Geschreven door studenten die geslaagd zijn Direct beschikbaar na je betaling Online lezen of als PDF Verkeerd document? Gratis ruilen 4,6 TrustPilot
logo-home
Tentamen (uitwerkingen)

Certified Ethical Hacker 312-50v10 Review questions and answers all correct

Beoordeling
-
Verkocht
-
Pagina's
8
Cijfer
A+
Geüpload op
24-06-2022
Geschreven in
2021/2022

Certified Ethical Hacker 312-50v10 Review An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of reach has the individual just performed? A. Reverse Social Engineering B. Tailgating C. Piggybacking D. Announced correct answer:B. Tailgating Which of the following is the best countermeasure to encrypting ransomwares? A. Use multiple antivirus software B. Keep some generation of off-line backup C. Analyze the ransomware to get decryption key of encrypted data D. Pay a ransom correct answer:B. Keep some generation of off-line backup If an attacker uses the command SELECT*FROM user WHERE name=x AND userid IS NULL; -; which type of SQL injection is the attacker performing? A. End of Line Comment B. UNION SQL Injection C. Illegal/Logically Incorrect Query D. Tautology correct answer:A. End of Line Comment Sophia travels a lot and worries that her laptop containing confidential documents might be stolen. What is the best protection that will work for her? A. Full Disk encryption B. BIOS password C. Hidden folders D. Password protected files correct answer:A. Full Disk encryption An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go to "www.MyPersonalB", that the user is directed to a phishing site. Which file does the attacker need to modify? A. B B. Sudoers C. Networks D. Hosts correct answer:D. Hosts Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS? A. Produces less false positives B. Can identify unknown attacks C. Requires vendor updates for a new threat D. Cannot deal with encrypted network traffic correct answer:B. Can identify unknown attacks You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use? A. c:gpedit B. c: C. c: D. c: correct answer:B. c: Which of the following act requires employers standard national numbers to identify them on standard transactions? A. SOX B. HIPAA C. DMCA D. PCI-DSS correct answer:B. HIPAA In Wireshark, the packet bytes panes show the data of the current packet in which format? A. Decimal B. ASCII only C. Binary D. Hexadecimal correct answer:D. Hexadecimal ________ is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients (resolvers) so as to reduce the threat of DNS poisoning, spoofing, and similar attacks. A. DNSSEC B. Resource records C. Resource transfer D. Zone transfer correct answer:A. DNSSEC PGP, SSL, and IKE are all examples of which type of cryptography? A. Hash Algorithm B. Digest C. Secret Key D. Public Key correct answer:D. Public Key Which of the following is considered as one of the most reliable forms of TCP scanning? A. TCP Connect/Full Open Scan B. Half-open Scan C. NULL scan D. Xmas Scan correct answer:A. TCP Connect/Full Open Scan Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet? A. ICMP Echo scanning B. SYN/FIN scanning using IP fragments C. ACK flag probe scanning D. IPID scanning correct answer:B. SYN/FIN scanning using IP fragments Which of the following is the BEST way to defend against network sniffing? A. Restrict Physical Access to Server Rooms hosting Critical Servers B. Use Static IP Address C. Using encryption protocols to secure network communications D. Register all machines MAC Address in a Centralized Database correct answer:C. Using encryption protocols to secure network communications You have successfully gained access to a Linux server and would like to ensure that the succeeding outgoing traffic for this server will not be caught by Network-Based Intrusion Detection Systems (NIDS). What is the best way to evade the NIDS? A. Out of band signaling B. Protocol Isolation C. Encryption D. Alternate Data Streams correct answer:C. Encryption What is the purpose of a demilitarized zone on a network? A. To scan all traffic coming through the DMZ to the internal network. B. To only provide direct access to nodes within the DMZ and protect the network behind it C. To provide a place to put the honeypot D. To contain the network devices you wish to protect correct answer:B. To only provide direct access to nodes within the DMZ and protect the network behind it You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement? A. All three servers need to be placed internally. B. A web server facing the Internet, an application server on the internal network, a database server on the internal network. C. A web server and the database server facing the Internet, an application server on the internal network. D. All three servers need to face the Internet so that they can communicate between themselves. correct answer:B A web serer facing the Internet, an application server on the internal network, a database server on the internal network. The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access to the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happing in the network? (See doc for pic) A. The ACL 104 needs to be first because is UDP B. The ACL 110 needs to be changed to port 8- C. The ACL for FTP must be before the ACL 110 D. The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router correct answer:D. The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router When conducting a penetration test, it is crucial to use all means to get all available information about the target network. One of the ways to do that is by sniffing the network. Which of the following cannot be performed by the passive network sniffing? A. Identifying operating systems, services, protocols and devices B. Modifying and replaying captured network traffic C. Collecting unencrypted information about usernames and passwords D. Capturing a network traffic for further analysis correct answer:B. Modifying and replaying captured network traffic A company's Web development team has become aware of a certain type of security vulnerability in their Web software. To mitigate the possibility of this vulnerability being exploited, the team wants to modify the software requirements to disallow users from entering HTML as input into their Web application. What kind of Web application vulnerability likely exists in their software? A. Cross-site scripting vulnerability B. Web site defacement vulnerability C. SQL injection vulnerability D. Cross-site Request Forgery vulnerability correct answer:A. Cross-site scripting vulnerability Insecure direct object reference is a type of vulnerability where the application does not verify if the user is authorized to access the internal object via its name or key. Suppose a malicious user Rob tries to get access to the account of a benign user Ned. Which of the following requests best illustrates an attempt to exploit an insecure direct object reference vulnerability? A. GET/restricted/goldtransfer?to=Rob&from=1 or 1=1 HTTP/1.1Host: B. GET/restricted/accounts/?name=Ned HTTP/1.1 Host: C. GET/restricted/count(Ned) HTTP/1.1 Host: D. GET/restricted/rn%00account%00Ned%00access HTTP/1.1 Host: correct answer:B. Get/restricted/accounts/?name=Ned HTTP/1.1 Host: Which tool allows analysts and pen testers to examine links between data using graphs and link analysis? A. Metasploit B. Cain & Abel C. Maltego D. Wireshark correct answer:C. Maltego Which of these is capable of searching for and locating rogue access points? A. HIDS B. NIDS C. WISS D. WIPS correct answer:D. WIPS A hacker is an intelligent individual with excellent computer skills and the ability to explore a computers software and hardware without the owners permission. Their intention can either be simply gain knowledge or to illegally make changes. Which of the following class of hacker refers to an individual who works both offensively and defensively at various times? A. White Hat B. Suicide Hacker C. Gray Hat D. Black Hat correct answer:C. Gray Hat Websites and web portals that provide web services commonly

