Save
Upgrade to remove ads
Busy. Please wait.
Log in with Clever
or

show password
Forgot Password?

Don't have an account?  Sign up 
Sign up using Clever
or

Username is available taken
show password


Make sure to remember your password. If you forget it there is no way for StudyStack to send you a reset link. You would need to create a new account.
Your email address is only used to allow you to reset your password. See our Privacy Policy and Terms of Service.


Already a StudyStack user? Log In

Reset Password
Enter the associated with your account, and we'll email you a link to reset your password.
focusNode
Didn't know it?
click below
 
Knew it?
click below
Don't Know
Remaining cards (0)
Know
0:00
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.

  Normal Size     Small Size show me how

FE - Ethical Hacc

Ethical Hacking Essentials/IT0202

QuestionAnswer
M1-2
Which statement best describes the term ethical hacker? ethical hacker? a person who mimics an attacker to evaluate the security posture of a network
Which type of threat actor uses cybercrime to steal sensitive data and reveal it publicly to embarrass a target? hacktivist
Which three options are phases in the Penetration Testing Execution Standard (PTES)? (Choose three.) Threat modeling, Exploitation, Reporting
Which type of penetration test would only provide the tester with limited information such as the domain names and IP addresses in the scope? unknown-environment test
Which tools should be used for testing the server and client platforms in an environment? vulnerability scanning tools
What characterizes a known environment penetration test? The tester could be provided with network diagrams, IP addresses, configurations, and user credentials.
Which threat actor term describes a well-funded and motivated group that will use the latest attack techniques for financial gain? organized crime
What kind of security weakness is evaluated by application-based penetration tests? logic flaws
What two resources are evaluated by a network infrastructure penetration test? (Choose two.) IPSs, AAA servers
Which option is a Linux distribution URL that provides a convenient learning environment about pen testing tools and methodologies? parrotsec.org
What are two examples of sensitive authentication data associated with a payment card that requires compliance with the Payment Card Industry Data Security Standard (PCI DSS)? (Choose two.) CAV2/CVC2/CVV2/CID, full magnetic strip data or equivalent data on a chip
Which U.S. government agency is responsible for enforcing the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act (GLB Act)? Federal Trade Commission (FTC)
A company hires a cybersecurity consultant to perform penetration tests and review the rules of engagement documents. What are three examples of typical elements in the rules of engagement document? testing timeline, preferred method of communication, location of testing
A company hires a cybersecurity consultant to perform penetration tests. The consultant is working with the company to set up communication procedures. Which two protocols should be considered for exchanging emails securely? PGP, S/MIME
An US university in California plans to offer online courses to students in partner universities in France and Germany. Which regulation should the university follow when those courses are offered? GDPR
A company hires a cybersecurity professional to perform penetration tests to assess government regulation compliance. Which legal document should be provided to the cybersecurity professional that specifies the expectations and constraint.. service-level agreement (SLA)
A contractor is hired to review and perform cybersecurity vulnerability assessments for a local health clinic facility. Which U.S. government regulation must the contractor understand before the contractor can start? HIPAA
In the healthcare sector, which term is used to define an entity that provides payment for medical services? health plan
An Internal Revenue Service office in New York is considering moving some services to a cloud computing platform. Which U.S. government regulation must the office follow in the process? FedRAMP
In e-commerce, what determines the application of the Payment Card Industry Data Security Standard (PCI DSS) requirements? primary account number
What is a state-sponsored attack? An attack perpetrated by governments worldwide to disrupt or steal information from other nations.
What is an insider threat attack? An attack perpetrated by disgruntled employees inside an organization.
When conducting an application-based penetration test on a web application, the assessment should also include testing access to which resources? back-end databases
What is the purpose of bug bounty programs used by companies? reward security professionals for finding vulnerabilities in the systems of the company
What characterizes a partially known environment penetration test? The test is a hybrid approach between unknown and known environment tests.
Collection of different matrices of tactics and techniques that adversaries use while preparing for an attack MITRE ATT&CK
Covers the high-level phases of web application security testing OWASP WSTG
Provides organizations with guidelines on planning and conducting information security testing NIST SP 800-115
Lays out repeatable and consistent security testing OSSTMM
Provides information about types of attacks and methods PTES
Which two options are phases in the Information Systems Security Assessment Framework (ISSAF)? Maintaining access; Vulnerability identification
Which two options are phases in the Open Source Security Testing Methodology Manual (OSSTMM)? Work Flow; Trust Analysis
Which penetration testing methodology is a comprehensive guide focused on web application testing? OWASP WSTG
Which option is a Linux distribution that includes penetration testing tools and resources? BlackArch
