STUDY GUIDE COMPREHENSIVE REVIEW
◉ _______ is one of the programs used to wardial. Answer: ToneLoc
◉ What are the default passwords used by SNMP?( Answer: Private
and Public
◉ What is the following command used for?
net use \targetipc$ "" /u:"" Answer: Connecting to a Linux computer
through Samba.
◉ What is the proper response for a NULL scan if the port is closed?
Answer: RST
◉ If you receive a RST packet while doing an ACK scan, it indicates
that the port is
open. Answer: True
◉ Ethereal works best on ____________. Answer: Networks using hubs
,◉ Which of the following are potential attacks on cryptography?
Answer: Chosen-Ciphertext Attack, Man-in-the-Middle Attack and
Replay Attack
◉ When Nmap performs a ping sweep, which of the following sets of
requests does it send to the
target device? Answer: ICMP ECHO_REQUEST & TCP ACK
◉ This kind of password cracsheets method uses word lists in
combination with numbers and
special characters: Answer: Hybrid
◉ How does a denial-of-service attack work? Answer: A hacker
prevents a legitimate user (or group of users) from accessing a
service
◉ Jason's Web server was attacked by a trojan virus. He runs
protocol analyzer and notices that the
Trojan communicates to a remote server on the Internet. Shown
below is the standard "hexdump"
representation of the network packet, before being decoded. Jason
wants to identify the trojan by
loosheets at the destination port number and mapping to a trojan-
port number database on the
,Internet. Identify the remote server's port number by decoding the
packet? Answer: Port 6667 (Net-Devil Trojan)
◉ 1 172.16.1.254 (172.16.1.254) 0.724 ms 3.285 ms 0.613 ms
2 ip68-98-176-1.nv.nv.cox.net (68.98.176.1) 12.169 ms 14.958 ms
13.416
ms
3 ip68-98-176-1.nv.nv.cox.net (68.98.176.1) 13.948 ms
ip68-100-0-1.nv.nv.cox.net
(68.100.0.1) 16.743 ms 16.207 ms
4 ip68-100-0-137.nv.nv.cox.net (68.100.0.137) 17.324 ms 13.933 ms
20.938 ms
5 68.1.1.4 (68.1.1.4) 12.439 ms 220.166 ms 204.170 ms
6 so-6-0-0.gar2.wdc1.Level3.net (67.29.170.1) 16.177 ms 25.943 ms
14.104 ms
7 unknown.Level3.net (209.247.9.173) 14.227 ms 17.553 ms 15.415
ms
8 so-0-1-0.bbr1.NewYork1.level3.net (64.159.1.41) 17.063 ms
20.960 ms
19.512 ms
9 so-7-0-0.gar1.NewYork1.Level3.net (64.159.1.182) 20.334 ms
19.440 ms
17.938 ms
, 10 so-4-0-0.edge1.NewYork1.Level3.net (209.244.17.74) 27.526 ms
18.317
ms 21.202 ms
11 uunet-level3-oc48.NewYork1.Level3.net (209.244.160.12) 21.411
ms
19.133 ms 18.830 ms
12 0.so-6-0-0.XL1.NYC4.ALTER.NET (152.63.21.78) 21.203 ms
22.670 ms
20.111 ms
1 Answer: A stateful inspection firewall
◉ A Buffer Overflow attack involves: Answer: Poorly written
software that allows an attacker to execute arbitrary code on a
target system
◉ Which of the following is the primary objective of a rootkit?
Answer: It replaces legitimate programs
◉ Which of the following best describes session key creation in SSL?
Answer: It is created by the client after verifying the server's identity
◉ Which of the following LM hashes represent a password of less
than 8 characters? Answer:
44EFCE164AB921CQAAD3B435B51404EE