CUSUM algorithm to identify and locate DoS attacks by filtering traffic and storing flow data in a graph?
  • Which field in the IP header indicates the maximum time a packet may remain on the network?
  • Which tool is commonly used for remote command execution on Windows hosts?
  • Which option lists the toolset used to track most shared content on social media using hashtags or keywords?
  • What is a fundamental characteristic of stateful inspection firewall behavior?
  • Which attack type occurs when attackers tamper with hardware or software prior to installation?
  • Which system is designed to detect intrusions and take actions to prevent them, often deployed behind firewalls?
  • Which phase involves preparing the final reports and recommendations for the customer?
  • Which term is a platform used to distribute Trojan, spyware, backdoor payloads among others?
  • Which tool checks web apps for SQL injection and XSS?
  • Which term refers to mechanisms that restrict unauthorized users from accessing critical assets?
  • Which tunneling protocol is commonly associated with Windows VPNs and is listed as PPTP in the material?
  • Which network tool exploits weaknesses in DHCP and other protocols and serves as a testing framework?
  • Which term is about reducing risk to an acceptable level through a security program?
  • What is an attack that exploits computer application vulnerabilities before patches are released called?
  • Which tool is described as a self-extracting RAR file containing a bypass component and a service component?
  • utility to clear event logs related to the system, application, and security
  • Which virus type infects Microsoft Word or similar applications by automatically performing a sequence of actions after triggering an application?
  • Which Android-based tool floods networks and can perform UDP, HTTP, or TCP floods?
  • Which IoT-focused Trojan is a self-propagating botnet that infects devices using default credentials on Telnet ports 23 or 2323?
  • Which vulnerability affected the GNU Bash shell due to crafted environment variables?
  • What term describes software applications that run automated tasks over the Internet and perform simple tasks such as web spidering and search engine indexing?
  • Which tools are used to footprint social networking sites to gather sensitive information about the target, including DOB, educational qualification, employment status, name of the relatives, and information about the organization that they are working for, including the business strategy, potential clients, and upcoming project plans?
  • Which statement describes Sublist3r most accurately?
  • Which query would locate the configuration page for the Cisco SPA504G IP phone?
  • Which two vulnerabilities are explicitly named as targets of the WebApp Security Scanner in the material?
  • Which term captures the hacker mindset that something is worth doing or interesting?
  • Which web shell variant allows attackers to monitor running processes, execute remote commands, and manage files including database access?
  • Which flag in hping3 would you use to collect the TCP sequence numbers generated by the target?
  • Which format is used to organize and describe 32-bit Windows executable file types such as EXE, DLL and ActiveX Controls?
  • Which device forwards frames using a MAC address table to deliver them to the correct port?
  • Which assessment conducts a configuration-level check to identify system configurations, user directories, file systems, and registry settings to evaluate potential compromise?
  • Which Metasploit module is used for no-operation instructions to block out buffers?
  • What term describes attackers exploiting weak and default configurations in volumes to escalate privileges and move laterally in the internal network?
  • An attack relying on unvalidated input or file injection into the application.
  • Which scan uses the IDLE/IPID Header Scan technique?
  • Which term describes a deception system that lures attackers by presenting common services like SMTP, FTP, HTTP, and TELNET?
  • Which tool is described as a cross-platform, open-source censorship circumvention tool that maps censorship patterns around the world?
  • Which layer consists of cloud services, a B2B layer that holds all the commercial transactions, and a database server that supplies an organization's production data in a structured form (e.g., MS SQL Server, MySQL server)?
  • Which solution is offered by third parties and can be hosted inside or outside the network, with a drawback that attackers can audit from outside?
  • Which technique captures traffic passively to infer the target's operating system without sending additional probes?
  • Which term refers to affecting the economy by blocking the flow of information?
  • Which ransomware is described as attacking victims through email campaigns and demanding bitcoins for decryption?
  • Attackers often use scripts in which binaries or shellcode are obfuscated and encoded; these script-based attacks may be embedded in documents as email attachments. This is known as what?
  • Which vulnerability forces a user's browser to perform an authenticated request to a server without the user's intent?
  • An XML parsing misconfiguration can allow an attacker to read internal files or resources. This vulnerability is called:
  • Which indicators are used to identify specific behavior related to malicious activities, such as document executing PowerShell script, and remote command execution?
  • When using -8 or --scan with Hping in scan mode and pairing -S, what scan type and port range are performed?