What does the “Health Monitoring” requirement mean when setting up a penetration test lab environment? The tester needs to be able to determine the causes when something crashes.
Which tool would be useful when performing a network infrastructure penetration test? bypassing firewalls and IPSs tool
Which tool should be used to perform an application-based penetration test? interception proxies tool
Which tools should be used to perform a wireless infrastructure penetration test? de-authorizing network devices tools
Sometimes a tester cannot virtualize a system to do the proper penetration testing. What action should be taken if a system cannot be tested in a virtualized environment? a full backup of the system
In the healthcare sector, which term defines an entity that processes nonstandard health information it receives from another entity into a standard format? healthcare clearinghouse
Provides general guidance and best practices for the management of cryptographic keying material Part 1: General
Provides guidance on policy and security planning requirements for U.S. government agencies Part 2: Best Practices for Key Management Organization
Provides guidance when using the cryptographic features of current systems Part 3: Application Specific Key Management Guidance
An employee of a cybersecurity consulting firm in the U.S. is assigned to help assess the system and operation vulnerabilities of several financial institutions in Europe. The task includes penetration tests for compliance. What is a key element the emp.. documentation of permission for performing the tests from the client institutions
A company hires a cybersecurity professional to perform penetration testing to assess government regulation compliance. Which document will be provided to the cybersecurity professional that specifies a detailed and descriptive list of all the deliv... statement of work (SOW)
A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. The company wants the consultant to disclose information to them and no one else. Which type of NDA agreement should be presented to the. unilateral NDA
A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. Which document must the consultant receive that specifies the agreement between the consultant and the company for the penetration testi. contract
A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. The consultant is preparing the final report after the penetration testing is completed. In which section of the report should the cons.. disclaimers
A company hires a cybersecurity consultant to perform penetration tests and review the rules of engagement documents. The consultant notices that one element specifies that the tests should be performd toward only web applications on websites www1.compa.. types of allowed or disallowed tests
A company hires a cybersecurity consultant to assess applications using different APIs. Which document should the company provide to the consultant about an XML-based language used to document a web service’s functionality? Web Services Description Language (WSDL) document
A company hires a cybersecurity consultant to assess applications using different APIs. Which document should the company provide to the consultant about a query language for APIs and a language for executing queries at runtime? GraphQL documentation
A company hires a cybersecurity consultant to assess vulnerability on crucial web application devices such as web and database servers. Which document should the company provide to help the consultant document and define what systems are in the testing? system and network architectural diagram
A company hires a cybersecurity consultant to perform penetration tests. What can cause scope creep of the engagement? ineffective identification of what technical and nontechnical elements will be required for the penetration test
A company hires a cybersecurity consultant to perform penetration tests. What should be the consultant’s first step in validating the engagement scope? Question the company contact person and review contracts.
A company hires a cybersecurity consultant to perform penetration tests. The consultant is discussing with the company about the penetration testing strategy. Which statement describes the term unknown-environment testing? This type of testing is where the consultant will be provided with very limited information about the targeted systems and network.
A company hires a cybersecurity consultant to perform penetration tests. What is the key difference between unknown-environment testing and known-environment testing? the amount of information provided to the consultant
_______________________________________________________________________ _______________________________________________________________________
_______________________________________________________________________ _______________________________________________________________________
M3-5
Which two tools could be used to gather DNS information passively? (Choose two.) Recon-ng; Dig
When performing passive reconnaissance, which Linux command can be used to identify the technical and administrative contacts of a given domain? whois
What guidance does the NIST Cybersecurity Framework provide to help improve an organization’s cybersecurity posture? The framework outlines standards and industry best practices.
What is the advantage of using the target Wi-Fi network for reconnaissance packet inspection? Physical access to the building may not be required.
A company hires a cybersecurity consultant to conduct a penetration test to assess vulnerabilities in network systems. The consultant is preparing the final report to send to the company. What is an important feature of a final penetration test report? It gives an accurate presentation of vulnerabilities.
When performing a vulnerability scan of a target, how can adverse impacts on traversed devices be minimized? The scan should be performed as close to the target as possible.
