ETHICAL HACKING ESSENTIALS EXAM PREP FULL ACTUAL
QUESTIONS WITH WELL DETAILED ANSWERS
Freddy, a penetration tester, plans to perform testing on an organization's network
infrastructure. Before initiating the process, he defined and decided the range of testing,
what will be tested, where testing will be performed from, and who will perform testing.
Identify the operation performed by Freddy before initiating the test.
A. reporting results
B. delivering results
C. performing the pen test
D. defining the scope
D. defining the scope
James, a certified pen tester, was appointed by an organization to test the organization's
security posture. James identified a security flaw in the network configuration and
exploited it to compromise the main system connected with several nodes.
In which of the following phases in penetration testing has James performed the above
activity?
A. attack phase
B. documenting phase
C. post-attack phase
D. pre-attack phase
,A. attack phase
Jude, a pen tester, was assigned to test the network of an organization. As part of the task,
Jude gathered as much information as possible about the organization. This information
helped Jude in performing other sophisticated attacks. He employed techniques such as
reconnaissance, port scanning, service scanning, and OS scanning to gather the
information.
Identify the penetration testing phase Jude was currently executing in the above scenario.
A. post-attack phase
B. pre-attack phase
C. documenting phase
D. attack phase
B. pre-attack phase
In which of the following penetration testing phases does the tester need to restore the
network to its original state, which includes cleaning up testing processes and removing
vulnerabilities orderly until the systems return to their prior states?
A. documenting phase
B. attack phase
C. post-attack phase
D. pre-attack phase
C. post-attack phase
,Identify the penetration testing methodology compiled by Pete Herzog and a standard set
for penetration testing to achieve security metrics.
A. National Institute of Standards and Technology
B. Open Source Security Testing Methodology Manual
C. Open Web Application Security Project
D. Information Systems Security Assessment Framework
B. Open Source Security Testing Methodology Manual
In which of the following situations is penetration testing required and conducted by a
professional penetration tester?
A. a new threat to the organization's infrastructure has been discovered
B. hardware or software is not updated or reinstalled
C. no change in the organization's policy
D. no changes have been made in the organization's infrastructure
A. a new threat to the organization's infrastructure has been discovered
Richard, a penetration tester, has recently joined the company for initiating the pen testing
process. He was a little negligent toward monitoring and responding to incidents during
and after the pen test. This resulted in repetitive and unwanted triggering of the incident-
handling processes, which disrupted the business continuity of the organization.
Identify the type of risk that evolved in the above scenario as a consequence of the pen
test.
, A. compliance issues
B. organizational risks
C. legal risks
D. technical risks
B. organizational risks
Identify the guideline that addresses the risks associated with penetration testing.
A. never used reserve addresses
B. use partial isolation and replication of target environment
C. use direct testing
D. never perform interruptible testing
B. use partial isolation and replication of target environment
Smith, a certified pen tester, was assigned to perform penetration testing on the
organization's network. As he knew that penetration testing might harm the network, he
followed a guideline that involves collecting sufficient evidence to determine whether any
vulnerabilities exist in the network.
Which of the following guidelines did Smith follow in the above scenario?
A. delay the effect of a test
B. perform interruptible testing
C. use indirect testing
QUESTIONS WITH WELL DETAILED ANSWERS
Freddy, a penetration tester, plans to perform testing on an organization's network
infrastructure. Before initiating the process, he defined and decided the range of testing,
what will be tested, where testing will be performed from, and who will perform testing.
Identify the operation performed by Freddy before initiating the test.
A. reporting results
B. delivering results
C. performing the pen test
D. defining the scope
D. defining the scope
James, a certified pen tester, was appointed by an organization to test the organization's
security posture. James identified a security flaw in the network configuration and
exploited it to compromise the main system connected with several nodes.
In which of the following phases in penetration testing has James performed the above
activity?
A. attack phase
B. documenting phase
C. post-attack phase
D. pre-attack phase
,A. attack phase
Jude, a pen tester, was assigned to test the network of an organization. As part of the task,
Jude gathered as much information as possible about the organization. This information
helped Jude in performing other sophisticated attacks. He employed techniques such as
reconnaissance, port scanning, service scanning, and OS scanning to gather the
information.
Identify the penetration testing phase Jude was currently executing in the above scenario.
A. post-attack phase
B. pre-attack phase
C. documenting phase
D. attack phase
B. pre-attack phase
In which of the following penetration testing phases does the tester need to restore the
network to its original state, which includes cleaning up testing processes and removing
vulnerabilities orderly until the systems return to their prior states?
A. documenting phase
B. attack phase
C. post-attack phase
D. pre-attack phase
C. post-attack phase
,Identify the penetration testing methodology compiled by Pete Herzog and a standard set
for penetration testing to achieve security metrics.
A. National Institute of Standards and Technology
B. Open Source Security Testing Methodology Manual
C. Open Web Application Security Project
D. Information Systems Security Assessment Framework
B. Open Source Security Testing Methodology Manual
In which of the following situations is penetration testing required and conducted by a
professional penetration tester?
A. a new threat to the organization's infrastructure has been discovered
B. hardware or software is not updated or reinstalled
C. no change in the organization's policy
D. no changes have been made in the organization's infrastructure
A. a new threat to the organization's infrastructure has been discovered
Richard, a penetration tester, has recently joined the company for initiating the pen testing
process. He was a little negligent toward monitoring and responding to incidents during
and after the pen test. This resulted in repetitive and unwanted triggering of the incident-
handling processes, which disrupted the business continuity of the organization.
Identify the type of risk that evolved in the above scenario as a consequence of the pen
test.
, A. compliance issues
B. organizational risks
C. legal risks
D. technical risks
B. organizational risks
Identify the guideline that addresses the risks associated with penetration testing.
A. never used reserve addresses
B. use partial isolation and replication of target environment
C. use direct testing
D. never perform interruptible testing
B. use partial isolation and replication of target environment
Smith, a certified pen tester, was assigned to perform penetration testing on the
organization's network. As he knew that penetration testing might harm the network, he
followed a guideline that involves collecting sufficient evidence to determine whether any
vulnerabilities exist in the network.
Which of the following guidelines did Smith follow in the above scenario?
A. delay the effect of a test
B. perform interruptible testing
C. use indirect testing