312-50V10 Practice Questions
943 real 312-50V10 exam questions with expert-verified answers and explanations. Page 4 of 19.
- Question #151Scanning Networks
You want to do an ICMP scan on a remote computer using hping2. What is the proper syntax?
hping2ICMP scannetwork scanningCLI syntax - Question #152Information Security and Ethical Hacking Fundamentals
If executives are found liable for not properly protecting their company's assets and information systems, what type of law would apply in this situation?
civil lawexecutive liabilitylegal frameworkcorporate governance - Question #153Cryptography
The company ABC recently contracted a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and th...
hashingdata integritydocument authenticationcryptographic verification - Question #154Evading IDS, Firewalls, and Honeypots
What is the way to decide how a packet will move from an untrusted outside host to a protected inside that is behind a firewall, which permits the hacker to determine which ports a...
firewalkingfirewall enumerationpacket filtering bypassport probing - Question #155Scanning Networks
What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?
OS fingerprintingactive fingerprintingcrafted packetsTCP/IP stack analysis - Question #156Evading IDS, Firewalls, and Honeypots
Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drown based on these scan results? TCP p...
firewalkingTTL exceededfirewall rule analysisport filtering - Question #157System Hacking
A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new docume...
dictionary attackpassword crackingwordlist attackPDF security - Question #158Scanning Networks
A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version install...
NMAPdevice fingerprintingport analysisprinter identification - Question #159Social Engineering
Bob received this text message on his mobile phone: "Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: [email protected]". Which st...
smishingphishingsocial engineeringimpersonation - Question #160Information Security and Ethical Hacking Fundamentals
When purchasing a biometric system, one of the considerations that should be reviewed is the processing speed. Which of the following best describes what it is meant by processing?
biometricsauthentication processingaccess controlbiometric performance - Question #161Hacking Web Applications
An attacker changes the profile information of a particular user (victim) on the target website. The attacker uses this string to update the victim's profile to a text file and the...
CSRFHTTP POSTweb application attackiframe injection - Question #162Sniffing
An attacker with access to the inside network of a small company launches a successful STP manipulation attack. What will he do next?
STP manipulationspanning tree protocolSPAN porttraffic redirection - Question #163Information Security and Ethical Hacking Fundamentals
Which access control mechanism allows for multiple systems to use a central authentication server (CAS) that permits users to authenticate once and gain access to multiple systems?
single sign-onCAScentralized authenticationaccess control - Question #164Malware Threats
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run?
tunneling virusantivirus evasionservice call interruptionstealth malware - Question #165Scanning Networks
If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used?
TCP SYN scanIDS detectionport scanningIDS evasion - Question #166Cryptography
There are several ways to gain insight on how a cryptosystem works with the goal of reverse engineering the process. A term describes when two pieces of data result in the value is...
hash collisioncryptographic hashcollision attackreverse engineering - Question #167Footprinting and Reconnaissance
A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer...
banner grabbingnetcatHTTP headersserver fingerprinting - Question #168Hacking Mobile Platforms
A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. The analyst will use the Blackjacking att...
BlackjackingBBProxyBlackberry securitymobile attack - Question #169System Hacking
What attack is used to crack passwords by using a precomputed table of hashed passwords?
rainbow tablepassword crackingprecomputed hashhash attack - Question #170Vulnerability Analysis
ShellShock had the potential for an unauthorized user to gain access to a server. It affected many internet- facing services, which OS did it not directly affect?
ShellShockbash vulnerabilityOS platformCVE - Question #171System Hacking
A network administrator discovers several unknown files in the root directory of his Linux FTP server. One of the files is a tarball, two are shell script files, and the third is a...
file system permissionsanonymous FTPnetcat backdoormisconfiguration - Question #172Hacking Web Applications
When you are testing a web application, it is very useful to employ a proxy tool to save every request and response. You can manually test every request and analyze the response to...
Burp Suiteweb proxyHTTP interceptionweb vulnerability testing - Question #173Information Security and Ethical Hacking Fundamentals
By using a smart card and pin, you are using a two-factor authentication that satisfies
two-factor authenticationsmart cardauthentication factorssomething you have - Question #174Cryptography
Cryptography is the practice and study of techniques for secure communication in the presence of third parties (called adversaries). More generally, it is about constructing and an...
SSLasymmetric encryptionkey exchangecryptography fundamentals - Question #175Cryptography
What is the difference between the AES and RSA algorithms?
AESRSAsymmetric vs asymmetricencryption algorithms - Question #176Hacking Wireless Networks
In 2007, this wireless security algorithm was rendered useless by capturing packets and discovering the passkey in a matter of seconds. This security flaw led to a network invasion...
