Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Examen

Ethical Hacking Essentials Complete Practice Test Questions and Answers

Note
-
Vendu
-
Pages
87
Grade
A+
Publié le
15-10-2024
Écrit en
2024/2025

Ethical Hacking Essentials Complete Practice Test Questions and Answers The assurance that the systems responsible for delivering, storing, and processing information are accessible when required by authorized users is referred to by which of the following elements of information security? - Answer-Available Identify the element of information security that refers to the quality of being genuine or uncorrupted as a characteristic of any communication, documents, or any data. - Answer- Authenticity Mark, a professional hacker, targets his opponent's website. He finds susceptible user inputs, injects malicious SQL code into the database, and tampers with critical information. Which of the following types of attack did Mark perform in the above scenario? - Answer- Active Attack Ruby, a hacker, visited her target company disguised as an aspiring candidate seeking a job. She noticed that certain sensitive documents were thrown in the trash near an employee's desk. She collected these documents, which included critical information that helped her to perform further attacks. Identify the type of attack performed by Ruby in the above scenario. - Answer-Close in Attack EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 2/87 James, a malware programmer, intruded into a manufacturing plant that produces computer peripheral devices. James tampered with the software inside devices ready to be delivered to clients. The tampered program creates a backdoor that allows unauthorized access to the systems. Identify the type of attack performed by James in the above scenario to gain unauthorized access to the delivered systems. - Answer-Distribution Attack Williams, an employee, was using his personal laptop within the organization's premises. He connected his laptop to the organization's internal network and began eavesdropping on the communication between other devices connected to the internal network. He sniffed critical information such as login credentials and other confidential data passing through the network. Identify the type of attack performed by Williams in the above scenario. - Answer-Insider Attack David, a professional hacker, has initiated a DDoS attack against a target organization. He developed a malicious code and distributed it through emails to compromise the systems. Then, all the infected systems were grouped together to launch a DDoS attack against the organization. Identify the type of attack launched by David on the target organization. - Answer-Botnet Jack is working as a malware analyst in an organization. He was assigned to inspect an attack performed against the organization. Jack determined that the attacker had restricted access to EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 3/87 the main computer's files and folders and was demanding an online payment to remove these restrictions. Which of the following type of attack has Jack identified in the above scenario? - Answer- Ransomware Identify the type of attack vector that focuses on stealing information from the victim machine without its user being aware and tries to deliver a payload affecting computer performance. - Answer-APT Attack Andrew, a professional hacker, drafts an email that appears to be legitimate and attaches malicious links to lure victims; he then distributes it through communication channels or mails to obtain private information like account numbers. Identify the type of attack vector employed by Andrew in the above scenario. - Answer- Phishing Identify the civilian act designed to protect investors and the public by increasing the accuracy and reliability of corporate disclosures. - Answer-Sarbanes - Oxley Act Which of the following ISO/IEC standard specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system within the context of an organization? - Answer-ISO/IEC 27001:2013 An organization located in Europe maintains a large amount of user data by following all the security-related laws. It also follows GDPR protection principles, one of which states that the organization should only collect and process data necessary for the specified task. EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 4/87 Which of the following GDPR protection principle is discussed in the above scenario? - Answer-Data Minimization Which of the following titles in The Digital Millennium Copyright Act (DMCA) allows the owner of a copy of a program to make reproductions or adaptations when these are necessary to use the program in conjunction with a system? - Answer-Title III: Computer Maintenance or Repair Which of the following countries has implemented "The Copyright Act 1968" and "The Patents Act 1990"? - Answer-Australia Given below are the various phases involved in the cyber kill chain methodology. 1. Installation 2. Delivery 3. Reconnaissance 4. Actions on objectives 5. Weaponization 6. Exploitation 7. Command and control What is the correct sequence of phases involved in the cyber kill chain methodology? - Answer-3 - 5 - 2 - 6 - 1 - 7 - 4 EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 5/87 In which of the following phases of cyber kill chain methodology does an adversary distribute USB drives containing malicious payload to the employees of the target organization? - Answer-Delivery Don, a professional hacker, initiated an attack on a target organization. During the course of this attack, he employed automated tools to collect maximum weak points, vulnerabilities, and other sensitive information across the target network. Which of the following phases of cyber kill chain methodology is Don currently executing in the above scenario? - Answer-Reconnaissance In which of the following phases of cyber kill chain methodology does the adversary create a deliverable malicious payload using an exploit and a backdoor? - Answer-Weaponization Clara, a security professional, while checking the data feeds of the domains, detects downloaded malicious files and unsolicited communication with the outside network based on the domains. Which of the following adversary behaviors was detected by Clara? - Answer-Unspecified proxy activities John, a professional hacker, was hired by a government agency to penetrate, gain top-secret information from, and damage other government agencies' information systems or networks. Based on the above scenario, which of the following classes of hacker does John fall in? - Answer-state-sponsored hackers EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 6/87 Lionel, a professional hacker motivated by political beliefs, plans to employ various techniques to create fear of large-scale disruption of computer networks. Which of the following types of threat actors does Lionel belong to in the above scenario? - Answer-Cyber Terrorists Which of the following types of threat actors helps both hackers find various vulnerabilities in a system and vendors improve products by checking limitations to make them more secure? - Answer-Gray Hats Allen, a CEO of a business organization, targeted his competitor. He penetrated the target network by using APTs and stayed undetected for years. He consequently gained access to critical information such as blueprints, formulas, product designs, marketing strategies, and trade secrets. Identify the class of hackers to which Allen belongs in the above scenario. - Answer- Industrial spies Identify the type of threat actors that include groups of individuals or communities involved in organized, planned, and prolonged criminal activities and who exploit victims from distinct jurisdictions on the Internet, making them difficult to locate. - Answer-Criminal Syndicates Given below are the various phases of hacking. 1. Reconnaissance 2. Gaining access EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024. Page 7/87 3. Maintaining access 4. Clearing tracks 5. Scanning What is the correct sequence of phases involved in hacking? - Answer-1 - 5 - 2 - 3 - 4 In which of the following phases of hacking does an attacker employ steganography and tunneling techniques to retain access to the victim's system, remain unnoticed, and remove evidence that might lead to prosecution? - Answer-Clearing Tracks In which of the following hacking phases do attackers extract information such as live machines, port, port status, OS details, device type, and system uptime to launch further attacks? - Answer-Scanning Lopez, a penetration tester, executes different phases of the hacking cycle in her organization. She detects that the network is susceptible to password cracki

