Fixed Single Master Operations Flexible Security Master Operations Flexible Single Master Operations Forest Single Master Operations Forest Security Master Operations Flexible Single Master Operations
The active direc
...
Fixed Single Master Operations Flexible Security Master Operations Flexible Single Master Operations Forest Single Master Operations Forest Security Master Operations Flexible Single Master Operations
The active directory database file is: - ANSWER NTDS.DAT NTDS.MDB MSAD.DIT NTDS.DIT MDAD.MDB NTDS.DIT
What command might you use to obtain a list of systems from a master browser, together with details about the version and available services. - ANSWER amap nbtstat lservers nbtquery hping3 lservers
What is used for authentication in a Microsoft Active Directory domain? - ANSWER RADIUS TACACS + TACACS + + Kerberos NIDS Kerberos
Which of the following Windows programs will list all the members of the Master Browser List? - ANSWER whoami dompromo lservers nbtstat None of the above nbtstat
"What does the following command achieve? - ANSWER
Telnet
- ANSWER
HEAD /HTTP/1.0 - ANSWER
- ANSWER
" - ANSWER This command returns the home page for the IP address specified This command opens a backdoor Telnet session to the IP address specified This command returns the banner of the website specified by the IP address This command allows a hacker to determine if the server has a SQL database None of these This command returns the banner of the website specified by the IP address
A system encrypts data prior to transmitting it over a network, and the system on the other end of the transmission media decrypts it. If the systems are using a symmetric encryption algorithm for encryption and decryption, which of the following statements is true? - ANSWER A symmetric encryption algorithm uses the same key to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm uses different keys to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm does not use keys to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm is an insecure method used to encrypt data transmitted over transmission media None of these A symmetric encryption algorithm uses the same key to encrypt and decrypt data at both ends of the transmission media
How many bits does SYSKEY use for encryption? - ANSWER 48 bits 56 bits 128 bits 256 bits None of these 128 bits
How many secret bits in a 128-bit WEP key? - ANSWER 128 64 104 40 96 104
In an IPSEC VPN there are four main attribute classes. Which of the following is NOT one of those classes? - ANSWER Encryption Algorithm Hash Algorithm Authentication Method Aggressive Mode Diffie-Hellman group Aggressive Mode
Of the following choices, what can you use to encrypt e-mail? - ANSWER HMAC RIPEMD PII S/ MIME None of these S/ MIME
Of the following choices, what is a benefit of IPsec? - ANSWER MAC filtering Flood guard Load balancing Payload encryption Secures your IP Payload encryption
Sally encrypted a project file with her public key. Later, an administrator accidentally deleted her account that had exclusive access to her private key. Can this project file be retrieved? - ANSWER No. If the private key is lost, the data cannot be retrieved Yes. The public key can decrypt the file Yes, if a copy of her public key is stored in escrow Yes, if the organization uses a recovery agent Yes, if she uses her password Yes, if the organization uses a recovery agent
What are the four mandatory transform attributes for an IKE Phase-1 SA? - ANSWER Encryption Algorithm, Hash Algorithm, Authentication Method, Diffie Hellman Group Encryption Algorithm, Key Length, Authentication Method, SA Lifetime SA Lifetime, Key length, PRF, Field Size SA Lifetime, Hash Algorithm, Authentication Method, PRF Protocol ID, Transform ID, IPsec Mode, Authentication Algorithm Encryption Algorithm, Hash Algorithm, Authentication Method, Diffie Hellman Group
What do programs, such as Tripwire, MD5sum, and Windows System File Protection, all rely on? - ANSWER Digital certificates Hashing Digital signatures Steganography Encryption Hashing
What does "export" signify for an SSL cipher - ANSWER It is a weak cipher that was acceptable for export under the old US cryptography export regulations It is the strongest cipher that is currently permitted to be exported from the US It is a cipher with integrated key escrow, which allows the NSA to recover the key It is a cipher that is suitable for encrypting information to be sent across national borders It is a stronger version of a cipher, similar to export versions of European lagers It is a weak cipher that was acceptable for export under the old US cryptography export regulations
