CEHv12 Exam Prep: Introduction
To Hacking - Information Security
Overview Exam Q’s and A’s
Which of the following techniques does an attacker use to snoop on the
communication between users or devices and record private information to
launch passive attacks? - -Eavesdropping
Explanation:
Session Hijacking: It is an attack where active session of the user is
intercepted and stolen by an attacker.
Privilege Escalation: It is a process of leveraging OS or application's bug,
design flaw or misconfiguration in order to obtain elevated access to their
resources.
Spoofing: It is a process of fooling the target device or user by tampering the
original message/request and pretending to be trusted origin.
Eavesdropping: It is the process of listening to the communication between
users or devices and record private information to launch attacks.
- Which of the following is the warfare category in which viruses, worms,
Trojan horses, or sniffers are used to make systems shut down automatically,
corrupt data, steal information or services, send fraudulent messages, and
access unauthorized data? - -Hacker Warfare
Explanation:
Psychological warfare: Psychological warfare is the use of various techniques
such as propaganda and terror to demoralize one's adversary in an attempt
to succeed in battle
Hacker warfare: The purpose of this type of warfare can vary from the
shutdown of systems, data errors, theft of information, theft of services,
system monitoring, false messaging, and access to data.
C2 warfare: In the computer security industry, C2 warfare refers to the
impact an attacker possesses over a compromised system or network that
they control.
Electronic warfare: It uses radio-electronic and cryptographic techniques to
degrade the communication.
- Which of the following categories of information warfare is a sensor-based
technology that can directly disrupt technological systems? - -Intelligence-
based warfare
Explanation:
, Economic warfare: It can affect the economy of a business or nation by
blocking the flow of information.
Intelligence-based warfare: Intelligence-based warfare is a sensor-based
technology that directly corrupts technological systems. According to Libicki,
"intelligence-based warfare" is warfare that consists of the design,
protection, and denial of systems that seek sufficient knowledge to dominate
the battlespace
Psychological warfare: Psychological warfare is the use of various techniques
such as propaganda and terror to demoralize one's adversary in an attempt
to succeed in battle.
Electronic warfare: Attempt to disrupt the means of sending information.
- Which of the following close-in attacks is performed by an attacker to
gather information by observing the target's activity at the closest
proximity? - -Shoulder surfing
Explanation:
Shoulder surfing: Performed by observing the target's activity at closest
proximity. Shoulder surfing steals personal information or confidential
information by peering over the target's shoulders.
Denial-of-service (DoS): Causing the services to be unavailable for the target
system.
ARP poisoning: ARP poisoning technique generally used by attackers to
perform sniffing on a target network.
DNS Spoofing: DNS spoofing, the attacker tricks a DNS server into believing
that it has received authentic information when, in reality, it has not received
any.
- Sam, an attacker, was hired to launch an attack on an organization to
disrupt its operations and gain access to a remote system for compromising
the organization's internal network. In the process, Sam launched an attack
to tamper with the data in transit to break into the organization's network.
What is the type of attack Sam has performed against the target
organization? - -Active Attack
Explanation:
Passive Attacks: Passive attacks do not tamper with the data and involve
intercepting and monitoring network traffic and data flow on the target
network
Insider Attacks: Insider attacks involve using privileged access to violate
rules or intentionally cause a threat to the organization's information or
information systems
Distribution Attacks: Distribution attacks occur when attackers tamper with
hardware or software prior to installation
To Hacking - Information Security
Overview Exam Q’s and A’s
Which of the following techniques does an attacker use to snoop on the
communication between users or devices and record private information to
launch passive attacks? - -Eavesdropping
Explanation:
Session Hijacking: It is an attack where active session of the user is
intercepted and stolen by an attacker.
Privilege Escalation: It is a process of leveraging OS or application's bug,
design flaw or misconfiguration in order to obtain elevated access to their
resources.
Spoofing: It is a process of fooling the target device or user by tampering the
original message/request and pretending to be trusted origin.
Eavesdropping: It is the process of listening to the communication between
users or devices and record private information to launch attacks.
- Which of the following is the warfare category in which viruses, worms,
Trojan horses, or sniffers are used to make systems shut down automatically,
corrupt data, steal information or services, send fraudulent messages, and
access unauthorized data? - -Hacker Warfare
Explanation:
Psychological warfare: Psychological warfare is the use of various techniques
such as propaganda and terror to demoralize one's adversary in an attempt
to succeed in battle
Hacker warfare: The purpose of this type of warfare can vary from the
shutdown of systems, data errors, theft of information, theft of services,
system monitoring, false messaging, and access to data.
C2 warfare: In the computer security industry, C2 warfare refers to the
impact an attacker possesses over a compromised system or network that
they control.
Electronic warfare: It uses radio-electronic and cryptographic techniques to
degrade the communication.
- Which of the following categories of information warfare is a sensor-based
technology that can directly disrupt technological systems? - -Intelligence-
based warfare
Explanation:
, Economic warfare: It can affect the economy of a business or nation by
blocking the flow of information.
Intelligence-based warfare: Intelligence-based warfare is a sensor-based
technology that directly corrupts technological systems. According to Libicki,
"intelligence-based warfare" is warfare that consists of the design,
protection, and denial of systems that seek sufficient knowledge to dominate
the battlespace
Psychological warfare: Psychological warfare is the use of various techniques
such as propaganda and terror to demoralize one's adversary in an attempt
to succeed in battle.
Electronic warfare: Attempt to disrupt the means of sending information.
- Which of the following close-in attacks is performed by an attacker to
gather information by observing the target's activity at the closest
proximity? - -Shoulder surfing
Explanation:
Shoulder surfing: Performed by observing the target's activity at closest
proximity. Shoulder surfing steals personal information or confidential
information by peering over the target's shoulders.
Denial-of-service (DoS): Causing the services to be unavailable for the target
system.
ARP poisoning: ARP poisoning technique generally used by attackers to
perform sniffing on a target network.
DNS Spoofing: DNS spoofing, the attacker tricks a DNS server into believing
that it has received authentic information when, in reality, it has not received
any.
- Sam, an attacker, was hired to launch an attack on an organization to
disrupt its operations and gain access to a remote system for compromising
the organization's internal network. In the process, Sam launched an attack
to tamper with the data in transit to break into the organization's network.
What is the type of attack Sam has performed against the target
organization? - -Active Attack
Explanation:
Passive Attacks: Passive attacks do not tamper with the data and involve
intercepting and monitoring network traffic and data flow on the target
network
Insider Attacks: Insider attacks involve using privileged access to violate
rules or intentionally cause a threat to the organization's information or
information systems
Distribution Attacks: Distribution attacks occur when attackers tamper with
hardware or software prior to installation