Meer zien Lees minder
Instelling
Vak

Voorbeeld van de inhoud

Certified Ethical Hacker 312-50v10 Review
An unauthorized individual enters a building following an employee through the employee entrance
after the lunch rush. What type of reach has the individual just performed?
A. Reverse Social Engineering
B. Tailgating
C. Piggybacking
D. Announced correct answer:B. Tailgating

Which of the following is the best countermeasure to encrypting ransomwares?
A. Use multiple antivirus software
B. Keep some generation of off-line backup
C. Analyze the ransomware to get decryption key of encrypted data
D. Pay a ransom correct answer:B. Keep some generation of off-line backup

If an attacker uses the command SELECT*FROM user WHERE name=x AND userid IS NULL; -; which type
of SQL injection is the attacker performing?
A. End of Line Comment
B. UNION SQL Injection
C. Illegal/Logically Incorrect Query
D. Tautology correct answer:A. End of Line Comment

Sophia travels a lot and worries that her laptop containing confidential documents might be stolen.
What is the best protection that will work for her?
A. Full Disk encryption
B. BIOS password
C. Hidden folders
D. Password protected files correct answer:A. Full Disk encryption

An attacker has installed a RAT on a host. The attacker wants to ensure that when a user attempts to go
to "www.MyPersonalBank.com", that the user is directed to a phishing site. Which file does the attacker
need to modify?
A. Boot.ini
B. Sudoers
C. Networks
D. Hosts correct answer:D. Hosts

Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a
signature-based IDS?
A. Produces less false positives
B. Can identify unknown attacks
C. Requires vendor updates for a new threat
D. Cannot deal with encrypted network traffic correct answer:B. Can identify unknown attacks

You are logged in as a local admin on a Windows 7 system and you need to launch the Computer
Management Console from command line. Which command would you use?

