1/42
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which of the following protocols distributes, inquiries into, retrieves, and posts news articles using a reliable stream-based transmission of news among the ARPA-Internet community?
NNTP
Which of the following protocols is vulnerable to a sniffing attack as passwords and data are sent in clear text?
FTP
Which of the following protocols is a TCP/IP-based protocol used to exchange management information between devices connected on a network?
snmp
telnet
is a protocol used for communicating with a remote host (via port 23) on a network using a command-line terminal
POP
allows a user’s workstation to access mail from a mailbox server. A user can send mail from the workstation to the mailbox server via SMTP.
SNMP
TCP/IP-based protocol used for exchanging management information between devices connected on a network. The first version of SNMP (SNMPv1) does not offer strong security, which leads to the transfer of data in a cleartext format.
In which of the following OSI layers do sniffers operate and perform an initial compromise?
data link
Smith, a professional hacker, initiated a network sniffing attack on the switched Ethernet environment of a target organization. He employed an automated tool to flood the switch with a fake physical address until the switch translation table became full. When the switch entered fail-open mode, it started acting as a hub by broadcasting packets. Now, Smith could easily accomplish his goal of network sniffing.
Identify the type of attack performed by Smith in the above scenario.
MAC flooding
Clark, a professional hacker, targeted an organization’s network to steal credentials being shared during active sessions. He collected the physical address of the legitimate users connected to the switch port. Then, Clark started spoofing his physical address with the physical address of a legitimate client and received all the traffic destined for that client.
Which of the following attacks has Clark performed in the above scenario?
MAC duplicating
DNS poisoning
the attacker tricks a DNS server into believing that it has received authentic information when, in reality, it has not received any. The attacker tries to redirect the victim to a malicious server instead of the legitimate server.
ARP spoofing
involves constructing a large number of forged ARP request and reply packets to overload a switch. When a machine sends an ARP request, it assumes that the ARP reply will come from the right machine
DHCP Starvation
an attacker floods the DHCP server by sending numerous DHCP requests and uses all of the available IP addresses that the DHCP server can issue.
MAC duplicating attack
the attacker first retrieves the MAC addresses of clients who are actively associated with the switch port. Then, the attacker spoofs a MAC address with the MAC address of the legitimate client. If the spoofing is successful, then the attacker can receive all the traffic destined for the client.
George, a professional hacker, targeted an organization’s server to cause reputational damage to the organization. For this purpose, he employed an ARP poisoning tool that forges ARP replies from the target server resulting in customers navigating to the attacker-owned host, which contains irrelevant information for the customers.
Which of the following tool helped George in the above scenario to perform an ARP poisoning attack?
Ettercap
Trape
is an OSINT analysis and research tool, which allows people to track and execute intelligent social engineering attacks in real time.
LUCY
enables organizations to take on the role of an attacker (phishing simulation) and identify gaps in both the technical infrastructure and security awareness.
Netstat
tool helps in collecting information about network connections operative in a Windows system.
Which of the following tool helps an attacker perform an ARP poisoning attack?
BetterCAP
Identify the technique that sends non-broadcast ARP to all the nodes in the network, and the node that runs in promiscuous mode broadcasts a ping message on the network with the local IP address but a different MAC address.
ARP method
Which of the following techniques is useful in detecting a system that runs in promiscuous mode and in turn helps detect sniffers installed on the network?
Ping method
Williams, a professional hacker, was hired by an organization to damage the reputation of their rival company. Williams spoofed a customer’s rival company’s IP address and initiated sending multiple ICMP ECHO request packets to an IP broadcast network. As a result, all the hosts together started sending responses to the customer’s IP address. These responses were sent to the customer machine, diverting significant traffic toward it and crashing it in the process.
Identify the type of attack performed by Williams in the above scenario.
Smurf Attack
Smurf Attack
, the attacker spoofs the source IP address with the victim’s IP address and sends a large number of ICMP ECHO request packets to an IP broadcast network.
Ping of death
attacker attempts to crash, destabilize, or freeze the target system or service by sending malformed or oversized packets using a simple ping command.
Fragmentation attack
destroys a victim’s ability to reassemble fragmented packets by flooding it with TCP or UDP fragments, resulting in reduced performance.
