🔒 Cybersecurity Study Guide — 23 Question Type Variants
Each of the 23 original questions is presented with multiple variant
phrasings — different ways the same concept can be tested. Master the concept, not just the
wording.
Question Type 1: IAAA Acronym
Original: What does the acronym IAAA stand for in information security?
📖 Source: 5_0_Introduction.txt, 5_1_Intro_to_IAAA.txt — "IAAA stands for Identity,
Authentication, Authorization, and Auditing/Accounting… It is the foundational framework for access
management."
Variant A — Multiple Choice (Reworded)
The access management framework that begins with claiming an identity and ends
with logging actions is known by which acronym?
- A) CIA
- B) IAAA
- C) AAA
- D) DAC
Reveal Answer
Correct Answer: B) IAAA
IAAA = Identity, Authentication, Authorization, Auditing/Accounting. CIA is the
Confidentiality-Integrity-Availability triad. AAA is a subset (Authentication, Authorization,
Accounting). DAC is Discretionary Access Control.
Variant B — Fill in the Blank
In the IAAA framework, the four stages in order are: ________, ________,
________, and ________.
Reveal Answer
Identity, Authentication, Authorization, Auditing/Accounting
The order matters: you must first claim who you are, prove it, receive permissions, then have
actions logged.
Variant C — Scenario-Based
A new employee enters their username (step 1), provides their password and
fingerprint (step 2), is granted access to HR files (step 3), and all file access is recorded in a log
(step 4). Which IAAA component does each step represent?
Reveal Answer
Step 1 = Identity, Step 2 = Authentication, Step 3 = Authorization,
Step 4 = Auditing
This is a real-world walkthrough of the entire IAAA pipeline.
Variant D — True/False
True or False: The IAAA framework includes "Integrity" as one of its four
components.
Reveal Answer
False
Integrity belongs to the CIA triad, not IAAA. The four As in IAAA are Identity, Authentication,
Authorization, and Auditing/Accounting.
Variant E — Ordering / Sequencing
Place the following IAAA steps in their correct sequence: Authorization,
Auditing, Authentication, Identity.
Reveal Answer
1. Identity → 2. Authentication → 3. Authorization → 4. Auditing
You cannot authenticate without first identifying; you cannot authorize without first
authenticating; and auditing records the results of all prior steps.
Question Type 2: Identity Examples
Original: Which of the following is a primary example of an Identity?
📖 Source: 5_2_Identity.txt — "Identity is a claim… examples include username, email
address, employee ID number. It is the public component—not a secret."
Variant A — Negative Selection
Which of the following is NOT an example of an identity?
- A) Username
- B) Employee ID Number
- C) Fingerprint
- D) Email Address
Reveal Answer
Correct Answer: C) Fingerprint
A fingerprint is a Type 3 authentication factor (something you are), not an identity claim.
Identities are public claims like usernames, email addresses, and employee IDs.
Variant B — Scenario-Based
When Sarah logs into her company portal, she first types
"sarah.jones@company.com" into the login form. Which component of IAAA is she performing?
- A) Authentication
- B) Authorization
- C) Identification
- D) Auditing
Reveal Answer
Correct Answer: C) Identification
Entering her email address is claiming her identity. Authentication comes next when she provides
her password/MFA token.
Variant C — True/False
True or False: A password is considered an Identity because it uniquely
identifies a user.
Reveal Answer
False
A password is an authentication factor (Type 1 — something you know). Identity is the public
claim (username, email). Passwords are secret and used to prove that identity, not
state it.
Variant D — Select All That Apply
Select ALL that are valid examples of an Identity: (a) Username, (b) Smart
Card, (c) Employee Badge Number, (d) Email Address, (e) PIN Code
Reveal Answer
Correct: (a) Username, (c) Employee Badge Number, (d) Email
Address
Smart Cards are "something you have" (authentication). PIN Codes are "something you know"
(authentication). The remaining three are public identity claims.
Variant E — Conceptual / Short Answer
Explain why an identity must be unique within a system and give two examples
of identities.
Reveal Answer
An identity must be unique so the system can distinguish one user from
another for proper authentication, authorization, and auditing. Examples: email address,
username, employee ID.
Question Type 3: Authentication Factor Types
Original: Match the Authentication Factor "Type" with the correct example.
📖 Source: 5_3_Authentication.txt — "Type 1 = Something you know (password, PIN), Type 2
= Something you have (smart card, OTP token), Type 3 = Something you are (biometrics — fingerprint, iris),
Type 4 = Somewhere you are (geolocation technology)."
Variant A — Multiple Choice
A retinal scan is an example of which authentication factor type?
- A) Type 1 — Something you know
- B) Type 2 — Something you have
- C) Type 3 — Something you are
- D) Type 4 — Somewhere you are
Reveal Answer
Correct Answer: C) Type 3 — Something you are
Retinal scans and all biometrics are Type 3 factors because they rely on your unique physical
characteristics.
Variant B — Categorization
Categorize each into Type 1, 2, or 3: (a) Security Question, (b) RSA Token,
(c) Voice Recognition, (d) Passphrase, (e) Smart Card, (f) Palm Vein Scan
Reveal Answer
Type 1 (Know): (a) Security Question, (d) Passphrase
Type 2 (Have): (b) RSA Token, (e) Smart Card
Type 3 (Are): (c) Voice Recognition, (f) Palm Vein Scan
Variant C — Scenario-Based
An employee swipes their company-issued smart card at a door reader. Which
authentication factor type is being used?
Reveal Answer
Type 2 — Something you have
A smart card is a physical token the user possesses.
Variant D — True/False
True or False: A One-Time Password (OTP) sent to a user's phone is a Type 1
authentication factor because the user must "know" the code.
Reveal Answer
False
An OTP is Type 2 (something you have) because it depends on possession of the device receiving
the code, not on memorized knowledge. The code itself is ephemeral and device-bound.
Variant E — Fill in the Blank
The four authentication factor types are: Type 1 = Something you
________, Type 2 = Something you ________, Type 3 = Something you ________, Type 4 = Somewhere you ________.
Reveal Answer
Know, Have, Are, Are (Geolocation)
Variant F — Type 4 Geolocation (Lecture 5.3)
A corporate VPN only allows login attempts from IP addresses originating within the United States. If an employee travels to another country, they are blocked. Which authentication factor type is this an example of?
- A) Type 1 — Something you know
- B) Type 2 — Something you have
- C) Type 3 — Something you are
- D) Type 4 — Somewhere you are
Reveal Answer
Correct Answer: D) Type 4 — Somewhere you are
Type 4 authentication uses geolocation technology (GPS, IP geolocation) to verify a user's physical location as a factor. Per Lecture 5.3, this is the fourth valid authentication type.
Variant G — True/False (Type 4)
True or False: According to the lecture material, there are only three types of authentication factors.
Reveal Answer
False
Lecture 5.3 defines four types: Type 1 (Something you know), Type 2 (Something you have), Type 3 (Something you are), and Type 4 (Somewhere you are — Geolocation Technology).
Question Type 4: MFA vs. Single-Factor Authentication
Original: True or False: A username/password followed by a PIN is MFA.
📖 Source: 5_3_Authentication.txt — "Multi-Factor Authentication requires two or more
different types of factors. Using two passwords is NOT MFA — both are Type 1."
Variant A — Multiple Choice
Which of the following scenarios is a valid example of Multi-Factor
Authentication (MFA)?
- A) Password + Security Question
- B) PIN + Passphrase
- C) Password + Fingerprint Scan
- D) Password + Second Password
Reveal Answer
Correct Answer: C) Password + Fingerprint Scan
Only option C combines two different factor types: Type 1 (password — know) + Type 3 (fingerprint
— are). All other options combine two Type 1 factors.