What are three considerations when planning a vulnerability scan on a target production network during a penetration test? (Choose three.) the timing of the scan; the available network bandwidth; the network topology
A penetration tester must run a vulnerability scan against a target. What is the benefit of running an authenticated scan instead of an unauthenticated scan? Authenticated scans can provide a more detailed picture of the target attack surface.
What useful information can be obtained by running a network share enumeration scan during a penetration test? systems on a network that are sharing files, folders, and printers
What initial information can be obtained when performing user enumeration in a penetration test? a valid list of users
How is open-source intelligence (OSINT) gathering typically implemented during a penetration test? by using public internet searches
A threat actor is looking at the IT and technical job postings of a target organization. What would be the most beneficial information to capture from these postings? the type of hardware and software used
What is the purpose of applying the Common Vulnerability Scoring System (CVSS) to a vulnerability detected by a penetration test? to calculate the severity of the vulnerability
Why is the Common Vulnerabilities and Exposures (CVE) resource useful when investigating vulnerabilities detected by a penetration test? It is an international consolidation of cybersecurity tools and databases.
When a penetration test identifies a vulnerability, how should the vulnerability be further verified? determine if the vulnerability is exploitable
What is the disadvantage of running a TCP Connect scan compared to running a TCP SYN scan during a penetration test? The extra packets required may trigger an IDS alarm.
What can be deduced when a tester enters the nmap -sF command to perform a TCP FIN scan and the target host port does not respond? that the port is open
What is the purpose of host enumeration when beginning a penetration test? to identify all active IP addresses within the scope of the test
Why would a penetration tester use the nmap -sF command? when a TCP SYN scan is detected by a network filter or firewall
In which circumstance would a penetration tester perform an unauthenticated scan of a target? when user credentials were not provided
What is required for a penetration tester to conduct a comprehensive authenticated scan against a Linux host? user credentials with root-level access to the target system
What is the disadvantage of conducting an unauthenticated scan of a target when performing a penetration test? Vulnerability of services running inside the target may not be detected.
What type of server is a penetration tester enumerating when they enter the nmap -sU command? DNS, SNMP, or DHCP server
Why would a penetration tester perform a passive reconnaissance scan instead of an active one? to collect information about a network without being detected
Which specification defines the format used by image and sound files to capture metadata? Exchangeable Image File Format (Exif)
_______________________________________________________________________ _______________________________________________________________________
M4:
What type of threat allows an attacker to obtain the credentials of a bank client by spoofing the login webpage of a financial institution? malvertising
What is a watering hole attack? an attack that exploits a website that is commonly accessed by members of a targeted organization
A user has found a USB pen drive in the corporate parking lot. What should the user do with this pen drive? deliver the pen drive to the security sector of the company
A new employee is celebrating their position with a large company by posting a picture of their access identification on social media. What kind of physical attack has the new employee unknowingly enabled? badge cloning
Which tool can send fake notifications to the browser of a victim? BeEF
Which tool permits post-exploitation activities, such as Windows reverse VNC DLL and reverse TCP shell? SET
A threat actor has sent a text message to a victim stating that they have won bitcoins in a bank contest. To claim their prize, the victim must click the provided link and enter their bank account information. What social enginee... SMS phishing
Which Apple iOS and Android tools can spoof a phone number, record calls, and generate different background noises? SpoofCard
What is the purpose of a vishing attack? to convince a victim on a phone call to disclose private or financial information
Who is the target of a whaling attack? upper managers such as the CEO or key individuals in an organization
Which tool can launch social engineering attacks and be integrated with third-party tools and frameworks such as Metasploit? SET
Which resource would mitigate piggybacking and tailgating? security guard
Which two access control options are commonly used in conjunction with access control vestibules? (Choose two.) proximity card and PIN; biometric scan
What two physical attacks are mitigated by using access control vestibules? (Choose two.) tailgating; piggybacking
Which Apple iOS and Android tool can be used to spoof a phone number? SpoofApp
Which tool provides a threat actor a web console to manipulate users who are victims of cross-site scripting (XSS) attacks? BeEF
Which social engineering physical attack statement is correct? Shoulder surfing can be prevented by using special screen filters for computer displays.
A threat actor has sent a phishing email to a victim stating that suspicious activity has been detected on their bank account and that they must immediately click on a provided link to change their password. What method of influenc... urgency
Apple is a company constantly working towards making its products and processes more environmentally friendly. Therefore, the Apple brand is associated with ideals and values that customers can relate to and support. What metho... likeness