WEPwardrivingwireless encryptionpacket capture - Question #177Scanning Networks
You are an Ethical Hacker who is auditing the ABC company. When you verify the NOC one of the machines has 2 connections, one wired and the other wireless. When you verify the conf...
static routesdual-homed hostnetwork routinginternal external gateway - Question #178Information Security and Ethical Hacking Fundamentals
An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that ha...
log correlationtime synchronizationNTPincident response - Question #179Scanning Networks
An attacker is using nmap to do a ping sweep and a port scanning in a subnet of 254 addresses. In which order should he perform these steps?
ping sweepport scanningnmaphost discovery - Question #180Enumeration
Look at the following output. What did the hacker accomplish?
DNS zone transferfierce toolDNS enumerationhost enumeration - Question #181Hacking Web Applications
Which tier in the N-tier application architecture is responsible for moving and processing data between the tiers?
N-tier architecturelogic tierapplication layersdata processing - Question #182Information Security and Ethical Hacking Fundamentals
An enterprise recently moved to a new office and the new neighborhood is a little risky. The CEO wants to monitor the physical perimeter and the entrance doors 24 hours. What is th...
physical securityCCTVperimeter monitoringsurveillance - Question #183Information Security and Ethical Hacking Fundamentals
Bob learned that his username and password for a popular game has been compromised. He contacts the company and resets all the information. The company suggests he use two-factor a...
two-factor authenticationbiometricsmulti-factor authenticationaccess control - Question #184Information Security and Ethical Hacking Fundamentals
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should...
auditingsecurity policyimpact assessmentcompliance - Question #185Scanning Networks
Which of the following Nmap commands will produce the following output?
NmapTCP SYN scanUDP scanfull port scan - Question #186Sniffing
As an Ethical Hacker you are capturing traffic from your customer network with Wireshark and you need to find and verify just SMTP traffic. What command in Wireshark will help you...
Wiresharkpacket filteringSMTPdisplay filters - Question #187Malware Threats
Which of the following programs is usually targeted at Microsoft Office products?
macro virusMicrosoft Officevirus typesmalware classification - Question #188Hacking Wireless Networks
A new wireless client is configured to join an 802.11 network. This client uses the same hardware and software as many of the other clients on the network. The client can see the n...
MAC filteringwireless associationWAP802.11 security - Question #189Cryptography
What is correct about digital signatures?
digital signatureshash bindingdocument integrityPKI - Question #190Evading IDS, Firewalls, and Honeypots
What does a firewall check to prevent particular ports and applications from getting packets into an organization?
firewall packet filteringtransport layerapplication layer headersport filtering - Question #191System Hacking
Which of the following programming languages is most susceptible to buffer overflow attacks, due to its lack of a built-in-bounds checking mechanism? Code: #include <string.h> int...
buffer overflowC++bounds checkingmemory exploitation - Question #192Hacking Web Applications
Scenario: 1. Victim opens the attacker's web site. 2. Attacker sets up a web site which contains interesting and attractive content like 'Do you want to make $1000 in a day?'. 3. V...
clickjackingtransparent iframeUI redressingweb attack - Question #193System Hacking
John the Ripper is a technical assessment tool used to test the weakness of which of the following?
John the Ripperpassword crackingpassword auditingsecurity tools - Question #194SQL Injection
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see...
SQL injectionsingle quoteinput validationinjection testing - Question #195Scanning Networks
You have successfully compromised a machine on the network and found a server that is alive on the same network. You tried to ping it but you didn't get any response back. What is...
ICMPpinghost discoveryfirewall rules - Question #196Information Security and Ethical Hacking Fundamentals
A large mobile telephony and data network operator has a data that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center...
network hardeningdefense in depthsecurity policyLinux security - Question #197Information Security and Ethical Hacking Fundamentals
Which of the following incident handling process phases is responsible for defining rules, collaborating human workforce, creating a back-up plan, and testing the plans for an orga...
incident handlingpreparation phaseincident responsesecurity planning - Question #198Scanning Networks
The following is part of a log file taken from the machine on the network with the IP address of 192.168.1.106: What type of activity has been logged?
port scanninglog analysisnetwork reconnaissanceintrusion detection - Question #199Information Security and Ethical Hacking Fundamentals
A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT...
remote access policydial-out modemsecurity auditpolicy compliance - Question #200Cryptography
Which of the following areas is considered a strength of symmetric key cryptography when compared with asymmetric algorithms?
symmetric encryptioncryptography performancespeed advantageencryption comparison