Variant B — Scenario-Based
A bank requires customers to enter their PIN and then insert a physical chip
card. Is this MFA? Explain why or why not.
Reveal Answer
Yes, this IS MFA.
A PIN is Type 1 (something you know) and a chip card is Type 2 (something you have). Two
different factor types = MFA.
Variant C — True/False (Reworded)
True or False: Entering a password and then answering "What is your mother's
maiden name?" constitutes Multi-Factor Authentication.
Reveal Answer
False
Both a password and a security question are Type 1 (something you know). MFA requires at LEAST
two different types.
Variant D — Short Answer
What is the minimum requirement for a system to claim it uses Multi-Factor
Authentication? Give an example combination.
Reveal Answer
The system must require at least two different types of authentication
factors. Example: Password (Type 1) + OTP from a mobile app (Type 2).
Variant E — Select All That Apply
Which of the following are valid MFA combinations? (Select all)
(a) Password + OTP Token
(b) Iris Scan + Fingerprint
(c) Smart Card + Retinal Scan
(d) PIN + Password
(e) Passphrase + Smart Card + Fingerprint
Reveal Answer
Valid MFA: (a), (c), (e)
(a) Type 1 + Type 2 ✓ | (b) Type 3 + Type 3 ✗ (same type) | (c) Type 2 + Type 3 ✓ | (d) Type 1 +
Type 1 ✗ | (e) Type 1 + Type 2 + Type 3 ✓ (three-factor)
Question Type 5: Role-Based Access Control (RBAC)
Original: Which method assigns permissions based on a user's role or job
function?
📖 Source: 5_4_Authorization.txt — "RBAC assigns permissions to roles, not individuals.
Users are placed in roles like 'HR Manager' or 'IT Admin'. When they change jobs, they simply move to a new
role."
Variant A — Scenario-Based
A hospital assigns "Nurse", "Doctor", and "Admin" roles. Each role has
specific system permissions. When Dr. Smith transfers departments, her permissions automatically update
to match the new department's "Doctor" role. Which access control model is being used?
- A) Discretionary Access Control (DAC)
- B) Mandatory Access Control (MAC)
- C) Role-Based Access Control (RBAC)
- D) Rule-Based Access Control
Reveal Answer
Correct Answer: C) RBAC
RBAC assigns permissions to roles. Moving a user to a different role automatically updates their
permissions without individually editing access rights.
Variant B — Compare & Contrast
How does Role-Based Access Control (RBAC) differ from an Access Control List
(ACL)?
Reveal Answer
RBAC assigns permissions to named roles (job functions), and users
inherit permissions by being assigned to a role. An ACL is attached to a specific object (file,
resource) and lists which users/groups can access that object and what operations they can
perform. RBAC scales better in large organizations.
Variant C — True/False
True or False: In RBAC, individual users are directly assigned permissions to
specific files and resources.
Reveal Answer
False
In RBAC, permissions are assigned to roles, not individual users. Users are then
assigned to roles, inheriting the permissions associated with that role.
Variant D — Multiple Choice (Different Angle)
A firewall that blocks all traffic after 6:00 PM regardless of the user is an
example of which type of access control?
- A) Role-Based Access Control (RBAC)
- B) Rule-Based Access Control
- C) Access Control Matrix
- D) Discretionary Access Control (DAC)
Reveal Answer
Correct Answer: B) Rule-Based Access Control
Rule-based applies global conditions (time-of-day, IP range, etc.) uniformly. RBAC is
specifically about job roles/functions. This is a common distractor pairing on exams.
Variant E — Fill in the Blank
In ________ access control, permissions follow the principle: "What does this
job need access to?" rather than "What does this individual user need?"
Reveal Answer
Role-Based (RBAC)
Variant F — MAC vs. DAC (Lecture 5.4)
In which access control model does the system administrator (not the data owner) set all access permissions based on security labels and clearance levels?
- A) Discretionary Access Control (DAC)
- B) Mandatory Access Control (MAC)
- C) Role-Based Access Control (RBAC)
- D) Rule-Based Access Control
Reveal Answer
Correct Answer: B) Mandatory Access Control (MAC)
In MAC, access decisions are made by the system based on security labels (e.g., Top Secret, Secret, Confidential) — not by the individual data owner. In DAC, the owner of the resource decides who gets access.
Variant G — ACL vs. Capability List (Lecture 5.4)
An Access Control Matrix can be decomposed in two ways. Which method is described as "column-based, organized by object" and which is "row-based, organized by subject"?
Reveal Answer
Column-based (by object) = Access Control List (ACL). Row-based (by subject) = Capability List.
Per Lecture 5.4: An ACL lists all subjects that can access a given object. A Capability List lists all objects a given subject can access. Both are derived from the Access Control Matrix to solve the sparse table problem.
Variant H — True/False (DAC)
True or False: In Discretionary Access Control (DAC), the owner of a file can grant or revoke access to other users at their own discretion.
Reveal Answer
True
DAC allows the data owner to control access. This is flexible but less secure than MAC because users may grant access carelessly. Most consumer operating systems (Windows, macOS) use DAC by default.
Question Type 6: Access Control Matrix (Sparse Table)
Original: True or False: An access control matrix is inefficient for large
systems because of its sparse table.
📖 Source: 5_4_Authorization.txt — "An access control matrix maps every subject to every
object… In large organizations this creates a 'sparse table' with many empty cells."
Variant A — Multiple Choice
What is the main scalability problem with an Access Control Matrix?
- A) It cannot represent read/write/execute permissions
- B) It results in a sparse table with mostly empty cells, wasting resources
- C) It only works for fewer than 10 users
- D) It cannot differentiate between users
Reveal Answer
Correct Answer: B)
As user and resource counts grow, the matrix becomes enormous with most cells empty (no access),
making it wasteful and hard to manage.
Variant B — Scenario-Based
A company with 10,000 employees and 50,000 files attempts to manage access
using a table where each row is a user and each column is a file. Most employees only access about 20
files. What problem will this approach cause?
Reveal Answer
The table would have 500 million cells (10,000 × 50,000), but only
about 200,000 would contain actual permissions. Over 99.9% of the cells would be empty—a classic
sparse table problem that wastes memory and is nearly impossible to administer.
Variant C — Short Answer
Name two alternatives to an Access Control Matrix that solve the sparse table
problem.
Reveal Answer
1) Access Control Lists (ACLs) — attach permission lists to individual
objects. 2) Role-Based Access Control (RBAC) — assign permissions to roles rather than
enumerating every user-object pair.
Variant D — True/False (Reworded)
True or False: An Access Control Matrix is the most efficient authorization
mechanism for organizations with thousands of users and resources.
Reveal Answer
False
It is among the LEAST efficient for large-scale environments due to the sparse table problem.
ACLs or RBAC are preferred.
Variant E — Capability List vs. ACL (Lecture 5.4)
A system stores a list for each user that says: "User Alice can access File1 (read), File2 (read/write), Printer1 (print)." This is organized by subject. What is this called?
- A) Access Control List (ACL)
- B) Capability List
- C) Role-Based Access Control
- D) Access Control Matrix
Reveal Answer
Correct Answer: B) Capability List
A Capability List is created by dividing the Access Control Matrix row-wise (by subject). It records what each subject can access. An ACL is column-wise (by object) — it records who can access each object.
Question Type 7: Auditing / Accounting
Original: Logging data to verify if users have accessed unauthorized files is
which step of IAAA?
📖 Source: 5_5_Auditing.txt — "Auditing involves tracking and recording user activity…
verifying compliance… ensuring accountability through logs."
Variant A — Scenario-Based
After a data breach, the security team reviews server logs to determine which
accounts accessed the compromised database and when. Which stage of IAAA is being leveraged?
