Unit 3: Enumeration, System Hacking, Malware - Practice Quiz

INT244 — Securing Computing Systems 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 What is the primary goal of Enumeration in the ethical hacking process?

A. To gather specific information like user names, shares, and services from a system
B. To encrypt the target's data
C. To crash the target system
D. To physically access the server room

2 Which phase of hacking immediately precedes Enumeration?

A. Clearing Tracks
B. Maintaining Access
C. Scanning
D. System Hacking

3 In Windows Enumeration, what is a 'Null Session'?

A. A connection using an encrypted VPN
B. A session with administrator privileges
C. An unauthenticated connection to the IPC$ share
D. A session that has been timed out

4 Which port is primarily associated with NetBIOS Name Service?

A. Port 137
B. Port 80
C. Port 21
D. Port 443

5 What command-line tool is used to display NetBIOS over TCP/IP statistics and current connections?

A. ping
B. tracert
C. ipconfig
D. nbtstat

6 What does SNMP stand for?

A. Secure Network Monitoring Protocol
B. System Node Maintenance Protocol
C. Simple Network Management Protocol
D. Standard Network Mapping Procedure

7 In SNMP, what is the 'MIB'?

A. Main Interface Bridge
B. Malware Infection Block
C. Management Information Base
D. Master IP Block

8 What are the two default community strings often used in SNMP?

A. default and secure
B. admin and user
C. root and guest
D. public and private

9 Which protocol is targeted during Directory Service Enumeration to query Active Directory?

A. FTP
B. SSH
C. LDAP
D. HTTP

10 What is the default TCP port for LDAP?

A. 25
B. 53
C. 3389
D. 389

11 Which SMTP command is used to verify if a user exists on the mail server?

A. QUIT
B. VRFY
C. DATA
D. HELO

12 Which SMTP command expands a mailing list to show its members?

A. EXPN
B. RCPT
C. MAIL
D. RSET

13 What is the definition of System Hacking?

A. Scanning a network for live hosts
B. The process of gaining access, escalating privileges, and hiding files
C. Developing security policies
D. Monitoring network traffic for anomalies

14 Which password attack involves trying every possible combination of characters?

A. Dictionary Attack
B. Brute Force Attack
C. Social Engineering
D. Shoulder Surfing

15 What is a 'Rainbow Table' used for?

A. Looking up pre-computed password hashes
B. Storing firewall rules
C. Encrypting email communications
D. Visualizing network traffic

16 Adding random bits of data to a password before hashing it to defeat Rainbow Tables is called:

A. Spiceing
B. Masking
C. Peppering
D. Salting

17 In Microsoft Windows, where are local user account passwords stored (in hashed form)?

A. In the boot.ini file
B. In the Registry SAM file
C. In the kernel32.dll
D. In the My Documents folder

18 What is the legacy authentication protocol used by older Windows systems, known for vulnerabilities?

A. RADIUS
B. OAUTH
C. NTLM
D. Kerberos

19 What is the primary authentication protocol used in Active Directory environments?

A. WEP
B. Kerberos
C. SSL
D. CHAP

20 What entity issues tickets in the Kerberos protocol?

A. The Gateway
B. The File Server
C. The Key Distribution Center (KDC)
D. The Client

21 What is 'Privilege Escalation'?

A. Resetting a password
B. Gaining higher-level access (e.g., Administrator) from a standard user account
C. Downgrading user rights to Guest
D. Moving laterally to another computer with same rights

22 Which tool allows an attacker to execute processes on a remote system, often used in Windows environments?

A. PsExec
B. Notepad
C. Paint
D. Calc

23 Software designed to infiltrate or damage a computer system without the owner's informed consent is collectively known as:

A. Freeware
B. Malware
C. Firmware
D. Shareware

24 What distinguishes a Computer Virus from a Worm?

A. A virus encrypts data, a worm deletes it
B. There is no difference
C. A virus travels over networks, a worm stays local
D. A virus requires a host program to replicate, while a worm is standalone

25 Which type of malware disguises itself as legitimate software to trick the user into installing it?

A. Virus
B. Logic Bomb
C. Worm
D. Trojan Horse

26 What is the primary function of Ransomware?

A. To turn the computer into a bot
B. To encrypt user files and demand payment for the decryption key
C. To display advertisements
D. To steal credit card numbers quietly