What method of influence is characterized when a celebrity endorses a product on social media? social proof
A salesperson is attempting to convince a customer to buy a product because limited supplies are available. Which social engineering method of influence is being used by the salesperson? scarcity
Which option is a voice over IP management tool that can be used to impersonate caller ID? Asterisk
Why would a threat actor use the Social-Engineering Toolkit (SET)? to send a spear phishing email
A threat actor has altered the host file for a commonly accessed website on the computer of a victim. Now when the user clicks on the website link, they are redirected to a malicious website. What type of attack has the threat actor accomplished? pharming
What is the act of gaining knowledge or information from a victim without directly asking for that particular information? elicitation
_______________________________________________________________________
M5:
Which NetBIOS service is used for connection-oriented communication? NetBIOS-SSN
NetBIOS Datagram Service UDP port 138
NetBIOS Name Service UDP port 137
SMB protocol TCP port 445
NetBIOS Session Service TCP port 139
Microsoft Remote Procedure Call (MS-RPC) TCP port 135
An attacker is launching a reflected DDoS attack in which the response traffic is made up of packets that are much larger than those that the attacker initially sent. Which type of attack is this? amplification
What is a common mitigation practice for ARP cache poisoning attacks on switches to prevent spoofing of Layer 2 addresses? DAI
Which kind of attack is an IP spoofing attack? On-path
Which four items are needed by an attacker to create a silver ticket for a Kerberos silver ticket attack? (Choose four.) 1. system account; 2. SID; 3. FQDN; 4. target service
Which attack is a post-exploitation activity that an attacker uses to extract service account credential hashes from Active Directory for offline cracking? Kerberoasting
What is a characteristic of a Kerberos silver ticket attack? It uses forged service tickets for a given service on a particular server.
Which is the default TCP port used in SMTP for non-encrypted communications? 25
The port registered by the Internet Assigned Numbers Authority (IANA) for SMTP over SSL (SMTPS). 465
The Secure SMTP (SSMTP) protocol for encrypted communications, as defined in RFC 2487, using STARTTLS. 587
The default port used by the IMAP protocol in non-encrypted communications. 143
The default port used by the POP3 protocol in encrypted communications. 995
The default port used by the IMAP protocol in encrypted (SSL/TLS) communications. 993
What is a DNS resolver cache on a Windows system? It is a temporary database that contains records of all the recent visits and attempted visits to websites and other internet domains.
What does the MFP feature in the 802.11w standard do to protect against wireless attacks? It helps defend against deauthentication attacks.
Which Wi-Fi protocol is most vulnerable to a brute-force attack during a Wi-Fi network deployment? WPS
Which is a characteristic of a Bluesnarfing attack? An attack that can be performed using Bluetooth with vulnerable devices in range. This attack actually steals information from the device of the victim.
Which tool can be used to perform a Disassociation attack? Airmon-ng
Match the attack type with the respective description.
Typically a BGP hijacking attack by configuring or compromising an edge router to announce prefixes that have not been assigned to the organization Route Manipulation attacks
The attacker forces a system to favor a weak encryption protocol or hashing algorithm that may be susceptible to other vulnerabilities Downgrade attacks
An attacker floods a server with bogus DISCOVER packets until the server exhausts the supply of IP addresses DHCP Starvation attack
An attacker bypass any layer 2 restrictions built to divide hosts VLAN Hopping attack
An attacker spoofs the physical address of the NIC device to match the address of another on a network in order to gain unauthorized access or launch a Man-in-the-Middle attack MAC address spoofing attack
Match the attack type with the respective description.
This attack uses spoofed packets that appear to be from the victim. Then the sources become unwitting participants in the attack by sending the response traffic back to the intended victim. Reflected DOS
This an attack in which the attacker exploits vulnerabilities in target servers to initially turn small queries into much larger payloads, which are used to bring down the servers of the victim. DNS Amplification
This occurs when the source of the attack generates the packets, regardless of protocol, application, and so on, that are sent directly to the victim of the attack. Direct DOS
This attack uses botnets that can be manipulated from a command and control (CnC, or C2) system. DDOS
What is a Kerberoasting attack? It is a post-exploitation attempt that is used to extract service account credential hashes from Active Directory for offline cracking.
Which is a characteristic of the pass-the-hash attack? capture of a password hash (as opposed to the password characters) and using the same hashed value for authentication and lateral access to other networked systems
Which two best practices would help mitigate FTP server abuse and attacks? (Choose two.) 1. use encryption at rest; 2. require re-authentication of inactive sessions
Match the SMTP command with the respective description.
Used to denote the email address of the sender MAIL
Used to cancel an email transaction RSET
Used to initiate a conversation with an Extended Simple Mail Transport Protocol server EHELO
Used to initiate the transfer of the contents of an email message DATA
Used to start a Transport Layer Security connection to an email server STARTTLS
Used to initiate an SMTP conversation with an email server HELO
Which Kali Linux tool or script can gather information on devices configured for SNMP? snmp-check
