Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest?
Reveal answer details Close answer details
Correct answerB
EC-COUNCIL · 312-50V10
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest? Reveal answer details Close answer detailsCorrect answerB
Single choice
What mechanism in Windows prevents a user from accidentally executing a potentially malicious batch (.bat) or PowerShell (. Reveal answer details Close answer detailsCorrect answerB
Single choice
A company's policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Reveal answer details Close answer detailsCorrect answerC
Single choice
The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. Also he needs to permit all FTP traffic to the rest of the network and deny all other traffic. ![]() Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is the most important phase of ethical hacking wherein you need to spend considerable amount of time? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is not a PCI compliance recommendation? Reveal answer details Close answer detailsCorrect answerC
Single choice
You have successfully gained access to a linux server and would like to ensure that the succeeding outgoing traffic from this server will not be caught by a Network Based Intrusion Detection Systems (NIDS). What is the best way to evade the NIDS? Reveal answer details Close answer detailsCorrect answerA Explanation When the NIDS encounters encrypted traffic, the only analysis it can perform is packet level analysis, since the application layer contents are inaccessible. Given that exploits against today's networks are primarily References:
Single choice
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature? Reveal answer details Close answer detailsCorrect answerB
Single choice
A company's security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate? Reveal answer details Close answer detailsCorrect answerA Explanation Cookies can store passwords and form content a user has previously entered, such as a credit card number or an address. References:
Single choice
This TCP flag instructs the sending system to transmit all buffered data immediately. Reveal answer details Close answer detailsCorrect answerC
Multiple choice
What ports should be blocked on the firewall to prevent NetBIOS traffic from not coming through the firewall if your network is comprised of Windows NT, 2000, and XP? Reveal answer details Close answer detailsCorrect answersB, C, E
Single choice
By using a smart card and pin, you are using a two-factor authentication that satisfies Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is an example of IP spoofing? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following options represents a conceptual characteristic of an anomaly-based IDS over a signature-based IDS? Reveal answer details Close answer detailsCorrect answerB
Single choice
If an e-commerce site was put into a live environment and the programmers failed to remove the secret entry point that was used during the application development, what is this secret entry point known as? Reveal answer details Close answer detailsCorrect answerD
Single choice
Matthew received an email with an attachment named "YouWon$10Grand.zip." The zip file contains a file named "HowToClaimYourPrize.docx.exe." Out of excitement and curiosity, Matthew opened the said file. What type of malware has Matthew encountered? Reveal answer details Close answer detailsCorrect answerB
Single choice
During an Xmas scan what indicates a port is closed? Reveal answer details Close answer detailsCorrect answerB
Single choice
An IT security engineer notices that the company's web server is currently being hacked. What should the engineer do next? Reveal answer details Close answer detailsCorrect answerC
Single choice
While performing ping scans into a target network you get a frantic call from the organization's security team. They report that they are under a denial of service attack. When you stop your scan, the smurf attack event stops showing up on the organization's IDS monitor. How can you modify your scan to prevent triggering this event in the IDS? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a wireless network detector that is commonly found on Linux? Reveal answer details Close answer detailsCorrect answerA
Single choice
Craig received a report of all the computers on the network that showed all the missing patches and weak passwords. What type of software generated this report? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a design pattern based on distinct pieces of software providing application functionality as services to other applications? Reveal answer details Close answer detailsCorrect answerA Explanation A service-oriented architecture (SOA) is an architectural pattern in computer software design in which application components provide services to other components via a communications protocol, typically over a network. References:
Single choice
You have compromised a server on a network and successfully opened a shell. You aimed to identify all operating systems running on the network. However, as you attempt to fingerprint all machines in the network using the nmap syntax below, it is not going through. ![]() What seems to be wrong? Reveal answer details Close answer detailsCorrect answerA Explanation You requested a scan type which requires root privileges. References:
Single choice
Which of the following statements is TRUE? Reveal answer details Close answer detailsCorrect answerA Explanation The OSI layer 2 is where packet sniffers collect their data. References:
Single choice
Which of the following can take an arbitrary length of input and produce a message digest output of 160 bit? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following cryptography attack is an understatement for the extraction of cryptographic secrets (e.g. Reveal answer details Close answer detailsCorrect answerD
Single choice
A hacker was able to easily gain access to a website. He was able to log in via the frontend user login form of the website using default or commonly used credentials. Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a preventive control? Reveal answer details Close answer detailsCorrect answerA
Single choice
An attacker has captured a target file that is encrypted with public key cryptography. Which of the attacks below is likely to be used to crack the target file? Reveal answer details Close answer detailsCorrect answerD
Single choice
An enterprise recently moved to a new office and the new neighborhood is a little risky. The CEO wants to monitor the physical perimeter and the entrance doors 24 hours. What is the best option to do this job? Reveal answer details Close answer detailsCorrect answerB
Single choice
Backing up data is a security must. However, it also has certain level of risks when mishandled. Which of the following is the greatest threat posed by backups? Reveal answer details Close answer detailsCorrect answerD
Single choice
Developers at your company are creating a web application which will be available for use by anyone on the Internet, The developers have taken the approach of implementing a Three-Tier Architecture for the web application. Reveal answer details Close answer detailsCorrect answerA
Single choice
You've just gained root access to a Centos 6 server after days of trying. What tool should you use to maintain access? Reveal answer details Close answer detailsCorrect answerB
Single choice
An unauthorized individual enters a building following an employee through the employee entrance after the lunch rush. What type of breach has the individual just performed? Reveal answer details Close answer detailsCorrect answerB
Single choice
If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the known plaintext attack used against DES which gives the result that encrypting plaintext with one DES key followed by encrypting it with a second DES key is no more secure than using a single key? Reveal answer details Close answer detailsCorrect answerB
Single choice
What tool should you use when you need to analyze extracted metadata from files you collected when you were in the initial stage of penetration test (information gathering)? Reveal answer details Close answer detailsCorrect answerC
Single choice
A distributed port scan operates by: Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following problems can be solved by using Wireshark? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following items of a computer system will an anti-virus program scan for viruses? Reveal answer details Close answer detailsCorrect answerA
Single choice
A security consultant decides to use multiple layers of anti-virus defense, such as end user desktop anti-virus and E-mail gateway. Reveal answer details Close answer detailsCorrect answerC
Single choice
Why is a penetration test considered to be more thorough than vulnerability scan? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following techniques does a vulnerability scanner use in order to detect a vulnerability on a target service? Reveal answer details Close answer detailsCorrect answerD
Single choice
To send a PGP encrypted message, which piece of information from the recipient must the sender have before encrypting the message? Reveal answer details Close answer detailsCorrect answerB
Single choice
You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing the source email to her boss's email( boss@company ). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your malicious links (these links contain malware) and send back the modified pdf, saying that the links don't work. She reads your email, opens the links, and her machine gets infected. You now have access to the company network. What testing method did you use? Reveal answer details Close answer detailsCorrect answerA Explanation Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme.
Single choice
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems. What kind of test is being performed? Reveal answer details Close answer detailsCorrect answerD
Single choice
An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections. When users accessed any page, the applet ran and exploited many machines. Which one of the following tools the hacker probably used to inject HTML code? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a component of a risk assessment? Reveal answer details Close answer detailsCorrect answerB
Single choice
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. Reveal answer details Close answer detailsCorrect answerD
Single choice
Log monitoring tools performing behavioral analysis have alerted several suspicious logins on a Linux server occurring during non-business hours. After further examination of all login activities, it is noticed that none of the logins have occurred during typical work hours. A Linux administrator who is investigating this problem realizes the system time on the Linux server is wrong by more than twelve hours. What protocol used on Linux servers to synchronize the time has stopped working? Reveal answer details Close answer detailsCorrect answerB
Single choice
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is: Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek? Reveal answer details Close answer detailsCorrect answerA Explanation tcptrace is a tool for analysis of TCP dump files. It can take as input the files produced by several popular packet-capture programs, including tcpdump/WinDump/Wireshark, snoop, EtherPeek, and Agilent NetMetrix. References:
Single choice
In 2007, this wireless security algorithm was rendered useless by capturing packets and discovering the passkey in a matter of seconds. This security flaw led to a network invasion of TJ Maxx and data theft through a technique known as wardriving. Which Algorithm is this referring to? Reveal answer details Close answer detailsCorrect answerA Explanation WEP is the currently most used protocol for securing 802.11 networks, also called wireless lans or wlans. Note: Wardriving is the act of searching for Wi-Fi wireless networks by a person in a moving vehicle, using a portable computer, smartphone or personal digital assistant (PDA). References:
Single choice
Which of the following BEST describes how Address Resolution Protocol (ARP) works? Reveal answer details Close answer detailsCorrect answerD
Single choice
How does an operating system protect the passwords used for account logins? Reveal answer details Close answer detailsCorrect answerA
Single choice
Seth is starting a penetration test from inside the network. He hasn't been given any information about the network. What type of test is he conducting? Reveal answer details Close answer detailsCorrect answerC
Single choice
While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. What specific octet within the subnet does the technician see? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which component of IPsec performs protocol-level functions that are required to encrypt and decrypt the packets? Reveal answer details Close answer detailsCorrect answerA
Single choice
Elliot is in the process of exploiting a web application that uses SQL as a back-end database. He's determined that the application is vulnerable to SQL injection, and has introduced conditional timing delays into injected queries to determine whether they are successful. What type of SQL injection is Elliot most likely performing? Reveal answer details Close answer detailsCorrect answerB
Single choice
What is the role of test automation in security testing? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Name two software tools used for OS guessing? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may be using TCP. Which other option could the tester use to get a response from a host using TCP? Reveal answer details Close answer detailsCorrect answerA
Single choice
PGP, SSL, and IKE are all examples of which type of cryptography? Reveal answer details Close answer detailsCorrect answerA Explanation Public-key algorithms are fundamental security ingredients in cryptosystems, applications and protocols. References:
Single choice
A software tester is randomly generating invalid inputs in an attempt to crash the program. Which of the following is a software testing technique used to determine if a software program properly handles a wide range of invalid input? Reveal answer details Close answer detailsCorrect answerC
Single choice
You are analysing traffic on the network with Wireshark. You want to routinely run a cron job which will run the capture against a specific set of IPs - 192.168.8.0/24. What command you would use? Reveal answer details Close answer detailsCorrect answerD
Single choice
An attacker uses a communication channel within an operating system that is neither designed nor intended to transfer information. What is the name of the communications channel? Reveal answer details Close answer detailsCorrect answerD
Single choice
Why would you consider sending an email to an address that you know does not exist within the company you are performing a Penetration Test for? Reveal answer details Close answer detailsCorrect answerD
Single choice
Risks = Threats x Vulnerabilities is referred to as the: Reveal answer details Close answer detailsCorrect answerA Explanation The most effective way to define risk is with this simple equation: Risk = Threat x Vulnerability x Cost This equation is fundamental to all information security. References:
Single choice
What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following types of firewalls ensures that the packets are part of the established session? Reveal answer details Close answer detailsCorrect answerA Explanation A stateful firewall is a network firewall that tracks the operating state and characteristics of network connections traversing it. The firewall is configured to distinguish legitimate packets for different types of connections. Only packets matching a known active connection (session) are allowed to pass the firewall. References:
Single choice
What is a successful method for protecting a router from potential smurf attacks? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which regulation defines security and privacy controls for Federal information systems and organizations? Reveal answer details Close answer detailsCorrect answerA Explanation NIST Special Publication 800-53, "Security and Privacy Controls for Federal Information Systems and Organizations," provides a catalog of security controls for all U.S. federal information systems except those related to national security. References:
Single choice
The chance of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. What is the closest approximate cost of this replacement and recovery operation per year? Reveal answer details Close answer detailsCorrect answerA Explanation The annualized loss expectancy (ALE) is the product of the annual rate of occurrence (ARO) and the References:
Single choice
While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting malicious input? Reveal answer details Close answer detailsCorrect answerC
Single choice
It is a regulation that has a set of guidelines, which should be adhered to by anyone who handles any electronic medical data. These guidelines stipulate that all medical practices must ensure that all necessary measures are in place while saving, accessing, and sharing any electronic medical data to keep patient data secure. Which of the following regulations best matches the description? Reveal answer details Close answer detailsCorrect answerA Explanation The HIPAA Privacy Rule regulates the use and disclosure of Protected Health Information (PHI) held by "covered entities" (generally, health care clearinghouses, employer sponsored health plans, health References:
Single choice
ViruXine.W32 virus hides their presence by changing the underlying executable code. This Virus code mutates while keeping the original algorithm intact, the code changes itself each time it runs, but the function of the code (its semantics) will not change at all. ![]() Here is a section of the Virus code: ![]() What is this technique called? Reveal answer details Close answer detailsCorrect answerA
Single choice
Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 (content:"|00 Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the correct PCAP filter to capture all TCP traffic going to or from host 192.168.0.125 on port 25? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the proper response for a NULL scan if the port is closed? Reveal answer details Close answer detailsCorrect answerE
Single choice
Which type of Nmap scan is the most reliable, but also the most visible, and likely to be picked up by and IDS? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are attempting to crack LM Manager hashed from Windows 2000 SAM file. You will be using LM Brute force hacking tool for decryption. What encryption algorithm will you be decrypting? Reveal answer details Close answer detailsCorrect answerB
Single choice
You are about to be hired by a well-known Bank to perform penetration tests. Which of the following documents describes the specifics of the testing, the associated violations, and essentially protects both the bank's interest and your liabilities as a tester? Reveal answer details Close answer detailsCorrect answerC
Single choice
An LDAP directory can be used to store information similar to a SQL database. LDAP uses a _____ database structure instead of SQL's _____ structure. Because of this, LDAP has difficulty representing many-to-one relationships. Reveal answer details Close answer detailsCorrect answerC
Single choice
One advantage of an application-level firewall is the ability to: Reveal answer details Close answer detailsCorrect answerB
Single choice
What type of vulnerability/attack is it when the malicious person forces the user's browser to send an authenticated request to a server? Reveal answer details Close answer detailsCorrect answerA
Single choice
There are several ways to gain insight on how a cryptosystem works with the goal of reverse engineering the process. Reveal answer details Close answer detailsCorrect answerA
Single choice
A pentester is using Metasploit to exploit an FTP server and pivot to a LAN. How will the pentester pivot using Metasploit? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is considered as one of the most reliable forms of TCP scanning? Reveal answer details Close answer detailsCorrect answerA
Single choice
The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE's Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the transport layer security (TLS) protocols defined in RFC6520. What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy? Reveal answer details Close answer detailsCorrect answerA Explanation The data obtained by a Heartbleed attack may include unencrypted exchanges between TLS parties likely to be confidential, including any form post data in users' requests. Moreover, the confidential data exposed could include authentication secrets such as session cookies and passwords, which might allow attackers to impersonate a user of the service. References:
Single choice
Which of the following is the least-likely physical characteristic to be used in biometric control that supports a large company? Reveal answer details Close answer detailsCorrect answerA Explanation There are two main types of biometric identifiers: Examples of physiological characteristics used for biometric authentication include fingerprints; DNA; face, hand, retina or ear features; and odor. Behavioral characteristics are related to the pattern of the behavior References:
Single choice
What network security concept requires multiple layers of security controls to be placed throughout an IT infrastructure, which improves the security posture of an organization to defend against malicious attacks or potential vulnerabilities? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which Metasploit Framework tool can help penetration tester for evading Anti-virus Systems? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following Linux commands will resolve a domain name into IP address? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following descriptions is true about a static NAT? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion? Reveal answer details Close answer detailsCorrect answerC
Single choice
During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called? Reveal answer details Close answer detailsCorrect answerA Explanation In a split DNS infrastructure, you create two zones for the same domain, one to be used by the internal network, the other used by the external network. Split DNS directs internal hosts to an internal domain name server for name resolution and external hosts are directed to an external domain name server for name resolution. References:
Single choice
A large mobile telephony and data network operator has a data that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the main reason the use of a stored biometric is vulnerable to an attack? Reveal answer details Close answer detailsCorrect answerD
Single choice
A company has hired a security administrator to maintain and administer Linux and Windows-based systems. Written in the nightly report file is the following: Firewall log files are at the expected value of 4 MB. The current time is 12am. Exactly two hours later the size has decreased considerably. Another hour goes by and the log files have shrunk in size again. Which of the following actions should the security administrator take? Reveal answer details Close answer detailsCorrect answerD |