MOD D04: Windows Services - PE problems Flashcards

1
Q

If a port is open, the service associated is able to be used.

[TRUE / FALSE]

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What port is HTTP traffic associated with?

A

Port 80

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What port is SMTP traffic associated with?

A

Port 25

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What port is Webmail SSL traffic associated with?

A

Port 2096

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What port is SSH traffic associated with?

A

Port 22

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What port is IMAP traffic associated with?

A

Port 143

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What protocol is port 110 traffic associated with?

A

POP3 protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What protocol is port 995 traffic associated with?

A

POP3s

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Service applications can be DLLs or executables.

[True / False]

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does SCP stand for, regarding Windows Services?

A

Service Control Program (SCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the most common SCP?

A

The most common SCP is the services.msc GUI.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Windows services typically run in the background.

[True / False]

A

TRUE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The service panel is used to manage tasks.

[True / False]

A

FALSE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

If you need to change settings on a service when it fails, what tab in the service panel allows you to make changes to this?

A

Recovery tab

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

If you wanted to access another machine remotely, which protocol would you use from the options below?

  • HTTP
  • SNMP
  • HTTPS
  • RDP
A

RDP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does RDP stand for?

A

Remote Desktop Protocol

17
Q

Where are authentication packages stored?

  • DLL’s
  • C:\
  • the Kernel
  • C:\Windows\System32\
A

DLLs

18
Q

What can adversaries modify to reveal credentials?

A

Auto start mechanism

19
Q

Local and Network Logon require the user to have an account in the SAM of that computer.

[True / False]

A

TRUE

Note: Both a local logon and a network logon require that the user has a user account in the Security Accounts Manager (SAM) on the local computer.

20
Q

What is the Network Service that resolves server names to IP addresses?

A

DNS

21
Q

What is the network service that provides secure transfer of web pages?

A

HTTPS

22
Q

What protocol used for the management and monitoring of network-connected devices?

A

SNMP

(Simple Network Management Protocol)

23
Q

POP3 and IMAP are protocols used with email technologies.

[True / False]

A

TRUE

24
Q

A network service is associated with a unique port number.

[True / False]

A

TRUE

25
Q

Only Microsoft provides services that run on Windows Server operating systems?

[True / False]

A

FALSE

26
Q

The principle of “______” states that a system should have no more capabilities that it requires to perform its intended purpose?

A

Least privilege

27
Q
A

Least privilege

28
Q

What is a utility used by Windows to stop, start, and manage background services used by Windows and applications.

A

services.msc

29
Q

What is a software component that permits an operating system to communicate with hardware devices?

A

Driver

30
Q

A digitally signed driver shows that it is untrusted.

[True / False]

A

FALSE

31
Q

When a service fails to start, typically an event is written to which log?

A

System

32
Q

Which of the following is the process of granting the user access only to the resources he or she is permitted to use?

A

Authorization

33
Q

Where is (are) most of the configurations for Windows stored?

A

Registry

34
Q

What command is used to start a service in Powershell?

A

start-service

35
Q

Which of the following items in Task Scheduler causes a task to run?

A

Trigger

36
Q

What is the authentication protocol used in a Windows domain environment to authenticate logons and grant accounts access to domain resources?

  • Putty
  • Hyper Text Transfer Protocol
  • Authentication
  • Kerberos
A

Kerberos

37
Q

Microsoft SBL is a database server.

[True / False]

A

FALSE

Note: Microsoft SQL is a DB server.

38
Q

Which process, typically a target of malware, verifies users logging on to a Windows computer or server, handles password changes, and creates access tokens?

A

Local Security Authority Server Service (LSASS)

39
Q

What service control manager handles all windows services?

A

services.exe