  • What may indicate the presence of a rootkit on a system?
  • Which protocol is used to transfer Usenet articles?
  • Which DNS record is used to store unstructured text data?
  • Attackers use brute forcing on the bucket URL to identify the correct URL.
  • Which wireless technology is designed for short-range communication between devices?
  • Crawl the Internet for IoT devices that are publicly accessible. What type of search engines is used for this purpose?
  • For competitive keyword research and compiling a list of Google keywords and AdWords for a site, which tool is described?
  • What is the purpose of the state parameter in OAuth?
  • Which attack exploits the security vulnerability of a database for attacks, injecting malicious code into strings that are later executed by the SQL server?
  • Which tool is a simple Internet server identification utility?
  • Which tool would you use to obtain system information such as host name and uptime?
  • What DNS architecture uses separate DNS servers for external and internal networks?
  • This attack is used when the attacker gets some information about the password.
  • Enabling the TCP timestamp option in hping3 is used to estimate what about the target?
  • Which tool shuts down and optionally reboots a computer?
  • Which term describes the overall framework for structuring information security across an organization?
  • What is the name of the Whois service that stores only the registrar's Whois server name?
  • Manipulate variables that reference files with "dot-dot-slash (../)" to access restricted directories in the application.
  • Which technology runs inside the application to detect and prevent runtime attacks?
  • Misconfigured service permissions may allow an attacker to do what on a Windows service?
  • What DNS record maps a domain to an IPv4 address?
  • An attack where the attacker changes parameters in requests to modify business logic, such as prices or permissions.
  • Shodan is a tool used for which primary purpose?
  • Which app is designed for iPhone and iPad and allows attackers to browse websites anonymously?
  • Which hosting technique allows multiple domains or websites to be hosted on the same server and supports global resource sharing?
  • Which service acts as a collaborative clearinghouse for phishing data and offers an open API?
  • What Cisco switch feature, also known as port mirroring, monitors network traffic on one or more ports?
  • Which term describes the interception of packets during transmission between a client and server in a TCP or UDP session?
  • Which malware type exploits firmware used for management operations to execute malicious code within the CPU?
  • Which term is defined as the existence of a weakness that may compromise security?
  • used to connect applications to database engines. In these attacks, attackers target a database connection that forms a link between a database server and its client software.
  • Which statement best differentiates Passive vs Active session hijacking?
  • Which CeWL command prints the help or usage information?
  • This type of malware exploits system executables, Flash, Java, and documents to run a shellcode that injects a malicious payload into memory; it uses files to gain the initial entry. What is this called?
  • The process of taking over an existing active session.
  • The DNS record used for service location is:
  • Which tool is a modified version of Snort IDS capable of packet manipulation and rewriting iptables rules, mainly used in GenII honeynets?
  • Which hping3 command performs an ICMP ping to the host 10.0.0.25?
  • Which tool performs metadata extraction on public documents by performing a Google search and downloading the documents, then extracting metadata with libraries such as Hachoir and PdfMiner?
  • What DNS resource record type defines the hostname and port for specific services?
  • Which technique substitutes insignificant bits to embed secret data?
  • What is the effect attackers aim for by targeting cloud storage buckets?
  • Which term describes an attack using deceptive emails or links to steal credentials?
  • Which tool is specifically designed to simulate phishing campaigns for training and security testing?
  • Which technique combines dictionary words with other methods and all possible combinations to crack passwords?
  • Which attack is described as monitoring resemblance of original data by feeding a detector with data from multiple perspectives?
  • Which tool displays the Security Identifier (SID) of a computer or user?
  • Which tool is described as an IP address and port scanner suitable for quick scans?
  • Which virus forms a shell around the target host program's code, making itself the original program with the host code as its sub-routine?
  • Which Unix-like command is commonly used for DNS reconnaissance to gather information about name servers and mail exchanges?
  • IDS is used to do what?
  • Which rootkit is described as intercepting the victim's account information before encryption and is installed when the user opens a malicious email attachment or advertisement?
  • Which CVSS metric captures environmental factors such as security controls and network topology?
  • Which tactic involves offering something enticing in exchange for important information such as login credentials?
  • Which term describes the practice of sending spam through instant messaging that leads to credential theft?
  • Which tool shows who is logged on locally and via resource sharing?
  • The layer that includes all physical devices present on the client side, such as laptops, smartphones, and computers.
