click below
click below
Normal Size Small Size show me how
FE - Ethical Hacc
Ethical Hacking Essentials/IT0202
| Question | Answer |
|---|---|
| M1-2 | |
| Which statement best describes the term ethical hacker? | ethical hacker? a person who mimics an attacker to evaluate the security posture of a network |
| Which type of threat actor uses cybercrime to steal sensitive data and reveal it publicly to embarrass a target? | hacktivist |
| Which three options are phases in the Penetration Testing Execution Standard (PTES)? (Choose three.) | Threat modeling, Exploitation, Reporting |
| Which type of penetration test would only provide the tester with limited information such as the domain names and IP addresses in the scope? | unknown-environment test |
| Which tools should be used for testing the server and client platforms in an environment? | vulnerability scanning tools |
| What characterizes a known environment penetration test? | The tester could be provided with network diagrams, IP addresses, configurations, and user credentials. |
| Which threat actor term describes a well-funded and motivated group that will use the latest attack techniques for financial gain? | organized crime |
| What kind of security weakness is evaluated by application-based penetration tests? | logic flaws |
| What two resources are evaluated by a network infrastructure penetration test? (Choose two.) | IPSs, AAA servers |
| Which option is a Linux distribution URL that provides a convenient learning environment about pen testing tools and methodologies? | parrotsec.org |
| What are two examples of sensitive authentication data associated with a payment card that requires compliance with the Payment Card Industry Data Security Standard (PCI DSS)? (Choose two.) | CAV2/CVC2/CVV2/CID, full magnetic strip data or equivalent data on a chip |
| Which U.S. government agency is responsible for enforcing the Privacy of Consumer Financial Information Rule of the Gramm-Leach-Bliley Act (GLB Act)? | Federal Trade Commission (FTC) |
| A company hires a cybersecurity consultant to perform penetration tests and review the rules of engagement documents. What are three examples of typical elements in the rules of engagement document? | testing timeline, preferred method of communication, location of testing |
| A company hires a cybersecurity consultant to perform penetration tests. The consultant is working with the company to set up communication procedures. Which two protocols should be considered for exchanging emails securely? | PGP, S/MIME |
| An US university in California plans to offer online courses to students in partner universities in France and Germany. Which regulation should the university follow when those courses are offered? | GDPR |
| A company hires a cybersecurity professional to perform penetration tests to assess government regulation compliance. Which legal document should be provided to the cybersecurity professional that specifies the expectations and constraint.. | service-level agreement (SLA) |
| A contractor is hired to review and perform cybersecurity vulnerability assessments for a local health clinic facility. Which U.S. government regulation must the contractor understand before the contractor can start? | HIPAA |
| In the healthcare sector, which term is used to define an entity that provides payment for medical services? | health plan |
| An Internal Revenue Service office in New York is considering moving some services to a cloud computing platform. Which U.S. government regulation must the office follow in the process? | FedRAMP |
| In e-commerce, what determines the application of the Payment Card Industry Data Security Standard (PCI DSS) requirements? | primary account number |
| What is a state-sponsored attack? | An attack perpetrated by governments worldwide to disrupt or steal information from other nations. |
| What is an insider threat attack? | An attack perpetrated by disgruntled employees inside an organization. |
| When conducting an application-based penetration test on a web application, the assessment should also include testing access to which resources? | back-end databases |
| What is the purpose of bug bounty programs used by companies? | reward security professionals for finding vulnerabilities in the systems of the company |
| What characterizes a partially known environment penetration test? | The test is a hybrid approach between unknown and known environment tests. |
| Collection of different matrices of tactics and techniques that adversaries use while preparing for an attack | MITRE ATT&CK |
| Covers the high-level phases of web application security testing | OWASP WSTG |
| Provides organizations with guidelines on planning and conducting information security testing | NIST SP 800-115 |
| Lays out repeatable and consistent security testing | OSSTMM |
| Provides information about types of attacks and methods | PTES |
| Which two options are phases in the Information Systems Security Assessment Framework (ISSAF)? | Maintaining access; Vulnerability identification |
| Which two options are phases in the Open Source Security Testing Methodology Manual (OSSTMM)? | Work Flow; Trust Analysis |
| Which penetration testing methodology is a comprehensive guide focused on web application testing? | OWASP WSTG |
| Which option is a Linux distribution that includes penetration testing tools and resources? | BlackArch |
| What does the “Health Monitoring” requirement mean when setting up a penetration test lab environment? | The tester needs to be able to determine the causes when something crashes. |
| Which tool would be useful when performing a network infrastructure penetration test? | bypassing firewalls and IPSs tool |
| Which tool should be used to perform an application-based penetration test? | interception proxies tool |
| Which tools should be used to perform a wireless infrastructure penetration test? | de-authorizing network devices tools |
| Sometimes a tester cannot virtualize a system to do the proper penetration testing. What action should be taken if a system cannot be tested in a virtualized environment? | a full backup of the system |
| In the healthcare sector, which term defines an entity that processes nonstandard health information it receives from another entity into a standard format? | healthcare clearinghouse |
| Provides general guidance and best practices for the management of cryptographic keying material | Part 1: General |
| Provides guidance on policy and security planning requirements for U.S. government agencies | Part 2: Best Practices for Key Management Organization |
| Provides guidance when using the cryptographic features of current systems | Part 3: Application Specific Key Management Guidance |
| An employee of a cybersecurity consulting firm in the U.S. is assigned to help assess the system and operation vulnerabilities of several financial institutions in Europe. The task includes penetration tests for compliance. What is a key element the emp.. | documentation of permission for performing the tests from the client institutions |
| A company hires a cybersecurity professional to perform penetration testing to assess government regulation compliance. Which document will be provided to the cybersecurity professional that specifies a detailed and descriptive list of all the deliv... | statement of work (SOW) |
| A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. The company wants the consultant to disclose information to them and no one else. Which type of NDA agreement should be presented to the. | unilateral NDA |
| A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. Which document must the consultant receive that specifies the agreement between the consultant and the company for the penetration testi. | contract |
| A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. The consultant is preparing the final report after the penetration testing is completed. In which section of the report should the cons.. | disclaimers |
| A company hires a cybersecurity consultant to perform penetration tests and review the rules of engagement documents. The consultant notices that one element specifies that the tests should be performd toward only web applications on websites www1.compa.. | types of allowed or disallowed tests |
| A company hires a cybersecurity consultant to assess applications using different APIs. Which document should the company provide to the consultant about an XML-based language used to document a web service’s functionality? | Web Services Description Language (WSDL) document |
| A company hires a cybersecurity consultant to assess applications using different APIs. Which document should the company provide to the consultant about a query language for APIs and a language for executing queries at runtime? | GraphQL documentation |
| A company hires a cybersecurity consultant to assess vulnerability on crucial web application devices such as web and database servers. Which document should the company provide to help the consultant document and define what systems are in the testing? | system and network architectural diagram |
| A company hires a cybersecurity consultant to perform penetration tests. What can cause scope creep of the engagement? | ineffective identification of what technical and nontechnical elements will be required for the penetration test |
| A company hires a cybersecurity consultant to perform penetration tests. What should be the consultant’s first step in validating the engagement scope? | Question the company contact person and review contracts. |
| A company hires a cybersecurity consultant to perform penetration tests. The consultant is discussing with the company about the penetration testing strategy. Which statement describes the term unknown-environment testing? | This type of testing is where the consultant will be provided with very limited information about the targeted systems and network. |
| A company hires a cybersecurity consultant to perform penetration tests. What is the key difference between unknown-environment testing and known-environment testing? | the amount of information provided to the consultant |
| _______________________________________________________________________ | _______________________________________________________________________ |
| _______________________________________________________________________ | _______________________________________________________________________ |
| M3-5 | |
| Which two tools could be used to gather DNS information passively? (Choose two.) | Recon-ng; Dig |
| When performing passive reconnaissance, which Linux command can be used to identify the technical and administrative contacts of a given domain? | whois |
| What guidance does the NIST Cybersecurity Framework provide to help improve an organization’s cybersecurity posture? | The framework outlines standards and industry best practices. |
| What is the advantage of using the target Wi-Fi network for reconnaissance packet inspection? | Physical access to the building may not be required. |
| A company hires a cybersecurity consultant to conduct a penetration test to assess vulnerabilities in network systems. The consultant is preparing the final report to send to the company. What is an important feature of a final penetration test report? | It gives an accurate presentation of vulnerabilities. |
| When performing a vulnerability scan of a target, how can adverse impacts on traversed devices be minimized? | The scan should be performed as close to the target as possible. |
| What are three considerations when planning a vulnerability scan on a target production network during a penetration test? (Choose three.) | the timing of the scan; the available network bandwidth; the network topology |
| A penetration tester must run a vulnerability scan against a target. What is the benefit of running an authenticated scan instead of an unauthenticated scan? | Authenticated scans can provide a more detailed picture of the target attack surface. |
