How can rainbow tables be defeated?
Reveal answer details Close answer details
Correct answerA
EC-COUNCIL · EC0-350
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
How can rainbow tables be defeated? Reveal answer details Close answer detailsCorrect answerA
Single choice
A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version installed. Considering the NMAP result below, which of the following is likely to be installed on the target machine by the OS? Starting NMAP 5.21 at 2011-03-15 11:06 NMAP scan report for 172.16.40.65 Host is up (1.00s latency). Not shown: 993 closed ports PORT STATE SERVICE 21/tcp open ftp 23/tcp open telnet 80/tcp open http 139/tcp open netbios-ssn 515/tcp open 631/tcp open ipp 9100/tcp open Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following display filters will you enable in Ethereal to view the three-way handshake for a connection from host 192.168.0.1? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is an automated vulnerability assessment tool? Reveal answer details Close answer detailsCorrect answerC
Single choice
Annie has just succeeded in stealing a secure cookie via a XSS attack. She is able to replay the cookie even while the session is invalid on the server. Why do you think this is possible? Reveal answer details Close answer detailsCorrect answerA
Single choice
Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal? What is odd about this attack? (Choose the most appropriate statement) Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following is most effective against passwords? Select the Answer: Reveal answer details Close answer detailsCorrect answerB
Single choice
You want to perform advanced SQL Injection attack against a vulnerable website. You are unable to perform command shell hacks on this server. What must be enabled in SQL Server to launch these attacks? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following techniques will identify if computer files have been changed? Reveal answer details Close answer detailsCorrect answerC
Single choice
A POP3 client contacts the POP3 server: Reveal answer details Close answer detailsCorrect answerB
Single choice
Advanced encryption standard is an algorithm used for which of the following? Reveal answer details Close answer detailsCorrect answerC
Single choice
You have just installed a new Linux file server at your office. This server is going to be used by several individuals in the organization, and unauthorized personnel must not be able to modify any data. What kind of program can you use to track changes to files on the server? Reveal answer details Close answer detailsCorrect answerC
Single choice
Tess King is making use of Digest Authentication for her Web site. Why is this considered to be more secure than Basic authentication? Reveal answer details Close answer detailsCorrect answerB
Single choice
While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handshaking of packets at the session layer of the OSI model. Which type of firewall is the tester trying to traverse? Reveal answer details Close answer detailsCorrect answerC
Single choice
You generate MD5 128-bit hash on all files and folders on your computer to keep a baseline check for security reasons? ![]() What is the length of the MD5 hash? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following problems can be solved by using Wireshark? Reveal answer details Close answer detailsCorrect answerD
Single choice
__________ is found in all versions of NTFS and is described as the ability to fork file data into existing files without affecting their functionality, size, or display to traditional file browsing utilities like dir or Windows Explorer Reveal answer details Close answer detailsCorrect answerA
Single choice
In order to show improvement of security over time, what must be developed? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the main reason the use of a stored biometric is vulnerable to an attack? Reveal answer details Close answer detailsCorrect answerD
Single choice
Erik notices a big increase in UDP packets sent to port 1026 and 1027 occasionally. He enters the following at the command prompt. $ nc -l -p 1026 -u -v In response, he sees the following message. cell(?(c)????STOPALERT77STOP! WINDOWS REQUIRES IMMEDIATE ATTENTION. Windows has found 47 Critical Errors. 1. Download Registry Repair from: www.reg-patch.com 2. Install Registry Repair 3. Run Registry Repair 4. Reboot your computer FAILURE TO ACT NOW MAY LEAD TO DATA LOSS AND CORRUPTION! What would you infer from this alert? Reveal answer details Close answer detailsCorrect answerD
Single choice
This kind of password cracking method uses word lists in combination with numbers and special characters: Reveal answer details Close answer detailsCorrect answerA
Single choice
After a client sends a connection request (SYN) packet to the server, the server will respond (SYN-ACK) with a sequence number of its choosing, which then must be acknowledged (ACK) by the client. This What attacks can you successfully launch against a server using the above technique? Reveal answer details Close answer detailsCorrect answerB
Single choice
Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network? Reveal answer details Close answer detailsCorrect answerD
Single choice
