Tag the questions with any skills you have. Your dashboard will track each student's mastery of each skill.
Give this quiz to my class
Q 1/65
Score 0
Which of the following techniques is commonly used to exploit privilege escalation vulnerabilities?
30
Denial of Service attacks
Weak password cracking
Exploitation of misconfigured services
Social engineering
Q 2/65
Score 0
What type of vulnerability allows attackers to gain higher access rights than intended?
30
Cross-site scripting
Denial of Service
SQL injection
Privilege escalation
65 questions
Q.
Which of the following techniques is commonly used to exploit privilege escalation vulnerabilities?
1
30 sec
Q.
What type of vulnerability allows attackers to gain higher access rights than intended?
2
30 sec
Q.
What is a common method attackers use to achieve privilege escalation on a system?
3
30 sec
Q.
What is one common indicator of a privilege escalation vulnerability?
4
30 sec
Q.
Which configuration could lead to privilege escalation if not properly secured?
5
30 sec
Q.
What type of attack often combines privilege escalation with gaining unauthorized access?
6
30 sec
Q.
Which of the following best describes a race condition vulnerability in the context of privilege escalation?
7
30 sec
Q.
What is a primary tool used by attackers to discover privilege escalation vulnerabilities in software?
8
30 sec
Q.
What kind of software misconfiguration might lead to privilege escalation?
9
30 sec
Q.
Which action can help mitigate the risk of privilege escalation vulnerabilities?
10
30 sec
Q.
What is a common method for privilege escalation on Linux systems?
11
30 sec
Q.
Which technique is often used for privilege escalation on Windows systems?
12
30 sec
Q.
What is a common sign of privilege escalation activity in a Windows environment?
13
30 sec
Q.
Which command can be used to list setuid binaries on a Linux system?
14
30 sec
Q.
What Windows service can be exploited for privilege escalation due to improper permissions?
15
30 sec
Q.
What is a potential privilege escalation attack vector specific to Linux kernel vulnerabilities?
16
30 sec
Q.
In Windows, what type of account can be targeted to elevate privileges through the use of Pass-the-Hash attacks?
17
30 sec
Q.
Which vulnerability is commonly exploited for privilege escalation in Windows systems involving DLL files?
18
30 sec
Q.
What is a common method for detecting privilege escalation attempts on Linux systems?
19
30 sec
Q.
Which command is used to check the effective user ID on a Linux system?
20
30 sec
Q.
What is a common method used to retrieve password hashes from a database?
21
30 sec
Q.
Which algorithm is frequently used for hashing passwords due to its adaptability and security features?
22
30 sec
Q.
What is one of the main vulnerabilities when using weak password hashing algorithms like MD5?
23
30 sec
Q.
What technique can be used to enhance the security of stored password hashes?
24
30 sec
Q.
What is the purpose of a 'rainbow table' in the context of password cracking?
25
30 sec
Q.
What is one of the first steps to take after dumping password hashes from a database?
26
30 sec
Q.
Which attack method leverages the use of precomputed hashes to crack passwords more quickly?
27
30 sec
Q.
What practice should be avoided to enhance password security when storing user passwords?
28
30 sec
Q.
What is a primary benefit of using the PBKDF2 algorithm for password hashing?
29
30 sec
Q.
What is the primary purpose of using a password manager?
30
30 sec
Q.
What type of web vulnerability allows attackers to inject malicious scripts into webpages viewed by other users?
31
30 sec
Q.
Which method is commonly used to prevent Cross-Site Scripting (XSS) attacks?
32
30 sec
Q.
What is the primary goal of a SQL Injection attack?
33
30 sec
Q.
Which of the following is NOT a common characteristic of a Cross-Site Request Forgery (CSRF) attack?
34
30 sec
Q.
What is an effective way to protect against Cross-Site Scripting (XSS) attacks in web applications?
35
30 sec
Q.
Which type of web exploit targets the trust a user has in a specific site to execute unauthorized actions?
36
30 sec
Q.
What type of attack involves an attacker manipulating client-side scripts of web pages to alter how they are displayed or to execute malicious scripts?
37
30 sec
Q.
What is a common consequence of a successful SQL Injection attack?
38
30 sec
Q.
Which technique is used to prevent SQL Injection vulnerabilities in web applications?
39
30 sec
Q.
What is the primary risk associated with Remote File Inclusion (RFI) vulnerabilities?
40
30 sec
Q.
What is the primary goal of penetration testing?
41
30 sec
Q.
Which phase of penetration testing involves gathering information about the target?
42
30 sec
Q.
What is a common tool used for network penetration testing?
43
30 sec
Q.
What is the purpose of the exploitation phase in penetration testing?
44
30 sec
Q.
What is the importance of the reporting phase in penetration testing?
45
30 sec
Q.
What type of penetration testing involves simulating an attack as if it were performed by a real hacker?
46
30 sec
Q.
What is the primary purpose of tools like GTFOBins and LOLBAS?
47
30 sec
Q.
What is Mimikatz primarily used for in cybersecurity?
48
30 sec
Q.
Which of the following best describes LOLBAS?
49
30 sec
Q.
What is a common technique associated with using GTFOBins?
50
30 sec
Q.
In what context is Mimikatz frequently used?
51
30 sec
Q.
What do GTFOBins and LOLBAS have in common?
52
30 sec
Q.
Which command-line utility is often targeted by Mimikatz for credential extraction?
53
30 sec
Q.
What type of actions do GTFOBins enable that are typically seen as suspicious?
54
30 sec
Q.
Which of the following is a known function of Mimikatz?
55
30 sec
Q.
What is a key motivation for using LOLBAS in an attack?
56
30 sec
Q.
What is the primary function of Mimikatz in the context of cybersecurity?
57
30 sec
Q.
What is Nmap primarily used for in network security?
58
30 sec
Q.
Which feature of Mimikatz allows it to perform credential dumping from Windows systems?
59
30 sec
Q.
What type of scan does Nmap perform to quickly detect which ports are open on a target system?
60
30 sec
Q.
Which of the following protocols can Mimikatz exploit to perform Kerberos ticket extraction?
61
30 sec
Q.
What command in Nmap is used to enable OS detection during a scan?
62
30 sec
Q.
Which Nmap command is commonly used to scan for open ports on a target host?
63
30 sec
Q.
What option in Nmap is used to enable OS detection?
64
30 sec
Q.
Which Nmap command is used to perform a version detection scan?