| What useful information can be obtained by running a network share enumeration scan during a penetration test? | systems on a network that are sharing files, folders, and printers |
| What initial information can be obtained when performing user enumeration in a penetration test? | a valid list of users |
| How is open-source intelligence (OSINT) gathering typically implemented during a penetration test? | by using public internet searches |
| A threat actor is looking at the IT and technical job postings of a target organization. What would be the most beneficial information to capture from these postings? | the type of hardware and software used |
| What is the purpose of applying the Common Vulnerability Scoring System (CVSS) to a vulnerability detected by a penetration test? | to calculate the severity of the vulnerability |
| Why is the Common Vulnerabilities and Exposures (CVE) resource useful when investigating vulnerabilities detected by a penetration test? | It is an international consolidation of cybersecurity tools and databases. |
| When a penetration test identifies a vulnerability, how should the vulnerability be further verified? | determine if the vulnerability is exploitable |
| What is the disadvantage of running a TCP Connect scan compared to running a TCP SYN scan during a penetration test? | The extra packets required may trigger an IDS alarm. |
| What can be deduced when a tester enters the nmap -sF command to perform a TCP FIN scan and the target host port does not respond? | that the port is open |
| What is the purpose of host enumeration when beginning a penetration test? | to identify all active IP addresses within the scope of the test |
| Why would a penetration tester use the nmap -sF command? | when a TCP SYN scan is detected by a network filter or firewall |
| In which circumstance would a penetration tester perform an unauthenticated scan of a target? | when user credentials were not provided |
| What is required for a penetration tester to conduct a comprehensive authenticated scan against a Linux host? | user credentials with root-level access to the target system |
| What is the disadvantage of conducting an unauthenticated scan of a target when performing a penetration test? | Vulnerability of services running inside the target may not be detected. |
| What type of server is a penetration tester enumerating when they enter the nmap -sU command? | DNS, SNMP, or DHCP server |
| Why would a penetration tester perform a passive reconnaissance scan instead of an active one? | to collect information about a network without being detected |
| Which specification defines the format used by image and sound files to capture metadata? | Exchangeable Image File Format (Exif) |
| _______________________________________________________________________ | _______________________________________________________________________ |
| M4: | |
| What type of threat allows an attacker to obtain the credentials of a bank client by spoofing the login webpage of a financial institution? | malvertising |
| What is a watering hole attack? | an attack that exploits a website that is commonly accessed by members of a targeted organization |
| A user has found a USB pen drive in the corporate parking lot. What should the user do with this pen drive? | deliver the pen drive to the security sector of the company |
| A new employee is celebrating their position with a large company by posting a picture of their access identification on social media. What kind of physical attack has the new employee unknowingly enabled? | badge cloning |
| Which tool can send fake notifications to the browser of a victim? | BeEF |
| Which tool permits post-exploitation activities, such as Windows reverse VNC DLL and reverse TCP shell? | SET |
| A threat actor has sent a text message to a victim stating that they have won bitcoins in a bank contest. To claim their prize, the victim must click the provided link and enter their bank account information. What social enginee... | SMS phishing |
| Which Apple iOS and Android tools can spoof a phone number, record calls, and generate different background noises? | SpoofCard |
| What is the purpose of a vishing attack? | to convince a victim on a phone call to disclose private or financial information |
| Who is the target of a whaling attack? | upper managers such as the CEO or key individuals in an organization |
| Which tool can launch social engineering attacks and be integrated with third-party tools and frameworks such as Metasploit? | SET |
| Which resource would mitigate piggybacking and tailgating? | security guard |
| Which two access control options are commonly used in conjunction with access control vestibules? (Choose two.) | proximity card and PIN; biometric scan |
| What two physical attacks are mitigated by using access control vestibules? (Choose two.) | tailgating; piggybacking |
| Which Apple iOS and Android tool can be used to spoof a phone number? | SpoofApp |
| Which tool provides a threat actor a web console to manipulate users who are victims of cross-site scripting (XSS) attacks? | BeEF |
| Which social engineering physical attack statement is correct? | Shoulder surfing can be prevented by using special screen filters for computer displays. |
| A threat actor has sent a phishing email to a victim stating that suspicious activity has been detected on their bank account and that they must immediately click on a provided link to change their password. What method of influenc... | urgency |
| Apple is a company constantly working towards making its products and processes more environmentally friendly. Therefore, the Apple brand is associated with ideals and values that customers can relate to and support. What metho... | likeness |
| What method of influence is characterized when a celebrity endorses a product on social media? | social proof |
