312-50V10 Exam Questions
937 real 312-50V10 exam questions with expert-verified answers and explanations. Page 19 of 19.
- Question #909Malware Threats
Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfilltrated by an...
fileless malwareapplication whitelisting bypassliving off the landAV evasion - Question #910Social Engineering
While browsing his Facebook teed, Matt sees a picture one of his friends posted with the caption. "Learn more about your friends!", as well as a number of personal questions. Matt...
social engineeringsecurity questionspretextingaccount compromise - Question #911Scanning Networks
Andrew is an Ethical Hacker who was assigned the task of discovering all the active devices hidden by a restrictive firewall in the IPv4 range in a given target network. Which of t...
host discoveryARP ping scanfirewall bypassIPv4 scanning - Question #912Evading IDS, Firewalls, and Honeypots
What is the minimum number of network connections in a multi homed firewall?
multi-homed firewallDMZnetwork interfacesfirewall architecture - Question #913Enumeration
which of the following protocols can be used to secure an LDAP service against anonymous queries?
LDAPanonymous queriesSSOdirectory service security - Question #914Information Security and Ethical Hacking Fundamentals
Why is a penetration test considered to be more thorough than vulnerability scan?
penetration testingvulnerability scanningactive exploitationmethodology comparison - Question #915Cryptography
Alice needs to send a confidential document to her coworker. Bryan. Their company has public key infrastructure set up. Therefore. Alice both encrypts the message and digitally sig...
PKIasymmetric encryptiondigital signaturepublic key infrastructure - Question #916Cryptography
Dorian Is sending a digitally signed email to Polly, with which key is Dorian signing this message and how is Poly validating It?
digital signatureprivate key signingpublic key verificationasymmetric cryptography - Question #917IoT and OT Hacking
An organization has automated the operation of critical infrastructure from a remote location. For this purpose, all the industrial control systems are connected to the Internet. T...
OT securityICS protectionindustrial control systemsFlowmon - Question #918Hacking Web Applications
John is investigating web-application firewall logs and observers that someone is attempting to inject the following: char buff[10]; buff[>o] - 'a': What type of attack is this?
buffer overflowWAF log analysisweb application attackscode injection - Question #919Hacking Mobile Platforms
Don, a student, came across a gaming app in a third-party app store and Installed it. Subsequently, all the legitimate apps in his smartphone were replaced by deceptive application...
Agent Smith attackmobile malwareapp replacementAndroid security - Question #920Sniffing
A pen tester is configuring a Windows laptop for a test. In setting up Wireshark, what river and library are required to allow the NIC to work in promiscuous mode?
WiresharkWinPcappromiscuous modepacket capture - Question #921Footprinting and Reconnaissance
You start performing a penetration test against a specific website and have decided to start from grabbing all the links from the main page. What Is the best Linux pipe to achieve...
web crawlinglink extractioncurl wgetweb reconnaissance - Question #922Sniffing
Scenario: Joe turns on his home computer to access personal online banking. When he enters as if he has never visited the site before. When he examines the website URL closer, he f...
DNS hijackingURL spoofingweb redirectionnetwork attack identification - Question #923Cryptography
This form of encryption algorithm is asymmetric key block cipher that is characterized by a 128-bit block size, and its key size can be up to 256 bits. Which among the following is...
Twofishblock ciphersymmetric encryptionkey size - Question #924Information Security and Ethical Hacking Fundamentals
At what stage of the cyber kill chain theory model does data exfiltration occur?
cyber kill chaindata exfiltrationactions on objectivesattack phases - Question #925Hacking Web Applications
Jason, an attacker, targeted an organization to perform an attack on its Internet-facing web server with the intention of gaining access to backend servers, which are protected by...
SSRFserver-side request forgeryweb server attacklocalhost abuse - Question #926Information Security and Ethical Hacking Fundamentals
infecting a system with malware and using phishing to gain credentials to a system or web application are examples of which phase of the ethical hacking methodology?
ethical hacking phasesgaining accessmalware deliveryphishing - Question #927Cryptography
John wants to send Marie an email that includes sensitive information, and he does not trust the network that he is connected to. Marie gives him the idea of using PGP. What should...
PGPpublic key encryptionasymmetric encryptionemail security - Question #928Vulnerability Analysis
A newly joined employee. Janet, has been allocated an existing system used by a previous employee. Before issuing the system to Janet, it was assessed by Martin, the administrator....
host-based assessmentvulnerability assessment typesregistry permissionsconfiguration errors - Question #929Enumeration
Allen, a professional pen tester, was hired by xpertTech solutWns to perform an attack simulation on the organization's network resources. To perform the attack, he took advantage...
NetBIOSNetBIOS codesport 139messenger service - Question #930Cryptography
What piece of hardware on a computer's motherboard generates encryption keys and only releases a part of the key so that decrypting a disk on a new piece of hardware is not possibl...
TPMhardware security moduledisk encryptionkey generation - Question #931Sniffing
Bill is a network administrator. He wants to eliminate unencrypted traffic inside his company's network. He decides to setup a SPAN port and capture all traffic to the datacenter....
SNMPUDP 161SNMP v3protocol security - Question #932Scanning Networks
In order to tailor your tests during a web-application scan, you decide to determine which web- server version is hosting the application. On using the sV flag with Nmap. you obtai...
banner grabbingNmap -sVweb server fingerprintingversion detection - Question #933Sniffing
Robin, a professional hacker, targeted an organization's network to sniff all the traffic. During this process. Robin plugged in a rogue switch to an unused port in the LAN with a...
STP attackspanning tree protocolrogue switchroot bridge manipulation - Question #934Information Security and Ethical Hacking Fundamentals
Widespread fraud ac Enron. WorldCom, and Tyco led to the creation of a law that was designed to improve the accuracy and accountability of corporate disclosures. It covers accounti...
SOXSarbanes-Oxleycompliance frameworkscorporate governance - Question #935Cloud Computing
Annie, a cloud security engineer, uses the Docker architecture to employ a client/server model in the application she is working on. She utilizes a component that can process API r...
Docker daemoncontainer architectureDocker APIcloud containers - Question #936Hacking Mobile Platforms
Which ios jailbreaking technique patches the kernel during the device boot so that it becomes jailbroken after each successive reboot?
iOS jailbreakingsemi-tethered jailbreakkernel patchingmobile security - Question #937Hacking Mobile Platforms
What is the file that determines the basic configuration (specifically activities, services, broadcast receivers, etc.) in an Android application?
AndroidManifest.xmlAndroid application structuremobile app configurationAPK components - Question #938Denial of Service
A DDOS attack is performed at layer 7 to take down web infrastructure. Partial HTTP requests are sent to the web infrastructure or applications. Upon receiving a partial request, t...
Slowlorislayer 7 DDoSpartial HTTP requestsapplication-layer attack - Question #939Social Engineering
Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer...
impersonationpretextingsocial engineeringphysical intrusion - Question #940Cryptography
Internet Protocol Security IPsec is actually a suite pf protocols. Each protocol within the suite provides different functionality. Collective IPsec does everything except.
IPsecnetwork layer securityVPN protocolsprotocol suite - Question #941Scanning Networks
Consider the following Nmap output: What command-line parameter could you use to determine the type and version number of the web server?
Nmap-sV flagversion detectionweb server fingerprinting - Question #942Evading IDS, Firewalls, and Honeypots
John, a professional hacker, decided to use DNS to perform data exfiltration on a target network, in this process, he embedded malicious data into the DNS protocol packets that eve...
DNS tunnelingdata exfiltrationfirewall bypassC&C communication - Question #943Malware Threats
which type of virus can change its own code and then cipher itself multiple times as it replicates?
polymorphic virusvirus classificationself-modifying codeencryption - Question #944Information Security and Ethical Hacking Fundamentals
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?
bug bountyvulnerability disclosureHackerOneresponsible disclosure - Question #945Social Engineering
An attacker redirects the victim to malicious websites by sending them a malicious link by email. The link appears authentic but redirects the victim to a malicious web page, which...
phishingmalicious linksocial engineeringcredential theft