Which of the following is a wireless network detector that is commonly found on Linux?
Reveal answer details Close answer details
Correct answerA
EC-COUNCIL · 312-50V9
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which of the following is a wireless network detector that is commonly found on Linux? Reveal answer details Close answer detailsCorrect answerA
Single choice
A Certificate Authority (CA) generates a key pair that will be used for encryption and decryption of email. Reveal answer details Close answer detailsCorrect answerB
Single choice
How can a policy help improve an employee's security awareness? Reveal answer details Close answer detailsCorrect answerA
Single choice
It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of the following terms best matches the definition? Reveal answer details Close answer detailsCorrect answerA Explanation A threat is a any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, or individuals through an information system via unauthorized access, destruction, disclosure, modification of information, and/or denial of service. Also, the potential for a threat-source to successfully exploit a particular information system vulnerability.
Single choice
What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data? Reveal answer details Close answer detailsCorrect answerD
Single choice
In many states sending spam is illegal. Thus, the spammers have techniques to try and ensure that no one knows they sent the spam out to thousands of users at a time. Which of the following best describes what spammers use to hide the origin of these types of e-mails? Reveal answer details Close answer detailsCorrect answerB
Single choice
A specific site received 91 ICMP_ECHO packets within 90 minutes from 47 different sites. 77 of the ICMP_ECHO packets had an ICMP ID:39612 and Seq:57072. 13 of the ICMP_ECHO packets had an ICMP ID:0 and Seq:0. What can you infer from this information? Reveal answer details Close answer detailsCorrect answerB
Single choice
An IT security engineer notices that the company's web server is currently being hacked. What should the engineer do next? Reveal answer details Close answer detailsCorrect answerC
Single choice
The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE's Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the transport layer security (TLS) protocols defined in RFC6520. What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy? Reveal answer details Close answer detailsCorrect answerA Explanation The data obtained by a Heartbleed attack may include unencrypted exchanges between TLS parties likely to be confidential, including any form post data in users' requests. Moreover, the confidential data exposed could include authentication secrets such as session cookies and passwords, which might allow attackers to impersonate a user of the service. References:
Single choice
During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to exploit this vulnerability? Reveal answer details Close answer detailsCorrect answerB
Single choice
A consultant has been hired by the V.P. of a large financial organization to assess the company's security posture. During the security testing, the consultant comes across child pornography on the V.P.'s computer. What is the consultant's obligation to the financial organization? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which access control mechanism allows for multiple systems to use a central authentication server (CAS) that permits users to authenticate once and gain access to multiple systems? Reveal answer details Close answer detailsCorrect answerD
Single choice
A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the best remediation against this type of attack? Reveal answer details Close answer detailsCorrect answerC
Single choice
An IT employee got a call from one of our best customers. The caller wanted to know about the company's network infrastructure, systems, and team. New opportunities of integration are in sight for both company and customer. What should this employee do? Reveal answer details Close answer detailsCorrect answerC
Single choice
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on? Reveal answer details Close answer detailsCorrect answerD
Single choice
A security engineer has been asked to deploy a secure remote access solution that will allow employees to connect to the company's internal network. Which of the following can be implemented to minimize the opportunity for the man-in-the-middle attack to occur? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is a detective control? Reveal answer details Close answer detailsCorrect answerC
Single choice
The chance of a hard drive failure is once every three years. The cost to buy a new hard drive is $300. It will require 10 hours to restore the OS and software to the new hard disk. It will require a further 4 hours to restore the database from the last backup to the new hard disk. The recovery person earns $10/hour. What is the closest approximate cost of this replacement and recovery operation per year? Reveal answer details Close answer detailsCorrect answerA Explanation The annualized loss expectancy (ALE) is the product of the annual rate of occurrence (ARO) and the single loss expectancy (SLE). Suppose than an asset is valued at $100,000, and the Exposure Factor (EF) for this asset is 25%. The single loss expectancy (SLE) then, is 25% * $100,000, or $25,000. References:
Single choice
ViruXine.W32 virus hides their presence by changing the underlying executable code. ![]() Here is a section of the Virus code: ![]() What is this technique called? Reveal answer details Close answer detailsCorrect answerA
Single choice
Craig received a report of all the computers on the network that showed all the missing patches and weak passwords. What type of software generated this report? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which Type of scan sends a packets with no flags set? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which security control role does encryption meet? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which type of Nmap scan is the most reliable, but also the most visible, and likely to be picked up by and IDS? Reveal answer details Close answer detailsCorrect answerD
