Question Bank
Academic Year 2024 – 2025
Seventh Semester
Computer Science and Engineering
CCS344 – Ethical Hacking
Regulations 2021
Part – A (2 Mark Questions)
Questio Question Name Blooms Blooms CO
n No.
Taxonomy Description No.
Unit – I Introduction
Two Marks
1. What is ethical hacking? K1 Remembering CO1
2. What is the primary role of a penetration K1 Remembering CO1
tester?
3. Distinguish between ethical hacking and K4 Analysing CO1
malicious hacking.
4. Why is understanding local laws important K1 Remembering CO1
in ethical hacking?
5. What is penetration testing? K1 Remembering CO1
6. Name the four layers of the TCP/IP model K1 Remembering CO1
7. List two protocols that operate at the K1 Understanding CO1
application layer.
8. List two core objectives of ethical hacking. K1 Remembering CO1
9. What is the function of the internet layer in K1 Remembering CO1
the TCP/IP model?
10. Distinguish between IPv4 and IPv6. K4 Analysing CO1
11. Name two common methods used by K1 Remembering CO1
intruders to gain unauthorized access.
12. What is an intruder attack? K1 Remembering CO1
13. What is physical security in the context of K1 Remembering CO1
cybersecurity?
14. Define black-box and white-box K1 Remembering CO1
penetration testing.
15. What is the purpose of subnetting in K1 Remembering CO1
networking?
16. What is a DoS attack? K1 Remembering CO1
17. Define the term "security posture" in K1 Remembering CO1
cybersecurity.
18. What is the Computer Fraud and Abuse Act K1 Creating CO1
(CFAA)?
19. Name two physical threats to a server room K1 Remembering CO1
and their countermeasures.
20. What is the purpose of biometric K1 Remembering CO1
authentication in physical security?
Unit – II Foot Printing, Reconnaissance and Scanning Networks
Two Marks
1. What is foot printing in cybersecurity? K1 Remembering CO2
2. Name any two types of information K1 Remembering CO2
obtained during the foot printing process.
3. What is the role of search engines in foot K1 Remembering CO2
printing?
4. How is foot printing performed using K1 Remembering CO2
email?
5. List two examples of web services used for K1 Remembering CO2
foot printing.
6. Why are social networking sites considered K1 Remembering CO2
valuable for foot printing?
7. What is competitive intelligence in the K1 Remembering CO2
context of foot printing?
8. List two examples of data collected from a K1 Remembering CO2
target website during foot printing.
9. Mention two commonly used foot printing K2 Understanding CO2
tools.
10. Define foot printing through social K1 Remembering CO2
engineering.
11. What is a port scan? K1 Remembering CO2
12. What is the primary purpose of network K1 Remembering CO2
scanning?
13. Distinguish between active and passive K4 Analysing CO2
scanning.
14. List two types of information obtained K1 Remembering CO2
during port scanning.
15. What is meant by scanning beyond IDS and K1 Remembering CO2
firewalls?
16. List two common scanning techniques. K1 Remembering CO2
17. What is the purpose of using stealth K1 Remembering CO2
scanning?
18. Name any two tools used for port scanning. K1 Remembering CO2
19. What is banner grabbing, and how is it used K1 Remembering CO2
in scanning?
20. .What are the main objectives of scanning a K1 Remembering CO2
network?
UNIT – III Enumeration and Vulnerability Analysis
TWO MARKS
1. Define enumeration in the context of K1 Remembering CO3
ethical hacking.
2. Mention two goals of enumeration during K2 Understanding CO3
penetration testing.
3. List any two protocols commonly targeted K1 Remembering CO3
in enumeration.
4. Explain the importance of enumeration in K2 Understanding CO3
vulnerability assessment.
5. What is NetBIOS, and why is it a target for K1 Remembering CO3
enumeration?
6. Name two tools used for NetBIOS K1 Remembering CO3
enumeration.
7. State any two pieces of information that K2 Understanding CO3
can be obtained via NetBIOS enumeration.
8. What port is typically associated with K1 Remembering CO3
NetBIOS over TCP/IP?
9. What is the default port used by SNMP, K1 Remembering CO3
and why is it significant in enumeration?
10. Mention two pieces of information that can K2 Understanding CO3
be retrieved through LDAP enumeration.
