System Hacking and Malware Flashcards
7 cards from real Certified Ethical Hacker practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 System Hacking and Malware flashcards as text
An attacker uses the SAM file extracted from a Windows host to recover plaintext passwords offline. Which tool is BEST suited for this cracking task?
Answer: John the Ripper
John the Ripper is a password-cracking tool that can attack NTLM/SAM hashes offline.
Which Windows technique allows an attacker to authenticate using a captured NTLM hash without ever cracking it to plaintext?
Answer: Pass-the-Hash
Pass-the-Hash reuses the captured NTLM hash directly to authenticate to remote services.
A rootkit that operates by modifying the kernel's system call table is classified as which type?
Answer: Kernel-level rootkit
Kernel-level rootkits hook or modify kernel structures such as the system call table.
During privilege escalation on Linux, an attacker finds a SUID binary owned by root. What does exploiting it most directly grant?
Answer: Execution with the file owner's (root) privileges
A SUID binary runs with the privileges of its owner, so a root-owned SUID can yield root execution.
Which technique hides data by embedding it inside the unused slack space or within an image file's least significant bits?
Answer: Steganography
Steganography conceals data within other files such as images using techniques like LSB embedding.
An attacker clears the Windows Security event log to cover their tracks. Which command-line tool can wipe a specific event log?
Answer: wevtutil
wevtutil cl Security clears the Windows Security event log.
Which malware type replicates itself across networks without requiring user interaction or a host file?
Answer: Worm
A worm self-propagates across networks autonomously without needing a host file or user action.