Nathalie,an employee of Corporation XYZ, has notice that Bob,one of her coworkers,has been abusing company assets and resources for his own personal gain. According to good ethics values,what should Nathalie do in this case?
-
A
Immediately install a network sniffer and keystroke recorder to monitor Bobs activities.
-
B
Retaliate by abusing Bobs resources; he does it to the company,hence why not do it against Bob himself.
-
C
Report Bob to upper management where a decision about a course of action can be made along with the HR and Legal department.
-
D
Nathalie should not get involved;this is none of her business. she should simply continue her work day and wait unit he gets caught.
Reveal answer details
Close answer details
Having just downloaded a new version of Cain & Abel,you wish to monitor your network for clear text passwords being sent. Knowing you are currently connected to a switch you will attempt to perform an ARP poisoning attack that will let you look at all the packets and not only packets sent to your own machine. What would you call this type of sniffing?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
This technique consists of using social to trick someone into revealing information they should not usually release to unathorized users. What do we call this technique or type of attack?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which tools and or techniques can be used to remove an Alternative Data Stream on an NTFS file? Choose two.
-
A
-
B
-
C
-
D
Copy the NTFS file containing the stream to a FAT partition,delete the original TFS file,copy the FAT file back to NTFS
Reveal answer details
Close answer details
There is a method which allows you to find information on hosts located behind a firewall by using packets similar to the packets used by Traceroute. This method attempts to find out what are the rules in place on the gateway. What is the name of this method?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 6
Multiple choice
Why are SYN port scans not as stealthy as what they originally were several years ago?Choose two.
-
A
Many firewall rulesets detect and block SYN scans
-
B
IDS systems look for SYN flag packets due to the proliferation of SYN flood-based denial of service attacks
-
C
RFC 3502 has redefined the TCP three-way handshake thus changing how SYN flags are used
-
D
The Internet backtone routers all block SYN flag packets according to new RFC 3705
Reveal answer details
Close answer details
Question 7
Multiple choice
Which of the following ports are used by the Simple Network Management Protocol? (Choose two)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which of the following would best represent the definition of a Penetration Test?
-
A
Testing of the effectiveness of applied security controls by breaking in and bypassing them.
-
B
Testing of the policies in place to see how compliant a company is with its own control definition.
-
C
Testing the effectiveness of applied security controls by evaluating vulnerabilities and reporting them to the client.
-
D
Testing the effectiveness of access control mechanisms by constant and deep inspection of all log files.Also called Deep Packet Inspection.
Reveal answer details
Close answer details
Why is it often recommended to rename the built-in Administrator account on a Windows 2000 domain? Choose the best answer.
-
A
Renaming the Guest account is of little value.
-
B
If you dont rename the Administrator account you will have NetBIOS name conflicts with the Administrator account from other domains in the forest.
-
C
Account lockout will not stop password guessing attacks via SMB filesharing or BASIC web authentication against the built-in Administrator account .
-
D
The default domain policy actually requires the Administrator account to be renamed.
Reveal answer details
Close answer details
Question 10
Multiple choice
Which Vulnerability Assessment tools perform dangerous/destructive scans.Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
From the items listed below,which would be expected from a cracker or hacker but NOT from an Ethical Hacker or Certified Penetration tester?
-
A
-
B
-
C
Disregard for potential losses
-
D
Presentation of a detailed report
Reveal answer details
Close answer details
Question 12
Multiple choice
What are some of the weaknesses that make LAN Manager Hashes much easier to crack by an attacker? (Select all that apply)
-
A
The 14 character password is split in two
-
B
The password is converted to Uppercase
-
C
The hash value is encrypted using MD5
-
D
The hash value is encrypted with AES
Reveal answer details
Close answer details
Question 13
Single choice
An attacker is sending packets with no flag set.This is also known as doing a NULL scan.Usually,operating system networking stacks will respond with a RST packe,however,some operating systems do not conform to this behavior and respond in appropriately. Such behavior could allow for the identification of the remote OS being used.Which of the following would be one of the Operating systems that responds differently?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Which of the following would best describe a scanning technique that is the most reliable but also the most noticeable on the target is being evaluated?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Single choice
Which of the following resource records would you inspect to find out how long a cache poisoning attack might be effective against a remote DNS server?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 16
Single choice
Looking at the graphic below,determine what web site was visited by the user located at IP address 192.168.1.104?
-
A
-
B
-
C
-
D
This sniffer capture is not from a web page request
Reveal answer details
Close answer details
Question 17
Single choice
Under the Windows platform,there is something refered to as Null Session. Which of the following statements would best describe what a null session consists of?
-
A
It is a session where zero bytes of traffic have been transferred
-
B
It is a session where erroneous commands are being used showing the a lack of knowledge of the user connected.
-
C
It is a remote session that is established anonymously to a window machine
-
D
It is a anonymous FTP session under the Windows platform
Reveal answer details
Close answer details
Question 18
Single choice
Bryce, who is a great security professional with a perfect track record,has just been called into his supervisor's office. His supervisor has the sad task of letting him know that hes the next position being cut in their downsizing effort.Bryce has been known to be a mellow type of person but the version of being unemployed after working for 25 years at the same company is just a bit too much for him.He cannot understand why newer employees with only a few years of experience have not been fired before him and why he is the one that must leave.Bryce tells himself that is employer is going to pay dearly for this and hes planning to use his skills to cause disruption within the company infrastructure. Which of the following term would best describe the reaction of Bryce?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 19
Single choice
When talking about databases search query languages,commands such as Select,Update,Insert,Grant,and Revoke would all the part of what language?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 20
Single choice
Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some of his external IP addresses. At first it looked like normal daily traffic but somehow it seems that after his internet facing hosts sends a SYN/ACK reply back to the connection request,the final ACK packet is never received from the remote host. What type of scan does this pattern indicate?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 21
Single choice
When referring to database,what would you call the number of rows within a table?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 22
Multiple choice
The SNMP protocol makes use of community sring to control access.There are two community strings being used; each of these strings allow you to perform only specific functions within the system being managed by SNMP.which of the following would represent the functions allowed by the two strings? Choose two)
-
A
Public Gives public access to anyone to reconfigure the device
-
B
Secret Gives read only access to the remote device being managed
-
C
Public Gives read only access to the remote device being managed
-
D
Private Gives read and write access to the remote device being managed
Reveal answer details
Close answer details
Question 23
Multiple choice
How does a system administrator prevent Idp.exe and user2sid.exe tools from retrieving domain usernames,SIDs,and other information from a Windows 2000 Domain Controller if no username and password are supplied?Choose two.
-
A
Add the Everyone group to the Pre-Windows 2000 Compatible Access group
-
B
Remove the Everyone group from the Pre-Windows 2000 Compatible Access group
-
C
set RestrictAnonymous registry key to two
-
D
Set RestrictAnonymous registry key to zero
Reveal answer details
Close answer details
Question 24
Multiple choice
DNS Spoofing can allow an attacker to sniff traffic that is meant to go to particular web sites. Which of the following tools can perform DNS Spoofing?Choose two.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
Password attack fall within two main categories:Social Attacks and Digital Attacks. Which of the following would not be considered a Social Attack on passwords?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Multiple choice
Which of these methods would be considered examples of active reconnaissance?(Choose three.)
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
Clement is someone who greatly enjoys fishing. Clement recently visited a web site that is very proactive in its attempt to save marine life. While on the site he downloaded a disobedience kit where his free CPU cycle can help contribute to the noble cause of saving the rainbow trout from extinction. Which of the following terms best describes Clementss activity?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
Which of the following statements would be TRUE when referring to Stream cliphers?
-
A
Stream Ciphers encrypt one digit at a time
-
B
Stream Ciphers divide the plaintext message into fixed group of bit and then encrpt these group of bits
-
C
Stream Ciphers are NOT very commonly used
-
D
Stream Ciphers can be implemented only in software
Reveal answer details
Close answer details
Question 29
Single choice
This document is a high level document that describes management intentions towards security. What is the name of the document?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
Name Servers are the Penetration Testers best friend.The Domain Name Registration database contains information about who registered a particular domain.What common command line as well as web based tool could be used to extract this information from the public database of Domain Name registration.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
When referring to databases,what would you call the number of rows within a table?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 32
Single choice
What software can alert an administrator to modified files (system or otherwise) by comparing new the hash to the hash on the original trusted file?Choose all that apply.NOTE:The term Choose all that apply in this and additional questions does not necessarily mean that there is more than one answer.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Multiple choice
Why are SYN port scans not as stealthy as what they originally were several years ago?Choose two.
-
A
Many firewall rulesets detect and block SYN scans
-
B
IDS systems look for SYN flag packets due to the proliferation of SYN flood-based denial of service attacks
-
C
RFC 3502 has redefined the TCP three-way handshake thus changing how SYN flags are used
-
D
The Internet-backbone routers all block SYN flag packets according to new RFC 3705
Reveal answer details
Close answer details
Question 34
Single choice
As you have learned in your Penetration Testing training or field experience,WEP is the encryption that was used with early WLAN implementation.it uses a stream cipher called RC4 to produce a string of bith that will be exclusive OR or XOR with the plain text to form the cliphertext.Which of the following statements represents the rules associated with XOR binary mathematics or comparison? Choose the best answer.
-
A
If both bits are different the result will be one,if both bits are the same the result will be a zero.
-
B
If both bits are different the result will be zero,if both bits are the same the result will be a one.
-
C
Only when both bits have a value of one,will the result be one.
-
D
Only when both bits have a value of zero,will the result be one.
Reveal answer details
Close answer details
Question 35
Single choice
What Windows techonology should prevent SMB Relay from sniffing user credentials in a man in the middle attack?Choose the best answer.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 36
Single choice
Nmap is the leading port scanner for security testing and penetration testing. As a tester it is a must have within your toolbox and you MUST be familiar with its basic syntax. Which of the following command lines would represent a Ping Sweep being performed using Nmap.
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 37
Single choice
One of the challenges when doing large scale security tests is the time required. If you have to scan a class B network it might take you a very long time. Scanrand is a tool that has been optimized to scan a large number of hosts in very little time.It was reported that it was used to scan about 8300 web servers in less than 4 seconds. How does scanrand achieve such an impressive benchmark?
-
A
It does not maintain any state
-
B
It makes use of multiple Network Interface Cards (NIC)
-
C
It has a probabilistic algorithm that can predict if a port is open or not
-
D
It does not attempt to use UDP due to the overhead involved
Reveal answer details
Close answer details
Question 38
Single choice
Which of the following would best describe the meaning of steganography?
-
A
The art and science of hiding information by embedding messages within other,seemingly harmless messages
-
B
The art and science of hiding information by encrypting it with a symmetric cipher where the key will be used only once
-
C
The art and science of hiding information by encrypting it using a public key encryption system where the key pair will be used only once
-
D
The art and science of hiding information by embedding redundant data within the primary data and then using XOR against the stream
Reveal answer details
Close answer details
|