_________ is a tool that can hide processes from the process list, can hide files, registry entries, and intercept keystrokes. Reveal answer details Close answer detailsCorrect answerB
Single choice
What is the proper response for a X-MAS scan if the port is closed? Reveal answer details Close answer detailsCorrect answerE
Single choice
A particular database threat utilizes a SQL injection technique to penetrate a target system. How would an attacker use this technique to compromise a database? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
What flags are set in a X-MAS scan?(Choose all that apply. Reveal answer details Close answer detailsCorrect answersC, D, F
Single choice
Lori is a Certified Ethical Hacker as well as a Certified Hacking Forensics Investigator working as an IT security consultant. Lori has been hired on by Kiley Innovators, a large marketing firm that recently underwent a string of thefts and corporate espionage incidents. Lori is told that a rival marketing company came out with an exact duplicate product right before Kiley Innovators was about to release it. The executive team believes that an employee is leaking information to the rival company. Lori questions all She finds one employee that appears to be sending very large email to this other marketing company, even though they should have no reason to be communicating with them. Lori tracks down the actual emails sent and upon opening them, only finds picture files attached to them. These files seem perfectly harmless, usually containing some kind of joke. Lori decides to use some special software to further examine the pictures and finds that each one had hidden text that was stored in each picture. What technique was used by the Kiley Innovators employee to send information to the rival marketing company? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the purpose of conducting security assessments on network resources? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which of the following statements about a zone transfer correct?(Choose three. Reveal answer details Close answer detailsCorrect answersA, C, E
Multiple choice
Which of the following are well know password-cracking programs?(Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, E
Single choice
A company has publicly hosted web applications and an internal Intranet protected by a firewall. Which technique will help protect against enumeration? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following countermeasure can specifically protect against both the MAC Flood and MAC Spoofing attacks? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion? Reveal answer details Close answer detailsCorrect answerC
Single choice
If an attacker's computer sends an IPID of 31400 to a zombie (Idle Scanning) computer on an open port, what will be the response? Reveal answer details Close answer detailsCorrect answerB
Single choice
What did the following commands determine? C: user2sid \earth guest S-1-5-21-343818398-789336058-1343024091-501 C:sid2user 5 21 343818398 789336058 1343024091 500 Name is Joe Domain is EARTH Reveal answer details Close answer detailsCorrect answerD
Single choice
Kevin has been asked to write a short program to gather user input for a web application. He likes to keep his code neat and simple. He chooses to use printf(str) where he should have ideally used printf(?s? str). What attack will his program expose the web application to? Reveal answer details Close answer detailsCorrect answerC
Single choice
Bill is a security analyst for his company. All the switches used in the company's office are Cisco switches. How can Bill accomplish this? Reveal answer details Close answer detailsCorrect answerA
Single choice
How can you determine if an LM hash you extracted contains a password that is less than 8 characters long? Reveal answer details Close answer detailsCorrect answerB
Single choice
Why attackers use proxy servers? Reveal answer details Close answer detailsCorrect answerD
Single choice
Consider the following code: URL:http://www.certified.com/search.pl? text=<script>alert(document.cookie)</script> If an attacker can trick a victim user to click a link like this, and the Web application does not validate input, then the victim's browser will pop up an alert showing the users current set of cookies. An attacker can do much more damage, including stealing passwords, resetting your home page, or redirecting the user to another Web site. What is the countermeasure against XSS scripting? Reveal answer details Close answer detailsCorrect answerB
Single choice
Joel and her team have been going through tons of garbage, recycled paper, and other rubbish in order to find some information about the target they are attempting to penetrate. How would you call this type of activity? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the main advantage that a network-based IDS/IPS system has over a host-based solution? Reveal answer details Close answer detailsCorrect answerA
Single choice