Montrer plus Lire moins
Établissement
2024/2025
Cours
2024/2025

Aperçu du contenu

EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024.




Ethical Hacking Essentials Complete
Practice Test Questions and Answers

The assurance that the systems responsible for delivering, storing, and processing information

are accessible when required by authorized users is referred to by which of the following

elements of information security? - Answer✔✔-Available


Identify the element of information security that refers to the quality of being genuine or

uncorrupted as a characteristic of any communication, documents, or any data. - Answer✔✔-

Authenticity


Mark, a professional hacker, targets his opponent's website. He finds susceptible user inputs,

injects malicious SQL code into the database, and tampers with critical information.


Which of the following types of attack did Mark perform in the above scenario? - Answer✔✔-

Active Attack


Ruby, a hacker, visited her target company disguised as an aspiring candidate seeking a job. She

noticed that certain sensitive documents were thrown in the trash near an employee's desk.

She collected these documents, which included critical information that helped her to perform

further attacks.


Identify the type of attack performed by Ruby in the above scenario. - Answer✔✔-Close in

Attack

Page 1/87

,EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024.



James, a malware programmer, intruded into a manufacturing plant that produces computer

peripheral devices. James tampered with the software inside devices ready to be delivered to

clients. The tampered program creates a backdoor that allows unauthorized access to the

systems.


Identify the type of attack performed by James in the above scenario to gain unauthorized

access to the delivered systems. - Answer✔✔-Distribution Attack


Williams, an employee, was using his personal laptop within the organization's premises. He

connected his laptop to the organization's internal network and began eavesdropping on the

communication between other devices connected to the internal network. He sniffed critical

information such as login credentials and other confidential data passing through the network.