11. Define NTP enumeration and its purpose in K1 Remembering CO3
network security.
12. State any two commands or tools used for K2 Understanding CO3
SMTP enumeration.
13. Explain how DNS enumeration aids K2 Understanding CO3
attackers in reconnaissance.
14. Differentiate between vulnerability K4 Analysing CO3
assessment and penetration testing.
15. What is the primary purpose of a K1 Remembering CO3
vulnerability assessment?
16. Name two common vulnerabilities found in K1 Remembering CO3
desktop operating systems.
17. State any two server-specific vulnerabilities K2 Understanding CO3
that attackers often exploit.
18. Identify two widely known Windows K3 Applying CO3
vulnerabilities from the past decade.
19. Name two tools used for detecting K1 Remembering CO3
vulnerabilities in Windows operating
systems.
20. List out two examples of vulnerabilities K1 Remembering CO4
commonly found in Linux operating
systems.
UNIT – IV System Hacking
TWO MARKS
1. What is web server hacking? K1 Remembering CO4
2. Identify two common vulnerabilities in web K3 Applying CO4
servers that attackers exploit.
3. List two consequences of a successful web K1 Remembering CO4
server attack.
4. Define the term "web application K1 Remembering CO4
vulnerability."
5. Explain why WPA2 is considered more K2 Understanding CO4
secure than WEP for wireless networks.
6. Explain why directory traversal is a K2 Understanding CO4
common attack on web servers.
7. Summarise how broken authentication can K2 Understanding CO4
lead to web application compromise.
8. Summarise the role of rogue access points K2 Understanding CO4
in wireless network attacks.
9. Identify two critical components of a web K3 Applying CO4
application that are often targeted by
attackers.
10. Explain how ethical hackers use proxy K2 Understanding CO4
tools in web application testing.
11. Define the term "WEP cracking" in the K1 Remembering CO4
context of wireless hacking.
12. List two examples of web application K1 Remembering CO4
vulnerabilities.
13. What is the purpose of a web vulnerability K1 Remembering CO4
scanner?
14. List two features of Burp Suite that aid in K1 Remembering CO4
security testing.
15. Identify two tools commonly used for K3 Applying CO4
security testing of web applications.
16. What is meant by hacking wireless K1 Remembering CO4
networks?
17. Identify two ethical implications of K1 Remembering CO4
wardriving.
18. List two challenges in securing wireless K1 Remembering CO4
networks.
19. Define wardriving in the context of K1 Remembering CO4
wireless networks.
20. List two tools used for wardriving K1 Remembering CO4
activities.
UNIT – V Network Protection Systems
TWO MARKS
1. Define Access Control List (ACL) and K1 Remembering CO5
mention its primary purpose in network
security.
2. Distinguish between standard and extended K4 Analysing CO5
ACLs in networking.
3. Mention two key considerations when K2 Understanding CO5
designing an ACL.
4. What is a Cisco Adaptive Security K1 Remembering CO5
Appliance (ASA) Firewall?
5. Explain two key features of the Cisco ASA K2 Understanding CO5
Firewall.
6. How does the Cisco ASA Firewall K1 Remembering CO5
implement stateful packet inspection?
7. What are the primary benefits of using K1 Remembering CO5
Cisco ASA for small to medium
businesses?
8. Name two commonly used tools for K1 Remembering CO5
firewall configuration analysis and explain
their importance.
9. What is the purpose of risk analysis in K1 Remembering CO5
firewall configuration?
10. How do misconfigurations in firewalls and K1 Remembering CO5
routers impact network security?
11. Mention two best practices for analysing K2 Understanding CO5
firewall and router configurations.
12. Distinguish between Intrusion Detection K4 Analysing CO5
Systems (IDS) and Intrusion Prevention
Systems (IPS).
13. What is the primary purpose of an IDS in a K1 Remembering CO5
network?
14. Explain how ACLs contribute to restricting K2 Understanding CO5
unauthorized access in a network.
15. How does an IPS mitigate potential K1 Remembering CO5
security threats in real-time?
16. Give one example each of network-based CO5
IDS and host-based IDS.
17. Explain the main difference between K2 Understanding CO5
network-based and host-based intrusion
prevention systems.
18. What are two advantages of using a host- K1 Remembering CO5
based intrusion detection system?
