← All Certified Ethical Hacker Flashcard Decks

System Hacking and Malware Flashcards

7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 System Hacking and Malware flashcards as text
  1. An attacker uses the SAM file extracted from a Windows host to recover plaintext passwords offline. Which tool is BEST suited for this cracking task?

    Answer: John the Ripper

    John the Ripper is a password-cracking tool that can attack NTLM/SAM hashes offline.

  2. Which Windows technique allows an attacker to authenticate using a captured NTLM hash without ever cracking it to plaintext?

    Answer: Pass-the-Hash

    Pass-the-Hash reuses the captured NTLM hash directly to authenticate to remote services.

  3. A rootkit that operates by modifying the kernel's system call table is classified as which type?

    Answer: Kernel-level rootkit

    Kernel-level rootkits hook or modify kernel structures such as the system call table.

  4. During privilege escalation on Linux, an attacker finds a SUID binary owned by root. What does exploiting it most directly grant?

    Answer: Execution with the file owner's (root) privileges

    A SUID binary runs with the privileges of its owner, so a root-owned SUID can yield root execution.

  5. Which technique hides data by embedding it inside the unused slack space or within an image file's least significant bits?

    Answer: Steganography

    Steganography conceals data within other files such as images using techniques like LSB embedding.

  6. An attacker clears the Windows Security event log to cover their tracks. Which command-line tool can wipe a specific event log?

    Answer: wevtutil

    wevtutil cl Security clears the Windows Security event log.

  7. Which malware type replicates itself across networks without requiring user interaction or a host file?

    Answer: Worm

    A worm self-propagates across networks autonomously without needing a host file or user action.