John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He observes that the We-are-secure server is vulnerable to a special type of DoS attack and he makes the following suggestions to the security authority to protect the server from this DoS attack. The countermeasures against this type of DoS attack are as follows: l Disabling IP-directed broadcasts at the We-are-secure router l Configuring local computers so as not to respond to such ICMP packets that are configured to be sent to IP broadcast addresses Which of the following DoS attacks has John discovered as a vulnerability for the We-are-secure security network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following is the first computer virus that was used to infect the boot sector of storage media formatted with the DOS File Allocation Table (FAT) file system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Sam, a bank employee, develops a program and uploads it to the bank's server. He deducts $1 a month from the account of every customer using the program. Probably no account holder will notice this type of illegal debit, but Sam will make a good amount of money every month. Which of the following types of cybercrime is Sam performing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following is an example of a worm used in the Linux operating system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You work as a Network Administrator for Infonet Inc. The company uses Wired Equivalent Privacy (WEP) for wireless security. Who among the following can authenticate from the access point of the network?
-
A
Only users within the company.
-
B
Only users with the correct WEP key.
-
C
-
D
Reveal answer details
Close answer details
A attack is designed to bring loss of network connectivity and services by consuming the bandwidth of a user's network.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
What is the name of the first computer virus that infected the boot sector of the MS-DOS operating system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following password cracking attacks is implemented by calculating all the possible hashes for a set of characters?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following malware spread through the Internet and caused a large DoS attack in 1988?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
Which of the following is provided by Digital signatures?
-
A
-
B
Integrity and Validation.
-
C
Authentication and Identification.
-
D
Identification and Validation.
Reveal answer details
Close answer details
Question 11
Single choice
Which of the following Trojans opens a very large number of Web browser windows?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Multiple choice
Which of the following components are usually found in an Intrusion detection system (IDS)? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 13
Multiple choice
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He has successfully completed the following pre-attack phases while testing the security of the server: - Footprinting - Scanning Now he wants to conduct the enumeration phase. Which of the following tools can John use to conduct it? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Multiple choice
Which of the following statements are true about routers? Each correct answer represents a complete solution. Choose all that apply.
-
A
Routers are responsible for making decisions about which of several paths network (or Internet) traffic will follow.
-
B
Routers organize addresses into classes, which are used to determine how to move packets from one network to another.
-
C
Routers do not limit physical broadcast traffic.
-
D
Routers act as protocol translators and bind dissimilar networks.
Reveal answer details
Close answer details
Question 15
Single choice
What is the critical evaluation of the most relevant information on a given topic known as?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He is using dumpster diving to gather information about Weare-secure, Inc. In which of the following steps of malicious hacking does dumpster diving come under?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Which of the following technologies is used to detect unauthorized attempts to access and manipulate computer systems locally or through the Internet or an intranet?
-
A
-
B
Intrusion detection system (IDS)
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
You are responsible for security at a company that uses a lot of Web applications. You are most concerned about flaws in those applications allowing some attacker to get into your network. What method would be best for finding such flaws?
-
A
-
B
Manual penetration testing
-
C
Automated penetration testing
-
D
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following statements explains the dumpster diving hacking technique?
-
A
This is an information gathering technique in which the attacker runs a software program to automatically call thousands of telephone numbers to find out a victim who has attached a modem to the Internet.
-
B
This is an information gathering technique in which an attacker rummages through all the discarded waste-papers in the victim's trash.
-
C
This is an information gathering technique in which the attacker calls the help center of the organization and asks someone to reset a password.
-
D
This is an information gathering technique in which the attacker injects a Trojan in the victim's computer.
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following tools provides a great solution for auditing and testing the recognition and response capabilities of the corporate security defenses?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
You work as a Network Administrator for Infonet Inc. The company's office has a wireless network. Wireless access point on the network works as a router and DHCP server. You want to configure a laptop to connect to the wireless network. What will you configure on the laptop to accomplish the task?
-
A
-
B
Internet service provider's DNS server address
-
C
-
D
Reveal answer details
Close answer details
Question 22
Single choice
Which of the following wireless networks transmits data probably at 115 Kbps?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following protocols of the TCP/IP suite is used in the application layer of the OSI model?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Multiple choice
Which of the following attacks CANNOT be detected by an Intrusion Detection System (IDS)? Each correct answer represents a complete solution. Choose all that apply.
-
A
Denial-of-Service (DoS) attack
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Victor is a novice Ethical Hacker. He is learning the hacking process, i.e., the steps taken by malicious hackers to perform hacking. Which of the following steps is NOT included in the hacking process?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Multiple choice
Firewalking is a technique that can be used to gather information about a remote network protected by a firewall. This technique can be used effectively to perform information gathering attacks. In this technique, an attacker sends a crafted packet with a TTL value that is set to expire one hop past the firewall. Which of the following are pre-requisites for an attacker to conduct firewalking? Each correct answer represents a complete solution. Choose all that apply.
-
A
ICMP packets leaving the network should be allowed.
-
B
An attacker should know the IP address of the last known gateway before the firewall.
-
C
There should be a backdoor installed on the network.
-
D
An attacker should know the IP address of a host located behind the firewall.
Reveal answer details
Close answer details
Question 27
Single choice
Which of the following cryptographic system services ensures that information will not be disclosed to any unauthorized person on a local network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
What level of encryption is used by syskey?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
According to the Internet Crime Report 2009, which of the following complaint categories is on the top?
-
A
-
B
-
C
Non-delivered merchandise/payment
-
D
Reveal answer details
Close answer details
Question 30
Single choice
You are the Administrator for a corporate network. You are concerned about denial of service attacks. Which of the following measures would be most helpful in defending against a Denial-of-Service (DoS) attack?
