Skip to main content

SEC504 Real Exam Questions

Hacker Tools, Techniques, Exploits and Incident Handling

328 questions available · Page 1 of 33

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Alice wants to prove her identity to Bob. Bob requests her password as proof of identity, which Alice
dutifully provides (possibly after some transformation like a hash function); meanwhile, Eve is
eavesdropping the conversation and keeps the password. After the interchange is over, Eve connects to
Bob posing as Alice; when asked for a proof of identity, Eve sends Alice's password read from the last
session, which Bob accepts.

Which of the following attacks is being used by Eve?

  1. A

    Replay

  2. B

    Firewalking

  3. C

    Session fixation

  4. D

    Cross site scripting

Show answer and explanation

Correct answer: A

Question 2 Single choice

Which of the following statements about Ping of Death attack is true?

  1. A

    In this type of attack, a hacker sends more traffic to a network address than the buffer can handle.

  2. B

    This type of attack uses common words in either upper or lower case to find a password.

  3. C

    In this type of attack, a hacker maliciously cuts a network cable.

  4. D

    In this type of attack, a hacker sends ICMP packets greater than 65,536 bytes to crash a system.

Show answer and explanation

Correct answer: D

Question 3 Single choice

John works as a professional Ethical Hacker. He is assigned a project to test the security of www.weare-secure.com. He enters a single quote in the input field of the login page of the We-are-secure Web site and receives the following error message:

Microsoft OLE DB Provider for ODBC Drivers error '0x80040E14'

This error message shows that the We-are-secure Website is vulnerable to __________.

  1. A

    A buffer overflow

  2. B

    A Denial-of-Service attack

  3. C

    A SQL injection attack

  4. D

    An XSS attack

Show answer and explanation

Correct answer: C

Question 4 Single choice

Which of the following malicious software travels across computer networks without the assistance of a user?

  1. A

    Worm

  2. B

    Virus

  3. C

    Hoax

  4. D

    Trojan horses

Show answer and explanation

Correct answer: A

Question 5 Single choice

Which of the following is the method of hiding data within another media type such as graphic or document?

  1. A

    Spoofing

  2. B

    Steganography

  3. C

    Packet sniffing

  4. D

    Cryptanalysis

Show answer and explanation

Correct answer: B

Question 6 Single choice

The Klez worm is a mass-mailing worm that exploits a vulnerability to open an executable attachment even in Microsoft Outlook's preview pane. The Klez worm gathers email addresses from the entries of the
default Windows Address Book (WAB).

Which of the following registry values can be used to identify this worm?

  1. A

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices

  2. B

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

  3. C

    HKEY_CURRENT_USER\Software\Microsoft\WAB\WAB4\Wab File Name = "file and pathname of the
    WAB file"

  4. D

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Show answer and explanation

Correct answer: C

Question 7 Single choice

You work as an Incident handler in Mariotrixt.Inc. You have followed the Incident handling process to handle the events and incidents. You identify Denial of Service attack (DOS) from a network linked to your internal enterprise network.

Which of the following phases of the Incident handling process should you follow next to handle this incident?

  1. A

    Containment

  2. B

    Preparation

  3. C

    Recovery

  4. D

    Identification

Show answer and explanation

Correct answer: A

Question 8 Single choice

Adam, a novice web user, is very conscious about the security. He wants to visit the Web site that is known to have malicious applets and code. Adam always makes use of a basic Web Browser to perform such testing.

Which of the following web browsers can adequately fill this purpose?

  1. A

    Mozilla Firefox

  2. B

    Internet explorer

  3. C

    Lynx

  4. D

    Safari

Show answer and explanation

Correct answer: C

Question 9 Single choice

You are monitoring your network's behavior. You find a sudden increase in traffic on the network. It seems to come in bursts and emanate from one specific machine. You have been able to determine that a user of that machine is unaware of the activity and lacks the computer knowledge required to be responsible for a computer attack.

What attack might this indicate?

  1. A

    Spyware

  2. B

    Ping Flood

  3. C

    Denial of Service

  4. D

    Session Hijacking

Show answer and explanation

Correct answer: A

Question 10 Single choice

In which of the following scanning methods do Windows operating systems send only RST packets irrespective of whether the port is open or closed?

  1. A

    TCP FIN

  2. B

    FTP bounce

  3. C

    XMAS

  4. D

    TCP SYN

Show answer and explanation

Correct answer: A