Ethical › Module 20 › Lesson 5
Quiz — Cryptography (CEH Domain)
12 APPLY across the 20-domain path and Topic 8 recap.
Opening
Cryptography — Path-Final Quiz
Twelve APPLY items on the sentences this 20-domain path refused to collapse: written permission and RoE still win; scans stay on localhost of a box you own; a CVE ID is not RCE; unique passwords plus MFA beat stuffing, and hashing is not encryption; you do not collect malware samples; sniffers stay on localhost or a network you administer; no phishing kits; no DoS floods; cookie flags (Secure, HttpOnly) are hygiene, not a hijack kit; firewalls are policies you build, not evasion recipes; parameterized SQL is the fix; home Wi-Fi, phones, IoT, and cloud accounts you own are the only gadget/tenant labs; Module 20 recap is YOUR file SHA-256 plus example.com public cert fields, keys redacted, ceh-crypto-lab.txt chmod 600. Cyberlium’s artifacts are $HOME/cyberlium-lab notes chmod 600. Hashcat, fake CAs, café MITM, dumps, LOIC, Gophish, sqlmap-against-strangers, and neighbor-camera hunts are all failing answers even when they look “more CEH.” This path is original Cyberlium teaching mapped to the CEH v13 domains — not official EC-Council training, not a certification, not exam dumps. Completing it does not grant CEH. Wrong answers still teach. Empty ethics lines fail. Next after this quiz is SQL Injection Theory in Web Security (OWASP Top 10): mechanism plus parameterized queries as the fix — still no live injection against random sites.
Knowledge Check
APPLY: A teammate finishes this path, treats Cyberlium XP as a CEH voucher, and wants to scan a café “because ethical hacking means hacking.” What is permission here, and what do you do?
Multiple choice
Knowledge Check
APPLY: True or False: If loopback is boring, the ethical scan lab is nmap of the campus /24 and the café gateway to “feed CEH Module 3.”
True or False
Knowledge Check
APPLY: A scanner lists CVE-2021-44228 next to python -m http.server on 127.0.0.1:8000. A classmate opens Metasploit “to verify RCE.” What is the row, and what do you do?
Multiple choice
Knowledge Check
APPLY: A teammate stores SHA-256(password), calls it encryption, skips MFA, and wants hashcat on a HaveIBeenPwned paste “for Module 20.” What are the controls, and what do you do?
Multiple choice
Knowledge Check
APPLY: A classmate wants to download a ransomware sample “to understand CEH malware families” and share it in Discord. What is hygiene here?
Multiple choice
Knowledge Check
APPLY: True or False: Promiscuous Wireshark on café Wi-Fi is ethical sniffing because the radio is in the air, and HTTPS means there are no remaining rules.
True or False
Knowledge Check
APPLY: After the social-engineering module, a teammate installs Gophish and wants to phish the class Discord as “CEH people-testing.” What do you do?
Multiple choice
Knowledge Check
APPLY: True or False: A few seconds of LOIC or a small SYN flood of a local shop is ethical because Module 10 is denial of service and you will stop when the page slows.
True or False
Knowledge Check
APPLY: A teammate wants to steal a classmate cookie from shared Wi-Fi “to learn session hijacking,” and says HTTPS already made flags pointless. What is the hygiene pairing?
Multiple choice
Knowledge Check
APPLY: A blog titled with a cert acronym publishes nmap decoys, fragments, and “firewall punch” one-liners as CEH evasion. What does Cyberlium tell you?
Multiple choice
Knowledge Check
APPLY: A teammate pastes a UNION SELECT cheat sheet and aims sqlmap at a random shop “before Topic 10.” What is the mechanism, and what is the fix?
Multiple choice
Knowledge Check
APPLY: You carry the 20-domain path into Web Security. Which pairing is true for wireless/phone/IoT/cloud AND this cryptography recap, and what opens after this quiz?
Multiple choice
Knowledge Check
APPLY: curl of http://192.168.0.1/ shows a home router login (TP-Link / Netgear / Huawei / "Router Admin"). Is that DEMO in scope as a hacking target?
Multiple choice
Answer all 13 knowledge checks to continue. (0/13 answered)