Vulnerability Assessment and Exploitation Flashcards
6 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Vulnerability Assessment and Exploitation flashcards as text
Which exploitation phase in CEH involves maintaining access to a compromised system for future use?
Answer: Maintaining Access
The Maintaining Access phase involves installing backdoors, rootkits, or Trojans to ensure persistent access to the compromised system for later use.
What is a 'zero-day vulnerability'?
Answer: A previously unknown vulnerability with no available patch
A zero-day vulnerability is a security flaw that is unknown to the vendor and has no available patch, making it particularly dangerous and valuable to attackers.
Which Metasploit payload type creates a connection from the target back to the attacker's machine?
Answer: Reverse Shell
A reverse shell payload causes the target machine to initiate a connection back to the attacker, often bypassing inbound firewall rules that block incoming connections.
What is the purpose of 'fuzzing' in vulnerability research?
Answer: Sending malformed or random data to an application to discover crashes and bugs
Fuzzing (fuzz testing) inputs large volumes of random or malformed data into an application to trigger unexpected behavior, crashes, or security vulnerabilities.
Which type of exploit takes advantage of a buffer overflow to overwrite the return address and redirect execution flow?
Answer: Stack-Based Buffer Overflow
A stack-based buffer overflow writes beyond a buffer's bounds on the stack, overwriting the return address with an attacker-controlled value to redirect code execution.
What does 'post-exploitation' refer to in a penetration testing engagement?
Answer: Actions taken after gaining initial access, such as privilege escalation and lateral movement
Post-exploitation encompasses activities after initial compromise including privilege escalation, lateral movement, data exfiltration, and establishing persistence.