- A) Identity
- B) Authentication
- C) Authorization
- D) Auditing / Accounting
Reveal Answer
Correct Answer: D) Auditing / Accounting
Reviewing logs after the fact to establish who did what and when is the core function of
auditing.
Variant B — Short Answer
Why is Auditing considered essential for both security and compliance?
Reveal Answer
Auditing provides accountability by creating an irrefutable record of
user actions. For security, it helps detect unauthorized access and breaches. For compliance, it
provides the evidence needed to prove adherence to regulations (HIPAA, SOX, PCI-DSS,
etc.).
Variant C — Multiple Choice (Different Angle)
Which of the following would be MOST useful during an audit?
- A) A user's email address
- B) A password hash file
- C) A detailed system access log with timestamps
- D) An access control matrix
Reveal Answer
Correct Answer: C) A detailed system access log with timestamps
Auditing depends on comprehensive logs that record who accessed what, when, and from where.
Variant D — True/False
True or False: Auditing only occurs after a security incident has been
detected.
Reveal Answer
False
Auditing is a continuous process. Logs are generated in real-time during normal operations and
are reviewed both routinely (for compliance) and reactively (after incidents).
Question Type 8: Subnet Host Addresses
Original: How many usable host addresses are available in the subnet
192.168.1.0/24?
📖 Source: Lecture 1.1_Network_Models.txt, Lecture 1_3_Network Communication.txt — "A
/24 subnet has 256 total addresses. Subtract 2 (network address + broadcast) = 254 usable hosts."
Variant A — Different Subnet
How many usable host addresses are available in the subnet 10.0.0.0/16?
- A) 65,536
- B) 65,534
- C) 256
- D) 254
Reveal Answer
Correct Answer: B) 65,534
/16 = 16 host bits → 2^16 = 65,536 total − 2 (network + broadcast) = 65,534 usable.
Variant B — Conceptual
When calculating usable host addresses in a subnet, why must you always
subtract 2 from the total number of addresses?
Reveal Answer
The first address (all host bits = 0) is reserved as the Network ID,
and the last address (all host bits = 1) is reserved as the Broadcast Address. Neither can be
assigned to a host.
Variant C — Calculation / Short Answer
A network has a /28 subnet mask. How many usable host addresses does it
provide? Show your work.
Reveal Answer
/28 = 32 − 28 = 4 host bits → 2^4 = 16 total − 2 = 14 usable
hosts.
Variant D — True/False
True or False: In a /24 network, the address 192.168.1.255 can be assigned to
a host device.
Reveal Answer
False
192.168.1.255 is the broadcast address for the 192.168.1.0/24 subnet and cannot be assigned to
any host.
Variant E — Formula-Based
What is the formula for calculating usable host addresses given a CIDR
notation of /n?
Reveal Answer
Usable Hosts = 2^(32 − n) − 2
Where 32 is the total bits in an IPv4 address, n is the prefix length, and you subtract 2 for the
network and broadcast addresses.
Question Type 9: Port-to-Service Mapping
Original: Match ports 22, 80, 443, 445 with SSH, HTTP, HTTPS, SMB.
📖 Source: Module_2.txt, Module 3.txt — "Common ports: 22 SSH, 80 HTTP, 443 HTTPS, 445
SMB… also 21 FTP, 23 Telnet, 25 SMTP, 53 DNS, 3389 RDP."
Variant A — Multiple Choice
Which port is used for encrypted web traffic (HTTPS)?
- A) 22
- B) 80
- C) 443
- D) 8080
Reveal Answer
Correct Answer: C) 443
Variant B — Extended Matching (More Ports)
Match each port to its service: 21, 22, 23, 25, 53, 80, 443, 445, 3389
Reveal Answer
21 = FTP | 22 = SSH | 23 = Telnet | 25 = SMTP | 53 = DNS | 80 = HTTP | 443 = HTTPS | 445 = SMB |
3389 = RDP
Variant C — Scenario-Based
A network scan reveals an open port 445 on a Windows server. What service is
likely running, and what type of attack might this be vulnerable to?
Reveal Answer
Port 445 runs SMB (Server Message Block) for Windows File Sharing. It
has been the target of major exploits like EternalBlue (MS17-010), which was used by WannaCry
ransomware.
Variant D — True/False
True or False: Port 22 is used for Telnet, a protocol that provides an
unencrypted remote command-line interface.
Reveal Answer
False
Port 22 is SSH (Secure Shell), which is encrypted. Telnet runs on port 23 and is unencrypted.
Variant E — Security Implication
Why would a security analyst be concerned if they found port 23 (Telnet) open
on a production server?
Reveal Answer
Telnet transmits data (including credentials) in plaintext, making it
vulnerable to sniffing attacks. SSH (port 22) should be used instead as it encrypts all
traffic.
Variant F — Extended Port Matching (Module 4)
Match each port to its service: 110, 123, 161, 389, 465, 587, 995
Reveal Answer
110 = POP3 | 123 = NTP (Network Time Protocol) | 161 = SNMP | 389 = LDAP | 465 = SMTPS (SMTP over SSL) | 587 = SMTP Submission (with STARTTLS) | 995 = POP3S (POP3 over SSL)
Variant G — Multiple Choice (LDAP/SNMP)
A network administrator needs to query a centralized directory to look up user accounts and group memberships. Which port and protocol would this traffic use?
- A) Port 161 — SNMP
- B) Port 389 — LDAP
- C) Port 110 — POP3
- D) Port 123 — NTP
Reveal Answer
Correct Answer: B) Port 389 — LDAP
LDAP (Lightweight Directory Access Protocol) on port 389 is used for directory services like Active Directory. SNMP (161) monitors network devices, POP3 (110) retrieves email, and NTP (123) synchronizes clocks.
Variant H — True/False (SNMP)
True or False: SNMP (Simple Network Management Protocol) uses ports 161 and 162 and is used for monitoring and managing network devices.
Reveal Answer
True
Port 161 is used for SNMP queries (polling devices), and port 162 is used for SNMP Traps (devices sending alerts to a management station).
Question Type 10: Vulnerability Scanning
Original: Which type of scanning compares results against a database of known
signatures?
📖 Source: Module 3.txt — "Vulnerability scanning checks open ports and services against
a CVE database… provides severity ratings and remediation guidance… Tools: Nessus, OpenVAS, Qualys."
Variant A — Compare & Contrast
What is the primary difference between a port scan and a vulnerability scan?
Reveal Answer
A port scan identifies which ports are open/closed/filtered on a
target. A vulnerability scan goes further by probing those services, comparing them against a
CVE/signature database, and reporting known vulnerabilities with severity levels and remediation
steps.
Variant B — Multiple Choice (Tool-Focused)
Which of the following tools is primarily a vulnerability scanner?
- A) Nmap
- B) Wireshark
- C) Nessus
- D) Netcat
Reveal Answer
Correct Answer: C) Nessus
Nmap is a port/network scanner. Wireshark is a packet analyzer. Netcat is a networking utility.
Nessus is specifically designed for vulnerability assessment.
Variant C — Short Answer
What is a CVE database and how does a vulnerability scanner use it?
Reveal Answer
CVE (Common Vulnerabilities and Exposures) is a publicly available
catalog of known security vulnerabilities, each with a unique ID. Vulnerability scanners compare
the software versions and configurations they detect against CVE entries to identify known flaws
and their severity.
Variant D — True/False
True or False: A vulnerability scanner can only detect network-level
vulnerabilities and cannot identify web application flaws.
Reveal Answer
False
Modern vulnerability scanners (especially web application scanners like OWASP ZAP, Burp Suite,
Nessus WAS) can detect web app flaws including XSS, SQL Injection, and path traversal.