27 Software that gathers information about a person or organization without their knowledge is called:

A. Logic Bomb
B. Adware
C. Ransomware
D. Spyware

28 Malware that automatically delivers advertisements is known as:

A. Botnet
B. Adware
C. Virus
D. Rootkit

29 What is 'Scareware'?

A. Malware that tricks users into buying unnecessary software by claiming their computer is infected
B. Software that screams when opened
C. A worm that spreads via email
D. A virus that deletes system 32

30 A type of malicious code that remains dormant until a specific event or date triggers it is called:

A. Logic Bomb
B. Spyware
C. Backdoor
D. Adware

31 What is a 'Rootkit'?

A. A kit for rooting Android phones
B. A password cracking tool
C. Software designed to hide the existence of other malware and maintain privileged access
D. A database scanning tool

32 A 'Polymorphic Virus' is difficult to detect because:

A. It only runs on Linux
B. It is invisible to the user
C. It changes its code or signature each time it infects a new file
D. It is written in Python

33 What is a 'Macro Virus'?

A. A virus that is very large in file size
B. A virus written in the macro language of applications like Microsoft Word or Excel
C. A virus that attacks Mac computers
D. A virus that infects the boot sector

34 A network of compromised computers controlled by an attacker is called a:

A. Intranet
B. Botnet
C. Subnet
D. Darknet

35 What is a 'Wrapper' or 'Binder' in the context of Trojans?

A. A type of antivirus
B. A firewall rule
C. A method of encrypting emails
D. A tool used to combine a malicious executable with a legitimate file

36 Which of the following describes a 'Drive-by Download'?

A. Downloading drivers for a printer
B. Unintended download of malware by visiting a compromised website
C. Downloading files to a USB drive
D. Manually downloading a virus for research

37 Under U.S. law, which act is primarily used to prosecute computer hacking and malware distribution?

A. HIPAA
B. GDPR
C. SOX
D. CFAA (Computer Fraud and Abuse Act)

38 In the context of malware and the law, what does 'Intent' typically determine?

A. The speed of the internet connection
B. The difference between accidental damage and criminal liability
C. The cost of the hardware
D. The programming language used

39 What is an 'Overt Channel'?

A. A legitimate, authorized communication path for transferring data
B. A channel used only by spies
C. A hidden communication path
D. An encrypted VPN

40 What is a 'Covert Channel'?

A. A TV channel for hackers
B. A standard FTP connection
C. A mechanism used to transfer information in a way that violates the system's security policy
D. A public chat room

41 Hiding data within the headers of TCP/IP packets is an example of:

A. Phishing
B. Overt Channel
C. Covert Storage Channel
D. Social Engineering

42 Manipulating system resources to signal information (e.g., CPU usage patterns) is an example of:

A. Multiplexing
B. Covert Storage Channel
C. Overt Channel
D. Covert Timing Channel

43 Steganography is best described as:

A. Scrambling text so it is unreadable
B. Hiding the existence of a message within another medium (like an image)
C. Scanning ports
D. Cracking passwords

44 Which tool is commonly used to extract password hashes from Windows memory (LSASS)?

A. Nmap
B. Ping
C. Mimikatz
D. Wireshark

45 What is a 'Zero-Day' exploit?

A. An attack that occurs at midnight
B. An attack that exploits a vulnerability unknown to the software vendor
C. An exploit that takes zero days to fix
D. A virus that lasts for zero days

46 What is the purpose of a 'Keylogger'?

A. To generate encryption keys
B. To lock the keyboard
C. To log into a website
D. To record every keystroke made by a user

47 Which Windows service is the 'Local Security Authority' responsible for validating users?

A. SVCHOST.EXE
B. WINLOGON.EXE
C. LSASS.EXE
D. EXPLORER.EXE

48 A malware that restricts access to the computer system until a fee is paid is specifically targeting which aspect of the CIA triad?

A. Confidentiality
B. Integrity
C. Non-repudiation
D. Availability

49 In Windows, what does the command net user do?

A. Displays network statistics
B. Adds, removes, or modifies user accounts
C. Connects to a shared folder
D. Starts a service

50 Which of the following is an example of a Multipartite Virus?

A. A virus that attacks multiple people
B. A virus that uses multiple encryption keys
C. A virus that attacks both the boot sector and executable files
D. A virus that has multiple parts