ETHICAL HACKING AND
COUNTERMEASURES COMPREHENSIVE
EXAMINATION TEST VERIFIED QUESTIONS
AND SOLUTIONS GRADED APLUS
●● Server Root
Answer: It is the top-level root directory under the directory tree in
which the server's configuration and error, executable, and log files are
stored.
●● Web Proxy
Answer: A proxy server that sits between the web client and the web
server to prevent IP blocking and maintain anonymity
●● Document Root
Answer: Stores critical HTML files related to the web pages of a domain
name that will be served in response to the requests
●● Which of the following components of a web server is located
between the web client and web server to pass all the requests and is also
used to prevent IP blocking and maintain anonymity?
Answer: Web proxy
,●● Which of the following components in a web server uses a technique
where multiple domains can be placed on the same server and allows
sharing of resources among various servers?
Answer: Virtual Hosting
●● Virtual Document Tree
Answer: This provides storage on a different machine or a disk after the
original disk is filled-up. It is case sensitive and can be used to provide
object-level security.
●● Edward, a professional hacker, targeted an organization's official
web page to damage the company's reputation. He employed the SQL
injection technique to access the targeted web page, applied
unauthorized modifications to change its visual appearance, and
displayed another page containing its own messages.
Identify the attack technique utilized by Edward in the above scenario.
A. DNS server hijacking
B. web server misconfiguration
C. website defacement
D. directory traversal attack
Answer: C. website defacement
, ●● Identity the web-based attack in which the attacker makes
unauthorized changes to a website's content that results in changes to the
visual appearance of the web page or website.
Answer: Website Defacement
●● Don, a professional hacker, targeted John's official email account and
wanted to access confidential data saved in his account. Don initiated the
process by entering the username and then used a predefined file with an
automated password cracking program. Eventually, Don succeeded in
cracking John's email account password.
Which of the following techniques has Don employed in the above
scenario?
A. brute-force attack
B. dictionary attack
C. keylogger attack
D. SQL injection
Answer: B. dictionary attack
●● Bob, a professional hacker, targeted administrator Alice's credentials
to log into a remote server. Bob employed both dictionary attacks and
brute-force attacks to crack the password. Using this method, Bob easily
obtained Alice's password and accessed the remote server.
COUNTERMEASURES COMPREHENSIVE
EXAMINATION TEST VERIFIED QUESTIONS
AND SOLUTIONS GRADED APLUS
●● Server Root
Answer: It is the top-level root directory under the directory tree in
which the server's configuration and error, executable, and log files are
stored.
●● Web Proxy
Answer: A proxy server that sits between the web client and the web
server to prevent IP blocking and maintain anonymity
●● Document Root
Answer: Stores critical HTML files related to the web pages of a domain
name that will be served in response to the requests
●● Which of the following components of a web server is located
between the web client and web server to pass all the requests and is also
used to prevent IP blocking and maintain anonymity?
Answer: Web proxy
,●● Which of the following components in a web server uses a technique
where multiple domains can be placed on the same server and allows
sharing of resources among various servers?
Answer: Virtual Hosting
●● Virtual Document Tree
Answer: This provides storage on a different machine or a disk after the
original disk is filled-up. It is case sensitive and can be used to provide
object-level security.
●● Edward, a professional hacker, targeted an organization's official
web page to damage the company's reputation. He employed the SQL
injection technique to access the targeted web page, applied
unauthorized modifications to change its visual appearance, and
displayed another page containing its own messages.
Identify the attack technique utilized by Edward in the above scenario.
A. DNS server hijacking
B. web server misconfiguration
C. website defacement
D. directory traversal attack
Answer: C. website defacement
, ●● Identity the web-based attack in which the attacker makes
unauthorized changes to a website's content that results in changes to the
visual appearance of the web page or website.
Answer: Website Defacement
●● Don, a professional hacker, targeted John's official email account and
wanted to access confidential data saved in his account. Don initiated the
process by entering the username and then used a predefined file with an
automated password cracking program. Eventually, Don succeeded in
cracking John's email account password.
Which of the following techniques has Don employed in the above
scenario?
A. brute-force attack
B. dictionary attack
C. keylogger attack
D. SQL injection
Answer: B. dictionary attack
●● Bob, a professional hacker, targeted administrator Alice's credentials
to log into a remote server. Bob employed both dictionary attacks and
brute-force attacks to crack the password. Using this method, Bob easily
obtained Alice's password and accessed the remote server.