Single choice
Passive reconnaissance involves collecting information through which of the following? Reveal answer details Close answer detailsCorrect answerD
Single choice
Internet Protocol Security IPSec is actually a suite of protocols. Each protocol within the suite provides Reveal answer details Close answer detailsCorrect answerD
Single choice
Which type of cryptography does SSL, IKE and PGP belongs to? Reveal answer details Close answer detailsCorrect answerD
Single choice
A developer for a company is tasked with creating a program that will allow customers to update their billing and shipping information. The billing address field used is limited to 50 characters. What pseudo code would the developer use to avoid a buffer overflow attack on the billing address field? Reveal answer details Close answer detailsCorrect answerD
Single choice
How can you determine if an LM hash you extracted contains a password that is less than 8 characters long? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which service in a PKI will vouch for the identity of an individual or company? Reveal answer details Close answer detailsCorrect answerB
Single choice
After gaining access to the password hashes used to protect access to a web based application, knowledge of which cryptographic algorithms would be useful to gain access to the application? Reveal answer details Close answer detailsCorrect answerA
Single choice
One advantage of an application-level firewall is the ability to Reveal answer details Close answer detailsCorrect answerB
Single choice
This kind of password cracking method uses word lists in combination with numbers and special characters: Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is the most important phase of ethical hacking wherein you need to spend considerable amount of time? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following describes a component of Public Key Infrastructure (PKI) where a copy of a private key is stored to provide third-party access and to facilitate recovery operations? Reveal answer details Close answer detailsCorrect answerD
Single choice
It is a widely used standard for message logging. It permits separation of the software that generates messages, the system that stores them, and the software that reports and analyzes them. This protocol is specifically designed for transporting event messages. Which of the following is being described? Reveal answer details Close answer detailsCorrect answerC
Single choice
You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line. Which command would you use? Reveal answer details Close answer detailsCorrect answerA Explanation To start the Computer Management Console from command line just type compmgmt.msc / computer:computername in your run box or at the command line and it should automatically open the Computer Management console. References:
Single choice
Which security strategy requires using several, varying methods to protect IT systems against attacks? Reveal answer details Close answer detailsCorrect answerA
Single choice
env x=`(){ :;};echo exploit` bash -c 'cat /etc/passwd' What is the Shellshock bash vulnerability attempting to do on an vulnerable Linux host? Reveal answer details Close answer detailsCorrect answerA Explanation To extract private information, attackers are using a couple of techniques. The simplest extraction attacks are in the form: References:
Single choice
What is the outcome of the comm"nc -l -p 2222 | nc 10.1.0.43 1234"? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a primary service of the U.S. Reveal answer details Close answer detailsCorrect answerA
Single choice
Nathan is testing some of his network devices. Nathan is using Macof to try and flood the ARP cache of these switches. Reveal answer details Close answer detailsCorrect answerA
Single choice
A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. What should you do? Reveal answer details Close answer detailsCorrect answerC
Single choice
A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT department had a dial-out modem installed. Which security policy must the security analyst check to see if dial-out modems are allowed? Reveal answer details Close answer detailsCorrect answerC
Single choice
What are the three types of authentication? Reveal answer details Close answer detailsCorrect answerB
Single choice
Take a look at the following attack on a Web Server using obstructed URL: ![]() How would you protect from these attacks? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is a strong post designed to stop a car? Reveal answer details Close answer detailsCorrect answerC
Single choice
What type of malware is it that restricts access to a computer system that it infects and demands that the user pay a certain amount of money, cryptocurrency, etc. Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a command line packet analyzer similar to GUI-based Wireshark? Reveal answer details Close answer detailsCorrect answerA Explanation tcpdump is a common packet analyzer that runs under the command line. It allows the user to display TCP/IP and other packets being transmitted or received over a network to which the computer is attached. References:
Single choice
Backing up data is a security must. However, it also have certain level of risks when mishandled. Which of the following is the greatest threat posed by backups? Reveal answer details Close answer detailsCorrect answerD
Single choice
