Which type of security document is written with specific step-by-step details?
Reveal answer details Close answer details
Correct answerB
EC-COUNCIL · 312-50V7
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which type of security document is written with specific step-by-step details? Reveal answer details Close answer detailsCorrect answerB
Single choice
How do you defend against DHCP Starvation attack? 100% Real Q&As | 100% Real Pass ![]() Reveal answer details Close answer detailsCorrect answerB
Single choice
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities? Reveal answer details Close answer detailsCorrect answerB
Single choice
You are programming a buffer overflow exploit and you want to create a NOP sled of 200 bytes in the program exploit.c ![]() What is the hexadecimal value of NOP instruction? Reveal answer details Close answer detailsCorrect answerD
Single choice
A botnet can be managed through which of the following? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following techniques will identify if computer files have been changed? Reveal answer details Close answer detailsCorrect answerC
Single choice
What sequence of packets is sent during the initial TCP three-way handshake? Reveal answer details Close answer detailsCorrect answerA
Single choice
How can rainbow tables be defeated? Reveal answer details Close answer detailsCorrect answerA
Single choice
To send a PGP encrypted message, which piece of information from the recipient must the sender have before encrypting the message? Reveal answer details Close answer detailsCorrect answerB
Single choice
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take? Reveal answer details Close answer detailsCorrect answerB
Single choice
In Trojan terminology, what is a covert channel? ![]() Reveal answer details Close answer detailsCorrect answerA
Single choice
Vulnerability scanners are automated tools that are used to identify vulnerabilities and misconfigurations of hosts. They also provide information regarding mitigating discovered vulnerabilities. ![]() Which of the following statements is incorrect? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following is a detective control? Reveal answer details Close answer detailsCorrect answerC
Single choice
Jacob is looking through a traffic log that was captured using Wireshark. Jacob has come across what appears to be SYN requests to an internal computer from a spoofed IP address. What is Jacob seeing here? Reveal answer details Close answer detailsCorrect answerB
Single choice
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the tester consider using? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
You just purchased the latest DELL computer, which comes pre-installed with Windows 7, McAfee antivirus software and a host of other applications. You want to connect Ethernet wire to your cable modem and start using the computer immediately. Windows is dangerously insecure when unpacked from the box, and there are a few things that you must do before you use it. Reveal answer details Close answer detailsCorrect answersA, C, D, E, F
Single choice
Low humidity in a data center can cause which of the following problems? Reveal answer details Close answer detailsCorrect answerC
Single choice
If a competitor wants to cause damage to your organization, steal critical secrets, or put you out of business, they just have to find a job opening, prepare someone to pass the interview, have that person hired, and they will be in the organization. ![]() How would you prevent such type of attacks? Reveal answer details Close answer detailsCorrect answerC
Single choice
Frederickson Security Consultants is currently conducting a security audit on the networks of Hawthorn Enterprises, a contractor for the Department of Defense. What method of attack is best suited to crack these passwords in the shortest amount of time? Reveal answer details Close answer detailsCorrect answerA
Single choice
The FIN flag is set and sent from host A to host B when host A has no more data to transmit (Closing a TCP connection). This flag releases the connection resources. However, host A can continue to receive data as long as the SYN sequence numbers of transmitted packets from host B are lower than the packet segment containing the set FIN flag. Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which initial procedure should an ethical hacker perform after being brought into an organization? Reveal answer details Close answer detailsCorrect answerC
Single choice
This attack uses social engineering techniques to trick users into accessing a fake Web site and divulging personal information. Attackers send a legitimate-looking e-mail asking users to update their information on the company's Web site, but the URLs in the e-mail actually point to a false Web site. Reveal answer details Close answer detailsCorrect answerC
Single choice
More sophisticated IDSs look for common shellcode signatures. But even these systems can be bypassed, by using polymorphic shellcode. This is a technique common among virus writers ?it basically hides the true nature of the shellcode in different disguises. How does a polymorphic shellcode work? Reveal answer details Close answer detailsCorrect answerA
Single choice