Which is a characteristic of a DNS poisoning attack? The DNS resolver cache is manipulated.
What UDP port number is used by SNMP protocol? 161
What two features are present on DNS servers using BIND 9.5.0 and higher that help mitigate DNS cache poisoning attacks? (Choose two.) 1. randomization of ports; 2. provision of cryptographically secure DNS transaction identifiers
_______________________________________________________________________ _______________________________________________________________________
_______________________________________________________________________ _______________________________________________________________________
M6-8
A web application configures client cookies with the HTTPOnly flag. What is the effect of this flag? It forces the web browser to have the cookies processed only by the server.
A user is using an online shopping website to order laptop computers. Which mechanism is used by the shopping site to securely maintain user authentication during shopping? session ID
A threat actor launches an SQL injection attack against a web site by sending multiple specific statements to the web site and reconstructing the key information the threat actor seeks. What type of SQL injection attack is the threat actor using? blind
Which two attributes can be set in a web application cookie to indicate it is a persistent cookie? (Choose two.) Expires, Max-Age
An organization has developed a network security policy stating that newly purchased routers and switches must be configured with advanced security measures before deploying them to the production network. Which threat does this policy mitigate? Default credential attack
Why should application developers change the session ID names used by common web application development frameworks? These session ID names can be used to fingerprint the application framework employed.
A company uses the Microsoft Active Directory service to manage the authentication and authorization of employee workstations. The company hires a cybersecurity professional to perform compliance penetration testing. Which type of penetration testing.... LDAP injection
What is the best practice to mitigate the vulnerabilities from a lack of proper error handling in an application? Use a well-thought-out scheme to provide meaningful error messages to the users but no useful information to an attacker.
Which component in the statement below is most likely user input on a web form? SELECT * FROM group WHERE attack = ‘network’ AND a-type LIKE ‘ping%’; ping
A company has hired a cybersecurity firm to assess web server security posture. To test for cross-site scripting vulnerabilities, the tester will use the string. Where would the tester use the string? in a user input field in a web form
Which cloud technology attack method could generate crafted packets to cause a cloud application to crash? resource exhaustion attack
Which option is a security vulnerability that affects IoT implementations? plaintext communication and data leakage
A threat actor uploaded a VM with malicious software to the VMware Marketplace. When an organization deploys the VM, the threat actor can manipulate the systems, applications, and user data. What type of VM vulnerability has been enabled? VM repository vulnerability
Which tool is an open-source framework used to test the security of iOS applications? Needle
Which credential harvesting tool could be used to send a spear phishing email with a link to a malicious site to a target victim? Social-Engineer Toolkit (SET)
Which tool helps software developers and cloud consumers deploy applications in the cloud and use the resources that the cloud provider offers? Cloud development kits (CDKs)
Which term is an essential characteristic of cloud computing as defined in NIST SP 800-145? resource pooling
Which two IoT systems should never be exposed to the Internet? (Choose two.) robots in a factory, turbines in a power plant
Which option is a collection of compute interface specifications designed to offer management and monitoring capabilities independently of the CPU, firmware, and operating system of the host? Intelligent Platform Management Interface (IPMI)
Which cloud technology attack method could a threat actor use to access a user or application account that allows access to more accounts and information? account takeover
Which three tools are living-off-the-land post-exploitation techniques? (Choose three.) Empire, PowerSploit, WinRM
An attacker wants to allow further connections to a compromised system and maintain persistent access. The attacker uses the Windows system command Enable-PSRemoting -SkipNetworkProfileCheck – Force. What tool is being enabled using this command? WinRM
What kind of malicious activity is performed by a lower-privileged user who accesses functions reserved for higher-privileged users? vertical privilege escalation
Which two C2 utilities are Python-based? (Choose two.) TrevorC2, Wsc2
What task can be accomplished with the steghide tool? to obfuscate, to evade and to cover the attacker tracks
Which C2 utility is a PowerShell-based tool that leverages WMI to create a C2 channel? WMImplant
After the exploitation phase, it is necessary to maintain a foothold in a compromised system to perform additional tasks. Which way could maintain persistence? creating a bind or reverse shell
A cybersecurity student is learning about Netcat commands that could be used in a penetration testing engagement. Which Netcat command is used to connect to a TCP port? nc -nv
Which Meterpreter command is used to execute Meterpreter commands that are listed inside a text file and also to help accelerate the actions taken on the victim system? resource
What procedure should be deployed to protect the network against lateral movement? VLANs
_______________________________________________________________________ 6.13.3
Which two functions are provided by a web proxy device? (Choose two.) caching of HTTP messages; enabling HTTP transfers across a firewall