| A salesperson is attempting to convince a customer to buy a product because limited supplies are available. Which social engineering method of influence is being used by the salesperson? | scarcity |
| Which option is a voice over IP management tool that can be used to impersonate caller ID? | Asterisk |
| Why would a threat actor use the Social-Engineering Toolkit (SET)? | to send a spear phishing email |
| A threat actor has altered the host file for a commonly accessed website on the computer of a victim. Now when the user clicks on the website link, they are redirected to a malicious website. What type of attack has the threat actor accomplished? | pharming |
| What is the act of gaining knowledge or information from a victim without directly asking for that particular information? | elicitation |
| _______________________________________________________________________ | |
| M5: | |
| Which NetBIOS service is used for connection-oriented communication? | NetBIOS-SSN |
| NetBIOS Datagram Service | UDP port 138 |
| NetBIOS Name Service | UDP port 137 |
| SMB protocol | TCP port 445 |
| NetBIOS Session Service | TCP port 139 |
| Microsoft Remote Procedure Call (MS-RPC) | TCP port 135 |
| An attacker is launching a reflected DDoS attack in which the response traffic is made up of packets that are much larger than those that the attacker initially sent. Which type of attack is this? | amplification |
| What is a common mitigation practice for ARP cache poisoning attacks on switches to prevent spoofing of Layer 2 addresses? | DAI |
| Which kind of attack is an IP spoofing attack? | On-path |
| Which four items are needed by an attacker to create a silver ticket for a Kerberos silver ticket attack? (Choose four.) | 1. system account; 2. SID; 3. FQDN; 4. target service |
| Which attack is a post-exploitation activity that an attacker uses to extract service account credential hashes from Active Directory for offline cracking? | Kerberoasting |
| What is a characteristic of a Kerberos silver ticket attack? | It uses forged service tickets for a given service on a particular server. |
| Which is the default TCP port used in SMTP for non-encrypted communications? | 25 |
| The port registered by the Internet Assigned Numbers Authority (IANA) for SMTP over SSL (SMTPS). | 465 |
| The Secure SMTP (SSMTP) protocol for encrypted communications, as defined in RFC 2487, using STARTTLS. | 587 |
| The default port used by the IMAP protocol in non-encrypted communications. | 143 |
| The default port used by the POP3 protocol in encrypted communications. | 995 |
| The default port used by the IMAP protocol in encrypted (SSL/TLS) communications. | 993 |
| What is a DNS resolver cache on a Windows system? | It is a temporary database that contains records of all the recent visits and attempted visits to websites and other internet domains. |
| What does the MFP feature in the 802.11w standard do to protect against wireless attacks? | It helps defend against deauthentication attacks. |
| Which Wi-Fi protocol is most vulnerable to a brute-force attack during a Wi-Fi network deployment? | WPS |
| Which is a characteristic of a Bluesnarfing attack? | An attack that can be performed using Bluetooth with vulnerable devices in range. This attack actually steals information from the device of the victim. |
| Which tool can be used to perform a Disassociation attack? | Airmon-ng |
| Match the attack type with the respective description. | |
| Typically a BGP hijacking attack by configuring or compromising an edge router to announce prefixes that have not been assigned to the organization | Route Manipulation attacks |
| The attacker forces a system to favor a weak encryption protocol or hashing algorithm that may be susceptible to other vulnerabilities | Downgrade attacks |
| An attacker floods a server with bogus DISCOVER packets until the server exhausts the supply of IP addresses | DHCP Starvation attack |
| An attacker bypass any layer 2 restrictions built to divide hosts | VLAN Hopping attack |
| An attacker spoofs the physical address of the NIC device to match the address of another on a network in order to gain unauthorized access or launch a Man-in-the-Middle attack | MAC address spoofing attack |
| Match the attack type with the respective description. | |
| This attack uses spoofed packets that appear to be from the victim. Then the sources become unwitting participants in the attack by sending the response traffic back to the intended victim. | Reflected DOS |
| This an attack in which the attacker exploits vulnerabilities in target servers to initially turn small queries into much larger payloads, which are used to bring down the servers of the victim. | DNS Amplification |
| This occurs when the source of the attack generates the packets, regardless of protocol, application, and so on, that are sent directly to the victim of the attack. | Direct DOS |
| This attack uses botnets that can be manipulated from a command and control (CnC, or C2) system. | DDOS |
| What is a Kerberoasting attack? | It is a post-exploitation attempt that is used to extract service account credential hashes from Active Directory for offline cracking. |
| Which is a characteristic of the pass-the-hash attack? | capture of a password hash (as opposed to the password characters) and using the same hashed value for authentication and lateral access to other networked systems |
| Which two best practices would help mitigate FTP server abuse and attacks? (Choose two.) | 1. use encryption at rest; 2. require re-authentication of inactive sessions |
| Match the SMTP command with the respective description. | |
| Used to denote the email address of the sender | |
| Used to cancel an email transaction | RSET |
| Used to initiate a conversation with an Extended Simple Mail Transport Protocol server | EHELO |
| Used to initiate the transfer of the contents of an email message | DATA |
| Used to start a Transport Layer Security connection to an email server | STARTTLS |
