Joe works as an engagement team lead with Xsecurity Inc. His pen testing team follows all the standard pentesting procedures, however, one of the team members inadvertently deletes a document containing the client's sensitive information. The client is suing Xsecurity for damages. Which part of the Penetration Testing Contract should Joe have written better to avoid this lawsuit?
-
A
Objective of the penetration test
-
B
-
C
Fees and project schedule
-
D
Reveal answer details
Close answer details
What is the objective of the following bash script? 
-
A
It gives a list of IP addresses that have an FTP port open
-
B
It tries to connect to FTP port on a target machine
-
C
It checks if a target host has the FTP port open and quits
-
D
It checks if an FTP port on a target machine is vulnerable to arracks
Reveal answer details
Close answer details
Which port does DHCP use for client connections?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Identify the attack represented in the diagram below: 
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following attributes has a LM and NTLMv1 value as 64bit + 64bit + 64bit and NTLMv2 value as 128 bits?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
After attending a CEH security seminar, you make a list of changes you would like to perform on your network to increase its security. One of the first things you change is to switch the Restrict Anonymous setting from 0 to 1 on your servers. This, as you were told, would prevent anonymous users from establishing a null session on the server. Using User info tool mentioned at the seminar, you succeed in establishing a null session with one of the servers. Why is that?
-
A
Restrict Anonymous must be set to "2" for complete security
-
B
Restrict Anonymous must be set to "3" for complete security
-
C
There is no way to always prevent an anonymous null session from establishing
-
D
Restrict Anonymous must be set to "10" for complete security
Reveal answer details
Close answer details
NTP protocol is used to synchronize the system clocks of computers with a remote time server or time source over a network. Which one of the following ports is used by NTP as its transport layer?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
What is the purpose of the Traceroute command?
-
A
For extracting information about the network topology, trusted routers, and firewall locations
-
B
For extracting information about closed ports
-
C
For extracting information about the server functioning
-
D
For extracting information about opened ports
Reveal answer details
Close answer details
How many possible sequence number combinations are there in TCP/IP protocol?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
An attacker with a malicious intention decided to hack confidential data from the target organization. For acquiring such information, he started testing IoT devices that are connected to the target network. He started monitoring the network traffic passing between the IoT devices and the network to verify whether credentials are being transmitted in clear text. Further, he also tried to crack the passwords using well-known keywords across all the interfaces. Which of the following IoT threats the attacker is trying to exploit?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
Rebecca, a security analyst, was auditing the network in her organization. During the scan, she found a service running on a remote host, which helped her to enumerate information related to user accounts, network interfaces, network routing and TCP connections. Which among the following services allowed Rebecca to enumerate the information?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
A framework for security analysis is composed of a set of instructions, assumptions, and limitations to analyze and solve security concerns and develop threat free applications. Which of the following frameworks helps an organization in the evaluation of the company's information security with that of the industrial standards?
-
A
Microsoft Internet Security Framework
-
B
Information System Security Assessment Framework
-
C
The IBM Security Framework
-
D
Nortell's Unified Security Framework
Reveal answer details
Close answer details
Question 13
Single choice
After passing her CEH exam, Carol wants to ensure that her network is completely secure. She implements a DMZ, statefull firewall, NAT, IPSEC, and a packet filtering firewall. Since all security measures were taken, none of the hosts on her network can reach the Internet. Why is that?
-
A
IPSEC does not work with packet filtering firewalls
-
B
NAT does not work with IPSEC
-
C
NAT does not work with statefull firewalls
-
D
Statefull firewalls do not work with packet filtering firewalls
Reveal answer details
Close answer details
Question 14
Single choice
Sam was asked to conduct penetration tests on one of the client's internal networks. As part of the testing process, Sam performed enumeration to gain information about computers belonging to a domain, list of shares on the individual hosts in the network, policies and passwords. Identify the enumeration technique.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Single choice
As a part of the pen testing process, James performs a FIN scan as given below:  What will be the response if the port is open?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Firewall is an IP packet filter that enforces the filtering and security policies to the flowing network traffic. Using firewalls in IPv6 is still the best way of protection from low level attacks at the network and transport layers. Which one of the following cannot handle routing protocols properly?