What is IKE? - ANSWER Internet Key Exchange Initial Key Exchange IBM Key Exchange Internal Key Exchange Integrated Key Exchange Internet Key Exchange
What is SSL used for? - ANSWER Encrypt data as it travels over a network Encrypt files located on a Web server Encrypt passwords for storage in a database Encrypt specific elements of data for application-specific purposes Encrypt digital certificates used to authenticate a Web site Encrypt data as it travels over a network
What is the length of the IV for a WEP key? - ANSWER 128 bits 64 bits 40 bits 24 bits 56 bits 24 bits
Which of the following algorithms could be used to negotiate a shared encryption key? - ANSWER Triple-DES SHA1 DES AES Diffie-Hellman Diffie-Hellman
Which of the following is the correct definition of WEP? - ANSWER Wireless Encrypted Password Wired Equivalent Privacy Wireless Enabled Password Wireless Extended Privacy Wired Equivalent Password Wired Equivalent Privacy
Which of the following key sizes is considered the minimum recommended for a new SSL certificate? - ANSWER 768 bits 1024 bits 2048 bits 3072 bits 256 bits 2048 bits
Which of the following protocols was developed to be used for key exchange? - ANSWER Diffie-Hellman MD5 Rijndael Base64 None of these Diffie-Hellman
Which of the following services does not encrypt its traffic? - ANSWER DNS All of these SSH FTPS TLS DNS
Which of the following statements accurately describes the relationship between keys in a PKI? - ANSWER Data encrypted with a public key can only be decrypted with the matching private key Data encrypted with a public key can only be decrypted with the matching public key Data encrypted with a private key can only be decrypted with the matching private key The public key always encrypts and the private key always decrypts None of these Data encrypted with a public key can only be decrypted with the matching private key
Which of the following uses the same key to encode and decode data? - ANSWER RSA El Gamel ECC RC5 None of these RC5
Which ports do you have to open on a firewall to allow IKE VPN to function correctly? - ANSWER All VPN associated Ports All ports UDP 500, Protocol 50 & 51 135 and 445 TCP ICMP UDP 500, Protocol 50 & 51
Which protocols are associated with IPsec? - ANSWER IP protocol 89 UDP port 500, IP protocol 50 and IP protocol 51. TCP port 1723 and IP protocol 47 IP protocol 94 TCP port 443 UDP port 500, IP protocol 50 and IP protocol 51.
Why can remote access VPNs not use Main Mode for IKE Phase-1 if the authentication method is pre-shared key? - ANSWER Because remote access servers always use aggressive mode for IKE Phase-1 Because XAUTH is not compatible with IKE Main Mode Because IKE Main Mode does not support the pre-shared key authentication method Because pre-shared key authentication with Main Mode requires that the peer's IP is known before the connection is established Because remote access clients always use aggressive mode for IKE Phase-1 Because pre-shared key authentication with Main Mode requires that the peer's IP is known before the connection is established
Which of the following is an example of multifactor authentication? - ANSWER Smart card and PIN Thumbprint and voice recognition Thumbprint and voice recognition Password and PIN Password and Breathalyser Smart card and PIN
Which of the following is the best example of a strong two factor authentication? - ANSWER A passcard and a token A token and a pin number A username and a password A hand scan and fingerprint scan None of these A token and a pin number
Which of the following vulnerabilities can be associated with Password Autocomplete being enabled on a web page visible from the Internet? - ANSWER Anyone on the Internet can login without authentication credentials Anyone on the Internet that knows a valid username for the web page would not need to know the password A SQL injection vulnerability would allow passwords to be extracted from the back-end database A file disclosure vulnerability would allow an attacker to read the list of Autocompleted passwords on the website A vulnerability on a client workstation could be leveraged to discover and take advantage of cached passwords A vulnerability on a client workstation could be leveraged to discover and take advantage of cached passwords