| Used to initiate an SMTP conversation with an email server | HELO |
| Which Kali Linux tool or script can gather information on devices configured for SNMP? | snmp-check |
| Which is a characteristic of a DNS poisoning attack? | The DNS resolver cache is manipulated. |
| What UDP port number is used by SNMP protocol? | 161 |
| What two features are present on DNS servers using BIND 9.5.0 and higher that help mitigate DNS cache poisoning attacks? (Choose two.) | 1. randomization of ports; 2. provision of cryptographically secure DNS transaction identifiers |
| _______________________________________________________________________ | _______________________________________________________________________ |
| _______________________________________________________________________ | _______________________________________________________________________ |
| M6-8 | |
| A web application configures client cookies with the HTTPOnly flag. What is the effect of this flag? | It forces the web browser to have the cookies processed only by the server. |
| A user is using an online shopping website to order laptop computers. Which mechanism is used by the shopping site to securely maintain user authentication during shopping? | session ID |
| A threat actor launches an SQL injection attack against a web site by sending multiple specific statements to the web site and reconstructing the key information the threat actor seeks. What type of SQL injection attack is the threat actor using? | blind |
| Which two attributes can be set in a web application cookie to indicate it is a persistent cookie? (Choose two.) | Expires, Max-Age |
| An organization has developed a network security policy stating that newly purchased routers and switches must be configured with advanced security measures before deploying them to the production network. Which threat does this policy mitigate? | Default credential attack |
| Why should application developers change the session ID names used by common web application development frameworks? | These session ID names can be used to fingerprint the application framework employed. |
| A company uses the Microsoft Active Directory service to manage the authentication and authorization of employee workstations. The company hires a cybersecurity professional to perform compliance penetration testing. Which type of penetration testing.... | LDAP injection |
| What is the best practice to mitigate the vulnerabilities from a lack of proper error handling in an application? | Use a well-thought-out scheme to provide meaningful error messages to the users but no useful information to an attacker. |
| Which component in the statement below is most likely user input on a web form? SELECT * FROM group WHERE attack = ‘network’ AND a-type LIKE ‘ping%’; | ping |
| A company has hired a cybersecurity firm to assess web server security posture. To test for cross-site scripting vulnerabilities, the tester will use the string. Where would the tester use the string? | in a user input field in a web form |
| Which cloud technology attack method could generate crafted packets to cause a cloud application to crash? | resource exhaustion attack |
| Which option is a security vulnerability that affects IoT implementations? | plaintext communication and data leakage |
| A threat actor uploaded a VM with malicious software to the VMware Marketplace. When an organization deploys the VM, the threat actor can manipulate the systems, applications, and user data. What type of VM vulnerability has been enabled? | VM repository vulnerability |
| Which tool is an open-source framework used to test the security of iOS applications? | Needle |
| Which credential harvesting tool could be used to send a spear phishing email with a link to a malicious site to a target victim? | Social-Engineer Toolkit (SET) |
| Which tool helps software developers and cloud consumers deploy applications in the cloud and use the resources that the cloud provider offers? | Cloud development kits (CDKs) |
| Which term is an essential characteristic of cloud computing as defined in NIST SP 800-145? | resource pooling |
| Which two IoT systems should never be exposed to the Internet? (Choose two.) | robots in a factory, turbines in a power plant |
| Which option is a collection of compute interface specifications designed to offer management and monitoring capabilities independently of the CPU, firmware, and operating system of the host? | Intelligent Platform Management Interface (IPMI) |
| Which cloud technology attack method could a threat actor use to access a user or application account that allows access to more accounts and information? | account takeover |
| Which three tools are living-off-the-land post-exploitation techniques? (Choose three.) | Empire, PowerSploit, WinRM |
| An attacker wants to allow further connections to a compromised system and maintain persistent access. The attacker uses the Windows system command Enable-PSRemoting -SkipNetworkProfileCheck – Force. What tool is being enabled using this command? | WinRM |
| What kind of malicious activity is performed by a lower-privileged user who accesses functions reserved for higher-privileged users? | vertical privilege escalation |
| Which two C2 utilities are Python-based? (Choose two.) | TrevorC2, Wsc2 |
| What task can be accomplished with the steghide tool? | to obfuscate, to evade and to cover the attacker tracks |
| Which C2 utility is a PowerShell-based tool that leverages WMI to create a C2 channel? | WMImplant |
| After the exploitation phase, it is necessary to maintain a foothold in a compromised system to perform additional tasks. Which way could maintain persistence? | creating a bind or reverse shell |
| A cybersecurity student is learning about Netcat commands that could be used in a penetration testing engagement. Which Netcat command is used to connect to a TCP port? | nc -nv |