Bob is going to perform an active session hijack against Brownies Inc. He has found a target that allows session oriented connections (Telnet) and performs the sequence prediction on the target operating system. He manages to find an active session due to the high level of traffic on the network. What is Bob supposed to do next? Reveal answer details Close answer detailsCorrect answerC
Single choice
A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. The analyst will use the Blackjacking attack method to demonstrate how an attacker could circumvent perimeter defenses and gain access to the corporate network. What tool should the analyst use to perform a Blackjacking attack? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
In keeping with the best practices of layered security, where are the best places to place intrusion detection/intrusion prevention systems? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Single choice
In the context of password security: a simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0phtCrack or John the Ripper, and running it against user accounts located by the application. The larger the word and word fragment selection, the more effective the dictionary attack is. The brute force method is the most inclusive - though slow. Usually, it tries every possible letter and number combination in its automated exploration. Reveal answer details Close answer detailsCorrect answerC
Single choice
In TCP communications there are 8 flags; FIN, SYN, RST, PSH, ACK, URG, ECE, CWR. These flags have decimal numbers assigned to them: FIN = 1 Jason is the security administrator of ASPEN Communications. He analyzes some traffic using Wireshark and has enabled the following filters. What is Jason trying to accomplish here? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection? Reveal answer details Close answer detailsCorrect answerB
Single choice
Web servers often contain directories that do not need to be indexed. You create a text file with search engine indexing restrictions and place it on the root directory of the Web Server. User-agent: * What is the name of this file? 100% Real Q&As | 100% Real Pass Reveal answer details Close answer detailsCorrect answerA
Single choice
While investigating a claim of a user downloading illegal material, the investigator goes through the files on the suspect's workstation. He comes across a file that is just called "file.txt" but when he opens it, he finds the following: 100% Real Q&As | 100% Real Pass ![]() What can he infer from this file? Reveal answer details Close answer detailsCorrect answerD
Single choice
A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use? Reveal answer details Close answer detailsCorrect answerA
Single choice
During a wireless penetration test, a tester detects an access point using WPA2 encryption. Which of the following attacks should be used to obtain the key? Reveal answer details Close answer detailsCorrect answerA
Single choice
Samuel is the network administrator of DataX Communications, Inc. He is trying to configure his firewall to block password brute force attempts on his network. He enables blocking the intruder's IP address for a period of 24 hours' time after more than three unsuccessful attempts. He is confident that this rule will secure his network from hackers on the Internet. But he still receives hundreds of thousands brute-force attempts generated from various IP addresses around the world. After some investigation he realizes that the intruders are using a proxy somewhere else on the Internet which has been scripted to enable the random usage of various proxies on each request so as not to get caught by the firewall rule. Later he adds another rule to his firewall and enables small sleep on the password attempt so that if the password is incorrect, it would take 45 seconds to return to the user to begin another attempt. Since an intruder may use multiple machines to brute force the password, he also throttles the number of connections that will be prepared to accept from a particular IP address. This action will slow the intruder's attempts. Samuel wants to completely block hackers brute force attempts on his network. What are the alternatives to defending against possible brute-force password attacks on his site? Reveal answer details Close answer detailsCorrect answerD
Single choice
To see how some of the hosts on your network react, Winston sends out SYN packets to an IP range. A number of IPs respond with a SYN/ACK response. Before the connection is established he sends RST packets to those hosts to stop the session. Winston has done this to see how his intrusion detection system will log the traffic. What type of scan is Winston attempting here? Reveal answer details Close answer detailsCorrect answerD
Single choice
Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. Which of the following is the correct bit size of the Diffie-Hellman (DH) group 5? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the main difference between a "Normal" SQL Injection and a "Blind" SQL Injection vulnerability? Reveal answer details Close answer detailsCorrect answerD
Single choice
You work for Acme Corporation as Sales Manager. The company has tight network security restrictions. You are trying to steal data from the company's Sales database (Sales.xls) and transfer them to your home computer. Your company filters and monitors traffic that leaves from the internal network to the Internet. How will you achieve this without raising suspicion? Reveal answer details Close answer detailsCorrect answerC