A Trojan horse is a destructive program that masquerades as a benign application. The software initially appears to perform a desirable function for the user prior to installation and/or execution, but in addition to the expected function steals information or harms the system. ![]() The challenge for an attacker is to send a convincing file attachment to the victim, which gets easily executed on the victim machine without raising any suspicion. Today's end users are quite knowledgeable about malwares and viruses. Instead of sending games and fun executables, Hackers today are quite successful in spreading the Trojans using Rogue security software. What is Rogue security software? Reveal answer details Close answer detailsCorrect answerB
Single choice
Take a look at the following attack on a Web Server using obstructed URL: http://www.example.com/script.ext?template%2e%2e%2e%2e%2e%2f%2e%2f%65%74%63%2f%70%61%73%73%77%64 The request is made up of: %2e%2e%2f%2e%2e%2f%2e%2f% = ../../../ %65%74%63 = etc %2f = / %70%61%73%73%77%64 = passwd How would you protect information systems from these attacks? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Exhibit ![]() Joe Hacker runs the hping2 hacking tool to predict the target host's sequence numbers in one of the hacking session. What does the first and second column mean? Select two. Reveal answer details Close answer detailsCorrect answersA, B
Single choice
ViruXine.W32 virus hides their presence by changing the underlying executable code. This Virus code mutates while keeping the original algorithm intact, the code changes itself each time it runs, but the function of the code (its semantics) will not change at all. ![]() Here is a section of the Virus code: ![]() What is this technique called? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a component of a risk assessment? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Attackers can potentially intercept and modify unsigned SMB packets, modify the traffic and forward it so that the server might perform undesirable actions. Alternatively, the attacker could pose as the server or client after a legitimate authentication and gain unauthorized access to data. Which of the following is NOT a means that can be used to minimize or protect against such an attack? Reveal answer details Close answer detailsCorrect answersA, B, D
Single choice
Which of the following represents the initial two commands that an IRC client sends to join an IRC network? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room? Reveal answer details Close answer detailsCorrect answerB
Single choice
When utilizing technical assessment methods to assess the security posture of a network, which of the following techniques would be most effective in determining whether end-user security training would be beneficial? Reveal answer details Close answer detailsCorrect answerB
Single choice
A digital signature is simply a message that is encrypted with the public key instead of the private key. Reveal answer details Close answer detailsCorrect answerB
Single choice
This TCP flag instructs the sending system to transmit all buffered data immediately. Reveal answer details Close answer detailsCorrect answerC
Single choice
An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database have not been compromised directly. They have also verified the Intrusion Detection System (IDS) logs and found no attacks that could have caused this. What is the mostly likely way the attacker has been able to modify the purchase price? Reveal answer details Close answer detailsCorrect answerB
Single choice
Every company needs a formal written document which spells out to employees precisely what they are allowed to use the company's systems for, what is prohibited, and what will happen to them if they break the rules. Two printed copies of the policy should be given to every employee as soon as possible after they join the organization. The employee should be asked to sign one copy, which should be safely filed by the company. No one should be allowed to use the company's computer systems until they have signed the policy in acceptance of its terms. What is this document called? Reveal answer details Close answer detailsCorrect answerB
Single choice
Study the snort rule given below and interpret the rule. alert tcp any any --> 192.168.1.0/24 111 (content:"|00 01 86 a5|"; msG. "mountd access";) Reveal answer details Close answer detailsCorrect answerD
Single choice
A covert channel is a channel that Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is a hashing algorithm? Reveal answer details Close answer detailsCorrect answerA
Single choice
When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy? Reveal answer details Close answer detailsCorrect answerB
Single choice
What is "Hacktivism"? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Which of the following are variants of mandatory access control mechanisms? (Choose two.) Reveal answer details Close answer detailsCorrect answersA, C
Multiple choice
How do you defend against ARP Spoofing? Select three. Reveal answer details Close answer detailsCorrect answersA, C, D
Single choice
One of the most common and the best way of cracking RSA encryption is to begin to derive the two prime numbers, which are used in the RSA PKI mathematical process. If the two numbers p and q are discovered through a _____________ process, then the private key can be derived. Reveal answer details Close answer detailsCorrect answerA
Single choice