Question Type 11: Legal Scanning Authorization
Original: True or False: Any user can legally scan any network because the
Internet is open.
📖 Source: Module 3.txt — "Unauthorized scanning is illegal… requires explicit,
documented permission… violations fall under CFAA."
Variant A — Scenario-Based
A security enthusiast discovers vulnerabilities on a local business's website
using Nmap and Nessus, then emails the business about the findings. The enthusiast had no prior
agreement with the business. Is this legal?
Reveal Answer
No, this is illegal.
Even with good intentions, scanning networks or systems without explicit, documented
authorization violates computer fraud and abuse laws (e.g., the CFAA in the US). Always obtain
written permission before testing.
Variant B — Multiple Choice
Before performing a penetration test on a client's network, what document
should a tester obtain FIRST?
- A) An NDA (Non-Disclosure Agreement)
- B) Written authorization / Rules of Engagement (RoE)
- C) An insurance policy
- D) A vulnerability report template
Reveal Answer
Correct Answer: B) Written authorization / Rules of Engagement
Without documented permission defining scope, timing, and methods, any scanning or testing is
unauthorized and potentially illegal. (NDAs are also important but authorization comes first.)
Variant C — True/False (Reworded)
True or False: If you own a network, you can legally perform vulnerability
scans on it without any additional authorization.
Reveal Answer
True
You have the legal right to scan and test systems you own. However, best practice is to still
document the scope and ensure you don't accidentally scan systems outside your ownership (e.g.,
ISP or cloud infrastructure not covered by your agreement).
Question Type 12: NMAP Ping Scan / Host Discovery
Original: Which NMAP scan type is most useful for quickly identifying live hosts?
📖 Source: Module 3.txt — "Ping Scan (-sn) sends ICMP echo requests… skips port
scanning… fastest method for host discovery."
Variant A — Command-Based
What does the Nmap flag -sn do?
- A) Performs a SYN stealth scan on all ports
- B) Runs Nmap scripts against the target
- C) Performs host discovery only (ping scan), skipping port scanning
- D) Performs a UDP scan
Reveal Answer
Correct Answer: C)
-sn = "ping scan" or "no port scan." It only determines which hosts on the network
are alive, without checking for open ports.
Variant B — Scenario-Based
You've been asked to quickly inventory all live devices on a 10.0.0.0/24
network. You don't need to know what services are running yet. Which Nmap scan type should you use?
Reveal Answer
Ping Scan: nmap -sn 10.0.0.0/24
This is the fastest way to enumerate live hosts without scanning ports.
Variant C — Compare & Contrast
Why is a Ping Scan faster than a TCP SYN Scan?
Reveal Answer
A Ping Scan only checks if hosts are alive (using ICMP/ARP), sending
one or a few packets per host. A TCP SYN Scan probes individual ports (potentially thousands per
host), requiring far more packets and time.
Variant D — True/False
True or False: A Ping Scan can identify which services are running on a target
host.
Reveal Answer
False
A Ping Scan only identifies if a host is alive. To determine running services, you need a port
scan (e.g., TCP SYN scan) and optionally a service/version detection scan (-sV).
Variant E — TCP ACK Scan (Module 4: -sA)
An Nmap scan returns results showing ports as either "filtered" or "unfiltered" but does NOT indicate whether ports are open or closed. Which scan type produces this kind of output?
- A) TCP SYN Scan (
-sS)
- B) TCP ACK Scan (
-sA)
- C) UDP Scan (
-sU)
- D) XMAS Tree Scan (
-sX)
Reveal Answer
Correct Answer: B) TCP ACK Scan (-sA)
The ACK scan doesn’t determine if ports are open/closed. Instead, it determines whether ports are filtered (blocked by a firewall) or unfiltered (reachable). It is primarily used for firewall rule mapping.
Variant F — XMAS Tree Scan (Module 4: -sX)
Which Nmap scan type sends packets with the FIN, URG, and PSH flags all set simultaneously, and gets its name from its packet resembling a “lit-up Christmas tree”?
- A) FIN Scan (
-sF)
- B) NULL Scan (
-sN)
- C) XMAS Tree Scan (
-sX)
- D) TCP Connect Scan (
-sT)
Reveal Answer
Correct Answer: C) XMAS Tree Scan (-sX)
The XMAS scan sets FIN, URG, and PSH flags. If a port is closed, the target responds with RST. If open, there is no response. It can evade some simple firewalls and IDS that only look for SYN packets.
Variant G — Detection Evasion (Module 4: -D and -f)
Match each Nmap evasion technique to its flag and purpose:
1) Decoy Scan 2) Fragmented Packets
Reveal Answer
1) Decoy Scan (-D) — Spoofs additional source IP addresses so the target sees scan traffic from multiple IPs, making it harder to identify the real attacker.
2) Fragmented Packets (-f) — Splits probe packets into tiny IP fragments to evade packet inspection by firewalls and IDS that cannot reassemble fragments properly.
Question Type 13: UDP vs. TCP Scan Speed
Original: True or False: A UDP Scan is generally faster than a TCP SYN Scan
because UDP is session-less.
📖 Source: Module 3.txt — "UDP scans are much slower… open ports may not respond at all…
scanner must wait for timeouts… significantly longer than TCP scans."
Variant A — Multiple Choice
Why are UDP scans typically much slower than TCP SYN scans?
- A) UDP packets are larger than TCP packets
- B) Open UDP ports often don't reply, forcing the scanner to wait for timeout periods
- C) UDP requires a three-way handshake
- D) UDP scans must check every port twice
Reveal Answer
Correct Answer: B)
Because UDP is connectionless, an open port may simply accept the packet silently without
responding. The scanner cannot distinguish between "open" and "filtered" without waiting for a
timeout, which dramatically slows the scan.
Variant B — Compare & Contrast
Explain the key difference in how TCP SYN scans and UDP scans determine if a
port is open.
Reveal Answer
TCP SYN scan: Sends a SYN packet. If the port is open, it receives a
SYN-ACK back (definitive response). If closed, it gets a RST.
UDP scan: Sends a UDP
packet. If the port is closed, it may get an ICMP "port unreachable" message. If the port is
open, there may be NO response at all, requiring the scanner to wait for a timeout—making it
ambiguous and slow.
Variant C — True/False (Reworded)
True or False: The lack of a response during a UDP scan definitively means the
port is closed.
Reveal Answer
False
No response could mean the port is open (accepting traffic silently) OR filtered (a firewall
dropped the packet). Only an ICMP "port unreachable" response definitively indicates a closed
port.
Question Type 14: Vulnerability Scanner Attack Detection
Original: Which attacks can a Vulnerability Scanner help identify? (XSS, SQLi,
Path Traversal)
📖 Source: Module 3.txt — "Vulnerability scanners can detect injection flaws, XSS,
directory/path traversal… by sending test payloads to inputs."
Variant A — Multiple Choice (Negative)
Which of the following is LEAST likely to be detected by an automated
vulnerability scanner?
- A) SQL Injection
- B) Cross-Site Scripting (XSS)
- C) Business Logic Flaws
- D) Path Traversal
Reveal Answer
Correct Answer: C) Business Logic Flaws
Automated scanners excel at detecting technical vulnerabilities (injection, XSS, traversal) by
sending test payloads. Business logic flaws (like allowing a user to apply a discount code
twice) require understanding of intended application behavior and typically need manual testing.
Variant B — Short Answer
Explain how a vulnerability scanner detects a SQL Injection vulnerability.
Reveal Answer
The scanner sends specially crafted SQL payloads (like
' OR 1=1 --) to input fields and URL parameters, then analyzes the response for
signs of SQL errors, unexpected data returns, or behavior changes that indicate the input was
executed as SQL code.