Single choice
A computer technician is using a new version of a word processing software package when it is discovered that a special sequence of characters causes the entire computer to crash. The technician researches the bug and discovers that no one else experienced the problem. What is the appropriate next step? Reveal answer details Close answer detailsCorrect answerD
Single choice
Employees in a company are no longer able to access Internet web sites on their computers. The network administrator is able to successfully ping IP address of web servers on the Internet and is able to open web sites by using an IP address in place of the URL. The administrator runs the nslookup command for www.eccouncil.org and receives an error message stating there is no response from the server. What should the administrator do next? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Buffer X in an Accounting application module for Brownies Inc. can contain 200 characters. The programmer makes an assumption that 200 characters are more than enough. Because there were no proper boundary checks being conducted, Bob decided to insert 400 characters into the 200-character buffer. (Overflows the buffer). Below is the code snippet: 100% Real Q&As | 100% Real Pass ![]() How can you protect/fix the problem of your application as shown above? Reveal answer details Close answer detailsCorrect answersA, D
Multiple choice
Which types of detection methods are employed by Network Intrusion Detection Systems (NIDS)? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, B
Single choice
One of the most common and the best way of cracking RSA encryption is to begin to derive the two prime numbers, which are used in the RSA PKI mathematical process. If the two numbers p and q are discovered through a _____________ process, then the private key can be derived. Reveal answer details Close answer detailsCorrect answerA
Single choice
Identify SQL injection attack from the HTTP requests shown below: Reveal answer details Close answer detailsCorrect answerA
Single choice
In which step Steganography fits in CEH System Hacking Cycle (SHC) Reveal answer details Close answer detailsCorrect answerE
Single choice
In which part of OSI layer, ARP Poisoning occurs? ![]() Reveal answer details Close answer detailsCorrect answerB
Single choice
An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces. Which of the following is the most likely reason for lack of management or control packets? Reveal answer details Close answer detailsCorrect answerD
Single choice
A security policy will be more accepted by employees if it is consistent and has the support of Reveal answer details Close answer detailsCorrect answerB
Single choice
While testing web applications, you attempt to insert the following test script into the search area on the company's web site: <script>alert('Testing Testing Testing')</script> Later, when you press the search button, a pop up box appears on your screen with the text "Testing Testing Testing". What vulnerability is detected in the web application here? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
A tester is attempting to capture and analyze the traffic on a given network and realizes that the network has several switches. What could be used to successfully sniff the traffic on this switched network? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Fred is the network administrator for his company. Fred is testing an internal switch. From an external IP address, Fred wants to try and trick this switch into thinking it already has established a session with his computer. How can Fred accomplish this? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which type of scan measures a person's external features through a digital video camera? Reveal answer details Close answer detailsCorrect answerC
Single choice
One of the effective DoS/DDoS countermeasures is 'Throttling'. Which statement correctly defines this term? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Which of the following techniques can be used to mitigate the risk of an on-site attacker from connecting to an unused network port and gaining full access to the network? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, C, E
Single choice
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on? Reveal answer details Close answer detailsCorrect answerD
Single choice
The following is a sample of output from a penetration tester's machine targeting a machine with the IP address of 192.168.1.106: ![]() What is most likely taking place? Reveal answer details Close answer detailsCorrect answerB
Single choice
Simon is security analyst writing signatures for a Snort node he placed internally that captures all mirrored traffic from his border firewall. From the following signature, what will Snort look for in the payload of the suspected packets? alert tcp $EXTERNAL_NET any -> $HOME_NET 27374 (msG. "BACKDOOR SIG - SubSseven 22";flags: A+; content: "|0d0a5b52504c5d3030320d0a|"; Reveal answer details Close answer detailsCorrect answerB
Single choice
__________ is found in all versions of NTFS and is described as the ability to fork file data into existing files without affecting their functionality, size, or display to traditional file browsing utilities like dir or Windows Explorer Reveal answer details Close answer detailsCorrect answerA
Single choice