-
A
"Internet-router-firewall-net architecture"
-
B
"Internet-firewall-router-net architecture"
-
C
"Internet-firewall/router(edge device)-net architecture"
-
D
"Internet-firewall -net architecture"
Reveal answer details
Close answer details
Question 17
Single choice
Which vulnerability assessment phase describes the scope of the assessment, identifies and ranks the critical assets, and creates proper information protection procedures such as effective planning, scheduling, coordination, and logistics?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
Harold is a web designer who has completed a website for ghttech.net. As part of the maintenance agreement he signed with the client, Harold is performing research online and seeing how much exposure the site has received so far. Harold navigates to google.com and types in the following search. link:www.ghttech.net What will this search produce?
-
A
All sites that link to ghttech.net
-
B
Sites that contain the code: link:www.ghttech.net
-
C
All sites that ghttech.net links to
-
D
All search engines that link to .net domains
Reveal answer details
Close answer details
Question 19
Single choice
An "idle" system is also referred to as what?
-
A
-
B
-
C
-
D
PC not connected to the Internet
Reveal answer details
Close answer details
Question 20
Single choice
Windows stores user passwords in the Security Accounts Manager database (SAM), or in the Active Directory database in domains. Passwords are never stored in clear text; passwords are hashed and the results are stored in the SAM. NTLM and LM authentication protocols are used to securely store a user's password in the SAM database using different hashing methods.  The SAM file in Windows Server 2008 is located in which of the following locations?
-
A
c:\windows\system32\config\SAM
-
B
c:\windows\system32\drivers\SAM
-
C
c:\windows\system32\Setup\SAM
-
D
c:\windows\system32\Boot\SAM
Reveal answer details
Close answer details
Question 21
Single choice
Which of the following acts provides federal protections for personal health information held by covered entities and gives patients an array of rights with respect to that information?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
Vulnerability assessment is an examination of the ability of a system or application, including the current security procedures and controls, to withstand assault.  What does a vulnerability assessment identify?
-
A
-
B
Weaknesses that could be exploited
-
C
Physical security breaches
-
D
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following is NOT related to the Internal Security Assessment penetration testing strategy?
-
A
Testing to provide a more complete view of site security
-
B
Testing focused on the servers, infrastructure, and the underlying software, including the target
-
C
Testing including tiers and DMZs within the environment, the corporate network, or partner company connections
-
D
Testing performed from a number of network access points representing each logical and physical segment
Reveal answer details
Close answer details
Question 24
Single choice
During a DHCP handshake in an IPv4 network, which of the following messages contains the actual IP addressing information for the clients to use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Which one of the following scans starts, but does not complete the TCP handshake sequence for each port selected, and it works well for direct scanning and often works well through firewalls?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
Which type of penetration testing will require you to send the Internal Control Questionnaires (ICQ) to the client?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
A user unknowingly installed a fake malicious banking app in his Android mobile. This app includes a configuration file that consists of phone numbers of the bank. When the user makes a call to the bank, he is automatically redirected to the number being used by the attacker. The attacker impersonates as a banking official. Also, the app allows the attacker to call the user, then the app displays fake caller ID on the user's mobile resembling call from a legitimate bank. Identify the attack being performed on the Android mobile user?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
A team of cyber criminals in Germany has sent malware-based emails to workers of a fast-food center which is having multiple outlets spread geographically. When any of the employees click on the malicious email, it will give backdoor access to the point of sale (POS) systems located at various outlets. After gaining access to the POS systems, the criminals will be able to obtain credit card details of the fast-food center's customers. In the above scenario, identify the type of attack being performed on the fast-food center?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
Which of the following equipment could a pen tester use to perform shoulder surfing?
-
A
-
B
Painted ultraviolet material
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
Alisa is a Network Security Manager at Aidos Cyber Security. During a regular network audit, she sent specially crafted ICMP packet fragments with different offset values into the network, causing a system crash. Which attack Alisa is trying to perform?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
What is the difference between penetration testing and vulnerability testing? 
