Ethical Hacker Methodology Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Ethical Hacker Methodology flashcards as text
An ethical hacker reviews a target company's job postings, employee LinkedIn profiles, and DNS records without sending any packets to the target. Which phase and technique is this?
Answer: Passive reconnaissance
Gathering information from public sources without directly interacting with the target is passive reconnaissance.
Which document is signed before an engagement begins to define what systems may be tested and the boundaries of the test?
Answer: Rules of Engagement
The Rules of Engagement defines scope, targets, timing, and limitations of the test.
During scanning, a tester uses Nmap with the -sS flag. What type of scan is being performed?
Answer: SYN stealth scan
The -sS flag performs a half-open SYN stealth scan that does not complete the TCP handshake.
What is the primary goal of the 'maintaining access' phase of the methodology?
Answer: Establish persistent access for return entry
Maintaining access focuses on creating persistence such as backdoors so the attacker can return.
Which phase involves clearing logs and removing tools to avoid detection by defenders?
Answer: Covering tracks
Covering tracks (clearing tracks) removes evidence such as logs and artifacts to evade detection.
Enumeration typically follows scanning. What does enumeration extract that scanning does not?
Answer: Active usernames, shares, and service details
Enumeration actively connects to extract detailed info like usernames, shares, and group memberships.
A penetration tester wants legal protection clarifying they are authorized to test. Which agreement is most relevant?
Answer: Get-out-of-jail-free / authorization letter
A signed authorization letter grants explicit legal permission to perform the testing.