Question - ANSWER Option 1 Option 2 Option 3 Option 4 Option 5 Correct Answer 1
What does NAC refer to in respect to Cisco? - ANSWER Network Access Control Network Authentication Command Network Administration Control Network Adapter Card Network Admission Control Network Admission Control
What is the significance of the string "SEP" in the configuration filename of a Cisco IP phone? - ANSWER It stands for Skinny Enchanced Phone It stands for Cisco Ethernet Phone, but someone misspelled it and the name stuck It stands for SIP Enhanced Phone No one knows It stands for Selsius Ethernet Phone, which was the original name of the Cisco IP phone It stands for Selsius Ethernet Phone, which was the original name of the Cisco IP phone
"What would be the effect of writing the string x to the following OID on a Cisco router running IOS 11? - ANSWER
.1.3.6.1.4.1.9.2.1.53.172.25.1.1" - ANSWER The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine The router whose IP address is 172.25.1.1 would have its system name changed to x The configuration file of the router would be downloaded to file x in the FTP root of the FTP server at 172.25.1.1 It would force the running config to be reloaded on the router whose IP address is 172.25.1.1 The configuration file x in the TFTP root of the TFTP server at 172.25.1.1 would be uploaded to the router The configuration file x in the TFTP root of the TFTP server at 172.25.1.1 would be uploaded to the router
"What would be the effect of writing the string x to the following OID on a Cisco router running IOS 11? - ANSWER
.1.3.6.1.4.1.9.2.1.55.172.25.1.1" - ANSWER The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine The router whose IP address is 172.25.1.1 would have its system name changed to x The configuration file of the router would be downloaded to file x in the FTP root of the FTP server at 172.25.1.1 It would force the running config to be reloaded on the router whose IP address is 172.25.1.1 The running config of the router would be downloaded to TFTP server at 172.25.1.1 and stored with a filename of x The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine
When downloading a Cisco router's config file, which of the following OIDs would be used to set the SourceFileType? - ANSWER 1.3.6.1.4.1.9.9.96.1.1.1.1.3.111 1.3.6.1.2.1.25.2.2.0 1.3.6.1.4.1.9.9.96.1.1.1.1.14.111 1.3.6.1.4.1.9.2.10.6.0 1.3.6.1.4.1.9.9.96.1.1.1.1.6.111 1.3.6.1.4.1.9.9.96.1.1.1.1.3.111
Which VLAN tag would a Cisco switch by default, use to tag your packets? - ANSWER VLAN0 VLAN1 VLAN99 VLAN100 nothing VLAN1
Which statement regarding a pentest report is true? - ANSWER Only the executive summary will be read by the IT/Information Security department. Senior management won't even bother with reading the report. Only the technical details will be read by the senior management. The IT/Information Security department won't even bother with reading the report. The technical details will be read by the IT/Information security people responsible. The technical details will be read by the IT/Information security people responsible.
What is Egress filtering (in terms of a network)? - ANSWER The practice of monitoring or potentially blocking incoming traffic from IP addresses that are not permitted to access the network. The practice of monitoring or potentially blocking outgoing traffic to IP addresses that are not permitted to be accessed. The practice of preventing employees from removing sensitive data via USB. The practice of preventing employees from installing viruses/malware via USB. Using air-gapped devices which have no interconnectivity. The practice of monitoring or potentially blocking outgoing traffic to IP addresses that are not permitted to be accessed.
Which Nmap command can allow you to perform an "Idle Zombie Scan" and what is the effect? - ANSWER Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses. Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of yours and the zombie addresses. Command: "nmap -f [target ip]. This gives you control of the target machine and adds it to your 1337 botnet. Command: "nmap -D [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of yours and the zombie addresses. Command: "nmap -D [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses. Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses.