What port scanning method is the most reliable but also the most detectable? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which type of Nmap scan is the most reliable, but also the most visible, and likely to be picked up by and IDS? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are trying to break into a highly classified top-secret mainframe computer with highest security system in place at Merclyn Barley Bank located in Los Angeles. You know that conventional hacking doesn't work in this case, because organizations such as banks are generally tight and secure when it comes to protecting their systems. In other words you are trying to penetrate an otherwise impenetrable system. How would you proceed? Reveal answer details Close answer detailsCorrect answerB
Single choice
Bob is a very security conscious computer user. He plans to test a site that is known to have malicious applets, code, and more. Bob always make use of a basic Web Browser to perform such testing. Which of the following web browser can adequately fill this purpose? Reveal answer details Close answer detailsCorrect answerC
Single choice
Leesa is the senior security analyst for a publicly traded company. The IT department recently rolled out an intranet for company use only with information ranging from training, to holiday schedules, to human resources data. Leesa wants to make sure the site is not accessible from outside and she also wants to ensure the site is Sarbanes-Oxley (SOX) compliant. Leesa goes to a public library as she wants to do some Google searching to verify whether the company's intranet is accessible from outside and has been indexed by Google. Leesa wants to search for a website title of "intranet" with part of the URL containing the word "intranet" and the words "human resources" somewhere in the webpage. What Google search will accomplish this? Reveal answer details Close answer detailsCorrect answerC
Single choice
The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is the advantage in encrypting the communication between the agent and the monitor in an Intrusion Detection System? Reveal answer details Close answer detailsCorrect answerB
Single choice
On a backdoored Linux box there is a possibility that legitimate programs are modified or trojaned. How is it possible to list processes and uids associated with them in a more reliable manner? Reveal answer details Close answer detailsCorrect answerB
Single choice
Once an intruder has gained access to a remote system with a valid username and password, the attacker will attempt to increase his privileges by escalating the used account to one that has increased privileges. such as that of an administrator. What would be the best countermeasure to protect against escalation of priveges? Reveal answer details Close answer detailsCorrect answerB
Single choice
When using Wireshark to acquire packet capture on a network, which device would enable the capture of all traffic on the wire? Reveal answer details Close answer detailsCorrect answerA
Single choice
_________ is one of the programs used to wardial. Reveal answer details Close answer detailsCorrect answerE
Single choice
Exhibit: Based on the following extract from the log of a compromised machine, what is the hacker really trying to steal? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
What are the limitations of Vulnerability scanners? (Select 2 answers) Reveal answer details Close answer detailsCorrect answersA, C
Multiple choice
How do you defend against ARP Poisoning attack? (Select 2 answers) ![]() Reveal answer details Close answer detailsCorrect answersA, C
Single choice
Cyber Criminals have long employed the tactic of masking their true identity. In IP spoofing, an attacker gains unauthorized access to a computer or a network by making it appear that a malicious message has come from a trusted machine, by "spoofing" the IP address of that machine. How would you detect IP spoofing? Reveal answer details Close answer detailsCorrect answerD
Single choice
Scanning for services is an easy job for Bob as there are so many tools available from the Internet. In order for him to check the vulnerability of XYZ, he went through a few scanners that are currently available. 1. Axent's NetRecon (http://www.axent.com) 2. SARA, by Advanced Research Organization (http://www-arc.com/sara) 3. VLAD the Scanner, by Razor (http://razor.bindview.com/tools/) However, there are many other alternative ways to make sure that the services that have been scanned will be more accurate and detailed for Bob. What would be the best method to accurately identify the services running on a victim host? Reveal answer details Close answer detailsCorrect answerB
Single choice
This attack technique is used when a Web application is vulnerable to an SQL Injection but the results of the Injection are not visible to the attacker. Reveal answer details Close answer detailsCorrect answerB
Single choice
Michael is a junior security analyst working for the National Security Agency (NSA) working primarily on breaking terrorist encrypted messages. The NSA has a number of methods they use to decipher encrypted messages including Government Access to Keys (GAK) and inside informants. The NSA holds secret backdoor keys to many of the encryption algorithms used on the Internet. The problem for the NSA, and Michael, is that terrorist organizations are starting to use custom-built algorithms or obscure algorithms purchased from corrupt governments. For this reason, Michael and other security analysts like him have been forced to find different methods of deciphering terrorist messages. One method that Michael thought of using was to hide malicious code inside seemingly harmless programs. Michael first monitors sites and bulletin boards used by known terrorists, and then he is able to glean email addresses to some of these suspected terrorists. Michael then inserts a stealth keylogger into a mapping program file readme.txt and then sends that as an attachment to the terrorist. This keylogger takes screenshots every 2 minutes and also logs all keyboard activity into a hidden file on the terrorist's computer. Then, the keylogger emails those files to Michael twice a day with a built in SMTP server. What technique has Michael used to disguise this keylogging software? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the correct PCAP filter to capture all TCP traffic going to or from host 192.168.0.125 on port 25? Reveal answer details Close answer detailsCorrect answerD
Single choice
When setting up a wireless network, an administrator enters a pre-shared key for security. Which of the following is true? Reveal answer details Close answer detailsCorrect answerA
Single choice
To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settings? Reveal answer details Close answer detailsCorrect answerC
Single choice
Bryan notices the error on the web page and asks Liza to enter liza' or '1'='1 in the email field. They are greeted with a message "Your login information has been mailed to [email protected]". What do you think has occurred? Reveal answer details Close answer detailsCorrect answerB
Single choice
The traditional traceroute sends out ICMP ECHO packets with a TTL of one, and increments the TTL until the destination has been reached. By printing the gateways that generate ICMP time exceeded messages along the way, it is able to determine the path packets take to reach the destination. The problem is that with the widespread use of firewalls on the Internet today, many of the packets that traceroute sends out end up being filtered, making it impossible to completely trace the path to the ![]() How would you overcome the Firewall restriction on ICMP ECHO packets? Reveal answer details Close answer detailsCorrect answerA
Single choice
Oregon Corp is fighting a litigation suit with Scamster Inc. Oregon has assigned a private investigative agency to go through garbage, recycled paper, and other rubbish at Scamster's office site in order to find relevant information. What would you call this kind of activity? Reveal answer details Close answer detailsCorrect answerC
Single choice
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which of the following statement correctly defines ICMP Flood Attack? (Select 2 answers) ![]() Reveal answer details Close answer detailsCorrect answersB, D
Single choice
Which definition among those given below best describes a covert channel? Reveal answer details Close answer detailsCorrect answerB
Single choice
One of your team members has asked you to analyze the following SOA record. What is the version? Rutgers.edu.SOA NS1.Rutgers.edu ipad.college.edu (200302028 3600 3600 604800 2400. Reveal answer details Close answer detailsCorrect answerA
Single choice
When Nmap performs a ping sweep, which of the following sets of requests does it send to the target device? Reveal answer details Close answer detailsCorrect answerB
Single choice
More sophisticated IDSs look for common shellcode signatures. But even these systems can be bypassed, by using polymorphic shellcode. This is a technique common among virus writers ?it basically hides the true nature of the shellcode in different disguises. How does a polymorphic shellcode work? Reveal answer details Close answer detailsCorrect answerA
Single choice
Ron has configured his network to provide strong perimeter security. As part of his network architecture, he has included a host that is fully exposed to attack. The system is on the public side of the demilitarized zone, unprotected by a firewall or filtering router. What would you call such a host? Reveal answer details Close answer detailsCorrect answerD
Single choice
What is the disadvantage of an automated vulnerability assessment tool? Reveal answer details Close answer detailsCorrect answerE
Multiple choice
A tester is attempting to capture and analyze the traffic on a given network and realizes that the network has several switches. What could be used to successfully sniff the traffic on this switched network? (Choose three.) Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Which of the following settings enables Nessus to detect when it is sending too many packets and the network pipe is approaching capacity? Reveal answer details Close answer detailsCorrect answerD
Single choice
Neil notices that a single address is generating traffic from its port 500 to port 500 of several other machines on the network. This scan is eating up most of the network bandwidth and Neil is concerned. Reveal answer details Close answer detailsCorrect answerD
Single choice
What type of port scan is shown below? ![]() Reveal answer details Close answer detailsCorrect answerC |