ETHICAL HACKING AND
COUNTERMEASURES EXAM SCRIPT FULL
REVIEW SHEET TESTED QUESTIONS AND
CORRECT ANSWERS
●● It is most important to obtain ________ before beginning a
penetration test.
Answer: Written permission
(Ethical hacking must be legally authorized to avoid violating laws like
the CFAA. Written permission defines the scope and limits of testing.)
●● A security exposure in an operating system or application software
component is called a(n)
Answer: Vulnerability
(A vulnerability is a flaw that attackers can exploit to gain unauthorized
access or cause harm.)
●● The second step of the hacking process is ________.
Answer: Scanning
,(After reconnaissance, scanning is performed to identify live hosts, open
ports, and potential vulnerabilities.)
●● When hackers talk about standards of behavior and moral issues of
right and wrong, what are they referring to?
A. Rules
B. Standards
C. Laws
D. Ethics
Answer: D. Ethics
(Ethics define the principles governing hacker behavior, distinguishing
ethical hacking from criminal activities.)
●● Hackers may justify their actions based on which of the following:
A. All information should be free.
B. Access to computers and their data should be unlimited.
C. Writing viruses, malware, or other code is not a crime.
D. Any of the above.
Answer: D. Any of the above.
,(All information should be free, Access should be unlimited, Writing
viruses/malware is not a crime)
(Some hackers believe in the free flow of information and justify
unauthorized access as ethical, though it is illegal.)
●● The individual responsible for releasing what is considered the first
Internet worm was:
A. Kevin Mitnick.
B. Robert T. Morris, Jr.
C. Adrian Lamo.
D. Kevin Poulsen.
Answer: B. Robert T. Morris, Jr.
(Robert T. Morris, Jr. created the first self-replicating internet worm in
1988, which led to widespread system slowdowns.)
●● A hacker with sufficient computing skills and expertise to launch
harmful attacks on computer networks and who uses those skills
illegally is best described as a(n):
A. disgruntled employee.
B. ethical hacker.
C. white-hat hacker.
, D. black-hat hacker.
Answer: D. Black-hat hacker
(Black-hat hackers exploit vulnerabilities for personal or financial gain,
breaking laws and causing harm.)
●● If a penetration test team does not have anything more than a list of
IP addresses of the organization's network, what type of test are the
penetration testers conducting?
A. Blind assessment
B. White box
C. Gray box
D. Black box
Answer: D. Black box
(A black-box test simulates an external attack where testers have no
prior knowledge of the target system.)
●● How is the practice of tricking employees into revealing sensitive
data about their computer system or infrastructure best described?
A. Ethical hacking
B. Dictionary attack
COUNTERMEASURES EXAM SCRIPT FULL
REVIEW SHEET TESTED QUESTIONS AND
CORRECT ANSWERS
●● It is most important to obtain ________ before beginning a
penetration test.
Answer: Written permission
(Ethical hacking must be legally authorized to avoid violating laws like
the CFAA. Written permission defines the scope and limits of testing.)
●● A security exposure in an operating system or application software
component is called a(n)
Answer: Vulnerability
(A vulnerability is a flaw that attackers can exploit to gain unauthorized
access or cause harm.)
●● The second step of the hacking process is ________.
Answer: Scanning
,(After reconnaissance, scanning is performed to identify live hosts, open
ports, and potential vulnerabilities.)
●● When hackers talk about standards of behavior and moral issues of
right and wrong, what are they referring to?
A. Rules
B. Standards
C. Laws
D. Ethics
Answer: D. Ethics
(Ethics define the principles governing hacker behavior, distinguishing
ethical hacking from criminal activities.)
●● Hackers may justify their actions based on which of the following:
A. All information should be free.
B. Access to computers and their data should be unlimited.
C. Writing viruses, malware, or other code is not a crime.
D. Any of the above.
Answer: D. Any of the above.
,(All information should be free, Access should be unlimited, Writing
viruses/malware is not a crime)
(Some hackers believe in the free flow of information and justify
unauthorized access as ethical, though it is illegal.)
●● The individual responsible for releasing what is considered the first
Internet worm was:
A. Kevin Mitnick.
B. Robert T. Morris, Jr.
C. Adrian Lamo.
D. Kevin Poulsen.
Answer: B. Robert T. Morris, Jr.
(Robert T. Morris, Jr. created the first self-replicating internet worm in
1988, which led to widespread system slowdowns.)
●● A hacker with sufficient computing skills and expertise to launch
harmful attacks on computer networks and who uses those skills
illegally is best described as a(n):
A. disgruntled employee.
B. ethical hacker.
C. white-hat hacker.
, D. black-hat hacker.
Answer: D. Black-hat hacker
(Black-hat hackers exploit vulnerabilities for personal or financial gain,
breaking laws and causing harm.)
●● If a penetration test team does not have anything more than a list of
IP addresses of the organization's network, what type of test are the
penetration testers conducting?
A. Blind assessment
B. White box
C. Gray box
D. Black box
Answer: D. Black box
(A black-box test simulates an external attack where testers have no
prior knowledge of the target system.)
●● How is the practice of tricking employees into revealing sensitive
data about their computer system or infrastructure best described?
A. Ethical hacking
B. Dictionary attack