Question 1
You have been hired to perform a black-box test for a client. How much information will you
be able to get from the client before commencing this test?
Question 1 options:
the IP address of the corporate web server
a list of employee e-mail addresses
the corporate name
system documentation only
Question 2
An attacker delivers a SYN packet to a target system and receives a SYN/ACK from a
listening port. The attacker responds with an RST packet to avoid completing the three-way
handshake. Which of following scanning methods is the attacker using?
Question 2 options:
XMAS scan
RST scan
ACK scan
SYN scan<
Question 3
If an organization has limited resources and money, which type of ethical hacking testing
method might be best suited for the client?
Question 3 options:
black-box testing