1 - Ethical Hacking Concepts Flashcards

1
Q

Define an ethical hacker

A

Ethical hackers conduct penetration tests for companies. Companies sometimes hire ethical hackers to break into the company’s network to find the weakest link in the network or network system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define a security hacker

A

Security testers do more than attempt to break in; they analyze the company’s security policy and procedures and report any vulnerability to management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the penetration testing methodologies?

A

White Box Model
Black Box Model
Gray Box Model

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a white box Model

A

The tester is told what network topology and technology the company is using and is given permission to interview IT personnel and company employees.
EG. the company might print the tester a network diagram showing all the company’s routers, switches, firewalls and IDSs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a black box model

A

Opposite of white box. Management don’t tell their staff a penetration test is being conducted. Nor do they give the tester any diagrams or describe what technologies the company is using. Management want to see the security tester’s ability to detect an attack.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Gray box model

A

Hybrid of white and black. Company gives tester partial information.
EG. they might get information about which Oss are used but not get an network diagrams.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What can you do legally?

A

Laws involving computer technology change as rapidly as technology itself, keep abreast of what’s happening in your area.
Laws vary from state to state and country to country – You should be aware of what these are.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What can’t you do legally?

A

You cannot carry out illegal actions such as:

  • Accessing a computer without permission
  • Destroying data without permission
  • Copying information without permission
  • Installing works or viruses
  • Denying users access to network resources
How well did you know this?
1
Not at all
2
3
4
5
Perfectly