ETHICAL HACKING ESSENTIALS COMPLETE PRACTICE
TEST (2025 EDITION) – FULL EXAM PREP WITH
VERIFIED QUESTIONS & ANSWERS
Sam, a new employee at an organization, received a phishing mail from an unauthorized
source on his official email ID. As Sam was not trained on email security, he opened the
email and clicked on the malicious link within the email, allowing the attacker to gain
backdoor access to the office network.
Identify the threat source in the above scenario.
Unintentional threats
Which of the following practices helps security professionals secure the network from
wireless threats?
Limit the strength of the wireless network
Which of the following practices can allow attackers to evade the wireless authentication
process?
Never update drivers on all wireless equipment
Which of the following countermeasures helps users defend their devices against
Bluetooth attacks?
Disable automatic connections to public Wi-Fi networks
Which of the following practices is NOT a countermeasure against Bluetooth attacks?
EDUCATIONAL SUPPORT • ACADEMIC RESOURCES • PROFESSIONAL GUIDANCE
,MINDPLUG SOLUTIONS — EMPOWERING MINDS, BUILDING FUTURES
Keep the device in the discoverable mode
Joan, a software developer, unintentionally included a password as a comment in a hybrid
mobile application that was developed for internal purposes and not expected to be
released into a production environment.
Identify the type of mobile risk demonstrated in the above scenario.
Extraneous functionality
Walter, a professional hacker, was trying to exploit nascent vulnerabilities in a target mobile
application. He utilized a technique to analyze the final core binary to determine its source
code and libraries. Further, this analysis gave him insights into the inner workings of the
application.
Identify the mobile risk exploited by Walter in the above scenario.
Reverse engineering
Identify the method that allows users to attain privileged control within the Android's
subsystem resulting in sensitive data exposure.
Rooting
Roger, a professional hacker, targeted an employee's mobile device, which the organization
allocated as a part of BYOD policy. Roger tricked the target employee into clicking on a
malicious link that appeared to be sent by the security team. Soon after the employee
clicked on the link, Roger installed malicious software that exploited the device's browser,
cookies, and security permissions.
Identify the type of attack performed by Roger in the above scenario.
EDUCATIONAL SUPPORT • ACADEMIC RESOURCES • PROFESSIONAL GUIDANCE
,MINDPLUG SOLUTIONS — EMPOWERING MINDS, BUILDING FUTURES
User-initiated code
In which of the following attacks do attackers exploit web page vulnerabilities to force an
unsuspecting user's browser to send unintended malicious requests?
Cross-site request forgery
James, a software developer at an organization, handed over a fully developed mobile
application to the testing team for validation. During validation, the testing team disabled
the two-factor authentication implemented on it and forgot to enable it before deployment.
This oversight allowed attackers to penetrate the server just by cracking users' credentials
as the two-factor authentication was disabled on the application.
Identify the mobile security risk demonstrated in the above scenario.
M10—Extraneous Functionality:
Code Tampering: This category covers binary patching, local resource modification,
method hooking, method swizzling, and dynamic memory modification.
M8
Insufficient Cryptography: The code applies cryptography to a sensitive information asset.
However, cryptography is insufficient in some ways. This category covers issues in which
cryptography is attempted but not performed correctly.
M5
EDUCATIONAL SUPPORT • ACADEMIC RESOURCES • PROFESSIONAL GUIDANCE
, MINDPLUG SOLUTIONS — EMPOWERING MINDS, BUILDING FUTURES
Extraneous Functionality: Often, developers include hidden backdoor functionality or other
internal development security controls that are not intended to be released into a
production environment. For example, a developer may accidentally include a password as
a comment in a hybrid app. Another example involves the disabling of two-factor
authentication during testing.
M10
Insecure Data Storage: Insecure data storage vulnerability arises when development teams
assume that users and malware will not have access to a mobile device's file system and
subsequently to sensitive information in the device's data stores. "Jailbreaking" or rooting a
mobile device bypasses encryption protection mechanism.
M2
Which of the following mobile risks can be raised from failure to identify the user, failure to
maintain the user's identity, or weaknesses in session management?
Insecure authentication
Identify the network-based attack in which the attacker eavesdrops on existing network
connections to intrude, read, and modify the data or insert fraudulent data into the
intercepted communication.
Man-in-the-middle
David, a professional hacker, was hired to attack mobile devices owned by an organization.
He broadcasted a well-crafted text message with a malicious link to all the organization's
mobile numbers to collect their personal and financial information.
EDUCATIONAL SUPPORT • ACADEMIC RESOURCES • PROFESSIONAL GUIDANCE