Which statement is true regarding IPSec filters when compared to TCP/IP filters? - ANSWER IPSec filters can be applied to individual interfaces. IPSec filters can block subtypes of ICMP (eg. Echo, timestamp, echo reply etc.) They are both the same thing. IPSec filter cannot block ICMP at all. IPSec cannot be used to filter, only to tunnel sensitive traffic over encrypted channels. IPSec filters can be applied to individual interfaces.
Which statement regarding Authorisation and Authentication is true? - ANSWER Authorisation is the process where requests to access a particular resource is granted or denied. Authentication is providing and validating identity. Authentication is the process where requests to access a particular resource is granted or denied. Authorisation is providing and validating identity. Authentication includes the execution rules that determines what functionality and data the user can access. Authentication and Authorisation are both the same thing. Neither Authentication nor Authorisation are important. Authorisation is the process where requests to access a particular resource is granted or denied. Authentication is providing and validating identity.
What is a valid example of Code Injection? - ANSWER SQL injection. HTML script injection. Remote file injection. Shell injection. All of the above. All of the above.
An accepted limitation of Diffie-Hellman key agreement protocol is - ANSWER It is vital to keep the shared prime secret It can only generate encryption keys up to 128 bits It is vulnerable to a man-in-the-middle attack An attacker who can monitor the exchange can determine the shared se It is possible for one of the peers to control the generated secret It is vulnerable to a man-in-the-middle attack
DES has an effective key length of which of the following? - ANSWER 48 bit 56 bit 64 bit 128 bit 256 bits 56 bit
What are the valid key lengths for the AES encryption cipher? - ANSWER 128 and 256 56, 112 and 168 64, 128 and 256 128, 192 and 256 128, 160 and 256 128, 192 and 256
What encryption standard was chosen as the replacement for 3DES? - ANSWER RC5 ECC Knapsack Rijndael Blowfish Rijndael
What happens if you digitally sign and inject a footer on an e-mail message in the wrong order? - ANSWER Nothing The message won't be sent The footer will invalidate the signature The footer will be illegible The header will show that the email is still valid The footer will invalidate the signature
What hashing algorithm produces a 128-bit hash value? - ANSWER MD5 3DES SHA-1 AES SHA-256 MD5
What is a hash function? - ANSWER An encryption algorithm for sending encrypted data to a trusted recipient A decryption algorithm to decrypt data from a trusted source An algorithm to scramble the characters in a string A one way mathematical function that does not allow the original value to be calculated from the result A random number generator A one way mathematical function that does not allow the original value to be calculated from the result
What is the blocksize of the AES encryption cipher? - ANSWER 64 bits 40 bits 56 bits 256 bits 128 bits 128 bits
What is the blocksize of the DES encryption cipher? - ANSWER 128 bits 112 bits 56 bits 64 bits 40 bits 64 bits
What is the difficulty with Symmetric encryption? - ANSWER Assurance of secure receipt of the secret key used both for encrypting and decrypting Assurance of secure receipt of the secret key used only for decrypting (separate key used for encrypting) Assurance of secure sending of the encrypted message Assurance of secure receipt of the encrypted message None of these Assurance of secure receipt of the secret key used both for encrypting and decrypting
What is the digest length for the SHA1 hash function? - ANSWER 192 bits 128 bits 160 bits 56 bits 256 bits 160 bits
What is the key size for the Data Encryption Standard (DES) encryption mechanism? - ANSWER 40 56 64 112 128 64
What is the purpose of message integrity codes (HMAC) - ANSWER To simultaneously verify confidentiality of message (via message sequencing) and authenticity of message (by use of a secret key) To ensure message integrity via cryptographic hashing functions To simultaneously verify both data integrity (via cryptographic hashing function) and message authenticity (by use of a secret key) To verify message authenticity and confidentiality via the use of a SHA hashing function None of these To simultaneously verify both data integrity (via cryptographic hashing function) and message authenticity (by use of a secret key)
