EHE: Chapter 2- ethical hacking fundamentals

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/28

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:46 PM on 9/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

29 Terms

1
New cards

Given below are the various phases involved in the cyber kill chain methodology.

  1. Installation

  2. Delivery

  3. Reconnaissance

  4. Actions on objectives

  5. Weaponization

  6. Exploitation

  7. Command and control


3 -> 5 -> 2 -> 6 -> 1 -> 7 -> 4

2
New cards

John, a professional hacker, targeted a newly joined employee of an organization. He sent a malicious payload via a phishing email that insisted that the user reset his official account’s password on a priority basis and warned that his account would be blocked if the email were ignored.

Identify the phase ofcyber kill chain methodologyJohn has performed in the above scenario.

delivery

3
New cards

installation

adversary downloads and installs more malicious software on the target system to maintain access to the target network for an extended period.

4
New cards

exploitation

After the weapon is transmitted to the intended victim, exploitation triggers the adversary’s malicious code to exploit a vulnerability in the operating system, application, or server on a target system.

5
New cards

reconnaissance

An adversary performs reconnaissance to collect as much information about the target as possible to probe for weak points before actually attacking. They look for information such as publicly available information on the Internet, network information, system information, and the organizational information of the target.

6
New cards

Clara, a security professional, while checking the data feeds of the domains, detects downloaded malicious files and unsolicited communication with the outside network based on the domains.

Which of the following adversary behaviors was detected by Clara?

unspecified proxy activities

7
New cards

James, a professional hacker, successfully penetrated the target’s network and now wants to gather as much information as possible. To achieve this, he uses a technique that can collect and combine as much information as possible, including business tactics of the organization, financial information, and network infrastructure information.

Which of the following techniques was used by James in the above scenario?

data staging

8
New cards

Adele, a professional hacker, initiated an attack on an organization. During the course of this attack, he established a two-way communication channel between the target system and his server to communicate and pass data back and forth. Additionally, he employed encryption to hide the communication channel.

Which of the following phases of cyber kill chain methodology was Adele performing in the above scenario?

command and control

9
New cards

Command and control

The adversary creates a command-and-control channel, which establishes two-way communication between the victim’s system and adversary-controlled server to communicate and pass data back and forth.

10
New cards

Weaponization

The adversary analyzes the data collected in the previous stage to identify the vulnerabilities and techniques that can exploit and gain unauthorized access to the target organization.

11
New cards

Given below are the various phases of hacking.

  1. Reconnaissance

  2. Gaining access

  3. Maintaining access

  4. Clearing tracks

  5. Scanning

What is the correct sequence of phases involved in hacking?


1 -> 5 -> 2 -> 3 -> 4



12
New cards

In which of the following phases of hacking does an attacker employ steganography and tunneling techniques to retain access to the victim’s system, remain unnoticed, and remove evidence that might lead to prosecution?

clearing tracks

13
New cards

in which of the following hacking phases do attackers extract information such as live machines, port, port status, OS details, device type, and system uptime to launch further attacks?

scanning

14
New cards

Lopez, a penetration tester, executes different phases of the hacking cycle in her organization. She detects that the network is susceptible to password cracking, buffer overflows, denial of service, and session hijacking attacks.

Identify the hacking phase Lopez was executing in the above scenario.

gaining acess

15
New cards

John, a security specialist, was requested by a client organization to check whether the security testing process was performed according to standard. He implemented a security audit on the organization’s network to ensure that the performed test was well-organized, efficient, and ethical.

John has conducted the audit following the steps given below.

  1. Talk to the client and discuss the needs to be addressed during testing

  2. Analyze the results of the testing and prepare a report

  3. Organize an ethical hacking team and prepare a schedule for testing

  4. Conduct the test

  5. Prepare and sign NDA documents with the client

  6. Present the findings to the client

Identify the correct sequence of the steps John has followed while performing the security audit.


1 -> 5 -> 3 -> 4 -> 2 -> 6

16
New cards

Which of the following Google advanced search operators displays websites that are similar to the URL specified?

related

17
New cards

cache

this operator displays Google's cached version of a web page instead of the current version of the web page.

18
New cards

allinurl

Restricts the results to those containing all the search keywords in the URL.

19
New cards

info

This operator finds information for the specified web page.

20
New cards

Megaping

MegaPing includes scanners such as Comprehensive Security Scanner, Port scanner (TCP and UDP ports), IP scanner, NetBIOS scanner, and Share Scanner. It provides the following information: NetBIOS names, Configuration info, open TCP and UDP ports, Transports, Shares, Users, Groups, Services, Drivers, Local Drives, Sessions, and Remote Time of Date, Printers.

21
New cards

Shellphish

ShellPhish is a phishing tool used to phish user credentials from various social networking platforms such as Instagram, Facebook, Twitter, and LinkedIn.

22
New cards

Netcraft

The Netcraft anti-phishing community is a giant neighborhood watch scheme, empowering the most alert and most expert members to defend everyone within the community against phishing attacks.

23
New cards

Tor Browser

used to access the deep and dark web, where it acts as a default VPN for the user and bounces the network IP address through several servers before interacting with the web.

24
New cards

nbtstat -c

Lists the contents of the NetBIOS name cache, the table of NetBIOS names and their resolved IP addresses

25
New cards

nbtstat -r

Displays a count of all names resolved by a broadcast or WINS server

26
New cards

mbtstat -R

Purges the name cache and reloads all #PRE-tagged entries from the Lmhosts file

27
New cards

nbtstat -S

Lists the current NetBIOS sessions and their status with the IP addresses

28
New cards

Given below is the syntax of the nbtstat command.

nbtstat [-a RemoteName] [-A IP Address] [-c] [-n] [-r] [-R] [-RR] [-s] [-S] [Interval]

Which of the following Nbtstat parameters in the above syntax purges the name cache and reloads all #PRE-tagged entries from the Lmhosts file?

-R

29
New cards