SYN flood attack
in a SYN attack, the attacker sends a large number of SYN requests to the target server (victim) with fake source IP addresses. The attack creates incomplete TCP connections that use up network resources.
Identify the attack technique that purely targets hardware devices by exploiting their security flaws and causes irreversible damage to the system hardware, requiring the victim to replace the hardware.
Phlashing
Phlashing
, purely target hardware and cause irreversible damage to the hardware. Unlike other types of DoS attacks, it sabotages the system hardware, requiring the victim to replace or reinstall the hardware.
ARP spoofing
involves constructing a large number of forged ARP request and reply packets to overload a switch.
DHCP Starvation attack
In a DHCP starvation attack, an attacker floods the DHCP server by sending numerous DHCP requests and uses all of the available IP addresses that the DHCP server can issue. As a result, the server cannot issue any more IP addresses, leading to a DoS attack.
MAC flooding
is a technique used to compromise the security of network switches that connect network segments or devices. Attackers use the MAC flooding technique to force a switch to act as a hub so that they can easily sniff the traffic.
Rachel, a network pen tester, was inspecting her organization’s network and web applications and was testing whether they were vulnerable to service disruption. She utilized a tool that could perform network stress testing and perform a DoS attack by flooding the server with TCP packets to interrupt the normal services.
Which of the following tool was utilized by Rachel in the above scenario?
Low orbit ion cannon
Noah, a professional hacker, planned to launch a DDoS attack on his target organization and disrupt their normal services. He employed a tool designed to attack up to 256 target URLs simultaneously, and it can also send HTTP POST and GET requests to a computer that uses lulz-inspired GUIs.
Which of the following tool helped Noah perform the DDoS attack?
High orbit ion cannon
Joe, an attacker, was hired to target a company’s server and make its services unavailable to valid users. Joe employed a command-line-oriented tool to initiate a DoS attack on the targeted website’s server by crafting custom ICMP echo request packets.
Which of the following command-line tool helped Joe launch the DoS attack?
hping3
Lopez, a professional hacker, targets his opponent’s system and performs spoofing attacks by using multiple intermediary and secondary machines. He exploited the TCP three-way handshake vulnerability and initiated sending requests to the intermediary hosts, reflecting the attack traffic to the target.
Identify the attack technique employed by Lopez in the above scenario.
DRDOS attack
DRDOS attack
k, involves the use of multiple intermediary and secondary machines that contribute to a DDoS attack against a target machine or application. A DRDoS attack exploits the TCP three-way handshake vulnerability.
Peer to peer attack
is a form of DDoS attack in which the attacker exploits a number of bugs in peer-to-peer servers to initiate a DDoS attack. Attackers exploit flaws found in networks that use the Direct Connect (DC++) protocol, which allows the exchange of files between instant-messaging clients.
Which of the following countermeasures helps security teams defend against DoS and DDoS attacks on the network and system?
prevent the use of get
Which of the following best practices should be followed to thwart DoS/DDoS attacks?
Block all inbound packet orginating from service port
Jack, a professional hacker, has targeted a website that uses linear algorithms to create shorter session IDs for logged-in users. Jack created a forged valid session ID and logged in to other accounts by studying the sequential pattern.
Which of the following weaknesses has Jack exploited in the above scenario to hijack session IDs?
Weak session ID generation
James, a professional hacker, performed a session hijacking attack against a victim connected to the same network. James captured the TCP sequence and acknowledgment numbers of the victim to craft his own packets. He then interrupted the connection between the server and the victim and injected the crafted packets into the server as a legitimate user.
Given below are different steps followed by James when performing session hijacking:
Session desynchronization
Monitor
Session ID prediction
Sniff
Command injection
Identify the correct sequence of steps involved in session hijacking.
4 -> 2 -> 1 -> 3 -> 5
In which of the following techniques does an attacker predict the sequence numbers that a victim host sends to create a connection that appears to originate from the host and then hijacks the communication?
blind hijacking
In which of the following session hijacking phases does an attacker break the connection to the victim’s machine by knowing the next sequence number (NSN)?
Sequence desynchronization
David, a network administrator, was assigned to analyze the network for signatures of a session hijacking attack on an organization. David captured all the network traffic using packet sniffing tools and used various filters to find any repeated ARP update packets.
Which of the following methods has David employed in the above scenario to detect session hijacking attacks?
manual method