  • Which tool finds vulnerabilities in an organization's web server and allows a user to evaluate the security posture using the same techniques currently employed by cyber criminals?
  • Which detection helps identify a compromised host by monitoring outbound connections and unusual ports?
  • The concept that provides information about the location and types of servers is:
  • Which attack uses TCP SYN flooding techniques with spoofed IP addresses to perform a DoS attack?
  • Which category represents malware that targets point-of-sale systems to steal payment card data?
  • Which practice involves encapsulating a network protocol within another protocol to traverse networks?
  • ManageEngine Firewall Analyzer is best described as what?
  • Which vulnerability enables attackers to install malware or trick victims into disclosing passwords, often via unsafe redirects or forwards that bypass access controls?
  • What is the name of a two-way HTTP tunneling software that connects two computers using HTTP-Tunnel Client and Server?
  • Which term relates to encrypting and compressing binaries while preserving functionality?
  • Which term describes gaining access to one network to obtain information enabling access to others?
  • Which tool audits Windows passwords and recovers them using dictionary, hybrid, rainbow table, and brute-force attacks?
  • What is the name of the phishing tool that reveals the victim's IP address and browser information to attackers?
  • Which method involves gathering sensitive information with the help of mobile applications?
  • Which is a dedicated stand-alone hardware device or part of a router; the network traffic is filtered using the packet filtering technique; used to filter out network traffic for large business networks?
  • Which Windows command is used to run a program with the credentials of another user?
  • Which concept is defined as the trustworthiness of preventing improper and unauthorized changes of data or resources?
  • Which item is used to obtain a clean forensic image of a system or drive for investigations?
  • Which routing protocol is widely used by Internet service providers to maintain huge routing tables and efficiently process Internet traffic?
  • What term describes a program or device that monitors data traveling over a network?
  • Which DNS record would you use to alias one domain to another?
  • What is a web-based script that provides access to a web server for attackers?
  • Which propagation method uses the compromised machine to accept connections and then transfer the toolkit to new hosts using special methods?
  • Which tool is an open-source network intrusion detection system capable of real-time traffic analysis and packet logging on IP networks?
  • Which service offers the latest business and financial information for researchers?
  • Which form of DoS is known as phlashing and sabotages hardware, often requiring hardware replacement?
  • Which Android app is designed to generate a scan report that aligns with PCI SSC guidelines?
  • Which resource focuses on vulnerability advisories and OS/device vulnerability details?
  • What is the primary function of the CAM table in a switch?
  • In PKI, which item binds a public key to an identity by means of a trusted certificate?
  • Which technique bypasses the Same Origin Policy to allow the malicious web page to communicate with local domains?
  • Which keylogger uses a forged Windows device driver to record keystrokes and remains undetectable by standard tools?
  • Which term identifies the sources, causes, and consequences of risks before harm occurs?
  • Which term describes filtering by IPs and ports in packet analysis?
  • What term refers to search engines used to locate files on FTP servers?
  • Which term refers to the IoT layer focusing on edge devices and local processing?
  • Which term refers to the technique of looking over someone’s shoulder as they enter information?
  • Which of the following is an example of a meta search engine?
  • Which technique involves analyzing traffic patterns to improve filtering and protection against DDoS?
  • Which tool is described as being able to generate comprehensive test reports and assist in fixing security problems that might exist in a company's website or web server?
  • Which Windows utility is used to adjust the last access timestamp behavior on NTFS volumes?
  • Which tool helps security professionals check for both LLMNR and NBNS spoofing?
  • Which name refers to a Linux kernel information gathering tool used to inform privilege escalation?
  • Which term best describes a web service designed using REST principles and HTTP methods, providing access to resources via standard verbs such as GET, POST, PUT, and DELETE?
  • Which service is commonly used in reconnaissance to identify a web server's operating system and potential vulnerabilities by analyzing HTTP response characteristics?
  • A business information and research tool that gets information from licensed and free sources and provides capabilities such as searching, alerting, dissemination, and business information management.
  • Which tool searches a vast number of social networking sites for a target username?
  • Which principle states that access should be provided only to the minimum necessary to perform tasks?
  • Which term refers to the activities carried out by an attacker to hide malicious acts?
  • The collection and analysis of information about threats and adversaries and the drawing of patterns that provide the ability to make knowledgeable decisions for preparedness, prevention, and response actions against various cyber-attacks. It helps the organization to identify and mitigate various business risks by converting unknown threats into known threats; it helps in implementing various advanced and proactive defense strategies
  • Which virus type overwrites the directory entry pointer to direct disk reads to the virus code instead of the actual program?