What is this: password 7 052D131D33556C081D021200 - ANSWER A password encoded with Unix crypt A password encoded with unsalted DES A password encoded with salted MD5 A password encoded with the reversible Cisco vigenere algorithm A password with the literal value "052D131D33556C081D021200" A password encoded with the reversible Cisco vigenere algorithm
Which encryption algorithm uses prime numbers to generate keys? - ANSWER RSA SHA S/ MIME PGP None of these RSA
Which is the least secure encryption cipher of those listed below? - ANSWER Triple-DES MD5 AES DES IDEA DES
Which of the following algorithms cannot be used for reversible encryption? - ANSWER 3DES SHA-256 Blowfish AES-128 Diffie Hellman SHA-256
Which of the following best describes Tripwire? - ANSWER It is used as a firewall to prevent attacks It is used as an IPS to defend against intruders It is used encrypt sensitive files It is used to verify integrity It is used as an IDS to detect intruders It is used to verify integrity
Which of the following changes to a file would result in its hash output being different, if subjected to the same hash function? - ANSWER rename the file extension change the content change the file size all of these None of these all of these
Which of the following cipher modes use a block cipher to generate a key stream that can be used as a stream cipher? - ANSWER CBC CFB ECB EDE ABC CFB
Which of the following encryption algorithms is an asymmetric cipher? - ANSWER DES 3DES AES RSA RC5 RSA
Which of the following is an advantage of using a salt value in a password encryption algorithm? - ANSWER The salt acts as a preservative, allowing a password to be used longer It allows the plaintext password to be recovered by decrypting the hash Two users with the same password will have different password hashes Password cracking is much faster The storage space for each hash is reduced by 50% Two users with the same password will have different password hashes
Which of the following is considered the weakest form of DES? - ANSWER DES ECB DES CBC DES CFM DES OFB DES EEB DES ECB
Which of the following is used for integrity? - ANSWER DES Diffie-Hellman MD5 AES None of these MD5
Which of the following represents the weakest form of security? - ANSWER DES ECB RC5 Base64 AES 3DES Base64
How would Bob prove to Alice that he is the original creator of a document? - ANSWER Sign it with Bob's private key Sign it with Bob's public key Sign it with Alice's private key Sign it with Alice's public key Hash the document Sign it with Bob's private key
Of the following choices, what is the best way to protect the confidentiality of data? - ANSWER Authentication Encryption Hashing PaaS PTH Encryption
"The following request to an IIS webserver is an example of what kind of attack? - ANSWER
http://www.example.com/scripts/..%255c../winnt/system32/attrib.exe?c:\*.*" - ANSWER Buffer overflow Cross-site scripting IIS Unicode double decode directory traversal SQL injection IIS Unicode single decode directory traversal IIS Unicode double decode directory traversal
"You discovered the following in the logs: - ANSWER
192.186.13.100/myserver.aspx..%255C..%255C..%255C..%255C..%255C..%255C..%255C..%255C..%255C..%255..c:\winnt\system32\cmd.exe%/c:dir - ANSWER
What is the hacker attempting to do?" - ANSWER Directory traversal attack Buffer overflow .+htr attack Execute MS Blaster None of these Directory traversal attack
"In the SOA record below, what is hostmaster.lab.net? - ANSWER
lab.net. - ANSWER 3600 IN SOA dc01.lab.net. hostmaster.lab.net. 2000093195 900 600 86400 3600" The canonical name of the primary DNS server The hostname of the mail server The email address of the administrator An alias for the canonical name of the primary DNS server The hostname of a secondary DNS server The email address of the administrator
"In the SOA record below, which is the serial number of the DNS server? - ANSWER
lab.net. - ANSWER 3600 IN SOA dc01.lab.net. hostmaster.lab.net. 2000093195 900 600 86400 3600" 2000093195 900 3600 86400 600 2000093195
"One of your team members has asked you to analyze the following SOA record: - ANSWER
Test123.com.SOA NS1.test123.com person.com (200509024 3600 3600 604800 2400) - ANSWER
Based on this information, which of the following is the correct TTL?" - ANSWER 200509024 3600 604800 2400 None of these 2400
The DNS entries for www.customer.com and www.example.com both point to the same IP address. How does the web server know which domain is being requested by the browser? - ANSWER It inspects the cookies sent by the client It uses the HTTP Host: header Both websites must have the same content It inspects the client's SSL certificate It uses a reverse DNS lookup of the client's IP address It uses the HTTP Host: header