Identify the type of attack performed by Williams in the above scenario. - Answer✔✔-Insider

Attack


David, a professional hacker, has initiated a DDoS attack against a target organization. He

developed a malicious code and distributed it through emails to compromise the systems. Then,

all the infected systems were grouped together to launch a DDoS attack against the

organization.


Identify the type of attack launched by David on the target organization. - Answer✔✔-Botnet


Jack is working as a malware analyst in an organization. He was assigned to inspect an attack

performed against the organization. Jack determined that the attacker had restricted access to




Page 2/87

,EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024.



the main computer's files and folders and was demanding an online payment to remove these

restrictions.


Which of the following type of attack has Jack identified in the above scenario? - Answer✔✔-

Ransomware


Identify the type of attack vector that focuses on stealing information from the victim machine

without its user being aware and tries to deliver a payload affecting computer performance. -

Answer✔✔-APT Attack


Andrew, a professional hacker, drafts an email that appears to be legitimate and attaches

malicious links to lure victims; he then distributes it through communication channels or mails

to obtain private information like account numbers.


Identify the type of attack vector employed by Andrew in the above scenario. - Answer✔✔-

Phishing


Identify the civilian act designed to protect investors and the public by increasing the accuracy

and reliability of corporate disclosures. - Answer✔✔-Sarbanes - Oxley Act


Which of the following ISO/IEC standard specifies the requirements for establishing,

implementing, maintaining, and continually improving an information security management

system within the context of an organization? - Answer✔✔-ISO/IEC 27001:2013


An organization located in Europe maintains a large amount of user data by following all the

security-related laws. It also follows GDPR protection principles, one of which states that the

organization should only collect and process data necessary for the specified task.
Page 3/87

, EMILLECT 2024/2025 ACADEMIC YEAR ©2024 EMILLECT. ALL RIGHTS RESERVED. FIRST PUBLISH OCTOBER 2024.



Which of the following GDPR protection principle is discussed in the above scenario? -

Answer✔✔-Data Minimization


Which of the following titles in The Digital Millennium Copyright Act (DMCA) allows the owner

of a copy of a program to make reproductions or adaptations when these are necessary to use

the program in conjunction with a system? - Answer✔✔-Title III: Computer Maintenance or

Repair


Which of the following countries has implemented "The Copyright Act 1968" and "The Patents

Act 1990"? - Answer✔✔-Australia


Given below are the various phases involved in the cyber kill chain methodology.


1. Installation


2. Delivery


3. Reconnaissance


4. Actions on objectives


5. Weaponization


6. Exploitation


7. Command and control


What is the correct sequence of phases involved in the cyber kill chain methodology? -

Answer✔✔-3 -> 5 -> 2 -> 6 -> 1 -> 7 -> 4



Page 4/87

École, étude et sujet

Établissement
2024/2025
Cours
2024/2025

Infos sur le Document

Publié le
15 octobre 2024
Nombre de pages
87
Écrit en
2024/2025
Type
Examen
Contient
Questions et réponses

Sujets

$12.99
Accéder à l'intégralité du document:

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Faites connaissance avec le vendeur

Seller avatar
Les scores de réputation sont basés sur le nombre de documents qu'un vendeur a vendus contre paiement ainsi que sur les avis qu'il a reçu pour ces documents. Il y a trois niveaux: Bronze, Argent et Or. Plus la réputation est bonne, plus vous pouvez faire confiance sur la qualité du travail des vendeurs.
Emillect West Virginia University
Voir profil
S'abonner Vous devez être connecté afin de suivre les étudiants ou les cours
Vendu
31
Membre depuis
1 année
Nombre de followers
2
Documents
3003
Dernière vente
1 semaine de cela
GOLDEN ORCHIDS STORE.

On this page, you find all documents, package deals, and flashcards offered by seller Emillect.

3.0

4 revues

5
1
4
0
3
2
2
0
1
1

Documents populaires

Récemment consulté par vous

Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Foire aux questions