ETHICAL HACKING AND
COUNTERMEASURES UPDATED ACTUAL
QUESTIONS AND CORRECT ANSWERS
COMPLETE STUDY GUIDE FULL SOLUTION
●● SNMP (Simple Network Management Protocol)
Answer: An Application-layer protocol used to exchange information
between network devices.
●● IMAP (Internet Message Access Protocol)
Answer: a common protocol for retrieving email messages via the
Internet
●● Post Office Protocol (POP)
Answer: A protocol that resides on an incoming mail server. The current
version is POP3.
●● Which of the following protocols is vulnerable to a sniffing attack as
passwords and data are sent in clear text?
Answer: (FTP) File Transfer Protocol
,●● Which of the following protocols is a TCP/IP based protocol used to
exchange management information between devices connected on a
network?
Answer: SNMP (Simple Network Management Protocol)
●● Which of the following protocols is used to communicate through
port 23 and allows an attacker to log into a network machine remotely
via a TCP connection to sniff keystrokes, including usernames and
passwords, that are sent in cleartext?
Answer: Telnet
●● Telnet
Answer: Port 23
●● In which of the following OSI layers do sniffers operate and perform
an initial compromise?
Answer: Data Link Layer
●● Smith, a professional hacker, initiated a network sniffing attack on
the switched Ethernet environment of a target organization. He
employed an automated tool to flood the switch with a fake physical
address until the switch translation table became full. When the switch
entered fail-open mode, it started acting as a hub by broadcasting
packets. Now, Smith could easily accomplish his goal of network
sniffing.
, Identify the type of attack performed by Smith in the above scenario.
A. ARP poisoning
B. DHCP starvation
C. DNS poisoning
D. MAC flooding
Answer: D. MAC flooding
●● MAC Flooding Attack
Answer: It's the act of attempting to overload the switches content
addressable memory table forcing legitimate MAC addresses out of
same. This can cause a DOS against the switch. This can be countered
via port security on the switch, by limiting the number of MAC
addresses the port can learn.
●● DNS poisoning
Answer: An attack that substitutes DNS addresses so that the computer
is automatically redirected to an attacker's device.
●● DHCP starvation attack
Answer: An attacker floods the DHCP server with bogus DHCP requests
and eventually the DHCP server pool is exhausted.
COUNTERMEASURES UPDATED ACTUAL
QUESTIONS AND CORRECT ANSWERS
COMPLETE STUDY GUIDE FULL SOLUTION
●● SNMP (Simple Network Management Protocol)
Answer: An Application-layer protocol used to exchange information
between network devices.
●● IMAP (Internet Message Access Protocol)
Answer: a common protocol for retrieving email messages via the
Internet
●● Post Office Protocol (POP)
Answer: A protocol that resides on an incoming mail server. The current
version is POP3.
●● Which of the following protocols is vulnerable to a sniffing attack as
passwords and data are sent in clear text?
Answer: (FTP) File Transfer Protocol
,●● Which of the following protocols is a TCP/IP based protocol used to
exchange management information between devices connected on a
network?
Answer: SNMP (Simple Network Management Protocol)
●● Which of the following protocols is used to communicate through
port 23 and allows an attacker to log into a network machine remotely
via a TCP connection to sniff keystrokes, including usernames and
passwords, that are sent in cleartext?
Answer: Telnet
●● Telnet
Answer: Port 23
●● In which of the following OSI layers do sniffers operate and perform
an initial compromise?
Answer: Data Link Layer
●● Smith, a professional hacker, initiated a network sniffing attack on
the switched Ethernet environment of a target organization. He
employed an automated tool to flood the switch with a fake physical
address until the switch translation table became full. When the switch
entered fail-open mode, it started acting as a hub by broadcasting
packets. Now, Smith could easily accomplish his goal of network
sniffing.
, Identify the type of attack performed by Smith in the above scenario.
A. ARP poisoning
B. DHCP starvation
C. DNS poisoning
D. MAC flooding
Answer: D. MAC flooding
●● MAC Flooding Attack
Answer: It's the act of attempting to overload the switches content
addressable memory table forcing legitimate MAC addresses out of
same. This can cause a DOS against the switch. This can be countered
via port security on the switch, by limiting the number of MAC
addresses the port can learn.
●● DNS poisoning
Answer: An attack that substitutes DNS addresses so that the computer
is automatically redirected to an attacker's device.
●● DHCP starvation attack
Answer: An attacker floods the DHCP server with bogus DHCP requests
and eventually the DHCP server pool is exhausted.