Ethical Hacking Midterm Exam 2024-2025
As of the writing, the CEH exam is based on ____ domains (subject areas) with which the
tester must be familiar. - ANSWER 22
In a(n) ____, the tester does more than attempt to break in; he or she also analyzes the
company's security policy and procedures and reports any vulnerabilities to
management. - ANSWER security test
This model is the ____ model; management does not tell staff that penetration testing is
taking place nor gives tester any diagrams or describe what technologies the company
uses. - ANSWER black box
____ is not a domain tested for the CEH exam. - ANSWER Red team testing
A ____ can be created that welcomes new users joining a chat session, even though a
person isn't actually present to welcome them. - ANSWER bot
An April 2009 article in USA Today revealed that the federal government is looking for
____ to pay them to secure the nation's networks. - ANSWER hackers
In the ____ model, the company might print out a network diagram showing all the
company's routers, switches, firewalls and intrusion detection systems (IDSs) or give
the tester a floor plan detailing where computer systems are located and what OSs are
running on these systems. - ANSWER white box
Many experienced penetration testers can also write computer programs or ____ in Perl
or the C language to implement network attacks. - ANSWER scripts
Penetration testers and security testers normally have a laptop computer configured
, with ____ and tools for hacking. - ANSWER multiple OSs
Some hackers are skilled operators of computers but others are younger inexperienced
individuals who experienced hackers call ____. - ANSWER script kiddies
Some of the most infamous cases are hacks carried out by ____ students, such as the
eBay hack of 1999. - ANSWER college
The International Council of Electronic Commerce Consultants (EC-Council) has
developed a certification designation called ____. - ANSWER Certified Ethical Hacker
(CEH)
The SysAdmin,Audit,Network, Security (SANS) Institute offers training and IT security
certifications through ____. - ANSWER Global Information Assurance Certification
(GIAC)
The U.S. Department of Justice labels all illegal access to computer or network systems
as "____". - ANSWER hacking
The ____ Institute Top 20 list details the most common network exploits and suggests
ways of correcting vulnerabilities. - ANSWER SANS
The ____ certification for security professionals is issued by the International
Information Systems Security Certifications Consortium (ISC2). - ANSWER Certified
Information Systems Security Professional (CISSP)
The ____ certification is awarded by the Institute for Security and Open Methodologies
(ISECOM), a non-profit organization that provides security training and certification
programs to security professionals. - ANSWER OSSTMM Professional Security Tester
(OPST)
The ____ certification uses the Open Source Security Testing Methodology Manual
(OSSTMM) as its normative methodology; the OSSTMM was written by Peter Herzog. -
As of the writing, the CEH exam is based on ____ domains (subject areas) with which the
tester must be familiar. - ANSWER 22
In a(n) ____, the tester does more than attempt to break in; he or she also analyzes the
company's security policy and procedures and reports any vulnerabilities to
management. - ANSWER security test
This model is the ____ model; management does not tell staff that penetration testing is
taking place nor gives tester any diagrams or describe what technologies the company
uses. - ANSWER black box
____ is not a domain tested for the CEH exam. - ANSWER Red team testing
A ____ can be created that welcomes new users joining a chat session, even though a
person isn't actually present to welcome them. - ANSWER bot
An April 2009 article in USA Today revealed that the federal government is looking for
____ to pay them to secure the nation's networks. - ANSWER hackers
In the ____ model, the company might print out a network diagram showing all the
company's routers, switches, firewalls and intrusion detection systems (IDSs) or give
the tester a floor plan detailing where computer systems are located and what OSs are
running on these systems. - ANSWER white box
Many experienced penetration testers can also write computer programs or ____ in Perl
or the C language to implement network attacks. - ANSWER scripts
Penetration testers and security testers normally have a laptop computer configured
, with ____ and tools for hacking. - ANSWER multiple OSs
Some hackers are skilled operators of computers but others are younger inexperienced
individuals who experienced hackers call ____. - ANSWER script kiddies
Some of the most infamous cases are hacks carried out by ____ students, such as the
eBay hack of 1999. - ANSWER college
The International Council of Electronic Commerce Consultants (EC-Council) has
developed a certification designation called ____. - ANSWER Certified Ethical Hacker
(CEH)
The SysAdmin,Audit,Network, Security (SANS) Institute offers training and IT security
certifications through ____. - ANSWER Global Information Assurance Certification
(GIAC)
The U.S. Department of Justice labels all illegal access to computer or network systems
as "____". - ANSWER hacking
The ____ Institute Top 20 list details the most common network exploits and suggests
ways of correcting vulnerabilities. - ANSWER SANS
The ____ certification for security professionals is issued by the International
Information Systems Security Certifications Consortium (ISC2). - ANSWER Certified
Information Systems Security Professional (CISSP)
The ____ certification is awarded by the Institute for Security and Open Methodologies
(ISECOM), a non-profit organization that provides security training and certification
programs to security professionals. - ANSWER OSSTMM Professional Security Tester
(OPST)
The ____ certification uses the Open Source Security Testing Methodology Manual
(OSSTMM) as its normative methodology; the OSSTMM was written by Peter Herzog. -