19. Define web filtering and mention its role in K1 Remembering CO5
network security.
20. List two methods used to implement web K1 Remembering CO5
filtering in an organization.
Part – B (16 Mark Questions)
Questio Question Name Blooms Blooms CO
n No. Description
Taxonom No.
y
Unit – I Introduction
Big Questions
1. Explain the role of ethical hackers in K2 Understanding CO1
enhancing an organization’s security. Discuss
the key skills required and the challenges
faced by ethical hackers in their work.
2. Identify the types of intruder attacks and their K3 Applying CO1
techniques. Summarise the strategies for
detecting and mitigating these attacks
effectively.
3. Examine the role of malware in network and K4 Analysing CO1
computer attacks. List and explain different
types of malware, such as ransomware,
spyware, and Trojans, and summarize
strategies for mitigating malware risks.
4. Explain the various types of penetration K2 Understanding CO1
testing (black-box, white-box, and grey-box).
Discuss the scenarios where each type is most
effective, with relevant examples.
5. What are the phases of a penetration test? K1 Remembering CO1
Discuss each phase in detail, providing
examples of tools and techniques used at each
stage.
6. Explain the role of the transport layer in data K2 Understanding CO1
transmission, focusing on the differences
between TCP and UDP. Explain the
significance of port numbers in network
communication with examples of common
port-based services.
7. Explain the TCP/IP model in detail, K2 Understanding CO1
describing the functions of each layer.
Compare and contrast the TCP/IP model with
the OSI model.
8. What is the role of the application layer in the K1 Remembering CO1
TCP/IP model? Discuss key application layer
protocols such as HTTP, FTP, and DNS,
providing real-world examples of their usage.
9. What is malware? Discuss the different types K1 Remembering CO1
of malware, such as viruses, worms, trojans,
ransomware, and spyware. Explain how
ethical hackers help in detecting and
mitigating malware threats.
10. Summarize the importance of understanding K2 Understanding CO1
cybersecurity laws and regulations. Identify
key legal frameworks that govern ethical
hacking in different regions. How do these
laws impact the actions of penetration testers?
Unit – II Foot Printing, Reconnaissance and Scanning
Big Questions
1. How can email systems be used for foot K1 Remembering CO2
printing? Explain the process of analysing
email headers and its significance.
2. Interpret a detailed workflow of a foot K5 Evaluating CO2
printing process for ethical hacking,
highlighting tools, methods, and expected
outputs at each stage.
3. What is competitive intelligence in the K1 Remembering CO2
context of foot printing? Discuss the tools and
techniques used for gathering competitive
intelligence.
4. What is port scanning, and why is it important K1 Remembering CO2
in penetration testing? Explain the
information that can be gathered through port
scanning.
5. Explain the various tools used for port K2 Understanding CO2
scanning, such as Nmap and Angry IP
Scanner. Compare their features, advantages,
and limitations.
6. Explain the concept of foot printing in ethical K2 Understanding CO2
hacking. Discuss its importance and outline
the various types of information an attacker
aims to gather during the foot printing phase.
7. Explain the concept of scanning beyond IDS
and firewalls. Discuss the methods used to
bypass security systems during scanning. K2 Understanding CO2
8. Design a case study where a network K6 Creativity CO2
scanning exercise identifies critical
vulnerabilities. Outline the tools used,
findings, and remediation steps.
9. Explain the difference between active and K2 Understanding CO2
passive network scanning. Discuss their
respective benefits and limitations in ethical
hacking.
10. What is banner grabbing? Explain how it is K1 Remembering CO2
used during network scanning to identify
services and their versions.
UNIT – III Enumeration and Vulnerability Analysis
Big Questions
1. Define vulnerability assessment and explain K1 Remembering CO3
its role in maintaining the security of IT
systems. Differentiate between manual and
automated vulnerability assessment tools with
examples.
2. Explain the process of enumeration in K2 Understanding CO3
penetration testing. Highlight the significance
of protocols like SNMP, LDAP, and DNS in
gathering critical information during
enumeration.
3. Explain the key stages of a vulnerability K2 Understanding CO3
assessment process. How can organizations
prioritize vulnerabilities for remediation?