-
A
Penetration testing goes one step further than vulnerability testing; while vulnerability tests check for known vulnerabilities, penetration testing adopts the concept of `in-depth ethical hacking'
-
B
Penetration testing is based on purely online vulnerability analysis while vulnerability testing engages ethical hackers to find vulnerabilities
-
C
Vulnerability testing is more expensive than penetration testing
-
D
Penetration testing is conducted purely for meeting compliance standards while vulnerability testing is focused on online scans
Reveal answer details
Close answer details
Question 32
Single choice
John, the penetration testing manager in a pen testing firm, needs to prepare a pen testing pricing report for a client. Which of the following factors does he need to consider while preparing the pen testing pricing report? 
-
A
Number of employees in the client organization
-
B
Complete structure of the organization
-
C
Number of client computers to be tested and resources required to perform a pen test
-
D
Number of servers available in the client organization
Reveal answer details
Close answer details
Question 33
Single choice
The first phase of the penetration testing plan is to develop the scope of the project in consultation with the client. Pen testing test components depend on the client's operating environment, threat perception, security and compliance requirements, ROE, and budget. Various components need to be considered for testing while developing the scope of the project.  Which of the following is NOT a pen testing component to be tested?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 34
Single choice
Stuart is a database penetration tester working with Regional Server Technologies. He was asked by the company to identify the vulnerabilities in its SQL database. Stuart wanted to perform a SQL penetration by passing some SQL commands through a web application for execution and succeeded with a command using a wildcard attribute indicator. Which of the following strings is a wildcard attribute indicator?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Single choice
Which of the following are the default ports used by NetBIOS service?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
Joe, an ECSA certified professional, is working on a pen testing engagement for one of his SME clients. He discovered the host file in one of the Windows machines has the following entry: 213.65.172.55 microsoft.com After performing a Whois lookup, Joe discovered the IP does not refer to Microsoft.com. The network admin denied modifying the host files. Which type of attack does this scenario present?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 37
Single choice
Robert is a network admin in XYZ Inc. He deployed a Linux server in his enterprise network and wanted to share some critical and sensitive files that are present in the Linux server with his subordinates. He wants to set the file access permissions using chmod command in such a way that his subordinates can only read/view the files but cannot edit or delete the files. Which of the following chmod commands can Robert use in order to achieve his objective?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 38
Single choice
Jim performed a vulnerability analysis on his network and found no potential problems. He runs another utility that executes exploits against his system to verify the results of the vulnerability test. The second utility executes five known exploits against his network in which the vulnerability analysis said were not exploitable. What kind of results did Jim receive from his vulnerability analysis?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
The penetration testers are required to follow predefined standard frameworks in making penetration testing reporting formats. Which of the following standards does NOT follow the commonly used methodologies in penetration testing?
-
A
National Institute of Standards and Technology (NIST)
-
B
Information Systems Security Assessment Framework (ISSAF)
-
C
Open Web Application Security Project (OWASP)
-
D
American Society for Testing Materials (ASTM)
Reveal answer details
Close answer details
Question 40
Single choice
John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the file server. He enables Lophtcrack program to sniffing mode. John sends Hillary an email with a link to Error! Reference source not found. What information will he be able to gather from this?
-
A
The SID of Hillary's network account
-
B
The network shares that Hillary has permissions
-
C
The SAM file from Hillary's computer
-
D
Hillary's network username and password hash
Reveal answer details
Close answer details
Question 41
Single choice
Sam is a penetration tester and network admin at McLaren & McLaren, based out of Washington. The company has recently deployed IPv6 in their network. Sam found problems with the protocol implementation and tried to redeploy IPv6 over IPv4. This time, he used the tunneling mechanism while deploying the IPv6 network. How does the tunneling mechanism work?
-
A
It encapsulates IPv6 packets in IPv4 packets
-
B
It transfers IPv4 first and the IPv6
-
C
It splits the IPv4 packets and provides a way to IPv6
-
D
It replaces IPv4 with IPv6
Reveal answer details
Close answer details
Question 42
Single choice
How does OS Fingerprinting help you as a pen tester?