What does the DNS SOA record type stand for? - ANSWER Start of Address Start of Answer Start of Authority Sausage Order Alert Statement of Address Start of Authority
"What does the following query attempt to do, where dns.target.com is a DNS server? - ANSWER
dig @dns.target.com version.bind txt chaos" - ANSWER Launch a Denial of Service attack Perform a zone transfer Update a secondary nameserver server from the primary Identify the software version Determine the authoritative nameserver for the version.bind zone Identify the software version
Which command will perform a DNS zone transfer of the domain "company.com" from the nameserver at 10.0.0.1? - ANSWER dig @10.0.0.1 company.com zone-transfer dig @10.0.0.1 company.com.zone dig @10.0.0.1 company.com ls dig @10.0.0.1 company.com any dig @10.0.0.1 company.com axfr dig @10.0.0.1 company.com axfr
Which command will retrieve the version number from default installations of the BIND nameserver software? - ANSWER dig @nameserver bind.version txt chaos dig @nameserver bind-version txt chaos dig @nameserver version.bind txt chaos dig @nameserver nameserver.version txt chaos dig @nameserver version.bind hinfo chaos dig @nameserver version.bind txt chaos
Which of the following commands attempts to obtain a zone transfer? - ANSWER dig @ all host @ all host @ axfr dig @ axfr nslookup -vv @ dig @ axfr
Which of the following is a type of DNS record? - ANSWER CNAME HINFO MX A All of the above All of the above
Which of the following is NOT a valid DNS record type? [Source: Name Server Operations Guide for BIND Release 4.9.5]. - ANSWER NWS News Server MX A CNAME HINFO NWS News Server
"Which of the following terms should replace something in the following description? [Source: Name Server Operations Guide for BIND Release 4.9.5]. - ANSWER
A thing is a point of delegation in the DNS tree. It contains all names from a certain point ‘‘downward’’ except those which are delegated to other things." - ANSWER Zone Domain Host Node Leaf Zone
Which protocol and port does a DNS zone transfer use? - ANSWER TCP port 43 TCP port 53 UDP port 43 TCP port 45 UDP port 53 TCP port 53
Which protocol and port does a normal DNS lookup use? - ANSWER UDP port 43 TCP port 45 TCP port 43 UDP port 53 TCP port 53 UDP port 53
While preparing to hack a targeted network, you would like to check the configuration of the DNS server. What port should you look for to attempt a zone transfer? - ANSWER UDP port 53 TCP port 79 TCP port 53 TCP port 79 None of these TCP port 53
You are hoping to exploit a DNS server and access the zone records. As such, when does a secondary name server request a zone transfer from a primary name server? - ANSWER When a secondary SOA serial number is higher than a primary SOA When a primary name server has had its service restarted When the TTL reaches 0 When a primary SOA serial number is higher that a secondary SOA When the serial numbers are the same When a primary SOA serial number is higher that a secondary SOA
You have become concerned that someone could attempt to poison your DNS server. What determines how long cache poisoning would last? - ANSWER A record CNAME SOA MX All of these SOA
How would you establish a null session to a windows host from a windows command shell? - ANSWER NET USE \\hostname\c$ "" /u:NULL NET USE \\hostname\c$ "" /u:"" NET USE \\hostname\ipc$ "" /u:"" NET USE \\hostname\ipc$ "" /u:NULL NET USE \\hostname\ipc$ NULL /u:NULL NET USE \\hostname\ipc$ "" /u:""
"You are preparing to attack several critical servers and perform the following command: - ANSWER
net use \\windows_server\ipc$ "" /u:"" - ANSWER
What is its purpose?" - ANSWER Grabbing the etc/passwd file Stealing the SAM Probing a Linux-based Samba server Establishing a null session It does nothing Establishing a null session
"Which part of the following SQL Server password hash is the salt value? - ANSWER
0x01008444930543174C59CC918D34B6A12C9CC9E" - ANSWER 1008444 84449305 43174C59 769F819B 12C9CC9E 84449305
How many characters is the output of an MD5sum? - ANSWER 128 characters 64 characters 32 characters 16 characters 24 characters 32 characters
Which of the following best describes what happens when two message digests produce the same hash? - ANSWER Fragments Collisions Agreements Hash completion "Pass the hash" Collisions
If, during an authorised penetration test, you discover evidence of an intrusion on the target, which of the following would be the most appropriate course of action for the team? - ANSWER Note the result and continue. Call the police. Identify the source of the attack and include it in the scope of the test. Gather as much evidence as possible. Halt all test activities and contact the customer. Halt all test activities and contact the customer.
What is the difference between a network vulnerability assessment and a penetration test? - ANSWER A penetration test identifies running services, and vulnerability assessments provide a more in-depth understanding of vulnerabilities. A penetration test enumerates resources, and a vulnerability assessment enumerates vulnerabilities. A penetration test exploits vulnerabilities, and a vulnerability assessment finds vulnerabilities. They are one and the same. A penetration test confirms that all the IT controls have been correctly implemented A penetration test exploits vulnerabilities, and a vulnerability assessment finds vulnerabilities.
What is the normal sequence of events in a penetration test? - ANSWER Testing, Scoping, Report Writing, Debrief Scoping, Testing, Report Writing, Debrief Debrief, Testing, Scoping, Report Writing Testing, Scoping, Debrief, Report Writing Scoping, Report Writing, Testing, Debrief Scoping, Testing, Report Writing, Debrief
Which process would you NOT expect to be included in a penetration test? - ANSWER Forensic investigation Scoping Testing Report Writing Debrief Forensic investigation
You have been asked to prepare a quote for a potential client who is requesting a penetration test. Which of the following listed items is the most important to ensure the success of the penetration test? - ANSWER A well-documented planned testing procedure A proper schedule that specifies the timed length of the test The involvement of the management of the client organisation The experience and qualifications of the staff involved in the pen test A safe and comfortable working environment The involvement of the management of the client organisation
You just noticed a member of your pen test team sending an email to an address that you know does not exist within the company for which you are contracted to perform the penetration test. Why is he doing this? - ANSWER To determine who is the holder of the root account To determine if the email server is vulnerable to a relay attack To test the networks IDS systems To generate a response back that will reveal information about email servers To exfiltrate data from the company's network to an external address To generate a response back that will reveal information about email servers
On a Unix system, what is the effect of the execute bit on a directory? - ANSWER It allows all files in the directory to be executed It allows the directory to be executed It allows the directory to be traversed It depends on the version of Unix that is being used It has no effect It allows the directory to be traversed
What effect would an octal umask of 0027 have on the permissions of new files? - ANSWER It has no effect on new files because it only affects existing files Remove SUID, SGID and Sticky bits, remove all owner permissions Add SUID, SGID and Sticky bits, add all owner permissions Add group write access, and add all permissions for others Remove group write access, and remove all permissions for others Remove group write access, and remove all permissions for others
What identifies the superuser on a Unix or Linux system? - ANSWER Any user with UID 65535 in the password file Anyone who logs on at the system console Any user that belongs to the "root" group in the group file The user with the username "root" in the password file Any user with UID 0 (zero) in the password file Any user with UID 0 (zero) in the password file
What would the command 'chmod 755 ' mean implement to '' - ANSWER Read and write access to owner and group and execute access to world Read, write and execute access to owner and read access to group and world Execute access to all and read, write and execute access to owner Read and execute access for all and read, write and execute access for owner None of these Read and execute access for all and read, write and execute access for owner
An organization has a web security gateway installed. What function is this performing? - ANSWER MAC filtering Caching content Hiding internal IP addresses Content filtering None of these Content filtering
Which of the following best describes a wrapper? - ANSWER Wrappers are used as tunneling programs. Wrappers are used to cause a Trojan to self execute when previewed within email. Wrappers are used as backdoors to allow unauthenticated access. Wrappers are used to package covert programs with overt programs. None of these Wrappers are used to package covert programs with overt programs.
