Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

Ethical Hacking Final Exam Questions and 100% Correct Answers

Document preview thumbnail
Preview 3 out of 16 pages

Which part of the security triad is concerned about denial-of-service attacks Availability Which phase of the Hacking Methodology is the safest in regards to the target becoming aware that you are planning an attack against it? Reconnaissance with OSINT What type of hacker can be either ethical or unethical, usually dependent on the highest bidder? gray hat What type of threat actor would hack a system to discover the names of doctors who perform abortions and then release those names to the internet in an attempt to spread anger and hatred among the anti-abortion population? hacktivist All systems on the internet are at risk from being attacked by hackers. Also, machines not on the internet, such as air-gapped networks, are similarly at risk. true ______________ exploits are mostly successful because they attack an undiscovered/unknown vulnerability in a system, zero-day What is the fundamental difference between hacking and ethical hacking? permissions to conduct the attack If you secure information in its original form, which of the following are you protecting? integrity Which of the following is the first step in Ethical Hacking methodology? none of these A __________________ is someone who does not have the expertise of a hacker and relies on ready-made tools as they can't write their own code. script kitty Nmap is considered an active form of reconnaissance. true The Whois website can be used to find domain and registrar information. true If theHarvester is provided with a domain name and ___________________, it can return user information such as: email accounts, host names, and sub-domain names. search engine name

Content preview

Ethical Hacking Final Exam Questions
and 100% Correct Answers
Which part of the security triad is concerned about denial-of-service attacks
✅Availability

Which phase of the Hacking Methodology is the safest in regards to the target
becoming aware that you are planning an attack against it? ✅Reconnaissance with
OSINT

What type of hacker can be either ethical or unethical, usually dependent on the highest
bidder? ✅gray hat

What type of threat actor would hack a system to discover the names of doctors who
perform abortions and then release those names to the internet in an attempt to spread
anger and hatred among the anti-abortion population? ✅hacktivist

All systems on the internet are at risk from being attacked by hackers. Also, machines
not on the internet, such as air-gapped networks, are similarly at risk. ✅true

______________ exploits are mostly successful because they attack an
undiscovered/unknown vulnerability in a system, ✅zero-day

What is the fundamental difference between hacking and ethical hacking?
✅permissions to conduct the attack

If you secure information in its original form, which of the following are you protecting?
✅integrity

Which of the following is the first step in Ethical Hacking methodology? ✅none of these

A __________________ is someone who does not have the expertise of a hacker and
relies on ready-made tools as they can't write their own code. ✅script kitty

Nmap is considered an active form of reconnaissance. ✅true

The Whois website can be used to find domain and registrar information. ✅true

If theHarvester is provided with a domain name and ___________________, it can
return user information such as: email accounts, host names, and sub-domain names.
✅search engine name

,The command nslookup can query the domain name system. So, you can give it a
domain name and nslookup will return its ip address. ✅true

What tool was demonstrated that could graphically illustrate all of the technologies,
services, and subdomains for a given domain AND the connections between each?
✅Maltego

Using whois.domaintools.com would allow you to find the ip address of a domain.
✅true

Signing up for websites using your personal e-mail address can lead to identity theft
attacks. ✅true

Disabling all unnecessary ports and services is one action a system administrator can
take to harden the system he is overseeing. This is sometimes referred to as a
countermeasure. ✅true

A common and often successful attack vector for hackers is an employee who
unknowingly gives out sensitive information that can provide an entry point into the
system. ✅true

Nmap can provide many types of information such as the services and version number
of the service running on different ports, and what ports are open for connections.
However, it cannot fingerprint an Operating System, that is, determine what OS and
version the system is running. ✅false

What operating system is the popular choice of hackers (both ethical and unethical)
because it comes installed with all types of hacking tools? ✅Kali Linux

Nikto is useful for checking for vulnerabilities in ___________________. ✅Web
servers

Output from a nikto vulnerability scan can be output to html for easier reading and
facilitating research on the weaknesses found. ✅true

The OSVDB (open source vulnerability data base) is a currently maintained data base
that you could use to find the most recent vulnerabilities found in different systems and
ways to mitigate these. ✅false

MBSA is a free security analyzer that IT professionals can use to scan a microsoft-
based system for insecure configuration settings and offers guidance to correct these
insecurities. One of the mitigations demonstrated in class was making sure that
passwords must change periodically. Allowing someone the permission to never change
their password is a great find for hackers! ✅true

, A yellow exclamation point icon is used in a MBSA report to indicate that a critical check
has failed. ✅false

MBSA can generate professional-looking reports that you can present to a client
showing the results of your investigation of the client's system. ✅true

A false positive is a condition that is shown as a result when it does not actually exist.
✅true

The windows operating system is one component that MBSA checks to see if the most
recent updates to the OS have been installed. ✅true

Lynis is a free vulnerability scanning tool used with Windows systems but must be
installed first. ✅false

In social engineering, if an attacker gives fake reason(s) for obtaining sensitive
information (username, password, etc...) from a victim, this is known as
__________________. ✅Pretexting

Which of the following was not a method or technique presented for obtaining sensitive
information from a victim? ✅all can be used to obtain information

This type of phishing attack targets high-level executives of a company like a president,
CIO (chief information officer), CFO (chief financial officer), etc... ✅whaling

Kali Linux has a social engineering tookit called SET that provides an attacker with
various means of help in conducting a social engineering attack. ✅true

Using elicitation, the attacker extracts information from a victim without asking direct
questions. ✅true

What is the name of the browser add-on that can help protect users from phishing
schemes when browsing the web. ✅netcraft

What is the name of the website that contains a repository of phished Websites. You
can enter a URL, and it will provide details of whether it is phished or not. ✅Phishtank

In the lab on social engineering, you used Kali Linux to create a payload that would be
stored on a target machine. When the payload ran it connected back to a listener on the
attack machine. This is known as a Reverse TCP shell. The attackers machine would
then gain control of the session on the target machine and could potentially do all sorts
of nefarious things. In the lab, what service was run to transfer the payload to the target
machine? ✅ftp

Document information

Uploaded on
September 24, 2024
Number of pages
16
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$10.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
twishfrancis
3.9
(42)
Sold
225
Followers
43
Items
10596
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions