The promiscuous mode is a configuration of a network card that makes the card pass all traffic it receives to the central processing unit rather than just packets addressed to it. Which of the following tools works by placing the host system network card into the promiscuous mode?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
John works as a professional Ethical Hacker. He has been assigned a project for testing the security of www.we-are-secure.com. He wants to corrupt an IDS signature database so that performing attacks on the server is made easy and he can observe the flaws in the We-are-secure server. To perform his task, he first of all sends a virus that continuously changes its signature to avoid detection from IDS. Since the new signature of the virus does not match the old signature, which is entered in the IDS signature database, IDS becomes unable to point out the malicious virus. Which of the following IDS evasion attacks is John performing?
-
A
-
B
-
C
-
D
Polymorphic shell code attack
Reveal answer details
Close answer details
Which of the following distributes incorrect IP address to divert the traffic?
-
A
-
B
Domain name server (DNS) poisoning
-
C
Reverse Address Resolution Protocol
-
D
Reveal answer details
Close answer details
Question 4
Multiple choice
What netsh command should be run to enable IPv6 routing? Each correct answer represents a part of the solution. Choose two.
-
A
netsh interface IPv6 show interface
-
B
netsh interface IPv6 add routes
-
C
netsh interface IPv6 set interface
-
D
netsh interface IPv6 add address
Reveal answer details
Close answer details
Smith works as a Network Administrator for HCP Inc. He sets up a DNS server on the network and enables DNS service on all computers. However, DNS is not working properly. Which of the following commands should Smith use to verify the DNS configuration?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following programs in UNIX is used to identify and fix lost blocks or orphans?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following tools can be used to check whether the network interface is in promiscuous mode or not?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 8
Multiple choice
Mark works as a Network Security Administrator for BlueWells Inc. The company has a Windowsbased network. Mark is giving a presentation on Network security threats to the newly recruited employees of the company. His presentation is about the External threats that the company recently faced in the past. Which of the following statements are true about external threats? Each correct answer represents a complete solution. Choose three.
-
A
These threats can be countered by implementing security controls on the perimeters of the network, such as firewalls, which limit user access to the Internet.
-
B
These are the threats intended to flood a network with large volumes of access requests.
-
C
These are the threats that originate from outside an organization in which the attacker attempts to gain unauthorized access.
-
D
These are the threats that originate from within the organization.
Reveal answer details
Close answer details
Question 9
Multiple choice
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple small-sized packets to the target computer. Hence, it becomes very difficult for an IDS to detect the attack signatures of such attacks. Which of the following tools can be used to perform session splicing attacks? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 10
Single choice
What is the order of the extension headers that is followed by IPv6?
-
A
Destination Options (first), Routing, IPv6 header, Hop-by-Hop, Fragment, Authentication, Encrypted Security Payload, Destination Options (second), followed by an Upper-layer header, indicating payload.
-
B
Routing, Hop-by-Hop, Destination Options (first), Fragment, Authentication, Encrypted Security Payload, Destination Options (second), followed by an Upper-layer header, indicating payload.
-
C
Fragment, Routing, Hop-by-Hop, Destination Options (first), Authentication, Encrypted Security Payload, Destination Options (second), followed by an Upper-layer header, indicating payload.
-
D
IPv6 header, Hop-by-Hop, Destination Options (first), Routing, Fragment, Authentication, Encrypted Security Payload, Destination Options (second), followed by an Upper-layer header, indicating payload.
Reveal answer details
Close answer details
Question 11
Single choice
You work as a Network Administrator for McRobert Inc. You want to know the NetBIOS name of your computer. Which of the following commands will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 12
Single choice
Which of the following terms is used to represent IPv6 addresses?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
What is the size of a subnet in IPv6?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following Web attacks is performed by manipulating codes of programming languages such as SQL, Perl, Java present in the Web pages?
-
A
-
B
-
C
Cross-Site Request Forgery
-
D
Cross-Site Scripting attack
Reveal answer details
Close answer details
Question 15
Single choice
Which of the following is an asymmetric encryption algorithm?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Victor works as a professional Ethical Hacker for SecureEnet Inc. He has been assigned a job to test an image, in which some secret information is hidden, using Steganography. Victor performs the following techniques to accomplish the task: 1. Smoothening and decreasing contrast by averaging the pixels of the area where significant color transitions occurs. 2. Reducing noise by adjusting color and averaging pixel value. 3. Sharpening, Rotating, Resampling, and Softening the image. Which of the following Steganography attacks is Victor using?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Which of the following is the default port for File Transport Protocol (FTP)?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 18
Multiple choice
You are using the TRACERT utility to trace the route to passguide.com. You receive the following output: Which of the following conclusions can you draw from viewing the output? Each correct answer represents a complete solution. Choose two.
-
A
-
B
One of the routers on the path to the destination is not functional.
-
C
The destination computer is not operational.
-
D
The IP address of the destination computer is not resolved.
Reveal answer details
Close answer details
Question 19
Single choice
Which of the following is a hardware/software platform that is designed to analyze, detect, and report on security related events. NIPS is designed to inspect traffic and based on its configuration or security policy, it can drop the malicious traffic?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Which of the following ports can be used for IP spoofing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Multiple choice
Victor works as a network administrator for DataSecu Inc. He uses a dual firewall Demilitarized Zone (DMZ) to insulate the rest of the network from the portions that is available to the Internet. Which of the following security threats may occur if DMZ protocol attacks are performed? Each correct answer represents a complete solution. Choose all that apply.
-
A
Attacker can perform Zero Day attack by delivering a malicious payload that is not a part of the intrusion detection/prevention systems guarding the network.
-
B
Attacker can gain access to the Web server in a DMZ and exploit the database.
-
C
Attacker managing to break the first firewall defense can access the internal network without breaking the second firewall if it is different.
-
D
Attacker can exploit any protocol used to go into the internal network or intranet of the com pany
Reveal answer details
Close answer details
Question 22
Multiple choice
Which of the following statements are true about snort? Each correct answer represents a complete solution. Choose all that apply.
-
A
It develops a new signature to find vulnerabilities.
-
B
It detects and alerts a computer user when it finds threats such as buffer overflows, stealth port scans, CGI attacks, SMB probes and NetBIOS queries, NMAP and other port scanners, well-known backdoors and system vulnerabilities, and DDoS clients.
-
C
It encrypts the log file using the 256 bit AES encryption scheme algorithm.
-
D
It is used as a passive trap to record the presence of traffic that should not be found on a network, such as NFS or Napster connections.
Reveal answer details
Close answer details
Question 23
Single choice
Which of the following ICMPv6 neighbor discovery messages is sent by hosts to request an immediate router advertisement, instead of waiting for the next scheduled advertisement?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 24
Single choice
Which of the following ports is used by e-mail clients to send request to connect to the server?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Which of the following monitors program activities and modifies malicious activities on a system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
Which of the following is used over the Internet for better security?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
________ is a command-line tool that can check the DNS registration of a domain controller.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Multiple choice
Which of the following are open-source vulnerability scanners?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 29
Single choice
Which of the following commands prints out the headers of packets regarding the boolean expression?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
Which of the following Linux/UNIX commands is used to delete files permanently so that the files cannot be recovered?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Fill in the blank
Fill in the blank with the appropriate term. ___________is the practice of monitoring and potentially restricting the flow of information outbound from one network to another
Reveal answer details
Close answer details
Accepted answerEGRESSFILTERING
Question 32
Single choice
Adam, a malicious hacker is running a scan. Statistics of the scan is as follows:  Which of the following types of port scan is Adam running?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Multiple choice
Which of the following tools allows an attacker to intentionally craft the packets to gain unauthorized access? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 34
Single choice
You work as a Network Administrator for Tech Perfect Inc. Your company has a Windows 2000- based network. You want to verify the connectivity of a host in the network. Which of the following utilities will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 35
Single choice
What is the process of detecting unauthorized access known as?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Multiple choice
Adam works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate computer of an unfaithful employee of SecureEnet Inc. Suspect's computer runs on Windows operating system. Which of the following sources will Adam investigate on a Windows host to collect the electronic evidences? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Unused and hidden partition
Reveal answer details
Close answer details
Question 37
Single choice
Which of the following forensic tool suite is developed for Linux operating system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 38
Single choice
Which of the following is a hardware/software platform that is designed to analyze, detect, and report on security related events. NIPS is designed to inspect traffic and based on its configuration or security policy, it can drop the malicious traffic?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 39
Single choice
In which of the following IDS evasion attacks does an attacker send a data packet such that IDS accepts the data packet but the host computer rejects it?
-
A
Fragmentation overlap attack
-
B
-
C
Fragmentation overwrite attack
-
D
Reveal answer details
Close answer details
Question 40
Single choice
Which of the following types of write blocker device uses one interface for one side and a different one for the other?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 41
Single choice
Which of the following wireless network standards operates on the 5 GHz band and transfers data at a rate of 54 Mbps?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 42
Single choice
Which of the following fields of the IPv6 header is similar to the TTL field of IPv4?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 43
Single choice
Which of the following is the purpose of creating a Demilitarized zone (DMZ) in an enterprise network?
-
A
-
B
Creating Autonomous Systems
-
C
-
D
Reveal answer details
Close answer details
Question 44
Multiple choice
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple smallsized packets to the target computer. Hence, it becomes very difficult for an IDS to detect the attack signatures of such attacks. Which of the following tools can be used to perform session splicing attacks? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 45
Single choice
You work as a Network Administrator for SmartCert Inc. The company's network contains five Windows 2003 servers and ninety Windows XP Professional client computers. You want to view all the incoming requests to an Internet Information Services (IIS) server and allow only requests that comply with a rule set, created by you, to be processed. You also want to detect the intrusion attempts by recognizing the strange characters in a URL on a Web server. What will you do to accomplish the task?
-
A
Use the Remote Desktop Protocol (RDP).
-
B
Use the HFNETCHK utility.
-
C
-
D
Configure a connection to the SQL database by using the RELOG command-line utility.
Reveal answer details
Close answer details
Question 46
Single choice
You work as a professional Computer Hacking Forensic Investigator. A project has been assigned to you to investigate Plagiarism occurred in the source code files of C#. Which of the following tools will you use to detect the software plagiarism?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 47
Single choice
John works as a professional Ethical Hacker. He has been assigned a project to test the security of www.we-are-secure.com. John wants to redirect all TCP port 80 traffic to UDP port 40, so that he can bypass the firewall of the We-are-secure server. Which of the following tools will John use to accomplish his task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 48
Single choice
Which of the following IP packet elements is responsible for authentication while using IPSec?
-
A
Authentication Header (AH)
-
B
Layer 2 Tunneling Protocol (L2TP)
-
C
Internet Key Exchange (IKE)
-
D
Encapsulating Security Payload (ESP)
Reveal answer details
Close answer details
Question 49
Single choice
Which of the following tools can be used for passive OS fingerprinting?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 50
Single choice
In which of the following IDS evasion techniques does an attacker deliver data in multiple small sized packets, which makes it very difficult for an IDS to detect the attack signatures of such attacks?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 51
Single choice
Which of the following honeypots is a low-interaction honeypot and is used by companies or corporations for capturing limited information about malicious hackers?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 52
Multiple choice
You work as a Network Administrator for Tech Perfect Inc. The company has a TCP/IP-based network. You have configured a firewall on the network. A filter has been applied to block all the ports. You want to enable sending and receiving of emails on the network. Which of the following ports will you open? Each correct answer represents a complete solution. Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 53
Single choice
Ryan, a malicious hacker submits Cross-Site Scripting (XSS) exploit code to the Website of Internet forum for online discussion. When a user visits the infected Web page, code gets automatically executed and Ryan can easily perform acts like account hijacking, history theft etc. Which of the following types of Cross- Site Scripting attack Ryan intends to do?
-
A
-
B
-
C
-
D
Document Object Model (DOM)
Reveal answer details
Close answer details
Question 54
Single choice
Which of the following ports can be used for IP spoofing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 55
Single choice
You work as a Network Administrator for Net Perfect Inc. The company has a Windows Server 2008 network environment. The servers on the network run Windows Server 2008 R2. All client computers on the network run Windows 7 Ultimate. You have configured DirectAccess feature on the laptop of few sales managers so that they can access corporate network from remote locations. Their laptops run Windows 7 Ultimate. Which of the following options does the DirectAccess use to keep data safer while traveling through travels public networks?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 56
Single choice
Which of the following ports is used by e-mail clients to send request to connect to the server?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 57
Single choice
Which of the following ports is used by NTP for communication?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 58
Single choice
Which of the following protocols is used to translate IP addresses to Ethernet addresses?
-
A
Border Gateway Protocol (BGP)
-
B
Routing Information Protocol (RIP)
-
C
Address Resolution Protocol (ARP)
-
D
Internet Control Message Protocol (ICMP)
Reveal answer details
Close answer details
Question 59
Single choice
Which of the following DNS resource records is used to resolve a host name to an IPv6 address?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 60
Single choice
You work as a technician for Tech Perfect Inc. You are troubleshooting an Internet name resolution issue. You ping your ISP's DNS server address and find that the server is down. You want to continuously ping the DNS address until you have stopped the command. Which of the following commands will you use?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 61
Multiple choice
Which of the following is included in a memory dump file?
-
A
-
B
-
C
Stop message and its parameters
-
D
The kernel-mode call stack for the thread that stopped the process from execution
Reveal answer details
Close answer details
Question 62
Single choice
Which of the following IPv6 transition technologies is used by the DirectAccess if a user is in a remote location and a public IPv4 address, instead of public IPv6 address, has been assigned to the computer?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 63
Single choice
Allen works as a professional Computer Hacking Forensic Investigator. A project has been assigned to him to investigate a computer, which is used by the suspect to sexually harass the victim using instant messenger program. Suspect's computer runs on Windows operating system. Allen wants to recover password from instant messenger program, which suspect is using, to collect the evidence of the crime. Allen is using Helix Live for this purpose. Which of the following utilities of Helix will he use to accomplish the task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 64
Single choice
Maria works as the Chief Security Officer for passguide Inc. She wants to send secret messages to the CEO of the company. To secure these messages, she uses a technique of hiding a secret message within an ordinary message. The technique provides 'security through obscurity'. What technique is Maria using?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 65
Single choice
You work as a Network Administrator for TechPerfect Inc. The company has a corporate intranet setup. A router is configured on your network to connect outside hosts to the internetworking. For security, you want to prevent outside hosts from pinging to the hosts on the internetwork. Which of the following steps will you take to accomplish the task?
-
A
Block the ICMP protocol through ACL.
-
B
Block the IPv6 protocol through ACL.
-
C
Block the UDP protocol through ACL.
-
D
Block the TCP protocol through ACL.
Reveal answer details
Close answer details
Question 66
Single choice
Which of the following techniques allows probing firewall rule-sets and finding entry points into the targeted system or network?
-
A
-
B
-
C
Distributed Checksum Clearinghouse
-
D
Reveal answer details
Close answer details
Question 67
Single choice
Which of the following is the default port for DNS zone transfer?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 68
Multiple choice
Which of the following work as traffic monitoring tools in the Linux operating system? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 69
Single choice
John works as a Network Administrator for DigiNet Inc. He wants to investigate failed logon attempts to a network. He uses Log Parser to detail out the failed logons over a specific time frame. He uses the following commands and query to list all failed logons on a specific date: logparser.exe file:FailedLogons.sql -i:EVT -o:datagrid SELECT timegenerated AS LogonTime, extract_token(strings, 0, '|') AS UserName FROM Security WHERE EventID IN (529; 530; 531; 532; 533; 534; 535; 537; 539. AND to_string(timegenerated,'yyyy-MM-dd HH:mm:ss') like '2004-09%' After investigation, John concludes that two logon attempts were made by using an expired account. Which of the following EventID refers to this failed logon?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 70
Single choice
Which of the following is not a valid Failed Logon EventID?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 71
Single choice
Maria works as a professional Ethical Hacker. She is assigned a project to test the security of www.we-are-secure.com. She wants to test a DoS attack on the We-are-secure server. She finds that the firewall of the server is blocking the ICMP messages, but it is not checking the UDP packets. Therefore, she sends a large amount of UDP echo request traffic to the IP broadcast addresses. These UDP requests have a spoofed source address of the We-are-secure server. Which of the following DoS attacks is Maria using to accomplish her task?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 72
Single choice
What is the easiest way to verify that name resolution is functioning properly on a TCP/IP network?
-
A
Use the TRACERT command with the /pingname parameter.
-
B
Ping the source host with its computer name.
-
C
Ping the source host with its IP address.
-
D
Check the IP statistics on the file server.
Reveal answer details
Close answer details
Question 73
Single choice
Which of the following snort keywords is used to match a defined payload value?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 74
Multiple choice
Host-based IDS (HIDS) is an Intrusion Detection System that runs on the system to be monitored. HIDS monitors only the data that it is directed to, or originates from the system on which HIDS is installed. Besides monitoring network traffic for detecting attacks, it can also monitor other parameters of the system such as running processes, file system access and integrity, and user logins for identifying malicious activities. Which of the following tools are examples of HIDS? Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 75
Single choice
What is the name of the first computer virus that infected the boot sector of the MS-DOS operating system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 76
Multiple choice
For a host to have successful Internet communication, which of the following network protocols are required? You should assume that the users will not manually configure the computer in anyway and that the measure of success will be whether the user can access Web sites after powering the computer and logging on. Each correct answer represents a complete solution. Choose all that apply.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
|