, A. c:gpedit
B. c:compmgmt.msc
C. c:ncpa.cp
D. c:services.msc correct answer:B. c:compmgmt.msc

Which of the following act requires employers standard national numbers to identify them on standard
transactions?
A. SOX
B. HIPAA
C. DMCA
D. PCI-DSS correct answer:B. HIPAA

In Wireshark, the packet bytes panes show the data of the current packet in which format?
A. Decimal
B. ASCII only
C. Binary
D. Hexadecimal correct answer:D. Hexadecimal

________ is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients
(resolvers) so as to reduce the threat of DNS poisoning, spoofing, and similar attacks.
A. DNSSEC
B. Resource records
C. Resource transfer
D. Zone transfer correct answer:A. DNSSEC

PGP, SSL, and IKE are all examples of which type of cryptography?
A. Hash Algorithm
B. Digest
C. Secret Key
D. Public Key correct answer:D. Public Key

Which of the following is considered as one of the most reliable forms of TCP scanning?
A. TCP Connect/Full Open Scan
B. Half-open Scan
C. NULL scan
D. Xmas Scan correct answer:A. TCP Connect/Full Open Scan

Which of the following scanning method splits the TCP header into several packets and makes it difficult
for packet filters to detect the purpose of the packet?
A. ICMP Echo scanning
B. SYN/FIN scanning using IP fragments
C. ACK flag probe scanning
D. IPID scanning correct answer:B. SYN/FIN scanning using IP fragments

Which of the following is the BEST way to defend against network sniffing?
A. Restrict Physical Access to Server Rooms hosting Critical Servers
B. Use Static IP Address
C. Using encryption protocols to secure network communications

Geschreven voor

Vak

Documentinformatie

Geüpload op
24 juni 2022
Aantal pagina's
8
Geschreven in
2021/2022
Type
Tentamen (uitwerkingen)
Bevat
Vragen en antwoorden

Onderwerpen

$14.49
Krijg toegang tot het volledige document:

Verkeerd document? Gratis ruilen Binnen 14 dagen na aankoop en voor het downloaden kun je een ander document kiezen. Je kunt het bedrag gewoon opnieuw besteden.
Geschreven door studenten die geslaagd zijn
Direct beschikbaar na je betaling
Online lezen of als PDF

Maak kennis met de verkoper

Seller avatar
De reputatie van een verkoper is gebaseerd op het aantal documenten dat iemand tegen betaling verkocht heeft en de beoordelingen die voor die items ontvangen zijn. Er zijn drie niveau’s te onderscheiden: brons, zilver en goud. Hoe beter de reputatie, hoe meer de kwaliteit van zijn of haar werk te vertrouwen is.
Classroom NURSING
Volgen Je moet ingelogd zijn om studenten of vakken te kunnen volgen
Verkocht
4886
Lid sinds
4 jaar
Aantal volgers
3234
Documenten
55444
Laatst verkocht
2 uur geleden
NURSING

Assignments, Case Studies, Research, Essay writing service, Questions and Answers, Discussions etc. for students who want to see results twice as fast. I have done papers of various topics and complexities. I am punctual and always submit work on-deadline. I write engaging and informative content on all subjects. Send me your research papers, case studies, psychology papers, etc, and I’ll do them to the best of my abilities. Writing is my passion when it comes to academic work. I’ve got a good sense of structure and enjoy finding interesting ways to deliver information in any given paper. I love impressing clients with my work, and I am very punctual about deadlines. Send me your assignment and I’ll take it to the next level. I strive for my content to be of the highest quality. Your wishes come first— send me your requirements and I’ll make a piece of work with fresh ideas, consistent structure, and following the academic formatting rules. For every student you refer to me with an order that is completed and paid transparently, I will do one assignment for you, free of charge!!!!!!!!!!!!

Lees meer Lees minder
4.0

1192 beoordelingen

5
631
4
216
3
196
2
40
1
109

Recent door jou bekeken

Waarom studenten kiezen voor Stuvia

Gemaakt door medestudenten, geverifieerd door reviews

Kwaliteit die je kunt vertrouwen: geschreven door studenten die slaagden en beoordeeld door anderen die dit document gebruikten.

Niet tevreden? Kies een ander document

Geen zorgen! Je kunt voor hetzelfde geld direct een ander document kiezen dat beter past bij wat je zoekt.

Betaal zoals je wilt, start meteen met leren

Geen abonnement, geen verplichtingen. Betaal zoals je gewend bent via iDeal of creditcard en download je PDF-document meteen.

Student with book image

“Gekocht, gedownload en geslaagd. Zo makkelijk kan het dus zijn.”

Alisha Student

Bezig met je bronvermelding?

Maak nauwkeurige citaten in APA, MLA en Harvard met onze gratis bronnengenerator.

Bezig met je bronvermelding?

Veelgestelde vragen