A company has five different subnets: 192.168.1.0, 192.168.2.0, 192.168.3.0, 192.168.4.0 and 192.168.5.0. How can NMAP be used to scan these adjacent Class C networks? Reveal answer details Close answer detailsCorrect answerA
Single choice
During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Reveal answer details Close answer detailsCorrect answerC
Multiple choice
John runs a Web server, IDS and firewall on his network. Recently his Web server has been under constant hacking attacks. He looks up the IDS log files and sees no intrusion attempts but the Web server constantly locks up and needs rebooting due to various brute force and buffer overflow attacks but still the IDS alerts no intrusion whatsoever. John becomes suspicious and views the Firewall logs and he notices huge SSL connections constantly hitting his Web server. How would John protect his network from these types of attacks? Reveal answer details Close answer detailsCorrect answersA, C
Single choice
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is War Dialing? Reveal answer details Close answer detailsCorrect answerA
Single choice
100% Real Q&As | 100% Real Pass An Attacker creates a zuckerjournals.com website by copying and mirroring HACKERJOURNALS.COM site to spread the news that Hollywood actor Jason Jenkins died in a car accident. The attacker then submits his fake site for indexing in major search engines. When users search for "Jason Jenkins", attacker's fake site shows up and dupes victims by the fake news. ![]() This is another great example that some people do not know what URL's are. Real website: Fake website: http://www.zuckerjournals.com 100% Real Q&As | 100% Real Pass ![]() The website is clearly not WWW.HACKERJOURNALS.COM. It is obvious for many, but unfortunately some people still do not know what an URL is. It's the address that you enter into the address bar at the top your browser and this is clearly not legit site, its www.zuckerjournals.com How would you verify if a website is authentic or not? Reveal answer details Close answer detailsCorrect answerD
Single choice
After a client sends a connection request (SYN) packet to the server, the server will respond (SYN-ACK) with a sequence number of its choosing, which then What attacks can you successfully launch against a server using the above technique? Reveal answer details Close answer detailsCorrect answerB
Single choice
Data hiding analysis can be useful in Reveal answer details Close answer detailsCorrect answerB
Single choice
What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room? Reveal answer details Close answer detailsCorrect answerB
Single choice
A certified ethical hacker (CEH) is approached by a friend who believes her husband is cheating. She offers to pay to break into her husband's email account in order to find proof so she can take him to court. What is the ethical response? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
This is an example of whois record. ![]() Sometimes a company shares a little too much information on their organization through public domain records. Reveal answer details Close answer detailsCorrect answersB, C
Single choice
While testing the company's web applications, a tester attempts to insert the following test script into the search area on the company's web sitE. Which vulnerability has been detected in the web application? Reveal answer details Close answer detailsCorrect answerD
Single choice
Paul has just finished setting up his wireless network. He has enabled numerous security features such as changing the default SSID, enabling WPA encryption, and enabling MAC filtering on his wireless router. Paul notices that when he uses his wireless connection, the speed is sometimes 54 Mbps and sometimes it is only 24Mbps or less. Paul connects to his wireless router's management utility and notices that a machine with an unfamiliar name is connected through his wireless connection. Paul checks the router's logs and notices that the unfamiliar machine has the same MAC address as his laptop. What is Paul seeing here? Reveal answer details Close answer detailsCorrect answerA
Single choice
You run nmap port Scan on 10.0.0.5 and attempt to gain banner/server information from services running on ports 21, 110 and 123. Here is the output of your scan results: ![]() Which of the following nmap command did you run? Reveal answer details Close answer detailsCorrect answerC
Single choice
Hayden is the network security administrator for her company, a large finance firm based in Miami. Hayden just returned from a security conference in Las Vegas What type of scan is Hayden attempting here? Reveal answer details Close answer detailsCorrect answerD
Single choice
What type of port scan is shown below? 100% Real Q&As | 100% Real Pass ![]() Reveal answer details Close answer detailsCorrect answerC
Single choice
This method is used to determine the Operating system and version running on a remote target system. What is it called? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which protocol and port number might be needed in order to send log messages to a log analysis tool that resides behind a firewall? Reveal answer details Close answer detailsCorrect answerC |