While performing online banking using a Web browser, a user receives an email that contains a link to an interesting Web site. When the user clicks on the link, another Web browser session starts and displays a video of cats playing a piano. The next business day, the user receives what looks like an email from his bank, indicating that his bank account has been accessed from a foreign country. The email asks the user to call his bank and verify the authorization of a funds transfer that took place. What Web browser-based security vulnerability was exploited to compromise the user? Reveal answer details Close answer detailsCorrect answerA Explanation Cross-site request forgery, also known as one-click attack or session riding and abbreviated as CSRF or XSRF, is a type of malicious exploit of a website where unauthorized commands are transmitted from a user that the website trusts. Example and characteristics Incorrect Answers:
Single choice
If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which tool allows analysts and pen testers to examine links between data using graphs and link analysis? Reveal answer details Close answer detailsCorrect answerA Explanation Maltego is proprietary software used for open-source intelligence and forensics, developed by Paterva. References:
Single choice
What is the main advantage that a network-based IDS/IPS system has over a host-based solution? Reveal answer details Close answer detailsCorrect answerA
Single choice
You are attempting to man-in-the-middle a session. Which protocol will allow you to guess a sequence number? Reveal answer details Close answer detailsCorrect answerA Explanation At the establishment of a TCP session the client starts by sending a SYN-packet (SYN=synchronize) with a sequence number. To hijack a session it is required to send a packet with a right seq-number, otherwise they are dropped. References:
Single choice
A company has hired a security administrator to maintain and administer Linux and Windows-based systems. Written in the nightly report file is the following: Firewall log files are at the expected value of 4 MB. The current time is 12am. Exactly two hours later the size has decreased considerably. Another hour goes by and the log files have shrunk in size again. Which of the following actions should the security administrator take? Reveal answer details Close answer detailsCorrect answerD
Single choice
A company's Web development team has become aware of a certain type of security vulnerability in their What kind of Web application vulnerability likely exists in their software? Reveal answer details Close answer detailsCorrect answerA Explanation Many operators of particular web applications (e.g. forums and webmail) allow users to utilize a limited subset of HTML markup. When accepting HTML input from users (say, <b>very</b> large), output References:
Multiple choice
Which of the following statements about a zone transfer is correct? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, C, E
Single choice
A new wireless client that is 802.11 compliant cannot connect to a wireless network given that the client can see the network and it has compatible hardware and software installed. Upon further tests and investigation it was found out that the Wireless Access Point (WAP) was not responding to the association requests being sent by the wireless client. What MOST likely is the issue on this scenario? Reveal answer details Close answer detailsCorrect answerB
Single choice
The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which type of security document is written with specific step-by-step details? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which of the following tools are used for enumeration? (Choose three.) Reveal answer details Close answer detailsCorrect answersB, D, E
Single choice
Suppose you've gained access to your client's hybrid network. Reveal answer details Close answer detailsCorrect answerC
Single choice
It is a short-range wireless communication technology intended to replace the cables connecting portable of fixed devices while maintaining high levels of security. It allows mobile phones, computers and other devices to connect and communicate using a short-range wireless connection. Which of the following terms best matches the definition? Reveal answer details Close answer detailsCorrect answerA Explanation Bluetooth is a standard for the short-range wireless interconnection of mobile phones, computers, and other electronic devices. References:
Single choice
Sid is a judge for a programming contest. Before the code reaches him it goes through a restricted OS and is tested there. If it passes, then it moves onto Sid. What is this middle step called? Reveal answer details Close answer detailsCorrect answerA
Single choice
A recent security audit revealed that there were indeed several occasions that the company's network was breached. After investigating, you discover that your IDS is not configured properly and therefore is unable to trigger alarms when needed. What type of alert is the IDS giving? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following settings enables Nessus to detect when it is sending too many packets and the network pipe is approaching capacity? Reveal answer details Close answer detailsCorrect answerD
Single choice
A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID card access system to a new server room on campus. The server room will house student enrollment information that is securely backed up to an off-site location. During a meeting with an outside consultant, the Chief Security Officer explains that he is concerned that the existing security controls have not been designed properly. Currently, the Network Administrator is responsible for approving and issuing RFID card access to the server room, as well as reviewing the electronic access logs on a weekly basis. Which of the following is an issue with the situation? Reveal answer details Close answer detailsCorrect answerA
Single choice
MX record priority increases as the number increases. (True/False.) Reveal answer details Close answer detailsCorrect answerB
Single choice
When security and confidentiality of data within the same LAN is of utmost priority, which IPSec mode should you implement? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the best defense against privilege escalation vulnerability? Reveal answer details Close answer detailsCorrect answerC
