Interview Questions Flashcards

1
Q
Name the protocols that run on these ports:
88
143
137-139
161-162
110
389
445
A
88 - Kerberos
143 - IMAP
137-139 - NetBIOS
161-162 - SNMP
110 - POP3
389 - LDAP
445 - SMB
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can Malware maintain persistence?

A

Auto-run key/Start Up, scheduled tasks,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What family of malware often targets Volume Shadow Copies?

A

Ransomware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Why would you see DNS going over TCP?

A

DNS Zone transfers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What do you know about Alternate Data Streams?

A

A half-assed implemented feature. ADS is a second stream of data stored in a file. This information isn’t natively seen by the OS, so adversaries can use it to hide information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Explain a Web shell.

A

Script that can be uploaded to a web server to enable remote administration. Can be used to pivot further internally.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
Name some Windows Event ID's:
4608
4609
4624
4625
A

4608 - Windows is starting up
4609 - Windows is shutting down
4624 - Account Successfully logged on
4625 - Account failed to log on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a .DLL file?

A

Dynamic Link Library file. Holds a repository of code other applications can reference

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is DLL search order hijacking?

A

Windows has a specified order in which it searches for DLL files. Attackers can put a DLL file by the same name in a directory Windows will search first before it finds the legitimate file.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name the 4 Windows NTFS Timestamps

A

File last accessed, file last modified, file created, and metadata last modified.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly