When purchasing a biometric system, one of the considerations that should be reviewed is the processing speed.
Which of the following best describes what it is meant by processing?
Reveal answer details Close answer details
Correct answerC
EC-COUNCIL · 312-50V11
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
When purchasing a biometric system, one of the considerations that should be reviewed is the processing speed. Which of the following best describes what it is meant by processing? Reveal answer details Close answer detailsCorrect answerC
Single choice
Tony wants to integrate a 128-bit symmetric block cipher with key sizes of 128,192, or 256 bits into a software program, which involves 32 rounds of computational operations that include substitution and permutation operations on four 32-bit word blocks using 8-variable S-boxes with 4-bit entry and 4-bit exit. Which of the following algorithms includes all the above features and can be integrated by Tony into the software program? Reveal answer details Close answer detailsCorrect answerD
Single choice
The Payment Card Industry Data Security Standard (PCI DSS) contains six different categories of control objectives. Each objective contains one or more requirements, which must be followed in order to achieve compliance. Which of the following requirements would best fit under the objective, "Implement strong access control measures"? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
Which of the following statements about a zone transfer is correct? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, C, E
Single choice
An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their job. The attacker gain access to the DNS server and redirect the direction www.google.com to his own IP address. Now when the employees of the office want to go to Google they are being redirected to the attacker machine. What is the name of this kind of attack? Reveal answer details Close answer detailsCorrect answerC
Single choice
If you want to only scan fewer ports than the default scan using Nmap tool, which option would you use? Reveal answer details Close answer detailsCorrect answerB
Single choice
Shiela is an information security analyst working at HiTech Security Solutions. She is performing service version discovery using Nmap to obtain information about the running services and their versions on a target system. Which of the following Nmap options must she use to perform service version discovery on the target host? Reveal answer details Close answer detailsCorrect answerC
Single choice
Nicolas just found a vulnerability on a public-facing system that is considered a zero-day vulnerability. He sent an email to the owner of the public system describing the problem and how the owner can protect themselves from that vulnerability. He also sent an email to Microsoft informing them of the problem that their systems are exposed to. What type of hacker is Nicolas? Reveal answer details Close answer detailsCorrect answerB Explanation A white hat (or a white hat hacker) is an ethical computer hacker, or a computer security expert, who focuses on penetration testing and in other testing methodologies that ensures the safety of an organization's information systems. Ethical hacking may be a term meant to imply a broader category than simply penetration testing. Contrasted with black hat, a malicious hacker, the name comes from Western films, where heroic and antagonistic cowboys might traditionally wear a white and a black hat respectively.
Single choice
"........is an attack type for a rogue Wi-Fi access point that appears to be a legitimate one offered on the premises, but actually has been set up to eavesdrop on wireless communications. It is the wireless version of the phishing scam. An attacker fools wireless users into connecting a laptop or mobile phone to a tainted hot-spot by posing as a legitimate provider. This type of attack may be used to steal the passwords of unsuspecting users by either snooping the communication link or by phishing, which involves setting up a fraudulent web site and luring people there." Fill in the blank with appropriate choice. Reveal answer details Close answer detailsCorrect answerA
Single choice
Peter extracts the SIDs list from Windows 2000 Server machine using the hacking tool "SIDExtractor". ![]() From the above list identify the user account with System Administrator privileges. Reveal answer details Close answer detailsCorrect answerF
Single choice
Scenario1: 1. Victim opens the attacker's web site. 2. Attacker sets up a web site which contains interesting and attractive content like 'Do you want to make 3. Victim clicks to the interesting and attractive content URL. 4. Attacker creates a transparent 'iframe' in front of the URL which victim attempts to click, so victim thinks that he/she clicks to the 'Do you want to make $1000 in a day?' URL but actually he/she clicks to the content or URL that exists in the transparent 'iframe' which is setup by the attacker. What is the name of the attack which is mentioned in the scenario? Reveal answer details Close answer detailsCorrect answerD
Single choice
Within the context of Computer Security, which of the following statements describes Social Engineering best? Reveal answer details Close answer detailsCorrect answerC
Single choice
You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing the source email to her boss's email (boss@company). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your malicious links (these links contain malware) and send back the modified pdf, saying that the links don't work. She reads your email, opens the links, and her machine gets infected. You now have access to the company network. What testing method did you use? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which protocol is used for setting up secure channels between two devices, typically in VPNs? Reveal answer details Close answer detailsCorrect answerC
Single choice
Let's imagine three companies (A, B and C), all competing in a challenging global environment. Company How do you prevent DNS spoofing? Reveal answer details Close answer detailsCorrect answerC
Single choice
Jim's company regularly performs backups of their critical servers. But the company cannot afford to send backup tapes to an off-site vendor for long-term storage and archiving. Instead, Jim's company keeps the backup tapes in a safe in the office. Jim's company is audited each year, and the results from this year's audit show a risk because backup tapes are not stored off-site. Reveal answer details Close answer detailsCorrect answerA
Single choice
What type of a vulnerability/attack is it when the malicious person forces the user's browser to send an authenticated request to a server? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which method of password cracking takes the most time and effort? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the least important information when you analyze a public IP address in a security alert? Reveal answer details Close answer detailsCorrect answerD
Single choice
Techno Security Inc. recently hired John as a penetration tester. He was tasked with identifying open ports in the target network and determining whether the ports are online and any firewall rule sets are encountered. John decided to perform a TCP SYN ping scan on the target network. Which of the following Nmap commands must John use to perform the TCP SVN ping scan? Reveal answer details Close answer detailsCorrect answerC
Single choice
One of your team members has asked you to analyze the following SOA record. What is the version? Rutgers.edu.SOA NS1.Rutgers.edu ipad.college.edu (200302028 3600 3600 604800 2400.) (Choose four.) Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a low-tech way of gaining unauthorized access to systems? Reveal answer details Close answer detailsCorrect answerA
Single choice
Jake, a professional hacker, installed spyware on a target iPhone to spy on the target user's activities. He can take complete control of the target mobile device by jailbreaking the device remotely and record audio, capture screenshots, and monitor all phone calls and SMS messages. What is the type of spyware that Jake used to infect the target device? Reveal answer details Close answer detailsCorrect answerB
Single choice
Due to a slowdown of normal network operations, the IT department decided to monitor internet traffic for all of the employees. Reveal answer details Close answer detailsCorrect answerC
Single choice
Identify the web application attack where the attackers exploit vulnerabilities in dynamically generated web pages to inject client-side script into web pages viewed by other users. Reveal answer details Close answer detailsCorrect answerB
Single choice
You are tasked to configure the DHCP server to lease the last 100 usable IP addresses in subnet to. 1.4.0/23. Which of the following IP addresses could be teased as a result of the new configuration? Reveal answer details Close answer detailsCorrect answerC
Single choice
PGP, SSL, and IKE are all examples of which type of cryptography? Reveal answer details Close answer detailsCorrect answerC
Single choice
Bob received this text message on his mobile phone: "Hello, this is Scott Smelby from the Yahoo Bank. Which statement below is true? Reveal answer details Close answer detailsCorrect answerA
Single choice
Jack, a professional hacker, targets an organization and performs vulnerability scanning on the target web server to identify any possible weaknesses, vulnerabilities, and misconfigurations. In this process, Jack uses an automated tool that eases his work and performs vulnerability scanning to find hosts, services, and other vulnerabilities in the target server. Which of the following tools is used by Jack to perform vulnerability scanning? Reveal answer details Close answer detailsCorrect answerC
Single choice
A company's security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate? Reveal answer details Close answer detailsCorrect answerB
Single choice
When configuring wireless on his home router, Javik disables SSID broadcast. He leaves authentication What is an accurate assessment of this scenario from a security perspective? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following provides a security professional with most information about the system's security posture? Reveal answer details Close answer detailsCorrect answerD
Single choice
Geena, a cloud architect, uses a master component in the Kubernetes cluster architecture that scans newly generated pods and allocates a node to them. This component can also assign nodes based on factors such as the overall resource requirement, data locality, software/hardware/policy restrictions, and internal workload interventions. Which of the following master components is explained in the above scenario? Reveal answer details Close answer detailsCorrect answerB
Single choice
Robert, a professional hacker, is attempting to execute a fault injection attack on a target IoT device. In this process, he injects faults into the power supply that can be used for remote execution, also causing the skipping of key instructions. Which of the following types of fault injection attack is performed by Robert in the above scenario? Reveal answer details Close answer detailsCorrect answerB
Single choice
ViruXine.W32 virus hides their presence by changing the underlying executable code. This Virus code mutates while keeping the original algorithm intact, the code changes itself each time it runs, but the function of the code (its semantics) will not change at all. ![]() Here is a section of the Virus code: ![]() What is this technique called? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a command line packet analyzer similar to GUI-based Wireshark? Reveal answer details Close answer detailsCorrect answerB
Single choice
John the Ripper is a technical assessment tool used to test the weakness of which of the following? Reveal answer details Close answer detailsCorrect answerA
Single choice
Jane is working as a security professional at CyberSol Inc. She was tasked with ensuring the authentication and integrity of messages being transmitted in the corporate network. To encrypt the messages, she implemented a security model in which every user in the network maintains a ring of public keys. In this model, a user needs to encrypt a message using the receiver's public key, and only the receiver can decrypt the message using their private key. What is the security model implemented by Jane to secure corporate messages? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which of the following tools are used for enumeration? (Choose three.) Reveal answer details Close answer detailsCorrect answersB, D, E
Single choice
Nathan is testing some of his network devices. Nathan is using Macof to try and flood the ARP cache of these switches. If these switches' ARP cache is successfully flooded, what will be the result? Reveal answer details Close answer detailsCorrect answerA
Single choice
From the following table, identify the wrong answer in terms of Range (ft). Standard Range (ft) 802.11a 150-150 802.11b 150-150 802.11g 150-150 802.16 (WiMax) 30 miles Reveal answer details Close answer detailsCorrect answerA
Single choice
jane invites her friends Alice and John over for a LAN party. Alice and John access Jane's wireless network without a password. However. Jane has a long, complex password on her router. What attack has likely occurred? Reveal answer details Close answer detailsCorrect answerC Explanation An evil twin may be a fraudulent Wi-Fi access point that appears to be legitimate but is about up to pay attention to wireless communications.[1] The evil twin is that the wireless LAN equivalent of the phishing scam.This type of attack could also be wont to steal the passwords of unsuspecting users, either by monitoring their connections or by phishing, which involves fixing a fraudulent internet site and luring people there.The attacker snoops on Internet traffic employing a bogus wireless access point. Unwitting web users could also be invited to log into the attacker's server, prompting them to enter sensitive information like usernames and passwords. Often, users are unaware they need been duped until well after the incident has occurred.When users log into unsecured (non-HTTPS) bank or e-mail accounts, the attacker intercepts the transaction, since it's sent through their equipment. The attacker is additionally ready to hook up with other networks related to the users' credentials.Fake access points are found out by configuring a wireless card to act as an access point (known as HostAP). they're hard to trace since they will be shut off instantly. The counterfeit access point could also be given an equivalent SSID and BSSID as a close-by Wi-Fi network. The evil twin are often configured to pass Internet traffic through to the legitimate access point while monitoring the victim's connection, or it can simply say the system is temporarily unavailable after obtaining a username and password.
Single choice
Mike, a security engineer, was recently hired by BigFox Ltd. The company recently experienced disastrous DoS attacks. The management had instructed Mike to build defensive strategies for the company's IT infrastructure to thwart DoS/ DDoS attacks. Mike deployed some countermeasures to handle jamming and scrambling attacks. What is the countermeasure Mike applied to defend against jamming and scrambling attacks? Reveal answer details Close answer detailsCorrect answerD
Single choice
In the context of password security, a simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0phtCrack or John the Ripper, and running it against user accounts located by the application. The larger the word and word fragment selection, the more effective the dictionary attack is. The brute force method is the most inclusive, although slow. It usually tries every possible letter and number combination in its automated exploration. Reveal answer details Close answer detailsCorrect answerC
Single choice
What do Trinoo, TFN2k, WinTrinoo, T-Sight, and Stracheldraht have in common? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is correct about digital signatures? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet? Reveal answer details Close answer detailsCorrect answerC
Single choice
Although FTP traffic is not encrypted by default, which layer 3 protocol would allow for end-to-end encryption of the connection? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which Metasploit Framework tool can help penetration tester for evading Anti-virus Systems? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is the primary objective of a rootkit? Reveal answer details Close answer detailsCorrect answerC
Single choice
Sam is working as a system administrator In an organization. He captured the principal characteristics of a vulnerability and produced a numerical score to reflect Its severity using CVSS v3.0 to property assess and prioritize the organization's vulnerability management processes. The base score that Sam obtained after performing cvss rating was 4.0. What is the CVSS severity level of the vulnerability discovered by Sam in the above scenario? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the following command used for? net use \targetipc$ "" /u:"" Reveal answer details Close answer detailsCorrect answerD
Single choice
Study the following log extract and identify the attack. ![]() Reveal answer details Close answer detailsCorrect answerD
Single choice
Clark, a professional hacker, was hired by an organization lo gather sensitive Information about its competitors surreptitiously. Clark gathers the server IP address of the target organization using Whole footprinting. Further, he entered the server IP address as an input to an online tool to retrieve information such as the network range of the target organization and to identify the network topology and operating system used in the network. What is the online tool employed by Clark in the above scenario? Reveal answer details Close answer detailsCorrect answerB
Single choice
BitLocker encryption has been implemented for all the Windows-based computers in an organization. You are concerned that someone might lose their cryptographic key. Therefore, a mechanism was implemented to recover the keys from Active Directory. What is this mechanism called in cryptography? Reveal answer details Close answer detailsCorrect answerB
Single choice
Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drawn based on these scan results? TCP port 21 no response TCP port 22 no response TCP port 23 Time-to-live exceeded Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the purpose of DNS AAAA record? Reveal answer details Close answer detailsCorrect answerD
Single choice
Sam, a web developer, was instructed to incorporate a hybrid encryption software program into a web application to secure email messages. Sam used an encryption software, which is a free implementation of the OpenPGP standard that uses both symmetric-key cryptography and asymmetric-key cryptography for improved speed and secure key exchange. What is the encryption software employed by Sam for securing the email messages? Reveal answer details Close answer detailsCorrect answerA
Single choice
Consider the following Nmap output: ![]() what command-line parameter could you use to determine the type and version number of the web server? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is the best countermeasure to encrypting ransomwares? Reveal answer details Close answer detailsCorrect answerC
Single choice
_________ is a type of phishing that targets high-profile executives such as CEOs, CFOs, politicians, and celebrities who have access to confidential and highly valuable information. Reveal answer details Close answer detailsCorrect answerB
Single choice
Leverox Solutions hired Arnold, a security professional, for the threat intelligence process. Arnold collected information about specific threats against the organization. From this information, he retrieved contextual information about security events and incidents that helped him disclose potential risks and gain insight into attacker methodologies. He collected the information from sources such as humans, social media, and chat rooms as well as from events that resulted in cyberattacks. In this process, he also prepared a report that includes identified malicious activities, recommended courses of action, and warnings for emerging attacks. What is the type of threat intelligence collected by Arnold in the above scenario? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
Peter, a Network Administrator, has come to you looking for advice on a tool that would help him perform SNMP enquires over the network. Which of these tools would do the SNMP enumeration he is looking for? Select the best answers. Reveal answer details Close answer detailsCorrect answersA, B, D
Single choice
An attacker redirects the victim to malicious websites by sending them a malicious link by email. The link appears authentic but redirects the victim to a malicious web page, which allows the attacker to steal the victim's data. What type of attack is this? Reveal answer details Close answer detailsCorrect answerA
Single choice
Gilbert, a web developer, uses a centralized web API to reduce complexity and increase the Integrity of updating and changing data. For this purpose, he uses a web service that uses HTTP methods such as PUT. POST. GET. and DELETE and can improve the overall performance, visibility, scalability, reliability, and portability of an application. What is the type of web-service API mentioned in the above scenario? Reveal answer details Close answer detailsCorrect answerC
Single choice
What does the -oX flag do in an Nmap scan? Reveal answer details Close answer detailsCorrect answerC
Single choice
What useful information is gathered during a successful Simple Mail Transfer Protocol (SMTP) enumeration? Reveal answer details Close answer detailsCorrect answerA
Single choice
What two conditions must a digital signature meet? Reveal answer details Close answer detailsCorrect answerB
Single choice
Firewalls are the software or hardware systems that are able to control and monitor the traffic coming in and out the target network based on pre-defined set of rules. Which of the following types of firewalls can protect against SQL injection attacks? Reveal answer details Close answer detailsCorrect answerC
Single choice
You have successfully comprised a server having an IP address of 10.10.0.5. You would like to enumerate all machines in the same network quickly. What is the best Nmap command you will use? Reveal answer details Close answer detailsCorrect answerB
Single choice
Ethical hacker jane Smith is attempting to perform an SQL injection attach. She wants to test the response time of a true or false response and wants to use a second command to determine whether the database will return true or false results for user IDs. Reveal answer details Close answer detailsCorrect answerC Explanation Union based SQL injection allows an attacker to extract information from the database by extending the results returned by the first query. The Union operator can only be used if the original/new queries have an equivalent structure Error-based SQL injection is an In-band injection technique where the error output from the SQL database is employed to control the info inside the database. In In-band injection, the attacker uses an equivalent channel for both attacks and collect data from the database.
Single choice
The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. He also needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router, nobody can access the ftp, and the permitted hosts cannot access the Internet. According to the next configuration, what is happening in the network? access-list 102 deny tcp any any access-list 104 permit udp host 10.0.0.3 any access-list 110 permit tcp host 10.0.0.2 eq www any access-list 108 permit tcp any eq ftp any Reveal answer details Close answer detailsCorrect answerB
Single choice
This form of encryption algorithm is asymmetric key block cipher that is characterized by a 128-bit block size, and its key size can be up to 256 bits. Which among the following is this encryption algorithm? Reveal answer details Close answer detailsCorrect answerA Explanation Twofish is an encryption algorithm designed by Bruce Schneier. It's a symmetric key block cipher with a block size of 128 bits, with keys up to 256 bits. it's associated with AES (Advanced Encryption Standard) and an earlier block cipher called Blowfish. Twofish was actually a finalist to become the industry standard for encryption, but was ultimately beaten out by the present AES.Twofish has some distinctive features that set it aside from most other cryptographic protocols. For one, it uses pre-computed, key-dependent S- boxes. An S-box (substitution-box) may be a basic component of any symmetric key algorithm which performs substitution. within the context of Twofish's block cipher, the S-box works to obscure the connection of the key to the ciphertext. Twofish uses a pre-computed, key-dependent S-box which suggests that the S-box is already provided, but depends on the cipher key to decrypt the knowledge .
Single choice
While performing an Nmap scan against a host, Paola determines the existence of a firewall. Reveal answer details Close answer detailsCorrect answerA
Single choice
Henry Is a cyber security specialist hired by BlackEye - Cyber security solutions. He was tasked with discovering the operating system (OS) of a host. He used the Unkornscan tool to discover the OS of the target system. As a result, he obtained a TTL value, which Indicates that the target system is running a Windows OS. Identify the TTL value Henry obtained, which indicates that the target OS is Windows. Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform? Reveal answer details Close answer detailsCorrect answerA
Single choice
Mr. Omkar performed tool-based vulnerability assessment and found two vulnerabilities. During analysis, he found that these issues are not true vulnerabilities. What will you call these issues? Reveal answer details Close answer detailsCorrect answerA
Single choice
Nedved is an IT Security Manager of a bank in his country. One day. he found out that there is a security breach to his company's email server based on analysis of a suspicious connection from the email server to an unknown IP Address. What is the first thing that Nedved needs to do before contacting the incident response team? Reveal answer details Close answer detailsCorrect answerC
Single choice
Kate dropped her phone and subsequently encountered an issue with the phone's internal speaker. Thus, she is using the phone's loudspeaker for phone calls and other activities. Bob, an attacker, takes advantage of this vulnerability and secretly exploits the hardware of Kate's phone so that he can monitor the loudspeaker's output from data sources such as voice assistants, multimedia messages, and audio files by using a malicious app to breach speech privacy. What is the type of attack Bob performed on Kate in the above scenario? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following represents the initial two commands that an IRC client sends to join an IRC network? Reveal answer details Close answer detailsCorrect answerA |