| Which Meterpreter command is used to execute Meterpreter commands that are listed inside a text file and also to help accelerate the actions taken on the victim system? | resource |
| What procedure should be deployed to protect the network against lateral movement? | VLANs |
| _______________________________________________________________________ | 6.13.3 |
| Which two functions are provided by a web proxy device? (Choose two.) | caching of HTTP messages; enabling HTTP transfers across a firewall |
| Match the HTTP status code contained in a web server response to the description. | |
| codes in the 200 range: | related to successful transactions |
| codes in the 300 range: | related to HTTP redirections |
| codes in the 400 range: | related to client errors |
| codes in the 500 range: | related to server errors |
| codes in the 100 range: | informational |
| --------------------------------------------------------------------------------- | |
| Match the elements in the URL ftp://xyz-company.com:2457/support/file;id=65?name=intro&r=true to the description. | |
| xyz-company.com | host |
| 2457 | port |
| support/file | path |
| ftp | scheme |
| name=intro&r=true | query-string |
| id=65 | path-segment-params |
| --------------------------------------------------------------------------------- | |
| Which function is provided by HTTP 2.0 to improve performance over HTTP 1.1? | HTTP 2.0 provides HTTP message multiplexing and requires fewer messages to download web content. |
| What is the best mitigation approach against session fixation attacks? | Ensure that the session ID is exchanged only though an encrypted channel. |
| Which international organization is dedicated to educating industry professionals, creating tools, and evangelizing best practices for securing web applications and underlying systems? | Open Web Application Security Project (OWASP) |
| Which statement describes an example of an out-of-band SQL injection attack? | An attacker launches the attack on a web site and forces the web application to send the query results via an email. |
| An attacker launches an SQL injection attack on a web application by trying to force the application requesting the back-end database to perform multiple SELECT queries. Which technique exploits the SQL injection vulnerability on the web application? | Union operator |
| Which type of SQL query is in the SQL statement select * from users where user = “admin”;? | static query |
| What is a potentially dangerous web session management practice? | including the session ID in the URL |
| A web application configures client cookies with the HTTPOnly flag. What is the effect of this flag? | It forces the web browser to have the cookies processed only by the server. |
| An attacker sends a request to an online university portal site with the information: SELECT * FROM group WHERE attack = ‘network’ AND a-type LIKE ‘ping%’; | HTTP parameter pollution |
| According to OWASP, which three statements are rules to prevent XSS attacks? (Choose three.) | Use HTML escape before inserting untrusted data into HTML element content | Use attribute escape before inserting untrusted data into HTML common attributes | Use JavaScript escape before inserting untrusted data into JavaScript data values |
| After some reconnaissance efforts, an attacker identified a web server hosted on a Linux system. The attacker then entered the URL shown below, | directory traversal |
| An attacker enters the following URL to exploit vulnerabilities in a web application: | remote file inclusion |
| Because of an insecure code practice, an attacker can leverage and completely compromise an application or the underlying system. What insecure code practice enabled this catastrophic threat? | use of hard-coded credentials |
| _______________________________________________________________________ | 7.3.3 |
| Which cloud technology attack method involves breaching the infrastructure to gather and steal information such as valid usernames, passwords, tokens, and PINs? | credential harvesting |
| Which cloud technology attack method could exploit a bug in a software application to gain access to resources that normally would not be accessible to a user? | privilege escalation |
| Which term describes when a lower-privileged user accesses functions reserved for higher-privileged users? | vertical privilege escalation |
| Which tool could be used to find vulnerabilities that could lead to metadata service attacks? | Nimbostratus |
| Which cloud technology attack method would require the threat actor to create a malicious application and install it into a SaaS, PaaS, or IaaS environment? | cloud malware injection attack |
| What is a common cause of data breaches in attacks against misconfigured cloud assets? | using insecure permission configurations for cloud object storage services |
| A threat actor has compromised a VM in a cloud environment that shares the same physical hardware as non-compromised VMs. Which cloud technology attack method could now be used to exfiltrate credentials, cryptogr.... | side-channel attack |
| Which mobile device vulnerability is targeted when a threat actor reverse engineers a mobile app to see how it creates and stores keys in the iOS Keychain? | insecure storage |
| --------------------------------------------------------------------------------- | |
| Match the Bluetooth Low Energy (BLE) phase to the description. | |
| Phase 1: | Transport-specific key distribution |
| Phase 2: | Short-term key generation |
| Phase 3: | Pairing feature exchange |
| --------------------------------------------------------------------------------- | |
| Which tool is a set of open-source analysis tools that uses the ClamAV antivirus engine to help detect vulnerabilities, Trojans, backdoors, and malware in Docker images and containers? | Dagda |
| Why do cloud architectures help minimize the impact of DoS or DDoS attacks compared to hosting services on-premise? | cloud providers use a distributed architecture |
