EH-01-P1: Introduction Flashcards

1
Q

Types of Hackers

A

Ethical, Unethical, Gray Hats

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What do Hackers do?

A
  1. Alter Functionality,
  2. Take Advantage,
  3. Security Professionals must remain up-to-date.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Hacker Teams

A
  1. Red Team
  2. Blue Team
  3. Purple Team
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Hacker Attack Maps

A
  1. Check Point
  2. Fortinet
  3. Talos Intelligence
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Certifications

A
  1. CEH = Certified Ethical Hacker
  2. OSCP = Offensive Security Certified Professional
  3. OSWE = Offensive Security Web Expert
  4. CISA = Cybersecurity and Infrastructure Security Agency
  5. CISM = Certified Information Security Manager
  6. CISSP = Certified Information Systems Security Professional
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Ethics: Penetration Testers

A
  1. Principle : Get Permission
  2. Integrity : Signing Non-disclosure agreements
  3. Legal Awareness: Laws
  4. Professionalism : Ethical and Professional Integrity
  5. Responsibilities: No malicious activity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Malware

A

Malicious Software to do:

  1. Damage
  2. Spy
  3. Steal Information
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Malware Types

A
  1. Virus : Replicates when executed
  2. Ransomware : encrypts data until ransom is paid
  3. Trojan Horse : Malware hidden in legitimate files
  4. Worm : Self-replicating
  5. Botnet : Zombie Network for DDoS
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Cyberattack Cycle
aka
Kill Chain

A
  1. Reconnaissance: Check for vulnerabilities
  2. Weaponization: Create payload
  3. Delivery:
  4. Exploit : Execute malware
  5. Command and Control: Gain System access.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Famous Cyber Attacks

A
  1. Stuxnet worm : Iran’s Nuclear Program
  2. Playstation : SQLi
  3. WannaCry via EternalBlue(NSA)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Unique Zero-Day Vulnerability

A

Newly Discovered vulnerability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

WannaCry Attack Chain

A
  1. EternalBlue via SMB
  2. WannaCry tries to connect to attacker C&C
  3. Encrypted Personal Files
How well did you know this?
1
Not at all
2
3
4
5
Perfectly