4. What is NetBIOS enumeration? Discuss the K1 Remembering CO3
potential risks associated with exposing
NetBIOS services and explain how attackers
exploit these vulnerabilities. Provide
examples of tools used in this process.
5. Analyse how embedded OS vulnerabilities K4 Analysing CO3
differ from those in traditional desktop or
server OS environments. What challenges do
organizations face in identifying and
mitigating these vulnerabilities?
6. Compare and contrast desktop OS and server K2 Understanding CO3
OS vulnerabilities. Provide examples of
common vulnerabilities in each and discuss
the potential impact on an organization if
exploited.
7. Explain the various types of information an K2 Understanding CO3
attacker can gather through enumeration
techniques. Support your answer with
examples of tools and protocols used
8. Explain the role of SNMP in network K2 Understanding CO3
management and how attackers can exploit
SNMP enumeration to gain unauthorized
access to critical information. What
countermeasures can be implemented?
9. Distinguish between how DNS and SMTP K4 Analysing CO3
enumeration can be used to identify potential
vulnerabilities in a network. Include examples
of tools and the information that can be
extracted using these protocols.
10. Explain the significance of NetBIOS K2 Understanding CO3
enumeration in network penetration testing.
How can organizations secure their systems
against such attacks?
UNIT – IV System Hacking
Big Questions
1. Identify three popular tools used for web K3 Applying CO4
server attacks. Examine their functionalities
and how ethical hackers or security testers use
them to identify vulnerabilities.
2. What are the common methods used to hack K1 Remembering CO4
web servers? Explain how vulnerabilities in
web servers can be exploited and their
potential consequences.
3. Summarise the critical components of web K2 Understanding CO4
applications. Explain how their
misconfigurations or vulnerabilities can lead
to attacks.
4. Compare and contrast SQL Injection and K2 Understanding CO4
Cross-Site Scripting (XSS) attacks. Highlight
their methods of execution, impact, and
prevention strategies.
5. Define wireless network hacking. Explain the K1 Remembering CO4
key challenges in securing wireless networks
and the methods used to exploit their
vulnerabilities.
6. Explain the concept of wardriving in the K2 Understanding CO4
context of wireless hacking. Examine its
ethical implications and the tools commonly
used in wardriving activities.
7. List five essential tools used by web attackers K1 Remembering CO4
and security testers. Explain the purpose and
features of each tool.
8. Identify the components of a wireless network K3 Applying CO4
and summarise how attackers exploit these
components during wireless hacking attempts.
9. List five tools used in wireless hacking. K1 Remembering CO4
Compare their capabilities and limitations in
both offensive (attacker) and defensive
(security tester) scenarios.
10. Construct a scenario demonstrating a common K6 Creating CO4
web attack (e.g., session hijacking). Examine
the tools and techniques used in such attacks
and provide countermeasures to prevent them.
UNIT – V Network Protection System
Big Questions
1. What are Access Control Lists (ACLs), and K1 Remembering CO5
how do they contribute to securing a network?
Provide examples to demonstrate their usage.
2. Define the Cisco Adaptive Security Appliance K1 Remembering CO5
(ASA) Firewall. Explain its core
functionalities and how it ensures stateful
packet inspection.
3. Compare and contrast standard and extended K2 Understanding CO5
ACLs in terms of functionality, configuration,
and use cases.
4. Identify three configuration and risk analysis K3 Applying CO5
tools used for firewalls and routers. Explain
how these tools help in securing network
infrastructures.
5. Summarise the common risks associated with K2 Understanding CO5
poorly configured firewalls and routers.
Provide strategies to mitigate these risks
effectively.
6. Construct a diagram illustrating the workflow K6 Creativity CO5
of an Intrusion Detection System (IDS) and
an Intrusion Prevention System (IPS). Explain
their key differences and use cases in network
security.
7. Examine the challenges of implementing IDS K4 Analysing CO5
and IPS in high-traffic environments. Provide
recommendations to address these challenges.
8. What is a Security Incident Response Team K1 Remembering CO5
(SIRT)? Explain its significance, key
responsibilities, and the steps involved in
incident response.
9. Examine the role of Cisco ASA in modern K4 Analysing CO5
enterprise network environments. Highlight
its advantages and potential limitations.
10. Summarise the concept of honeypots in K2 Understanding CO5
cybersecurity. List and explain different types
of honeypots and their practical applications
in threat analysis.