-
A
It defines exactly what software the target has installed
-
B
It doesn't depend on the patches that have been applied to fix existing security holes
-
C
It opens a security-delayed window based on the port being scanned
-
D
It helps to research vulnerabilities that you can use to exploit on a target system
Reveal answer details
Close answer details
Question 43
Single choice
Smith, a pen tester, has been hired to analyze the security posture of an organization and is trying to find the operating systems used in the network using Wireshark. What can be inferred about selected packet in the Wireshark screenshot below? 
-
A
The machine with IP 10.0.0.10 is running on Linux
-
B
The machine with IP 10.0.0.12 is running on Linux
-
C
The machine with IP 10.0.0.12 is running on Windows
-
D
The machine with IP10.0.0.10 is running on Windows
Reveal answer details
Close answer details
Question 44
Single choice
Identify the policy that defines the standards for the organizational network connectivity and security standards for computers that are connected in the organizational network.
-
A
Information-Protection Policy
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 45
Single choice
Transmission Control Protocol (TCP) is a connection-oriented four layer protocol. It is responsible for breaking messages into segments, re-assembling them at the destination station, and re-sending. Which one of the following protocols does not use the TCP?
-
A
Reverse Address Resolution Protocol (RARP)
-
B
HTTP (Hypertext Transfer Protocol)
-
C
SMTP (Simple Mail Transfer Protocol)
-
D
Reveal answer details
Close answer details
Question 46
Single choice
HTTP protocol specifies that arbitrary binary characters can be passed within the URL by using %xx notation, where 'xx' is the
-
A
ASCII value of the character
-
B
Binary value of the character
-
C
Decimal value of the character
-
D
Hex value of the character
Reveal answer details
Close answer details
Question 47
Single choice
Which one of the following is a supporting tool for 802.11 (wireless) packet injections, it spoofs 802.11 packets to verify whether the access point is valid or not?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 48
Single choice
Which of the following statements is true about the LM hash?
-
A
Disabled in Windows Vista and 7 OSs
-
B
Separated into two 8-character strings
-
C
Letters are converted to the lowercase
-
D
Padded with NULL to 16 characters
Reveal answer details
Close answer details
Question 49
Single choice
Many security and compliance projects begin with a simple idea: assess the organization's risk, vulnerabilities, and breaches. Implementing an IT security risk assessment is critical to the overall security posture of any organization. An effective security risk assessment can prevent breaches and reduce the impact of realized breaches.  What is the formula to calculate risk?
-
A
-
B
Risk = Goodwill x Reputation
-
C
Risk = Loss x Exposure factor
-
D
Reveal answer details
Close answer details
Question 50
Single choice
Harold is a security analyst who has just run the rdisk /s command to grab the backup SAM file on a computer. Where should Harold navigate on the computer to find the file?
-
A
-
B
-
C
%systemroot%\system32\drivers\etc
-
D
%systemroot%\system32\LSA
Reveal answer details
Close answer details
Question 51
Single choice
During an internal network audit, you are asked to see if there is any RPC server running on the network and if found, enumerate the associate RPC services. Which port would you scan to determine the RPC server and which command will you use to enumerate the RPC services?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 52
Single choice
Nick is a penetration tester in Stanbiz Ltd. As a part of his duty, he was analyzing the network traffic by using various filters in the Wireshark tool. While sniffing the network traffic, he used "tcp.port==1433" Wireshark filter for acquiring a specific database related information since port number 1433 is the default port of that specific target database. Which of the following databases Nick is targeting in his test?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 53
Single choice
In the context of penetration testing, what does blue teaming mean? 
-
A
A penetration test performed with the knowledge and consent of the organization's IT staff
-
B
It is the most expensive and most widely used
-
C
It may be conducted with or without warning
-
D
A penetration test performed without the knowledge of the organization's IT staff but with permission from upper management
Reveal answer details
Close answer details
Question 54
Single choice
One needs to run "Scan Server Configuration" tool to allow a remote connection to Nessus from the remote Nessus clients. This tool allows the port and bound interface of the Nessus daemon to be configured. By default, the Nessus daemon listens to connections on which one of the following?
-
A
Localhost (127.0.0.1) and port 1241
-
B
Localhost (127.0.0.1) and port 1240
-
C
Localhost (127.0.0.1) and port 1246
-
D
Localhost (127.0.0.0) and port 1243
Reveal answer details
Close answer details
|