Match the HTTP status code contained in a web server response to the description.
codes in the 200 range: related to successful transactions
codes in the 300 range: related to HTTP redirections
codes in the 400 range: related to client errors
codes in the 500 range: related to server errors
codes in the 100 range: informational
---------------------------------------------------------------------------------
Match the elements in the URL ftp://xyz-company.com:2457/support/file;id=65?name=intro&r=true to the description.
xyz-company.com host
2457 port
support/file path
ftp scheme
name=intro&r=true query-string
id=65 path-segment-params
---------------------------------------------------------------------------------
Which function is provided by HTTP 2.0 to improve performance over HTTP 1.1? HTTP 2.0 provides HTTP message multiplexing and requires fewer messages to download web content.
What is the best mitigation approach against session fixation attacks? Ensure that the session ID is exchanged only though an encrypted channel.
Which international organization is dedicated to educating industry professionals, creating tools, and evangelizing best practices for securing web applications and underlying systems? Open Web Application Security Project (OWASP)
Which statement describes an example of an out-of-band SQL injection attack? An attacker launches the attack on a web site and forces the web application to send the query results via an email.
An attacker launches an SQL injection attack on a web application by trying to force the application requesting the back-end database to perform multiple SELECT queries. Which technique exploits the SQL injection vulnerability on the web application? Union operator
Which type of SQL query is in the SQL statement select * from users where user = “admin”;? static query
What is a potentially dangerous web session management practice? including the session ID in the URL
A web application configures client cookies with the HTTPOnly flag. What is the effect of this flag? It forces the web browser to have the cookies processed only by the server.
An attacker sends a request to an online university portal site with the information: SELECT * FROM group WHERE attack = ‘network’ AND a-type LIKE ‘ping%’; HTTP parameter pollution
According to OWASP, which three statements are rules to prevent XSS attacks? (Choose three.) Use HTML escape before inserting untrusted data into HTML element content | Use attribute escape before inserting untrusted data into HTML common attributes | Use JavaScript escape before inserting untrusted data into JavaScript data values
After some reconnaissance efforts, an attacker identified a web server hosted on a Linux system. The attacker then entered the URL shown below, directory traversal
An attacker enters the following URL to exploit vulnerabilities in a web application: remote file inclusion
Because of an insecure code practice, an attacker can leverage and completely compromise an application or the underlying system. What insecure code practice enabled this catastrophic threat? use of hard-coded credentials
_______________________________________________________________________ 7.3.3
Which cloud technology attack method involves breaching the infrastructure to gather and steal information such as valid usernames, passwords, tokens, and PINs? credential harvesting
Which cloud technology attack method could exploit a bug in a software application to gain access to resources that normally would not be accessible to a user? privilege escalation
Which term describes when a lower-privileged user accesses functions reserved for higher-privileged users? vertical privilege escalation
Which tool could be used to find vulnerabilities that could lead to metadata service attacks? Nimbostratus
Which cloud technology attack method would require the threat actor to create a malicious application and install it into a SaaS, PaaS, or IaaS environment? cloud malware injection attack
What is a common cause of data breaches in attacks against misconfigured cloud assets? using insecure permission configurations for cloud object storage services
A threat actor has compromised a VM in a cloud environment that shares the same physical hardware as non-compromised VMs. Which cloud technology attack method could now be used to exfiltrate credentials, cryptogr.... side-channel attack
Which mobile device vulnerability is targeted when a threat actor reverse engineers a mobile app to see how it creates and stores keys in the iOS Keychain? insecure storage
---------------------------------------------------------------------------------
Match the Bluetooth Low Energy (BLE) phase to the description.
Phase 1: Transport-specific key distribution
Phase 2: Short-term key generation
Phase 3: Pairing feature exchange
---------------------------------------------------------------------------------
Which tool is a set of open-source analysis tools that uses the ClamAV antivirus engine to help detect vulnerabilities, Trojans, backdoors, and malware in Docker images and containers? Dagda
Why do cloud architectures help minimize the impact of DoS or DDoS attacks compared to hosting services on-premise? cloud providers use a distributed architecture
Which option is a characteristic of a VM hypervisor? Type 1 hypervisors are also known as native or bare-metal hypervisors.
A threat actor has compromised a VM in a data center and discovered a vulnerability that provides access to data in another VM. What type of VM vulnerability has been discovered? VM escape vulnerability
Which tool can be used to perform on-path attacks in BLE implementations? GATTacker
Which tool is an open-source container vulnerability scanner that can be used to find vulnerabilities in a Docker image? Anchore’s Grype