Part – C (16 Mark Questions)
Questio Question Name Blooms Blooms CO
n No. Description
Taxonom No.
y
Unit – I Introduction
Big Questions
1. Provide an overview of the TCP/IP model. K2 Understanding CO1
Explain the functions of the Application,
Transport, and Internet layers with practical
examples.
2. Summarize the importance of IP addressing in K2 Understanding CO1
networking. Differentiate between IPv4 and
IPv6, highlighting the need for the transition
to IPv6.
3. What are intruder attacks? Describe the K1 Remembering CO1
methods used by attackers to gain
unauthorized access and suggest
countermeasures to address such threats.
4. Explain the importance of physical security in K2 Understanding CO1
an organization's overall security strategy.
Provide examples of physical security
measures to prevent intrusions.
5. Explain the role of security professionals and K2 Understanding CO1
penetration testers in ethical hacking. How do
their actions contribute to enhancing an
organization's cybersecurity posture?
Unit – II Foot Printing, Reconnaissance and Scanning
Big Questions
1. Analyse the role of website analysis and email K4 Analysing CO2
tracking in foot printing. Provide examples of
tools and techniques used for competitive
intelligence.
2. Explain foot printing through social K2 Understanding CO2
engineering. How does it differ from technical
foot printing ? Highlight tools commonly
used in such activities.?
3. Explain the process of port scanning in detail. K2 Understanding CO2
Discuss various port-scanning tools and
techniques commonly used in penetration
testing.
4. List out the major scanning techniques used K1 Remembering CO2
for discovering open ports and services on a
network. Compare their efficiency and risk
levels.
5. Explain popular foot printing tools and their K2 Understanding CO2
functionalities. How do they assist in
gathering information about a target system or
network?
UNIT – III Enumeration and Vulnerability Analysis
Big Questions
1. Distinguish between vulnerabilities in desktop K4 Analysing CO3
and server operating systems. Provide
examples of common vulnerabilities and their
potential impacts.
2. Discuss Windows OS vulnerabilities in detail. CO3
Highlight common attack vectors and the
tools used to identify and mitigate these
vulnerabilities.
3. Explain Linux OS vulnerabilities. Compare K2 Understanding CO3
them with Windows OS vulnerabilities and
discuss tools and techniques used for their
detection and mitigation.
4. What are embedded OS vulnerabilities? K1 Remembering CO3
Discuss their unique challenges and provide
examples of vulnerabilities in IoT and other
embedded systems.
5. List and describe tools used for identifying K1 Remembering CO3
vulnerabilities in Windows operating systems.
Provide examples of their application in real-
world scenarios.
UNIT – IV System Hacking
Big Questions
1. List and describe the tools commonly used in K1 Remembering CO4
wireless network attacks. How do security
professionals use similar tools to enhance
wireless network security?
2. Analyse the role of ethical hacking in K4 Analysing CO4
securing wireless networks. How can
penetration testing help identify and mitigate
wireless vulnerabilities?
3. Explain the components of a wireless network K2 Understanding CO4
and their role in communication. How do
these components introduce potential security
risks?
4. What is wardriving? Explain the methodology K1 Remembering CO4
and tools used for wardriving and discuss its
implications for wireless network security.
5. Explain the concept of wireless network K2 Understanding CO4
hacking. Explain the techniques attackers use
to compromise wireless networks and the
countermeasures to prevent these attacks.
UNIT – V Network Protection System
Big Questions
1. Explain the concept of Access Control Lists K2 Understanding CO5
(ACLs) and their role in network protection.
How can ACLs be effectively implemented
and managed?
2. Explain the features and functions of Cisco K2 Understanding CO5
Adaptive Security Appliance (ASA)
Firewalls. Discuss how they enhance network
security.
3. Compare and contrast network-based and K2 Understanding CO5
host-based Intrusion Detection Systems (IDS)
and Intrusion Prevention Systems (IPS).
Discuss their respective advantages and
limitations.
4. Examine the importance of a layered network K4 Analysing CO5
protection strategy. How do firewalls,
IDS/IPS, web filtering, and honeypots work
together to secure a network?
5. What is a honeypot in network security? K1 Remembering CO5
Discuss its types, purpose, and how it helps in
detecting and analyzing cyber threats.