112-52 Exam Questions
175 real 112-52 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1Information Gathering and Vulnerability Analysis
Which technique is commonly used to enable packet sniffing on a network?
packet sniffingpromiscuous modenetwork reconnaissancepacket capture - Question #2Wireless Network Security
Which mobile-specific attack can be performed through public Wi-Fi networks?
Rogue Access PointWi-Fi SecurityMobile SecurityWireless Attacks - Question #3Information Gathering and Vulnerability Analysis
Which of the following best describes a zero-day vulnerability?
zero-day vulnerabilityvulnerability disclosurepatch managementexploit timing - Question #4Attacks and Countermeasures
What is a critical countermeasure for protecting OT environments?
OT SecurityPatch ManagementVulnerability ManagementSystem Hardening - Question #5Web Application Security
What is a primary security measure to prevent Cross-Site Scripting (XSS) attacks?
XSS PreventionContent Security PolicyWeb Application SecurityInput Validation - Question #6Information Gathering and Vulnerability Analysis
Which strategy is crucial for enhancing the security of IoT devices?
IoT securitypenetration testingvulnerability assessmentsecurity best practices - Question #7Attacks and Countermeasures
Which security measure MOST effectively reduces unauthorized access in cloud environments?
Access Control PoliciesCloud SecurityUnauthorized Access PreventionLeast Privilege - Question #8Information Gathering and Vulnerability Analysis
What is the primary purpose of packet sniffing in a network security context?
packet sniffingnetwork monitoringtraffic analysisnetwork reconnaissance - Question #9Ethical Hacking Fundamentals
What is the role of containerization in cloud security?
ContainerizationCloud SecurityApplication IsolationSecurity Controls - Question #10Ethical Hacking Fundamentals
Which deployment model in cloud computing is owned, managed, and operated by a business, organization, or entity exclusively?
Cloud deployment modelsPrivate cloudCloud securityInfrastructure - Question #11Attacks and Countermeasures
Which technique involves trying all possible combinations of characters until the correct password is found?
Brute force attackPassword attackAuthenticationAttack types - Question #12Information Gathering and Vulnerability Analysis
Which of the following best describes a vulnerability in the context of information security?
vulnerability definitionrisk assessmentthreat vs vulnerabilitysecurity fundamentals - Question #13Ethical Hacking Fundamentals
Which phase of the ethical hacking cycle involves gathering information about the target?
reconnaissanceethical hacking cycleinformation gatheringtarget profiling - Question #14Wireless Network Security
Which of the following is a common wireless network-specific attack technique?
wireless attacksIV attackWEP/WPAencryption cryptanalysis - Question #15Attacks and Countermeasures
Which of the following is considered a physical threat?
Physical SecurityTailgatingAccess ControlThreat Classification - Question #16Attacks and Countermeasures
What is the best way to mitigate social engineering attacks in an organization?
Social EngineeringEmployee TrainingSecurity AwarenessRisk Mitigation - Question #17Wireless Network Security
What is the main goal of a Bluetooth attack?
Bluetooth attacksWireless securityUnauthorized accessDevice compromise - Question #18Wireless Network Security
What is an effective countermeasure against wireless sniffing?
Wireless SniffingWPA3 EncryptionWireless SecurityEncryption Protocols - Question #19Attacks and Countermeasures
Which attack involves overwhelming a web server with traffic, making it inaccessible to legitimate users?
Denial of ServiceDoS AttacksNetwork FloodingWeb Server Attacks - Question #20Information Gathering and Vulnerability Analysis
What vulnerability is particularly concerning for IoT devices due to their widespread and often unattended deployment?
IoT SecurityDefault ConfigurationsVulnerability AnalysisDevice Hardening - Question #21Information Gathering and Vulnerability Analysis
Which is a security challenge unique to IoT environments?
IoT SecurityFirmware UpdatesPatch ManagementDevice Vulnerabilities - Question #22Web Application Security
Which type of attack exploits the trust that a site has in a user's browser?
XSSbrowser trustweb attacksscript injection - Question #23Attacks and Countermeasures
Which tool is widely used for password recovery by trying millions of combinations per second?
password crackingbrute force attacksJohn the Ripperpassword recovery tools - Question #24Information Gathering and Vulnerability Analysis
Containers offer a lightweight alternative to virtual machines by sharing the host OS's kernel. What is a key security practice for containers?
Container SecurityVulnerability ScanningContainer ImagesSecurity Best Practices - Question #25Ethical Hacking Fundamentals
Which principle ensures that only authorized individuals can access information?
CIA TriadConfidentialityAccess ControlSecurity Fundamentals - Question #26Information Gathering and Vulnerability Analysis
What is the primary purpose of a vulnerability scanner?
vulnerability scannervulnerability detectionsecurity assessmentpenetration testing - Question #27Ethical Hacking Fundamentals
Which legislation is specifically designed to protect the privacy of electronic health records?
Privacy legislationHIPAAHealth recordsCompliance - Question #28Attacks and Countermeasures
Which of the following is an example of a passive attack?
passive attacksattack classificationeavesdroppingactive vs passive - Question #29Ethical Hacking Fundamentals
What differentiates a vulnerability scan from a penetration test?
Vulnerability ScanningPenetration TestingAssessment TechniquesExploitation - Question #30Ethical Hacking Fundamentals
What is the primary objective of penetration testing?
Penetration TestingSecurity AssessmentEthical HackingVulnerability Evaluation - Question #31Attacks and Countermeasures
Which of the following is an effective countermeasure against ransomware attacks?
ransomwareantiviruspatch managementmalware defense - Question #32Information Gathering and Vulnerability Analysis
What is the primary function of a vulnerability assessment?
vulnerability assessmentsecurity weaknessesrisk identificationsystem security - Question #33Wireless Network Security
Which is a wireless network attack?
Rogue Access PointWireless AttacksWiFi SecurityNetwork Threats - Question #34Ethical Hacking Fundamentals
What distinguishes a white hat hacker from other types of hackers?
white hat hackingethical hackinghacker typeslegal security practices - Question #35Attacks and Countermeasures
Phishing attacks typically occur through which medium?
phishingsocial engineeringemail attacksattack vectors - Question #36Ethical Hacking Fundamentals
What is the primary goal of an information security program?
CIA TriadInformation Security ProgramData ProtectionSecurity Objectives - Question #37Attacks and Countermeasures
Which of the following is the MOST effective countermeasure against SQL Injection attacks?
SQL InjectionParameterized QueriesInput ValidationSecurity Countermeasures - Question #38Attacks and Countermeasures
Which countermeasure can help in reducing the risk of tailgating?
tailgatingphysical securitybiometric authenticationaccess control - Question #39Information Gathering and Vulnerability Analysis
Which of the following is a common mobile platform vulnerability?
mobile securityencryptiondata protectionvulnerabilities - Question #40Ethical Hacking Fundamentals
In which phase of the Cyber Kill Chain does a hacker deliver a payload to a target system?
Cyber Kill ChainDelivery PhaseAttack MethodologyPayload Delivery - Question #41Attacks and Countermeasures
What are effective countermeasures against IoT threats? (Choose two)
IoT SecurityDevice HardeningNetwork SegmentationFirmware Patching - Question #42Information Gathering and Vulnerability Analysis
Which activity is part of a vulnerability assessment process?
vulnerability assessmentvulnerability identificationsecurity testingvulnerability management - Question #43Ethical Hacking Fundamentals
Which phase in the ethical hacking cycle involves finding exploitable vulnerabilities in the target system?
Ethical Hacking PhasesVulnerability IdentificationGaining AccessSystem Assessment - Question #44Attacks and Countermeasures
Which of the following is a significant mobile platform attack vector?
mobile platform securityapp-based threatsattack vectorsmobile malware - Question #45Attacks and Countermeasures
What is the primary goal of social engineering attacks?
Social EngineeringInformation DisclosureHuman VulnerabilityManipulation Tactics - Question #46Information Gathering and Vulnerability Analysis
Which phase of the hacking cycle involves gathering detailed information about target systems and services?
EnumerationInformation GatheringHacking CycleService Probing - Question #47Information Gathering and Vulnerability Analysis
Which phase of penetration testing involves gathering information about the target?
ReconnaissancePenetration Testing PhasesInformation GatheringPTES - Question #48Attacks and Countermeasures
Which of the following is an effective countermeasure against mobile device threats?
Mobile SecurityPatch ManagementThreat MitigationSecurity Hardening - Question #49Ethical Hacking Fundamentals
Which of the following is a common communication protocol used by IoT devices?
IoT protocolsMQTTcommunication standardsdevice messaging - Question #50Wireless Network Security
Which measure significantly improves wireless network security?
WPA3 encryptionwireless network securityaccess controlencryption standards