Which of the following scan types would be the least accurate scan considering that may other network conditions could indicate that the port is open even though it might not be open?
Reveal answer details Close answer details
Correct answerB
Mile2 · ML0-320
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which of the following scan types would be the least accurate scan considering that may other network conditions could indicate that the port is open even though it might not be open? Reveal answer details Close answer detailsCorrect answerB
Single choice
If the DS Client software has been installed on Windows 95,Windows 98,and NT 4 comptuers,what setting of the LanMan Authentication level should be applied to counteract LanMan hash sniffing and offline cracking? Choose the best Answer:. Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following password and encyption cracking methods is guaranteed to successfully crack any password or encryption algorithm? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
What are some of the weaknesses that make LAN Manager Hashes much easier to crak by an attacker? (Select all that apply.) Reveal answer details Close answer detailsCorrect answersA, B
Multiple choice
Why wouldn't it be surprising to find netcat on a trojaned-computer?Choose three. Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Which tool speeds up offline password cracking by precomputing tables of password hashes?Choose the best Answer:. Reveal answer details Close answer detailsCorrect answerC
Single choice
Most search engine support Advanced Search Operators; as a Penetrtion Tester you must be familiar with some of the larger search engines such as Geogle.There is a wealth of information to be gathered from these public databases. Which of the following operators would you use if you attempt to find an older copy of a website that might have information which is no longer available on the target website? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
Which of the following are reasons why LAN Manager hashes stored in the SAM file are considered relatively easy to crack?Choose two. Reveal answer details Close answer detailsCorrect answersB, C
Single choice
Julius has been hired to perform a test on Certkiller .com networks. Julius knows that Certkiller .com has a large team of security administrators who are very proactive in their security approach. Which of the following would be the most practical solution and the easiest to implement? Reveal answer details Close answer detailsCorrect answerD
Single choice
Bob is doing a penetration test. How could Bob succeed in getting a copy of the SAM database if it locked while the system is up and running? Reveal answer details Close answer detailsCorrect answerC
Single choice
On Wireless networks, what is the Service Set Identify used for? Reveal answer details Close answer detailsCorrect answerC
Single choice
This technique consists of using social to trick someone into revealing information they should not usually release to unathorized users. What do we call this technique or type of attack? Reveal answer details Close answer detailsCorrect answerC
Single choice
Having just downloaded a new version of Cain & Abel,you wish to monitor your network for clear text passwords being sent. What would you call this type of sniffing? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following password implementation is found only in Windows 2000 and newer Windows versions? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Keystroke loggers can be found in which of the following forms?Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, D
Single choice
Which of the following SQL scripts will discover the usernames and hashed passwords from a MSSQL server? Reveal answer details Close answer detailsCorrect answerC
Single choice
Clement is someone who greatly enjoys fishing. Which of the following terms best describes Clementss activity? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Spyware is either hardware or software installed on a computer which gather information about the user for later retrieval by whoever controls the Spyware. What are the two ctegories of Spyware that exist? (Choose two from the list below) Reveal answer details Close answer detailsCorrect answersA, D
Multiple choice
What technologies could a company deploy to protect all data passing from an employees home computer to the corporate intranet?Choose two. Reveal answer details Close answer detailsCorrect answersA, B
Single choice
What technology has made trojans easy to distribute?Choose the best Answer:. Reveal answer details Close answer detailsCorrect answerC
Multiple choice
How does a system administrator prevent Idp.exe and user2sid.exe tools from retrieving domain usernames,SIDs,and other information from a Windows 2000 Domain Controller if no username and password are supplied?Choose two. Reveal answer details Close answer detailsCorrect answersB, C
Single choice
Nathalie has just received a message from her boyfriend,Clement,who is telling her about this severe Popoute virus that none of the virus companies have been able to stop. In the same message Clement is asking her to pass the message along to anyone she can in order to ensure they will protect themselves before infection.After validating with her IT department it becomes obvious that there was no virus named Popoute that ever existed and that resources have been wasted by the large amount of emails that were sent and time wasted. What would you call such activities? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following statements would best describe the act of signing a message with a Digital Signature? Reveal answer details Close answer detailsCorrect answerA
Single choice
After completing your reconnaissance and scanning,which of the following would be the next logical step performed bye the Pen Tester? Reveal answer details Close answer detailsCorrect answerB
Single choice
Pen testing is another area of security where acronyms and expressions abound. What does the term rooting refers to? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following might be used to give false positives when a UDP scan is being performed against a DMZ server running DNS? Choose the best Answer:. Reveal answer details Close answer detailsCorrect answerD
Single choice
Cracking encryption is often impossible due to time constraints whereby it would take hundreds of years in some cases. Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the most secure method of implementing Software Restriction Policies to prevent users from running both unauthorized and undesirable software?Choose the best Answer:. Reveal answer details Close answer detailsCorrect answerD
Single choice
Bob is working as an Instrusion Detection System administrator for a company called CCCure. What type of scan does this pattern indicate? Reveal answer details Close answer detailsCorrect answerC
Single choice
In symmetric cryptosystem,how many keys are needed to communicate securely between 10 different people who all wish to have a key pair to talk to each other? Reveal answer details Close answer detailsCorrect answerC
Single choice
Looking at the SOA records presented below,for how long will the secondary DNS servers attempt to contact the primary DNS server before a zone be considered dead. Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which of the following actions can often be used as countermeasures to port scans?Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, C, D
Single choice
Which of the following penetration framework is Open Source and offers features that are similar to some of its rival commercial tools? Reveal answer details Close answer detailsCorrect answerC
Single choice
How would you call a malware that is set to trigger at a specific date,or sometime in the future? Reveal answer details Close answer detailsCorrect answerC
Single choice
You have collected a series of messages that are all encrypted. You do not have access to the matching plaintext nor do you have any idea of the key and algorithm that were used to encrypt those messages.You will attempt a crypto attack in order to find the key. How would you call such an attack? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
When doing an ACK flag scanning the target host is sent TCP packets with the ACK flag set and the reply is then analyzed. Which of the following items within the response packets would be used to determine if the port was open on the remote host?(Choose two) Reveal answer details Close answer detailsCorrect answersA, D
Single choice
Johnny has just installed a small utility to calculate subnet masks. After installing this utility he was pormpted by his firewall to accept a connection outbound to a server he was not familiar with. What type of malware was he a victim of? Reveal answer details Close answer detailsCorrect answerC |