Variant C — Matching
Match the vulnerability type to its description:
1) XSS 2) SQL Injection 3) Path Traversal
- (a) Manipulating file paths (e.g.,
../../etc/passwd) to access unauthorized files
- (b) Injecting malicious scripts into web pages viewed by other users
- (c) Inserting database commands through user input fields
Reveal Answer
1-b, 2-c, 3-a
Variant D — True/False
True or False: A vulnerability scanner can detect both Cross-Site Scripting
(XSS) and SQL Injection vulnerabilities.
Reveal Answer
True
Modern vulnerability scanners are equipped to test for both by injecting test payloads and
analyzing responses.
Question Type 15: CIA Triad + Authentication + Non-repudiation
Original: Match Confidentiality, Availability, Integrity, Authentication, and
Non-repudiation with their descriptions.
📖 Source: Module_2.txt, 5_0_Introduction.txt — "CIA Triad: Confidentiality
(encryption), Integrity (hashing), Availability (redundancy)… Non-repudiation: irrefutable proof of action."
Variant A — Multiple Choice (Single Concept)
Which security principle ensures that data has not been tampered with during
transmission?
- A) Confidentiality
- B) Integrity
- C) Availability
- D) Non-repudiation
Reveal Answer
Correct Answer: B) Integrity
Integrity ensures data is only modified by authorized parties. Hashing algorithms (SHA-256, MD5)
are commonly used to verify integrity.
Variant B — Scenario-Based
A hospital's patient records system goes down during a power outage and
doctors cannot access critical information. Which principle of the CIA triad has been violated?
Reveal Answer
Availability
The data still exists and hasn't been stolen or modified, but it cannot be accessed when needed.
UPS systems, redundancy, and failover clusters mitigate availability risks.
Variant C — Matching (Technologies)
Match each security technology to the CIA principle it primarily supports:
1) AES Encryption 2) SHA-256 Hash 3) RAID Storage 4) Digital Signatures
Reveal Answer
1) AES Encryption → Confidentiality
2) SHA-256 Hash → Integrity
3) RAID Storage → Availability
4) Digital Signatures → Non-repudiation (and Integrity)
Variant D — Short Answer
What is Non-repudiation and why is it important in digital communications?
Reveal Answer
Non-repudiation ensures that the sender of a message or performer of an
action cannot deny doing so. It is achieved through digital signatures, audit trails, and
logging. It is crucial for legal evidence, financial transactions, and contract enforcement in
digital environments.
Variant E — True/False
True or False: Encrypting a file ensures both its Confidentiality and
Integrity.
Reveal Answer
False (partially)
Encryption primarily ensures Confidentiality (only authorized parties can read it). While some
encryption modes (like AES-GCM) provide integrity checks, standard encryption alone does not
guarantee integrity. A separate hash or MAC is needed to verify data hasn't been modified.
Question Type 16: NIST and Standards Organizations
Original: Which organization develops cybersecurity standards, guidelines, and
best practices?
📖 Source: Module_2.txt — "NIST (National Institute of Standards and Technology)…
develops frameworks like NIST CSF… IEEE for hardware/networking standards (802.11)… IETF for internet
protocols (RFCs)."
Variant A — Matching
Match each organization with its primary focus:
1) NIST 2) IEEE 3) IETF 4) PKCS
- (a) Internet protocol standards (RFCs)
- (b) Public-key cryptography standards
- (c) Cybersecurity frameworks and government standards
- (d) Hardware and networking standards (802.x)
Reveal Answer
1-c, 2-d, 3-a, 4-b
Variant B — Multiple Choice (Specific Framework)
The NIST Cybersecurity Framework (CSF) is widely used by organizations to
manage and reduce cybersecurity risk. Which agency publishes it?
- A) NSA
- B) CISA
- C) NIST
- D) FBI
Reveal Answer
Correct Answer: C) NIST
NIST publishes the CSF as well as SP 800-series publications covering topics from risk management
to cryptographic standards.
Variant C — True/False
True or False: The IEEE is primarily responsible for developing standards for
internet routing protocols like TCP/IP.
Reveal Answer
False
The IETF (Internet Engineering Task Force) manages TCP/IP and internet protocol standards through
RFCs. IEEE focuses on hardware, networking standards (802.3 Ethernet, 802.11 Wi-Fi), and
electrical engineering.
Variant D — Fill in the Blank
________ is a U.S. government agency that develops standards and guidelines
for cybersecurity, including the widely-adopted ________ Cybersecurity Framework.
Reveal Answer
NIST; NIST (CSF)
Variant E — S/MIME and Email Security (Lecture 2.3)
Which standard, developed by the IETF, is used to ensure the authenticity, integrity, and confidentiality of email communications through digital signatures and encryption?
- A) PKCS
- B) S/MIME
- C) PGP
- D) TLS
Reveal Answer
Correct Answer: B) S/MIME
S/MIME (Secure/Multipurpose Internet Mail Extensions) is an IETF standard for securing email with encryption and digital signatures. PKCS (Public Key Cryptography Standards) was developed by RSA Laboratories for general cryptographic operations. PGP is an alternative email encryption method. TLS secures transport-layer connections, not specifically email content.
Variant F — PKCS (Lecture 2.3)
True or False: The Public Key Cryptography Standards (PKCS) were developed by the IEEE to standardize wireless networking protocols.
Reveal Answer
False
PKCS was developed by RSA Laboratories (not IEEE) to standardize public-key cryptographic operations such as key exchange, digital signatures, and certificate requests. IEEE develops networking standards like 802.11 (Wi-Fi).
Question Type 17: Threat Definitions (Social Engineering, Trojan, DDoS)
Original: True/False on Social Engineering, Trojans, and DDoS definitions.
📖 Source: Module_2.txt, Module 3.txt — "Social engineering tricks humans… Trojans
disguise as legitimate software but do NOT self-replicate… Worms auto-replicate… DDoS uses many machines
(botnet) to overwhelm a target."
Variant A — Multiple Choice
Which type of malware disguises itself as legitimate software but does NOT
self-replicate?
- A) Worm
- B) Virus
- C) Trojan
- D) Ransomware
Reveal Answer
Correct Answer: C) Trojan
Trojans masquerade as useful programs. Worms self-replicate automatically. Viruses attach to
files and require user action to spread.
Variant B — Matching
Match each malware type to its key characteristic:
1) Worm 2) Trojan 3) Virus 4) Ransomware
- (a) Encrypts victim's data and demands payment
- (b) Self-replicates across networks without user interaction
- (c) Disguises as legitimate software; requires user to install it
- (d) Attaches to existing files; requires user action to execute and spread
Reveal Answer
1-b, 2-c, 3-d, 4-a
Variant C — Scenario-Based
An attacker calls a company receptionist, pretends to be from IT support, and
asks for the receptionist's login credentials "to fix a network issue." What type of threat is this?
Reveal Answer
Social Engineering (specifically, Pretexting or Vishing — voice
phishing)
Social engineering manipulates humans into divulging sensitive information by exploiting trust
and authority.
Variant D — Compare & Contrast
What is the difference between a DoS attack and a DDoS attack?
Reveal Answer
A DoS (Denial of Service) attack comes from a single source flooding a
target. A DDoS (Distributed DoS) attack uses many compromised machines (a botnet) to
simultaneously flood the target, making it much harder to block and far more powerful.
Variant E — True/False (Reworded)
True or False: A worm requires user interaction (like opening an email
attachment) to propagate to other systems.
Reveal Answer
False
Worms self-replicate and spread automatically without user interaction, often exploiting network
vulnerabilities. Viruses and Trojans typically require user action.