| Which option is a characteristic of a VM hypervisor? | Type 1 hypervisors are also known as native or bare-metal hypervisors. |
| A threat actor has compromised a VM in a data center and discovered a vulnerability that provides access to data in another VM. What type of VM vulnerability has been discovered? | VM escape vulnerability |
| Which tool can be used to perform on-path attacks in BLE implementations? | GATTacker |
| Which tool is an open-source container vulnerability scanner that can be used to find vulnerabilities in a Docker image? | Anchore’s Grype |
| _______________________________________________________________________ | 8.3.3 |
| Which resource is a Windows utility that combines the old CMD functionality with a new scripting/cmdlet instruction set with built-in system administration functionality? | PowerShell |
| An attacker opens a port or a listener on the compromised system and waits for a connection. The goal is to connect to the victim from any system, execute commands, and further manipulate the victim. What type of malicious activity is being performed? | bind shell |
| Which resource is a lightweight and portable tool that allows the creation of bind and reverse shells from a compromised host? | Netcat |
| Which two resources are C2 utilities? (Choose two.) | Socat | Twittor |
| Which living-off-the-land post-exploitation technique can get directory listings, copy and move files, get a list of running processes, and perform administrative tasks? | PowerShell |
| Which resource is an open-source framework that allows rapid deployment of post-exploitation modules, including keyloggers, bind and reverse shells, and adaptable communication to evade detection? | Empire |
| Which resource is a single-page JavaScript web application that can be used to find complex attack paths in Microsoft Azure? | BloodHound |
| Which utility can be used to write scripts or applications to automate administrative tasks on remote computers and can also be used by malware to perform different activities in a compromised system? | WMI |
| Which Sysinternals tool is used by penetration testers to modify Windows registry values and connect a compromised system to another system? | PsExec |
| After compromising a system during a penetration testing engagement, all penetration work should be cleaned up, including extra files, system changes, and modified logs. The media sanitation methodology should be discusse... | NIST SP 800-88 |
| What is the main advantage of Remote Desktop over Sysinternals? | It gives a full, interactive GUI of the remote compromised computer. |
| An attacking system has a listener (port open), and the victim initiates a connection back to the attacking system. What type of vulnerability does this situation describe? | reverse shell |
| A cybersecurity student is learning about Netcat commands that could be used in a penetration testing engagement. The student wants to use Netcat as a port scanner. What command should be used? | nc -z |
| Which two commands are the same in Meterpreter and Linux or Unix-based systems? (Choose two.) | pwd | cat |
| _______________________________________________________________________ | _______________________________________________________________________ |
| _______________________________________________________________________ | _______________________________________________________________________ |
| M9-10 | |
| Which industry-standard method has created a catalog of known vulnerabilities that provides a score indicating the severity of a vulnerability? | CVSS |
| Which vulnerability catalog creates a list of publicly known vulnerabilities, each assigned an ID number, description, and reference? | CVE |
| Match the CVSS metric group with the respective information. | _______________________________________________________________________ |
| Environmental metric group | includes modified base metrics, confidentiality, integrity, and availability requirements |
| Base metric group | includes exploitability metrics and impact metrics |
| Temporal metric group | includes exploit code maturity, remediation level, and report confidence |
| _______________________________________________________________________ | _______________________________________________________________________ |
| Which three items are included in the base metric group used by CVSS? (Choose three.) | attack complexity; integrity impact; user interaction |
| Which item is included in the environmental metric group used by CVSS? | confidentiality requirements |
| Which item is included in the temporal metric group used by CVSS? | exploit code maturity |
| Which tool can ingest the results from many penetration testing tools a cybersecurity analyst uses and help this professional produce reports in formats such as CSV, HTML, and PDF? | Dradis |
| Match the description to the respective control category. | _______________________________________________________________________ |
| Key rotation | Technical control |
| Input sanitization | Technical control |
| Secure software development life cycle | Administrative control |
| Role-based access control | Administrative control |
| Time-of-day restrictions | Operational control |
| Job rotation | Operational control |
| Video surveillance | Physical control |
| Biometric controls | Physical control |
| _______________________________________________________________________ | _______________________________________________________________________ |
| Which two items are examples of technical controls that can be recommended as mitigations and remediation of the vulnerabilities found during a pen test? (Choose two.) | multifactor authentication; certificate management |
| A recent pen-test results in a cybersecurity analyst report, including information on process-level remediation, patch management, and secrets management solutions. Which control category is represented by this example? | technical |
| Which document provides several cheat sheets and detailed guidance on preventing vulnerabilities such as cross-site scripting, SQL injection, and command injection? | OWASP |
| A cybersecurity analyst report should contain minimum password requirements and policies and procedures. These are examples that are included in which control category? | administrative |
| Which control category includes information on mandatory vacations and user training in the cybersecurity analyst report? | operational |
| When creating a cybersecurity analyst report, which control category includes information concerning the access control vestibule? | physical |
| Match the term to the respective description. | _______________________________________________________________________ |
| false negative | malicious activities that are not detected by a network security device |
| true negative | an intrusion detection device identifies an activity as acceptable behavior and the activity is acceptable |
| false positive | a security device triggers an alarm, but there is no malicious activity or actual attack taking place |
| true positive | a successful identification of a security attack or a malicious event |
| _______________________________________________________________________ | _______________________________________________________________________ |
| Which kind of event is also called a “benign trigger”? | false positive |
| What kind of events diminishes the value and urgency of real alerts? | false positives |
| Which kinds of events are malicious activities not detected by a network security device? | false negatives |
| Which kind of event occurs when an intrusion detection device identifies an activity as acceptable behavior and the activity is acceptable? | true negatives |
| Which kind of event is a successful identification of a security attack? | true positive |
| Which example of technical control is recommended to mitigate and prevent vulnerabilities such as cross-site scripting, cross-site request forgery, SQL injection, and command injection? | user input sanitization |
| Which example of administrative controls enables administrators to control what users can do at both broad and granular levels? | RBAC |
| A document entitled “Building an Information Technology Security Awareness and Training Program” succinctly defines why security education and training are so important for users. The document defines ways to improve the security operations of an organiz. | NIST SP 800-50 |
| How is the score that CVSS provides interpreted? | scores are rated from 0 to 10, with 10 being the most severe |
| What control category does system hardening belong to? | technical |
| Which two items are programming logic constructs? (Choose two.) | Boolean operators; Conditionals |
| Which two items are data structures used in programming languages? (Choose two.) | Arrays; Lists |
| Which two items can be included in a library? (Choose two.) | Message templates; Subroutines |
| What is the definition of a procedure used in an application software? | It is a section of code that is created to perform a specific task. |
| Which programming language data structure is a special variable with more than one value at a time? | Array |
| Which term describes a programming language component such as JavaScript Object Notation (JSON)? | Data structures |
| What kind of data structure in Python is represented in the example below?cves = [‘CVE-2022-0945’, ‘CVE-2023-1234’, ‘CVE-2022-0987’] | List |
| Which programming language elements perform similar tasks? | Procedures and functions |
| What is the definition of a library in application software? | It is a collection of resources that can be reused by programs. |
| Which domain name database query utility has been restricted by the European Union´s General Data Protection Regulation (GDPR) to protect privacy? | Whois |
| What are two tools that can be used to perform active reconnaissance? (Choose two.) | Zenmap; Enum4linux |
| What are two tools that can be used to perform credential attacks? (Choose two.) | Mimikatz; Patator |
| Which Linux distribution comes with more than 1900 security penetration testing tools? | BlackArch Linux |
| Which tool is designed to find metadata and hidden information in documents? | FOCA |
| Which programming language element is a block of code that can be reused multiple times to execute a specific task? | Function |
| Which tool organizes query entities within the Entity Palette and calls the search options “transforms”? | Maltego |
| Which programming language element is a code template that includes initial variables and functions for creating an object? | Class |
| Which passive reconnaissance tool can be used to find information about devices and networks on the Internet? | Censys |
| What is a command-line tool that allows for interactive or non-interactive command execution? | Bash |
| Which popular Linux penetration testing distribution is based on Debian GNU/Linux and has evolved from WHoppiX, WHAX, and BackTrack? | Kali Linux |
| Which vulnerability scanner tool offers a cloud-based service that performs continuous monitoring, vulnerability management, and compliance checking? | Qualys |
| Which option is a PowerShell-based post-exploitation tool that can maintain persistence on a compromised system and run PowerShell agents without the need for powershell.exe? | Empire |
| Which tool can be used with Metasploit to maintain stealth and avoid detection from security controls implemented by an organization? | Veil |
| Which encoding method can secretly exfiltrate confidential data in the payload of DNS packets? | Base64 |
| Which option is a Linux distribution tool for forensic evidence collection? | CAINE |
| _______________________________________________________________________ | _______________________________________________________________________ |
| _______________________________________________________________________ | _______________________________________________________________________ |