While scanning the target network, you discovered that all the web servers in the DMZ respond to ACK packets on port 80. What does this tell you? - ANSWER All the servers are Windows based The target organization is not using an IDS All the servers are UNIX based The target organization is using a packet filter Port 80 is blocked The target organization is using a packet filter
Of the following choices, which one provides the most security for FTP? - ANSWER FTP active mode FTPS TFTP SCP SSH FTPS
"What does the following PORT command mean? - ANSWER
PORT 10,2,0,2,10,10" - ANSWER The FTP client at 10.2.0.2 will be listening on TCP 10 The FTP client at 10.2.0.2 will be listening on TCP 110 The FTP client at 10.2.0.2 will be listening on TCP 1010 The FTP client at 10.2.0.2 will be listening on TCP 2570 The FTP client at 10.2.0.2 will be listening on TCP 257 The FTP client at 10.2.0.2 will be listening on TCP 1010
What does the acronym FTP stand for? - ANSWER Fast Transfer Protocol File Transit Protocol Fast Transport Protocol Fully Transferable Protocol File Transfer Protocol File Transfer Protocol
You discover an Internet accessible anonymous FTP server on a client's internal network, which is vulnerable to the FTP bounce attack. What is the impact of this vulnerability? - ANSWER Attackers could exploit the vulnerability to access any file on the FTP server Attackers could exploit the vulnerability to upload files to the FTP server Attackers could exploit the vulnerability to port scan other systems on the client's internal network Attackers could exploit the vulnerability to intercept network traffic on the client's internal network Attackers could exploit the vulnerability to gain administrative access to the FTP server Attackers could exploit the vulnerability to port scan other systems on the client's internal network
An idle scan makes use of which of the following parameters? - ANSWER The datagram size The segment size The IPID The ACK number None of these The IPID
"Consider the following output from your connection to an open port on a target: - ANSWER
C:\>telnet 10.10.10.1 8000 - ANSWER
Microsoft Windows XP [Version 5.1.2600] - ANSWER
(C) Copyright 1985-2001 Microsoft Corp. - ANSWER
E:\inetpub\scripts> - ANSWER
Which of the following services are most likely listening on TCP port 8000 of the target?" - ANSWER IIS FTP SMTP Telnet Windows command shell Windows command shell
How can you tell when a TCP port is open on a target IP address? - ANSWER No response is received The target returns SYN|ACK The target returns RST The target returns SYN The target returns ACK The target returns SYN|ACK
How can you tell when a UDP port is closed on a target IP address? - ANSWER No response is received The target returns an ICMP_TIME_EXCEEDED The target returns a TCP reset packet The target returns an ICMP_PORT_UNREACHABLE It is not possible to tell when a UDP port is closed on a target IP address The target returns an ICMP_PORT_UNREACHABLE
If nmap is used to scan a port and returns the status 'open|filtered', what does this mean? - ANSWER The TCP port is open but not responding The TCP port is either open or filtered The UDP port has been filtered by a firewall The UDP port has been filtered or is listening but not responding None of these The UDP port has been filtered or is listening but not responding
"What does it mean if traceroute output includes a time annotation of !X, as in the following extract from traceroute output? - ANSWER
[Show More]