Variant F — Historical Malware Matching (Lecture Material)
Match each historical malware to its key characteristic or significance:
1) Morris Worm 2) Code Red 3) SQL Slammer 4) Michelangelo
- (a) Exploited a buffer overflow in Microsoft IIS web server
- (b) One of the first recognized internet worms (1988), demonstrated the danger of self-replicating code
- (c) Exploited blank/default SA passwords in Microsoft SQL Server, spread extremely rapidly
- (d) A boot-sector virus that activated on March 6th (Michelangelo’s birthday) and overwrote data
Reveal Answer
1-b, 2-a, 3-c, 4-d
The Morris Worm (1988) was one of the first internet worms. Code Red exploited a buffer overflow in IIS. SQL Slammer exploited default blank admin passwords and propagated at record speed. Michelangelo was a date-triggered boot-sector virus.
Variant G — Scenario (Historical)
In 2003, a piece of malware infected over 75,000 SQL Server instances within 10 minutes by exploiting default blank administrator passwords. No user interaction was required. What type of malware was this, and what was its name?
Reveal Answer
SQL Slammer — a Worm
SQL Slammer was a worm because it self-replicated without user interaction, exploiting a known vulnerability (blank SA passwords) in Microsoft SQL Server.
Question Type 18: Attacker Categories
Original: Match descriptions with Hacktivism, Cyber Terrorism, and Cyber
Criminals.
📖 Source: Module_2.txt — "Hacktivists are politically motivated… Cyber Terrorists cause
fear through digital attacks… Cyber Criminals seek financial gain… Script Kiddies use tools without
understanding… Nation States are government-sponsored."
Variant A — Multiple Choice
Anonymous, a group known for launching cyber attacks against governments and
corporations that conflict with their political views, would best be classified as:
- A) Cyber Criminals
- B) Hacktivists
- C) Nation-State Actors
- D) Script Kiddies
Reveal Answer
Correct Answer: B) Hacktivists
Hacktivists are politically or ideologically motivated, using hacking to promote their cause or
protest organizations they oppose.
Variant B — Extended Matching
Categorize each attacker:
(a) A group deploys ransomware to extort millions from companies
(b) A teenager uses downloaded hacking tools to deface a website for fun
(c) A group attacks power grid infrastructure to instill fear
(d) A foreign government sponsors hackers to steal trade secrets
(e) Protesters DDoS a bank's website after a controversial policy
Reveal Answer
(a) Cyber Criminals
(b) Script Kiddie
(c) Cyber Terrorist
(d) Nation-State Actor
(e) Hacktivist
Variant C — Short Answer
What distinguishes a Hacktivist from a Cyber Criminal?
Reveal Answer
The primary motivation: Hacktivists are driven by political or
ideological beliefs (activism). Cyber Criminals are driven specifically by financial gain
(profit). Both may use similar techniques, but their goals differ.
Variant D — True/False
True or False: Cyber Terrorism is primarily motivated by financial gain.
Reveal Answer
False
Cyber Terrorism is motivated by a desire to cause fear, panic, or damage based on political,
religious, or ideological objectives—not financial gain. Financial motivation characterizes
Cyber Criminals.
Question Type 19: Network Reconnaissance Tools
Original: Match Ping, Trace Route, NSLookup, and Whois with their capabilities.
📖 Source: Module 3.txt, Lecture 1_3_Network Communication.txt — "Ping uses ICMP…
Traceroute maps packet paths and hops… NSLookup queries DNS… Whois provides domain registration/ownership
info."
Variant A — Multiple Choice
You want to find out who registered the domain "example.com" and when it
expires. Which tool would you use?
- A) Ping
- B) Traceroute
- C) NSLookup
- D) Whois
Reveal Answer
Correct Answer: D) Whois
Whois queries domain registration databases to reveal ownership, registrar, creation/expiration
dates, and often contact information.
Variant B — Scenario-Based
A user reports that the website "shop.company.com" is loading slowly. You want
to see where the network delay is occurring along the route. Which tool do you use?
Reveal Answer
Traceroute (tracert on Windows, traceroute on Mac/Linux)
Traceroute shows each hop (router) along the path to the destination and the latency at each hop,
helping you identify where delays occur.
Variant C — Command-Based
What is the difference between these two commands?
ping 8.8.8.8
traceroute 8.8.8.8
Reveal Answer
ping sends ICMP echo requests to check if the host is
reachable and measures round-trip time. traceroute maps every intermediate router
(hop) between your machine and the destination, showing the full network path and latency at
each hop.
Variant D — Select All That Apply
Which of the following tools can be used during the reconnaissance phase of a
penetration test? (Select all)
(a) Ping (b) NSLookup (c) Whois (d) Traceroute (e) Nmap
Reveal Answer
All of them: (a), (b), (c), (d), (e)
All five tools gather information about targets—live hosts, DNS records, domain ownership,
network paths, and open ports.
Question Type 20: NSLookup Reverse Resolution
Original: True or False: NSLookup can only resolve domain→IP, not IP→domain.
📖 Source: Module 3.txt — "NSLookup can perform both forward (domain → IP) and reverse
(IP → domain) lookups using PTR records."
Variant A — Multiple Choice
What type of DNS record is queried when performing a reverse DNS lookup (IP →
domain)?
- A) A Record
- B) CNAME Record
- C) MX Record
- D) PTR Record
Reveal Answer
Correct Answer: D) PTR Record
PTR (Pointer) records map IP addresses back to domain names. A records do the opposite (domain →
IP). CNAME is an alias. MX is for mail servers.
Variant B — Command-Based
How would you use NSLookup to find the domain name associated with IP address
93.184.216.34?
Reveal Answer
nslookup 93.184.216.34
Simply passing an IP address to nslookup triggers a reverse DNS lookup, querying PTR records to
return the associated hostname.
Variant C — Short Answer
Name two types of DNS lookups that NSLookup can perform and describe each.
Reveal Answer
1) Forward Lookup: Resolves a domain name (e.g., google.com) to an IP
address by querying A/AAAA records.
2) Reverse Lookup: Resolves an IP address to a domain name by querying PTR records.
Variant D — True/False (DNS Record Focus)
True or False: An "A Record" in DNS maps an IP address to a domain name.
Reveal Answer
False
An A Record maps a domain name to an IPv4 address (forward lookup). A PTR Record maps an IP
address back to a domain name (reverse lookup).
Variant E — DNS Record Type Matching (Lecture 2.4)
Match each DNS record type to its function:
1) A 2) AAAA 3) MX 4) NS 5) CNAME 6) TXT 7) PTR
Reveal Answer
1) A — Maps a domain name to an IPv4 address
2) AAAA — Maps a domain name to an IPv6 address
3) MX — Specifies the mail exchange server(s) for a domain
4) NS — Identifies the authoritative name server(s) for a domain
5) CNAME — Creates an alias that points one domain name to another
6) TXT — Stores arbitrary text information (used for SPF, DKIM, domain verification)
7) PTR — Maps an IP address back to a domain name (reverse lookup)
Variant F — Multiple Choice (MX Record)
When you send an email to user@example.com, your mail server queries DNS to find out which server handles mail for example.com. Which DNS record type is queried?
- A) A Record
- B) NS Record
- C) MX Record
- D) CNAME Record
Reveal Answer
Correct Answer: C) MX Record
MX (Mail Exchange) records specify which server(s) should receive email for a given domain. NS records identify the authoritative DNS server, not the mail server.
Variant G — True/False (AAAA vs. A)
True or False: An AAAA record serves the same function as an A record but maps a domain name to an IPv6 address instead of IPv4.
Reveal Answer
True
An A record maps domain → IPv4. An AAAA record maps domain → IPv6. The "AAAA" name reflects that IPv6 addresses are four times as long as IPv4.