  • Which command queries the ntpd daemon about its current state and requests changes in that state?
  • Which tool analyzes email headers and reveals information such as sender's geographical location and IP address?
  • In this phase, an attacker aims to gain access to a resource that can be used for performing further attacks or financial gain.
  • This type of attack is used to deface websites virtually by adding extra HTML-based content.
  • The payload example that inserts a new row demonstrates which SQL operation?
  • Allows clients and servers to communicate in distributed client/server programs.
  • Which attack lures the victim to click a bogus link that redirects to the attacker's server?
  • Which term is used to avoid dynamic analysis by protecting itself from programmer and debugger intervention?
  • What is the ability to run multiple operating systems on a single physical system, or multiple instances of one operating system and share underlying resources?
  • Which option lists the HTTP methods commonly used to perform CRUD operations in REST?
  • What term describes programs that capture data from information packets as they travel over networks?
  • Why is the redirect_uri critical in OAuth flows?
  • Which tool is used for session hijacking on Android devices connected to a common wireless network?
  • Which technique overlays only certain controls, masking buttons with hyperlinks and misleading labels?
  • Which attacker technique allows executing malicious programs at system startup to maintain persistence and enable remote execution?
  • Which service model provides virtual machines and other abstracted hardware and operating systems that may be controlled through a service API?
  • Which detection identifies compromised hosts by tracking outbound connections and anomalies to locate a command and control server?
  • Which term describes the set of actions to address risk, including accept, avoid, mitigate, transfer, and share?
  • Which technique involves impersonating financial institutions to trick users into submitting credentials?
  • What term describes a malicious script installed on a target server to grant remote control?
  • Which virus type attempts to install itself inside the file it infects?
  • Which attack type involves injecting shell commands through crafted inputs to the server?
  • Which pair of technologies are commonly described as securing communications with public-key cryptography and digital certificates?
  • Which term refers to a type of fileless malware that exploits NodeJS, a program that executes JavaScript outside the browser?
  • Which DDoS attack floods the target with spoofed ACK and PUSH ACK packets, rendering the system non-functional?
  • Which hardware component attached to the keyboard cable can capture keystrokes and store them in its own memory?
  • This technique hides information in a drawing, painting, letter, music, or a symbol.
  • What is the name of the evasion technique that employs overlapping TCP sequence numbers in small fragments to bypass reassembly checks?
  • What is the field called that involves monitoring and influencing an organization's online reputation across digital channels?
  • Which client-side attack exploits vulnerabilities in the data compression feature of TLS, SPDY, and HTTPS?
  • A technique that exploits dynamic file include mechanisms to use a remote file on the server.
  • Which literal text string is used to display pages from Google's cache?
  • Which command retrieves email account information for a specified email address?
  • Which command would you use to discover network resources available on a remote machine?
  • Which platform is commonly used to access legal and public records, including documents related to legal, news, and business sources?
  • Which malware is associated with a hidden fake cat game embedded in malware and not displayed at execution?
  • Which patch enables run-init support in klibc for modern Ubuntu systems?
  • Which service focuses on press release distribution and regulatory disclosure?
  • Which attack spoofs the victim's IP address and sends a large number of ICMP ECHO requests to an IP broadcast network, amplifying traffic?
  • Which protocol is used to map an IP address to a MAC address by broadcasting to the local network?
  • Which field is used to determine the length of the packet reported in fingerprint datasets?
  • The DNS record that contains authoritative information about zone transfers, including the primary name server and admin email is:
  • Spiking is described as which activity?
  • Hackers sniff credentials during transit by capturing Internet packets. Which term best describes this activity?
  • What protocol provides IP addresses to hosts on a network?
  • Which term focuses on ensuring controls are in place and assesses the probability of new risks arising?
  • Which tool is used to discover information about internet-connected devices, including routers and cameras?
  • What is the general term for an attack where an application loads a malicious library by abusing the library search order, enabling code execution?
  • Which category of tools records the actions of malware and helps extract the resulting log files?
  • Which ransomware is known for infecting millions of unpatched servers by using RSA-2048 asymmetric encryption?
  • Which DNS record maps an IP address to a hostname for reverse DNS lookups?
  • Which category of tool is used to observe and inspect the sequence of Win32 API calls within applications?