_______________________________________________________________________ 8.3.3
Which resource is a Windows utility that combines the old CMD functionality with a new scripting/cmdlet instruction set with built-in system administration functionality? PowerShell
An attacker opens a port or a listener on the compromised system and waits for a connection. The goal is to connect to the victim from any system, execute commands, and further manipulate the victim. What type of malicious activity is being performed? bind shell
Which resource is a lightweight and portable tool that allows the creation of bind and reverse shells from a compromised host? Netcat
Which two resources are C2 utilities? (Choose two.) Socat | Twittor
Which living-off-the-land post-exploitation technique can get directory listings, copy and move files, get a list of running processes, and perform administrative tasks? PowerShell
Which resource is an open-source framework that allows rapid deployment of post-exploitation modules, including keyloggers, bind and reverse shells, and adaptable communication to evade detection? Empire
Which resource is a single-page JavaScript web application that can be used to find complex attack paths in Microsoft Azure? BloodHound
Which utility can be used to write scripts or applications to automate administrative tasks on remote computers and can also be used by malware to perform different activities in a compromised system? WMI
Which Sysinternals tool is used by penetration testers to modify Windows registry values and connect a compromised system to another system? PsExec
After compromising a system during a penetration testing engagement, all penetration work should be cleaned up, including extra files, system changes, and modified logs. The media sanitation methodology should be discusse... NIST SP 800-88
What is the main advantage of Remote Desktop over Sysinternals? It gives a full, interactive GUI of the remote compromised computer.
An attacking system has a listener (port open), and the victim initiates a connection back to the attacking system. What type of vulnerability does this situation describe? reverse shell
A cybersecurity student is learning about Netcat commands that could be used in a penetration testing engagement. The student wants to use Netcat as a port scanner. What command should be used? nc -z
Which two commands are the same in Meterpreter and Linux or Unix-based systems? (Choose two.) pwd | cat
_______________________________________________________________________ _______________________________________________________________________
_______________________________________________________________________ _______________________________________________________________________
M9-10
Which industry-standard method has created a catalog of known vulnerabilities that provides a score indicating the severity of a vulnerability? CVSS
Which vulnerability catalog creates a list of publicly known vulnerabilities, each assigned an ID number, description, and reference? CVE
Match the CVSS metric group with the respective information. _______________________________________________________________________
Environmental metric group includes modified base metrics, confidentiality, integrity, and availability requirements
Base metric group includes exploitability metrics and impact metrics
Temporal metric group includes exploit code maturity, remediation level, and report confidence
_______________________________________________________________________ _______________________________________________________________________
Which three items are included in the base metric group used by CVSS? (Choose three.) attack complexity; integrity impact; user interaction
Which item is included in the environmental metric group used by CVSS? confidentiality requirements
Which item is included in the temporal metric group used by CVSS? exploit code maturity
Which tool can ingest the results from many penetration testing tools a cybersecurity analyst uses and help this professional produce reports in formats such as CSV, HTML, and PDF? Dradis
Match the description to the respective control category. _______________________________________________________________________
Key rotation Technical control
Input sanitization Technical control
Secure software development life cycle Administrative control
Role-based access control Administrative control
Time-of-day restrictions Operational control
Job rotation Operational control
Video surveillance Physical control
Biometric controls Physical control
_______________________________________________________________________ _______________________________________________________________________
Which two items are examples of technical controls that can be recommended as mitigations and remediation of the vulnerabilities found during a pen test? (Choose two.) multifactor authentication; certificate management
A recent pen-test results in a cybersecurity analyst report, including information on process-level remediation, patch management, and secrets management solutions. Which control category is represented by this example? technical
Which document provides several cheat sheets and detailed guidance on preventing vulnerabilities such as cross-site scripting, SQL injection, and command injection? OWASP
A cybersecurity analyst report should contain minimum password requirements and policies and procedures. These are examples that are included in which control category? administrative
Which control category includes information on mandatory vacations and user training in the cybersecurity analyst report? operational
When creating a cybersecurity analyst report, which control category includes information concerning the access control vestibule? physical
Match the term to the respective description. _______________________________________________________________________
false negative malicious activities that are not detected by a network security device
true negative an intrusion detection device identifies an activity as acceptable behavior and the activity is acceptable