Question Type 21: Root Name Servers
Original: How many Root Name Servers exist globally?
📖 Source: Module 3.txt — "13 logical root name server IP addresses (A through M)…
managed by different organizations… hundreds of physical servers via Anycast."
Variant A — Multiple Choice (Reworded)
The global DNS root server system consists of how many unique logical server
identities?
Reveal Answer
Correct Answer: B) 13
Named A through M. While there are hundreds of physical servers worldwide, they share only 13 IP
addresses via Anycast routing.
Variant B — Short Answer
Explain how there can be only 13 root server IPs but hundreds of physical root
servers worldwide.
Reveal Answer
Anycast routing allows multiple physical servers spread across
different geographic locations to share the same IP address. When a DNS query is sent to a root
server IP, the network routes it to the nearest physical instance, providing redundancy and low
latency without needing more than 13 logical addresses.
Variant C — True/False
True or False: Each of the 13 root name servers is operated by the same
organization.
Reveal Answer
False
The 13 root servers are managed by 12 different organizations including Verisign, ICANN, NASA, US
Army, and various universities and research institutions.
Variant D — Conceptual
What role do Root Name Servers play in the DNS resolution process?
Reveal Answer
Root Name Servers are the first step in resolving a domain name when
the answer isn't cached. They don't store individual domain records; instead, they direct
queries to the appropriate Top-Level Domain (TLD) servers (e.g., .com, .org, .net), which then
point to the authoritative name servers for the specific domain.
Question Type 22: Metasploit Payload Types
Original: Match Singles, Stagers, and Stages with their functionality.
📖 Source: Module_4.txt — "Singles: self-contained payloads… Stagers: tiny, establish
connection back to attacker… Stages: larger payloads downloaded by stagers."
Variant A — Multiple Choice
In Metasploit, a small payload whose only job is to establish a communication
channel between the attacker and victim is called a:
- A) Single
- B) Stager
- C) Stage
- D) Meterpreter
Reveal Answer
Correct Answer: B) Stager
Stagers are intentionally tiny so they fit within exploit buffer constraints. Their sole purpose
is to open a connection, then download the larger Stage payload.
Variant B — Scenario-Based
An attacker exploits a buffer overflow vulnerability. Due to the limited
buffer size, they can only inject a very small payload. This payload connects back to their server and
downloads a full Meterpreter shell. Identify which payload types are being used and in what order.
Reveal Answer
First: A Stager (small payload that fits in the buffer and establishes
the connection). Second: A Stage (the full Meterpreter shell downloaded by the stager).
Variant C — Compare & Contrast
What is the difference between a Single payload and a Stager + Stage
combination in Metasploit?
Reveal Answer
A Single is completely self-contained — it performs its entire function
in one payload (e.g., adding a user account). A Stager + Stage combination splits the work: the
stager is small and only establishes a connection, then the Stage (the larger, feature-rich
payload) is downloaded through that connection. The split approach is used when exploit buffer
sizes are too small for the full payload.
Variant D — Naming Convention
In Metasploit, how can you tell the difference between a Single payload and a
Stager/Stage payload just by looking at the payload name?
Reveal Answer
Singles use underscores ( _ ) between components: e.g.,
windows/shell_reverse_tcp. Stager/Stage combinations use forward slashes ( / ):
e.g., windows/shell/reverse_tcp. The extra "/" separates the stage from the
stager.
Variant E — True/False
True or False: A "Stage" payload in Metasploit is designed to be as small as
possible to fit within an exploit's buffer space.
Reveal Answer
False
That describes a Stager, not a Stage. Stages are the larger payloads that get downloaded after
the stager has already established a connection. Stages don't have the same size constraints
because they're sent over the established channel.
Question Type 23: Meterpreter
Original: Which payload provides an interactive session between attacker and
victim?
📖 Source: Module_4.txt — "Meterpreter is an advanced, dynamically extensible payload…
runs entirely in memory… provides interactive command shell… can dump hashes, pivot, migrate processes."
Variant A — Multiple Choice (Feature-Focused)
Which Metasploit payload operates entirely in memory, never writing to disk,
making it particularly difficult for antivirus to detect?
- A) A Single reverse shell
- B) Meterpreter
- C) A Stager payload
- D) An executable Stage
Reveal Answer
Correct Answer: B) Meterpreter
Meterpreter is designed to reside entirely in memory through DLL injection, never touching the
disk, which is a key reason it evades many traditional antivirus solutions.
Variant B — Short Answer
List three things an attacker can do with a Meterpreter session.
Reveal Answer
1) Dump password hashes (hashdump)
2) Take screenshots or record keystrokes
3) Pivot to other systems on the network
(Also: migrate between processes, upload/download files, execute commands, escalate privileges,
enable RDP, clear event logs)
Variant C — True/False
True or False: Meterpreter writes itself to the victim's hard drive as an
executable file.
Reveal Answer
False
Meterpreter resides entirely in memory using DLL injection. This "fileless" approach helps it
avoid detection by file-based antivirus scanners.
Variant D — Scenario-Based
After exploiting a vulnerability, an attacker gains a session that allows them
to run hashdump, screenshot, getsystem, and portfwd
commands on the victim machine. What type of session do they have?
Reveal Answer
A Meterpreter session
These are all Meterpreter-specific commands. A basic shell would not have these capabilities
without additional tools.
Variant E — Compare & Contrast
What advantages does a Meterpreter session offer over a basic command shell?
Reveal Answer
Meterpreter advantages over a basic shell:
• Runs in memory (no files on disk = stealthier)
• Encrypted communication channel
• Dynamically extensible (load new modules on-the-fly)
• Built-in commands for privilege escalation, pivoting, hash dumping, keylogging, and more
• Can migrate between processes to avoid detection
• A basic shell only provides command-line access with no advanced post-exploitation features
Question Type 24: Kerberos & PKI Components
New: Match Kerberos components to their functions.
📖 Source: 5_3_Authentication.txt — "Kerberos uses a Key Distribution Center (KDC) consisting of an Authentication Server (AS) and a Ticket Granting Server (TGS)… tickets prove identity without resending credentials."
Variant A — Matching
Match each Kerberos component to its function:
1) Key Distribution Center (KDC) 2) Authentication Server (AS) 3) Ticket Granting Server (TGS) 4) Ticket Granting Ticket (TGT)
Reveal Answer
1) KDC — The trusted third party that manages the entire ticketing system; contains both the AS and TGS.
2) AS — Handles the initial authentication of a user and issues a Ticket Granting Ticket (TGT).
3) TGS — Accepts the TGT and issues service-specific tickets allowing access to particular resources.
4) TGT — A time-limited token issued by the AS that proves the user has already authenticated; presented to the TGS to request service tickets.
Variant B — Scenario-Based (Kerberos Flow)
Alice wants to access a file server. She first logs in with her password. The system verifies her credentials and gives her a special token. She then presents this token to request access specifically to the file server, and receives a service ticket. Identify each Kerberos step.
Reveal Answer
Step 1: Alice authenticates to the Authentication Server (AS) with her credentials.
Step 2: The AS issues a Ticket Granting Ticket (TGT).
Step 3: Alice presents the TGT to the Ticket Granting Server (TGS).
Step 4: The TGS issues a Service Ticket for the file server.
Step 5: Alice presents the Service Ticket to the file server to gain access.
Variant C — Multiple Choice
In Kerberos, which component is the trusted third party that manages the entire authentication and ticketing process?
- A) Authentication Server (AS)
- B) Ticket Granting Server (TGS)
- C) Key Distribution Center (KDC)
- D) Certificate Authority (CA)
Reveal Answer
Correct Answer: C) Key Distribution Center (KDC)
The KDC is the central trusted authority that contains both the AS and TGS. A Certificate Authority (CA) is part of PKI, not Kerberos.
