ACTUAL Exam Questions and CORRECT
Answers
TCP 143 - CORRECT ANSWER- IMAP Port
TCP 443 - CORRECT ANSWER- HTTPS Port
UDP 123 - CORRECT ANSWER- NTP Port
TCP 389, 636 - CORRECT ANSWER- LDAP Ports
TCP 110 - CORRECT ANSWER- POP3 Port
UDP 69 - CORRECT ANSWER- TFTP Port
SLE x EF x ARO = ALE - CORRECT ANSWER- Quantitative Risk Analysis Formula.
Risk = Likelihood x Impact - CORRECT ANSWER- Qualitative Risk Analysis Formula.
Residual Risk - CORRECT ANSWER- The remaining risk after analysis and controls are put
in place.
whisker - CORRECT ANSWER- A popular tool used for session splicing.
Boot Sector Virus - CORRECT ANSWER- A virus type that moves the Master Boot Record
(MBR) to another location on the hard disk and copies itself to the original location of the MBR.
, Macro Virus - CORRECT ANSWER- A virus type that targets Microsoft Office programs.
Metric - CORRECT ANSWER- A standard of measurement that is recorded over time to
show improvement.
Open Source Intelligence (OSINT) - CORRECT ANSWER- A type of passive
reconnaissance that collects information from publicly available sources.
salt - CORRECT ANSWER- A random string added to a password to defeat rainbow tables.
TCP 25 - CORRECT ANSWER- The open port used by an email relay for spam and
phishing attacks.
TCP 9100 - CORRECT ANSWER- The most common network printer port
black box - CORRECT ANSWER- A penetration test type in which the tester has no prior
knowledge of the internal systems.
detective control - CORRECT ANSWER- A control type that discovers events after they
happen.
social engineering - CORRECT ANSWER- A hacking technique used on people to
determine if they need more training.
hashing - CORRECT ANSWER- A one-way encryption that is used to see if files have
maintained their integrity.
WHOIS - CORRECT ANSWER- A system that consists of a publicly available set of
databases that contain domain name registration and contact information.