  • Which option best describes a TLS data compression vulnerability attack?
  • Which insider type is described as harming the organization and selling confidential information to outsiders?
  • Which protocol uses XML to transfer data and is simpler and lighter than SOAP?
  • Which tool creates fake 802.11b beacon frames with randomly generated ESSID and BSSID assignments?
  • An attack focusing on exploiting server misconfigurations to allow unauthorized access or data theft.
  • Which protocol is the standard for remote authentication and accounting in network access control?
  • Which mechanism allows an organization to manage a secure network environment by selecting the appropriate security levels for different zones?
  • Which Android app can sniff and intercept web session profiles over a Wi-Fi connection to a mobile and runs on rooted devices?
  • Which procedure dumps the volatile memory and analyzes it to detect the rootkit?
  • Which open-source software under GNU is used to create virtual machines and is efficient in deploying honeypots?
  • Which term refers to the runtime mechanism used to adapt legacy software to newer Windows versions?
  • Which option is a security application that detects ARP-based attacks and complements firewall protection?
  • Which term refers to the ongoing process of controlling and reducing exposure to risk through appropriate controls?
  • Which free and open-source web security scanner helps find SQL injection and XSS vulnerabilities in web applications?
  • Which tool is used mainly to find metadata and hidden information in the documents it scans?
  • Which tool is used to gather a list of words from the target website to create a wordlist?
  • Which protocol uses sequence numbers to ensure ordered data delivery?
  • Which honeypots employ fake databases that make attackers believe the data is real and help identify attack patterns and threat actors?
  • Which IP address and port scanner is mentioned as a tool for quick scans?
  • Which technique involves obtaining access tokens of other users or generating spoofed tokens to escalate privileges and perform malicious activities by evading detection?
  • In SQL injection, which character is commonly used to terminate a string literal?
  • The identified security incidents are analyzed, validated, categorized, and prioritized; the IH&R team further analyzes the compromised device to find incident details such as the type of attack, its severity, target, impact, and method of propagation. What is this step?
  • Which technique involves generating a series of tiny fragments with overlapping TCP sequence numbers to evade detection?
  • Which process is described as listing the open ports and services by sending a sequence of messages to identify the services on the target computer?
  • Which technique determines the operating system running on a remote target by analyzing banners?
  • What describes the attacker connecting a rogue switch into the network by tricking a legitimate switch and creating a trunk link between them?
  • Which term refers to the impact an attacker has over a compromised system or network that they control?
  • Which self-contained NirSoft utility is described as a self-extracting RAR containing a bypass component and a service component?
  • An open-source scanner that identifies SIP devices and PBX servers on a target network. It can be helpful for system administrators when used as a network inventory tool.
  • Which phase occurs after viruses spread where they start corrupting the files and programs of the host system?
  • Which tool is an open-source tester for web apps and browser vulnerabilities?
  • Which term best describes ensuring that only authorized personnel access and use information, supporting information security and business continuity?
  • Which tool lists the possible domains hosted on the same web server as another domain?
  • What is the main security weakness of WEP that makes it susceptible to rapid key cracking?
  • Who vouches for the identity of an individual or organization within a public key infrastructure?
  • Which technique involves collecting information about server locations and types?
  • A software program installed on a computer, like normal software; it is generally used to filter traffic for individual home users; it only filters traffic for the computer on which it is installed?
  • Which attack involves duplicating the SOAP message body during TLS translation to impersonate a legitimate user?
  • Which tool checks web applications for SQL injections and XSS and also scans ports?
  • Which category of software provides information about a user's activity on desktops and transmits it to third parties without consent?
  • Which focus is emphasized in manual web application security testing?
  • Makes use of algorithms that input unlabeled training data to attempt to deduce all the categories. Unsupervised learning is further divided into two subcategories, namely, clustering and dimensionality reduction. Which term describes this approach?
  • Which SNMP concept is described as a virtual database containing a formal description of all network objects SNMP manages?
  • Which term describes an attack where the attacker obtains information about the target device from its specifications, by examining the chipset with a multimeter to identify features like ground pins?
  • Which technology is used to power a many-to-many defense in DDoS mitigation?
  • zIPS is described as a mobile intrusion prevention system app that protects iOS and Android devices and can detect threats by analyzing behavior.
  • Which protocol is used to map an IP address to a MAC address by broadcasting (as per the material)?
  • Which timing attack involves sending crafted request packets to the website using JavaScript?
  • Which SNMP concept is described as a virtual database containing a formal description of all the network objects that SNMP manages?
  • Port 1723/TCP, UDP is used by which VPN protocol?
  • What is the primary purpose of the Nmap Scripting Engine (NSE)?
  • Which technique determines which ports are open and if the packets can pass through the packet filter and the firewall?
  • Which ensures that the system that processes, delivers, and stores information is accessible to authorized users when required?
  • Which Windows security assessment framework can be used to identify misconfigured services on a target OS?
  • Which act was designed to protect investors by increasing the accuracy and reliability of corporate disclosures?
  • In Sublist3r, which command-line option specifies the domain name to enumerate subdomains for?
  • Which malware type overwrites the host's code completely or partially with viral code?
  • Which command retrieves all publicly available email addresses related to the domain microsoft.com along with email account information?
  • Which utility is commonly used to perform DNS lookups and can query specific record types?
  • What technique uses one protocol to carry data from another protocol, effectively tunneling it through a different transport?
  • Which technique overlays the legitimate page and uses a higher z-index, often loading it in an invisible iframe?
  • Which indicators are described as useful for identifying the operating system on the target machine and other tasks?
  • Which Windows system file stores the RAM contents when the computer enters hibernation?
  • Which ICMP technique queries the target for the time to obtain time information?
  • Which tool enumerates OS-level user accounts on Solaris via the SMTP service?
  • Which tactic describes an attacker following closely behind an authorized person through a door that requires key access?
  • Which type of tool hides malicious code through various techniques to evade detection and removal by security tools?
  • Which keylogger uses electromagnetic sound or a camera to capture keystroke data?
  • Which tool is described as patch management software that scans the network and installs and manages patches?
  • Which term refers to listing active hosts and IP addresses to identify hosts, ports, and services on a network?
  • Which hosting technique enables multiple domains to be served from the same server, enabling resource sharing across a global company?
  • Which pattern targets the Asterisk web management portal?
  • RADIUS provides which two services in network access control?
  • Which attack involves spoofing the source IP to send ICMP Echo requests to an IP broadcast network to flood the target?
  • Which scan type is a variant of inverse TCP scanning that uses the FIN, URG, and PUSH flags set to send a TCP frame to a remote device?
  • A Windows utility used to set the NTFS volume behavior parameter, DisableLastAccess, which controls enabling or disabling of the last access timestamp.
  • Which technique analyzes network traffic by dividing signals into spectral components and examining energy in spectral windows to reveal anomalies?
  • Which tool is designed for checking lists of HTTPS and SOCKS proxies for "hone pots"?
  • Mobile Privacy Shield is described as which of the following?
  • What is a known drawback of product-based security solutions?
  • AlienVault OSSIM is an open-source SIEM that provides what capabilities?
  • XML-based description of web services
  • Which virus stores itself with the same filename as the target program file?
  • What is a primary purpose of a web proxy for clients?
  • Which protocol is used by a client system to request a service from a server?
  • What term refers to unauthorized listening of conversations or reading of messages?
  • Which file is described as containing the passwords themselves?
  • Which port is Kerberos authentication system associated with?
  • Which category describes attacks that target applications running on a company's information system to gain unauthorized access?
  • Which scanning technique can be used to probe the existence of a firewall and its rule sets?
  • Which vulnerability arises when privileged functions are accessible without proper authorization checks, such as changing user roles by non-privileged users?
  • What attack involves connecting a rogue switch to change the operation of STP and sniff traffic?
  • Which tool is Immunity's CANVAS?
  • Which tools are used to gather information about target IoT devices, such as manufacturer details and open ports?
  • Which command demonstrates a TCP traceroute?
  • Which browser-based attack uses a browser to host persistent malicious code that survives page navigation and closes?
  • Which attack uses a time-delayed HTTP header to hold an HTTP connection open and exhaust web-server resources without sending the full request?
  • Which directory stores the critical HTML files related to a domain name and is sent in response to requests?
  • Which XML editor and development environment is used for modeling, editing, transforming, and debugging XML-related technologies?
  • An attacker intercepts an established connection between two communicating parties by using spoofed packets and then pretends to be one of those parties.
  • Which zone has no heavy restrictions and is considered controlled?
  • Which Nmap command is designed to scan both TCP and UDP ports?
  • Which security standard governs protection of payment card data?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy