Which of the following reads and writes data across network connections by using the TCP/IP protocol?
Reveal answer details Close answer details
Correct answerC
SANS · SEC504
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which of the following reads and writes data across network connections by using the TCP/IP protocol? Reveal answer details Close answer detailsCorrect answerC
Single choice
Adam works as a Security Administrator for Umbrella Inc. A project has been assigned to him to test the network security of the company. He created a webpage to discuss the progress of the tests with employees who were interested in following the test. Visitors were allowed to click on a company's icon to mark the progress of the test. Adam successfully embeds a keylogger. He also added some statistics on the webpage. The firewall protects the network well and allows strict Internet access. How was security compromised and how did the firewall respond? Reveal answer details Close answer detailsCorrect answerA
Single choice
John works as a professional Ethical Hacker. He is assigned a project to test the security of www.weare-secure.com. He enters a single quote in the input field of the login page of the We-are-secure Web site and receives the following error message: Microsoft OLE DB Provider for ODBC Drivers error '0x80040E14' This error message shows that the We-are-secure Website is vulnerable to __________. Reveal answer details Close answer detailsCorrect answerC
Single choice
You want to use PGP files for steganography. Which of the following tools will you use to accomplish the task? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are concerned about rootkits on your network communicating with attackers outside your network. Reveal answer details Close answer detailsCorrect answerC
Single choice
Adam, a malicious hacker is running a scan. Statistics of the scan is as follows: Scan directed at open port: ClientServer 192.5.2.92:4079 ---------FIN--------->192.5.2.110:23192.5.2.92:4079 <----NO RESPONSE--- ---192.5.2.110:23 Scan directed at closed port: ClientServer 192.5.2.92:4079 ---------FIN--------->192.5.2.110:23 192.5.2.92:4079<-----RST/ACK----------192.5.2.110:23 Which of the following types of port scan is Adam running? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which of the following hacking tools provides shell access over ICMP? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following tools is an automated tool that is used to implement SQL injections and to retrieve data from Web server databases? Reveal answer details Close answer detailsCorrect answerB
Single choice
Maria works as the Chief Security Officer for PassGuide Inc. She wants to send secret messages to the CEO of the company. To secure these messages, she uses a technique of hiding a secret message within an ordinary message. The technique provides 'security through obscurity'. What technique is Maria using? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Which of the following are the automated tools that are used to perform penetration testing? Each correct answer represents a complete solution. Choose two. Reveal answer details Close answer detailsCorrect answersB, D
Single choice
You run the following bash script in Linux: for i in 'cat hostlist.txt' ;do nc -q 2 -v $i 80 < request.txt done Where, hostlist.txt file contains the list of IP addresses and request.txt is the output file. Which of the following tasks do you want to perform by running this script? Reveal answer details Close answer detailsCorrect answerB
Single choice
What is the major difference between a worm and a Trojan horse? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
Which of the following statements are true about a keylogger? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
Which of the following types of rootkits replaces regular application binaries with Trojan fakes and modifies the behavior of existing applications using hooks, patches, or injected code? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following tools can be used to detect the steganography? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following actions is performed by the netcat command given below? nc 55555 < /etc/passwd Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which of the following Linux rootkits allows an attacker to hide files, processes, and network connections? Reveal answer details Close answer detailsCorrect answersC, D
Multiple choice
Which of the following functions can you use to mitigate a command injection attack? Each correct answer represents a part of the solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B
Single choice
Which of the following attacks can be overcome by applying cryptography? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following options scans the networks for vulnerabilities regarding the security of a network? Reveal answer details Close answer detailsCorrect answerC
Multiple choice
You want to add a netbus Trojan in the chess.exe game program so that you can gain remote access to a friend's computer. Which of the following tools will you use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersB, C
Multiple choice
Which of the following tools are used as a network traffic monitoring tool in the Linux operating system? Reveal answer details Close answer detailsCorrect answersB, C, D
Multiple choice
Andrew, a bachelor student of Faulkner University, creates a gmail account. He uses 'Faulkner' as the password for the gmail account. After a few days, he starts receiving a lot of e-mails stating that his gmail account has been hacked. He also finds that some of his important mails have been deleted by someone. Which of the following methods has the attacker used to crack Andrew's password? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersC, D, F, G, H
Multiple choice
Which of the following functions in c/c++ can be the cause of buffer overflow? Each correct answer represents a complete solution. Choose two. Reveal answer details Close answer detailsCorrect answersB, C
Single choice
Which of the following tools is used to attack the Digital Watermarking? Reveal answer details Close answer detailsCorrect answerB
Single choice
John, a part-time hacker, has accessed in unauthorized way to the www.yourbank.com banking Website and stolen the bank account information of its users and their credit card numbers by using the SQL injection attack. Now, John wants to sell this information to malicious person Mark and make a deal to get a good amount of money. Since, he does not want to send the hacked information in the clear text format Which of the following tools is John using for steganography? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is the process of comparing cryptographic hash functions of system executables and configuration files? Reveal answer details Close answer detailsCorrect answerB
Fill in the blank
Fill in the blank with the appropriate name of the tool. ______ scans for rootkits by comparing SHA-1 hashes of important files with known good ones in online database. A. rkhunter Reveal answer details Close answer detailsAccepted answerA
Single choice
Adam, a malicious hacker purposely sends fragmented ICMP packets to a remote target. The total size of this ICMP packet once reconstructed is over 65,536 bytes. Reveal answer details Close answer detailsCorrect answerB
Single choice
You work as a Security Administrator for Net Perfect Inc. The company has a Windows-based network. Which of the following scanning techniques can you use to accomplish the task? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following types of scan does not open a full TCP connection? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following scanning tools is also a network analysis tool that sends packets with nontraditional IP stack parameters and allows the scanner to gather information from the response packets generated? Reveal answer details Close answer detailsCorrect answerD
Single choice
You are monitoring your network's behavior. You find a sudden increase in traffic on the network. It seems to come in bursts and emanate from one specific machine. You have been able to determine that a user of that machine is unaware of the activity and lacks the computer knowledge required to be responsible for a computer attack. What attack might this indicate? Reveal answer details Close answer detailsCorrect answerA
Single choice
Adam, a malicious hacker, wants to perform a reliable scan against a remote target. He is not concerned about being stealth at this point. Which of the following type of scans would be most accurate and reliable? Reveal answer details Close answer detailsCorrect answerB
Single choice
Adam works as a Security Analyst for Umbrella Inc. Company has a Windows-based network. All computers run on Windows XP. Manager of the Sales department complains Adam about the unusual behavior of his computer. He told Adam that some pornographic contents are suddenly appeared on his computer overnight. Adam suspects that some malicious software or Trojans have been installed on the computer. He runs some diagnostics programs and Port scanners and found that the Port 12345, 12346, and 20034 are open. Adam also noticed some tampering with the Windows registry, which causes one application to run every time when Windows start. Which of the following is the most likely reason behind this issue? Reveal answer details Close answer detailsCorrect answerC
Single choice
Who are the primary victims of smurf attacks on the contemporary Internet system? Reveal answer details Close answer detailsCorrect answerA
Multiple choice
Which of the following are the limitations for the cross site request forgery (CSRF) attack? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B
Single choice
Your IDS discovers that an intruder has gained access to your system. You immediately stop that access, change passwords for administrative accounts, and secure your network. You discover an odd account (not administrative) that has permission to remotely access the network. What is this most likely? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following Trojans is used by attackers to modify the Web browser settings? Reveal answer details Close answer detailsCorrect answerA
Single choice
John works as a Penetration Tester in a security service providing firm named you-are-secure Inc. <script>alert('Hi, John')</script>After pressing the search button, a pop-up box appears on his screen with the text - "Hi, John." Which of the following attacks can be performed on the Web site tested by john while considering the above scenario? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
You work as a Network Administrator for Net Perfect Inc. The company has a Windows-based network. Which of the following vulnerabilities can be fixed using Nessus? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, C
Single choice
You want to create an SSH tunnel for POP and SMTP protocols. Which of the following commands will you run? Reveal answer details Close answer detailsCorrect answerD
Multiple choice
Which of the following programming languages are NOT vulnerable to buffer overflow attacks? Each correct answer represents a complete solution. Choose two. Reveal answer details Close answer detailsCorrect answersB, D
Single choice
Which of the following is executed when a predetermined event occurs? Reveal answer details Close answer detailsCorrect answerB
Multiple choice
Which of the following can be used to perform session hijacking? Each correct answer represents a complete solution. Choose all that apply. Reveal answer details Close answer detailsCorrect answersA, B, D
Single choice
John works as an Ethical Hacker for PassGuide Inc. He wants to find out the ports that are open in PassGuide's server using a port scanner. However, he does not want to establish a full TCP connection. Which of the following scanning techniques will he use to accomplish this task? Reveal answer details Close answer detailsCorrect answerC
Single choice
You want to scan your network quickly to detect live hosts by using ICMP ECHO Requests. What type of scanning will you perform to accomplish the task? Reveal answer details Close answer detailsCorrect answerD
Single choice
Which of the following types of channels is used by Trojans for communication? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data, denialof-service, or unauthorized changes to system hardware, software, or data? Reveal answer details Close answer detailsCorrect answerB
Single choice
Jason, a Malicious Hacker, is a student of Baker university. He wants to perform remote hacking on the server of DataSoft Inc. to hone his hacking skills. The company has a Windows-based network. Jason successfully enters the target system remotely by using the advantage of vulnerability. He places a Trojan to maintain future access and then disconnects the remote session. The employees of the company complain to Mark, who works as a Professional Ethical Hacker for DataSoft Inc., that some computers are very slow. Mark diagnoses the network and finds that some irrelevant log files and signs of Trojans are present on the computers. He suspects that a malicious hacker has accessed the network. Mark takes the help from Forensic Investigators and catches Jason. Which of the following mistakes made by Jason helped the Forensic Investigators catch him? Reveal answer details Close answer detailsCorrect answerD |