Variant D — True/False
True or False: In Kerberos, a user must re-enter their password every time they want to access a different network resource.
Reveal Answer
False
Kerberos provides Single Sign-On (SSO). After the initial authentication, the user receives a TGT that can be presented to the TGS to obtain service tickets for different resources without re-entering credentials.
Variant E — Short Answer (Kerberos vs. PKI)
What is the key difference between Kerberos authentication and PKI (Public Key Infrastructure) authentication?
Reveal Answer
Kerberos uses symmetric-key cryptography and a centralized trusted third party (KDC) that issues time-limited tickets. PKI uses asymmetric (public/private) key pairs and digital certificates issued by a Certificate Authority (CA). Kerberos is typically used within a single organization's network (e.g., Active Directory), while PKI is used for broader trust (e.g., HTTPS, S/MIME).
Question Type 25: Network Topologies
New: Identify characteristics and failure points of network topologies.
📖 Source: Lecture 1_2_Network Topologies.txt — "Ring topology: failure of a single node can disrupt the entire network… Star: dependent on a centralized server/hub… Bus: shares a medium, requires collision controls."
Variant A — Matching
Match each topology to its primary vulnerability:
1) Ring 2) Star 3) Bus 4) Mesh
- (a) Single point of failure at the central hub/switch
- (b) A single node failure can disrupt the entire network
- (c) Shared medium requires collision handling; a cable break splits the network
- (d) Most fault-tolerant but highest cost due to redundant connections
Reveal Answer
1-b, 2-a, 3-c, 4-d
Variant B — Scenario-Based
A company’s network uses a central switch. All 50 computers connect directly to this switch. When the switch fails, the entire office loses network connectivity. Which topology is this, and what is its weakness?
Reveal Answer
Star Topology. Its weakness is the single point of failure at the central device (switch/hub). If that device fails, all connected nodes lose connectivity.
Variant C — Multiple Choice
In which topology does data travel in one direction around a loop, and the failure of a single node can disrupt communication for all nodes?
- A) Star
- B) Bus
- C) Ring
- D) Full Mesh
Reveal Answer
Correct Answer: C) Ring
In a ring topology, each node connects to exactly two others forming a circle. Data passes sequentially. A break at any point disrupts the loop (unless a dual-ring/FDDI configuration is used).
Variant D — True/False
True or False: A Bus topology uses a shared communication medium and requires a mechanism like CSMA/CD to handle data collisions.
Reveal Answer
True
In a bus topology, all devices share a single cable (backbone). CSMA/CD (Carrier Sense Multiple Access with Collision Detection) is used to manage collisions when multiple devices transmit simultaneously.
Variant E — Network Scope Classification (Lecture 1.1)
Classify each network by its geographic scope:
1) Connects devices within a single building 2) Spans a city or campus 3) Connects networks across countries or continents
Reveal Answer
1) LAN (Local Area Network)
2) MAN (Metropolitan Area Network)
3) WAN (Wide Area Network)
Question Type 26: Disaster Management Categorization
New: Categorize disaster scenarios by severity level.
📖 Source: Module 3.txt (Lecture 3.4) — "Low-level: human errors, single server failure. Medium-level: virus attacks, prolonged power failures. High-level: earthquakes, fires, terrorism."
Variant A — Categorization
Categorize each event as Low, Medium, or High-level disaster:
(a) An intern accidentally deletes a database table
(b) A ransomware attack encrypts 60% of company servers
(c) An earthquake destroys the primary data center
(d) A single web server crashes due to a software bug
(e) A power outage lasts 48 hours affecting multiple systems
(f) A terrorist bomb threat forces evacuation of the building
Reveal Answer
Low: (a) Human error, (d) Single server failure
Medium: (b) Virus/ransomware attack, (e) Prolonged power failure
High: (c) Earthquake/natural disaster, (f) Terrorism
Variant B — Multiple Choice
According to disaster management classification, a widespread virus attack that takes down multiple systems for several days would be categorized as:
- A) Low-level disaster
- B) Medium-level disaster
- C) High-level disaster
- D) Not classified as a disaster
Reveal Answer
Correct Answer: B) Medium-level disaster
Virus attacks and prolonged outages are medium-level. High-level is reserved for events causing physical destruction or posing existential threats (natural disasters, terrorism, fires).
Variant C — Short Answer
What are the three levels of disaster categorization, and give one example of each?
Reveal Answer
Low-level: Minor incidents with limited impact (e.g., human error, single server failure).
Medium-level: Significant disruptions affecting multiple systems (e.g., virus/ransomware attacks, extended power failures).
High-level: Catastrophic events with widespread destruction (e.g., earthquakes, fires, terrorism).
Variant D — True/False
True or False: A single server failure caused by a software bug is classified as a High-level disaster.
Reveal Answer
False
A single server failure is a Low-level disaster. High-level disasters involve widespread physical destruction or threats such as earthquakes, fires, or terrorism.
Question Type 27: TCP/IP Model vs. OSI Model
New: Map protocols to their TCP/IP layers and compare TCP/IP to OSI.
📖 Source: Lecture 1_3_Network Communication.txt — "TCP/IP has 4 layers: Application, Transport, Internet/Network, Network Access… Transport layer contains TCP and UDP… Network layer uses IP and ICMP… Application layer includes HTTP, FTP, SMTP, DNS."
Variant A — Layer Mapping
Place each protocol into its correct TCP/IP layer:
HTTP, TCP, IP, ARP, FTP, UDP, ICMP, SMTP, DNS, Ethernet
Reveal Answer
Application Layer: HTTP, FTP, SMTP, DNS
Transport Layer: TCP, UDP
Internet/Network Layer: IP, ICMP
Network Access Layer: ARP, Ethernet
Variant B — Multiple Choice
In the TCP/IP model, which layer is responsible for end-to-end transport of messages between servers, and which two protocols operate at this layer?
- A) Application Layer — HTTP and FTP
- B) Transport Layer — TCP and UDP
- C) Internet Layer — IP and ICMP
- D) Network Access Layer — Ethernet and ARP
Reveal Answer
Correct Answer: B) Transport Layer — TCP and UDP
The Transport Layer handles end-to-end communication. TCP provides reliable, connection-oriented delivery. UDP provides fast, connectionless delivery.
Variant C — OSI vs. TCP/IP Comparison
The OSI model has 7 layers while the TCP/IP model has 4. Which OSI layers are combined into the TCP/IP Application layer?
Reveal Answer
The TCP/IP Application layer combines OSI layers 5 (Session), 6 (Presentation), and 7 (Application).
Similarly, OSI layers 1 (Physical) and 2 (Data Link) combine into the TCP/IP Network Access layer.
Variant D — Scenario-Based
A network technician uses the ping command to test connectivity to a remote server. The ping command sends ICMP Echo Request packets. At which TCP/IP layer does ICMP operate?
- A) Application Layer
- B) Transport Layer
- C) Internet/Network Layer
- D) Network Access Layer
Reveal Answer
Correct Answer: C) Internet/Network Layer
ICMP operates at the Internet (Network) layer alongside IP. It is used for error reporting and network diagnostics (ping, traceroute), not for transporting application data.
Variant E — True/False
True or False: DNS operates at the Transport layer of the TCP/IP model because it can use both TCP and UDP.
Reveal Answer
False
DNS is an Application layer protocol. While it does use UDP (port 53) for standard queries and TCP (port 53) for zone transfers, DNS itself operates at the Application layer. TCP and UDP are the Transport layer protocols it relies on.
📚 Total: 27 Question Types × ~5-7 Variants each = 150+ unique practice questions
Refined with lecture cross-referencing — Generated from /ExtractedText/