Single choice
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from financial problems, and the CEH is worried that the company will go out of business and end up not paying. What actions should the CEH take? Reveal answer details Close answer detailsCorrect answerB
Single choice
It is a short-range wireless communication technology that allows mobile phones, computers and other devices to connect and communicate. This technology intends to replace cables connecting portable devices with high regards to security. Reveal answer details Close answer detailsCorrect answerA
Single choice
Which mode of IPSec should you use to assure security and confidentiality of data within the same LAN? Reveal answer details Close answer detailsCorrect answerA Explanation When transport mode is used, IPSec encrypts only the IP payload. Transport mode provides the protection of an IP payload through an AH or ESP header. Encapsulating Security Payload (ESP) provides confidentiality (in addition to authentication, integrity, and anti-replay protection) for the IP payload. Incorrect Answers: References:
Single choice
What two conditions must a digital signature meet? Reveal answer details Close answer detailsCorrect answerA
Single choice
Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 111 (content:"|00 01 86 a5|"; msG. "mountd access";) Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following command line switch would you use for OS detection in Nmap? Reveal answer details Close answer detailsCorrect answerB
Single choice
A company recently hired your team of Ethical Hackers to test the security of their network systems. The company wants to have the attack be as realistic as possible. They did not provide any information besides the name of their company. What phase of security testing would your team jump in right away? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which type of security feature stops vehicles from crashing through the doors of a building? Reveal answer details Close answer detailsCorrect answerB
Single choice
How do employers protect assets with security policies pertaining to employee surveillance activities? Reveal answer details Close answer detailsCorrect answerD
Single choice
A company is using Windows Server 2003 for its Active Directory (AD). What is the most efficient way to crack the passwords for the AD users? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the main disadvantage of the scripting languages as opposed to compiled programming languages? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are performing information gathering for an important penetration test. You have found pdf, doc, and images in your objective. You decide to extract metadata from these files and analyze it. What tool will help you with the task? Reveal answer details Close answer detailsCorrect answerA Explanation Metagoofil is an information gathering tool designed for extracting metadata of public documents (pdf,doc,xls,ppt,docx,pptx,xlsx) belonging to a target company. Metagoofil will perform a search in Google to identify and download the documents to local disk and then will extract the metadata with different libraries like Hachoir, PdfMiner? and others. With the results it will generate a report with usernames, software versions and servers or machine names that will help Penetration testers in the information gathering phase. References:
Single choice
Which of the following Nmap commands will produce the following output? Output: ![]() Reveal answer details Close answer detailsCorrect answerD
Single choice
In an internal security audit, the white hat hacker gains control over a user account and attempts to acquire access to another account's confidential files and information. How can he achieve this? Reveal answer details Close answer detailsCorrect answerC
Single choice
Employees in a company are no longer able to access Internet web sites on their computers. The network administrator is able to successfully ping IP address of web servers on the Internet and is able to open web sites by using an IP address in place of the URL. The administrator runs the nslookup command for www.eccouncil.org and receives an error message stating there is no response from the server. What should the administrator do next? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform? Reveal answer details Close answer detailsCorrect answerA Explanation Kismet is a network detector, packet sniffer, and intrusion detection system for 802.11 wireless LANs.
Single choice
You have successfully compromised a machine on the network and found a server that is alive on the same network. You tried to ping it but you didn't get any response back. What is happening? Reveal answer details Close answer detailsCorrect answerA Explanation The ping utility is implemented using the ICMP "Echo request" and "Echo reply" messages. References:
Single choice
What is the proper response for a NULL scan if the port is closed? Reveal answer details Close answer detailsCorrect answerE
Single choice
Which system consists of a publicly available set of databases that contain domain name registration contact information? Reveal answer details Close answer detailsCorrect answerA
Single choice
Supposed you are the Chief Network Engineer of a certain Telco. Your company is planning for a big business expansion and it requires that your network authenticate users connecting using analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network. Which AAA protocol would you implement? Reveal answer details Close answer detailsCorrect answerD
Single choice
Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he is evaluating. Bob is familiar with password weaknesses and key loggers. Which of the following options best represents the means that Bob can adopt to retrieve passwords from his clients hosts and servers? Reveal answer details Close answer detailsCorrect answerA |