-
A
Implement network based antivirus.
-
B
Place a honey pot in the DMZ.
-
C
Implement a strong password policy.
-
D
Shorten the timeout for connection attempts.
Reveal answer details
Close answer details
Question 31
Single choice
Which of the following is an example of a social engineering attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 32
Single choice
Which of the following proxy servers is placed anonymously between the client and remote server and handles all of the traffic from the client?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Single choice
Which of the following laws was formed by the legislative branch of the United States government?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 34
Multiple choice
Which of the following parameters are required to be followed on receiving a suspicious mail according to the Department of Justice? Each correct answer represents a part of the solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Multiple choice
Rick works as a Computer Forensic Investigator for BlueWells Inc. He has been informed that some confidential information is being leaked out by an employee of the company. Rick suspects that someone is sending the information through email. He checks the emails sent by some employees to other networks. Rick finds out that Sam, an employee of the Sales department, is continuously sending text files that contain special symbols, graphics, and signs. Rick suspects that Sam is using the Steganography technique to send data in a disguised form. Which of the following techniques is Sam using? Each correct answer represents a part of the solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
Which of the following Incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an enterprise?
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 37
Single choice
Which of the following forensic tool suite is developed for Linux operating system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 38
Single choice
Which of the following statements correctly defines a script kiddie?
-
A
He is an individual who breaks communication systems to perform hacking.
-
B
He is an individual who has lost respect and integrity as an employee in any organization.
-
C
He is an individual who uses hacking programs developed by others to attack information systems and spoil websites.
-
D
He is an individual who is an expert in various computer fields such as operating systems, networking, hardware, software, etc. and enjoys the mental challenge of decoding computer programs, solving network vulnerabilities and security threats, etc
Reveal answer details
Close answer details
Question 39
Single choice
Which of the following tools automates the password guessing in NetBIOS sessions and can also be used to perform a manual dictionary attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 40
Multiple choice
Adam, a novice Web user is getting large amount of unsolicited commercial emails on his email address. He suspects that the emails he is receiving are the Spam. Which of the following steps will he take to stop the Spam? Each correct answer represents a complete solution. Choose all that apply.
-
A
Forward a copy of the spam to the ISP to make the ISP conscious of the spam.
-
B
Send an email to the domain administrator responsible for the initiating IP address.
-
C
Close existing email account and open new email account.
-
D
Report the incident to the FTC (The U.S. Federal Trade Commission) by sending a copy of the spam message.
Reveal answer details
Close answer details
Question 41
Multiple choice
By gaining full control of router, hackers often acquire full control of the network. Which of the following methods are commonly used to attack Routers? Each correct answer represents a complete solution. Choose all that apply.
-
A
By launching Social Engineering attack
-
B
By launching Sequence++ attack
-
C
-
D
By launching Max Age attack
Reveal answer details
Close answer details
Question 42
Multiple choice
You are a professional Computer Hacking forensic investigator. You have been called to collect the evidences of Buffer Overflows or Cookie snooping attack. Which of the following logs will you review to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 43
Multiple choice
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He has successfully completed the following steps of the preattack phase: -Information gathering -Determining network range -Identifying active machines -Finding open ports and applications -OS fingerprinting -Fingerprinting services Now John wants to perform network mapping of the We-are-secure network. Which of the following tools can he use to accomplish his task? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 44
Single choice
You have made a program secure.c to display which ports are open and what types of services are running on these ports. You want to write the program's output to standard output and simultaneously copy it into a specified file. Which of the following commands will you use to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 45
Multiple choice
Jason works as a System Administrator for Passguide Inc. The company has a Windows-based network. Sam, an employee of the company, accidentally changes some of the applications and system settings. He complains to Jason that his system is not working properly. To troubleshoot the problem, Jason diagnoses the internals of his computer and observes that some changes have been made in Sam's computer registry. To rectify the issue, Jason has to restore the registry. Which of the following utilities can Jason use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
Maria works as the Chief Security Officer for PassGuide Inc. She wants to send secret messages to the CEO of the company. To secure these messages, she uses a technique of hiding a secret message within an ordinary message. The technique provides 'security through obscurity'. What technique is Maria using?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 47
Multiple choice
You work as a professional Computer Hacking Forensic Investigator for DataEnet Inc. You want to investigate e-mail information of an employee of the company. The suspected employee is using an online e-mail system such as Hotmail or Yahoo. Which of the following folders on the local computer will you review to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
Temporary Internet Folder
-
D
Reveal answer details
Close answer details
Question 48
Single choice
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He observes that the We-are-secure server is vulnerable to a special type of DoS attack and he makes the following suggestions to the security authority to protect the server from this DoS attack. The countermeasures against this type of DoS attack are as follows: Disabling IP-directed broadcasts at the We-are-secure router Configuring local computers so as not to respond to such ICMP packets that are configured to be sent to IP broadcast addresses Which of the following DoS attacks has John discovered as a vulnerability for the We-are-secure security network?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 49
Multiple choice
Which of the following software can be used to protect a computer system from external threats (viruses, worms, malware, or Trojans) and malicious attacks? Each correct answer represents a part of the solution. Choose all that apply.
-
A
Employee monitoring software
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Multiple choice
Brutus is a password cracking tool that can be used to crack the following authentications: -HTTP (Basic Authentication) -HTTP (HTML Form/CGI) -POP3 (Post Office Protocol v3) -FTP (File Transfer Protocol) -SMB (Server Message Block) -Telnet Which of the following attacks can be performed by Brutus for password cracking? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
-
E
Reveal answer details
Close answer details
Question 51
Single choice
Which of the following is a transport layer circuit-level proxy server?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|