false positive a security device triggers an alarm, but there is no malicious activity or actual attack taking place
true positive a successful identification of a security attack or a malicious event
_______________________________________________________________________ _______________________________________________________________________
Which kind of event is also called a “benign trigger”? false positive
What kind of events diminishes the value and urgency of real alerts? false positives
Which kinds of events are malicious activities not detected by a network security device? false negatives
Which kind of event occurs when an intrusion detection device identifies an activity as acceptable behavior and the activity is acceptable? true negatives
Which kind of event is a successful identification of a security attack? true positive
Which example of technical control is recommended to mitigate and prevent vulnerabilities such as cross-site scripting, cross-site request forgery, SQL injection, and command injection? user input sanitization
Which example of administrative controls enables administrators to control what users can do at both broad and granular levels? RBAC
A document entitled “Building an Information Technology Security Awareness and Training Program” succinctly defines why security education and training are so important for users. The document defines ways to improve the security operations of an organiz. NIST SP 800-50
How is the score that CVSS provides interpreted? scores are rated from 0 to 10, with 10 being the most severe
What control category does system hardening belong to? technical
Which two items are programming logic constructs? (Choose two.) Boolean operators; Conditionals
Which two items are data structures used in programming languages? (Choose two.) Arrays; Lists
Which two items can be included in a library? (Choose two.) Message templates; Subroutines
What is the definition of a procedure used in an application software? It is a section of code that is created to perform a specific task.
Which programming language data structure is a special variable with more than one value at a time? Array
Which term describes a programming language component such as JavaScript Object Notation (JSON)? Data structures
What kind of data structure in Python is represented in the example below?cves = [‘CVE-2022-0945’, ‘CVE-2023-1234’, ‘CVE-2022-0987’] List
Which programming language elements perform similar tasks? Procedures and functions
What is the definition of a library in application software? It is a collection of resources that can be reused by programs.
Which domain name database query utility has been restricted by the European Union´s General Data Protection Regulation (GDPR) to protect privacy? Whois
What are two tools that can be used to perform active reconnaissance? (Choose two.) Zenmap; Enum4linux
What are two tools that can be used to perform credential attacks? (Choose two.) Mimikatz; Patator
Which Linux distribution comes with more than 1900 security penetration testing tools? BlackArch Linux
Which tool is designed to find metadata and hidden information in documents? FOCA
Which programming language element is a block of code that can be reused multiple times to execute a specific task? Function
Which tool organizes query entities within the Entity Palette and calls the search options “transforms”? Maltego
Which programming language element is a code template that includes initial variables and functions for creating an object? Class
Which passive reconnaissance tool can be used to find information about devices and networks on the Internet? Censys
What is a command-line tool that allows for interactive or non-interactive command execution? Bash
Which popular Linux penetration testing distribution is based on Debian GNU/Linux and has evolved from WHoppiX, WHAX, and BackTrack? Kali Linux
Which vulnerability scanner tool offers a cloud-based service that performs continuous monitoring, vulnerability management, and compliance checking? Qualys
Which option is a PowerShell-based post-exploitation tool that can maintain persistence on a compromised system and run PowerShell agents without the need for powershell.exe? Empire
Which tool can be used with Metasploit to maintain stealth and avoid detection from security controls implemented by an organization? Veil
Which encoding method can secretly exfiltrate confidential data in the payload of DNS packets? Base64
Which option is a Linux distribution tool for forensic evidence collection? CAINE
_______________________________________________________________________ _______________________________________________________________________
_______________________________________________________________________ _______________________________________________________________________
Created by: Jsean-Ed_DR
 

 



Voices

Use these flashcards to help memorize information. Look at the large card and try to recall what is on the other side. Then click the card to flip it. If you knew the answer, click the green Know box. Otherwise, click the red Don't know box.

When you've placed seven or more cards in the Don't know box, click "retry" to try those cards again.

If you've accidentally put the card in the wrong box, just click on the card to take it out of the box.

You can also use your keyboard to move the cards as follows:

If you are logged in to your account, this website will remember which cards you know and don't know so that they are in the same box the next time you log in.

When you need a break, try one of the other activities listed below the flashcards like Matching, Snowman, or Hungry Bug. Although it may feel like you're playing a game, your brain is still making more connections with the information to help you out.

To see how well you know the information, try the Quiz or Test activity.

Pass complete!
"Know" box contains:
Time elapsed:
Retries:
restart all cards