312-50V11 Practice Questions
1,039 real 312-50V11 exam questions with expert-verified answers and explanations. Page 10 of 21.
- Question #451Evading IDS, Firewalls, and Honeypots
Session splicing is an IDS evasion technique in which an attacker delivers data in multiple, smallsized packets to the target computer, making it very difficult for an IDS to detec...
session splicingIDS evasionWhiskerpacket fragmentation - Question #452Scanning Networks
Which of the following tools can be used for passive OS fingerprinting?
passive OS fingerprintingtcpdumppacket capturetraffic analysis - Question #453Evading IDS, Firewalls, and Honeypots
You are the Systems Administrator for a large corporate organization. You need to monitor all network traffic on your local network for suspicious activities and receive notificati...
network-based IDStraffic monitoringintrusion detectionalert notification - Question #454Evading IDS, Firewalls, and Honeypots
You work as a Security Analyst for a retail organization. In securing the company's network, you set up a firewall and an IDS. However, hackers are able to attack the network. Afte...
false negativeIDS misconfigurationalert typesdetection failure - Question #455Evading IDS, Firewalls, and Honeypots
Which of the following types of firewalls ensures that the packets are part of the established session?
stateful inspectionsession trackingfirewall typespacket filtering - Question #456Information Security and Ethical Hacking Fundamentals
During a security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?
security auditIS auditorsecurity proceduresgovernance - Question #457Information Security and Ethical Hacking Fundamentals
Which of the following statements regarding ethical hacking is incorrect?
ethical hacking principlesrules of engagementpenetration testing scopehacker ethics - Question #458Vulnerability Analysis
Craig received a report of all the computers on the network that showed all the missing patches and weak passwords. What type of software generated this report?
vulnerability scannerpatch managementweak passwordssecurity reporting - Question #459Sniffing
An attacker is trying to redirect the traffic of a small office. That office is using their own mail server, DNS server and NTP server because of the importance of their job. The a...
DNS spoofingDNS poisoningtraffic redirectionname resolution attack - Question #460Footprinting and Reconnaissance
The company ABC recently discovered that their new product was released by the opposition before their premiere. They contract an investigator who discovered that the maid threw aw...
dumpster divingphysical reconnaissanceinformation gatheringsocial engineering - Question #461Scanning Networks
An attacker tries to do banner grabbing on a remote web server and executes the following command. $ nmap -sV host.domain.com -p 80 He gets the following output. scan report for ho...
banner grabbingnmapservice version detectionHTTP - Question #462Vulnerability Analysis
Sid is a judge for a programming contest. Before the code reaches him it goes through a restricted OS and is tested there. If it passes, then it moves onto Sid. What is this middle...
fuzzingsandboxcode testingvulnerability analysis - Question #463Scanning Networks
You're doing an internal security audit and you want to find out what ports are open on all the servers. What is the best way to find out?
port scanningnmapnetwork auditopen ports - Question #464Cryptography
Which protocol is used for setting up secured channels between two devices, typically in VPNs?
IPSecVPNsecure channelstunneling protocols - Question #465Scanning Networks
The establishment of a TCP connection involves a negotiation called 3 way handshake. What type of message sends the client to the server in order to begin this negotiation?
TCP handshakeSYN packetTCP/IPconnection establishment - Question #466Enumeration
Look at the following output. What did the hacker accomplish? ; <<>> DiG 9.7.-P1 <<>> axfr domam.com @192.168.1.105 ;; global options: +cmd domain.com. 3600 IN SOA srv1.domain.com....
DNS zone transferAXFRDiGDNS enumeration - Question #467Information Security and Ethical Hacking Fundamentals
What network security concept requires multiple layers of security controls to be placed throughout an IT infrastructure, which improves the security posture of an organization to...
defense in depthlayered securitysecurity controlsIT infrastructure - Question #468Evading IDS, Firewalls, and Honeypots
If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used?
IDS evasionTCP SYN scanport scanningnetwork detection - Question #469Evading IDS, Firewalls, and Honeypots
Which Intrusion Detection System is best applicable for large environments where critical assets on the network need extra security and is ideal for observing sensitive network seg...
NIDSintrusion detectionnetwork monitoringIDS types - Question #470Information Security and Ethical Hacking Fundamentals
Your next door neighbor, that you do not get along with, is having issues with their network, so he yells to his spouse the network's SSID and password and you hear them both clear...
ethicswireless securityresponsible disclosurelegal compliance - Question #471Cryptography
Which of the following is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal condi...
HeartbleedOpenSSLSSL/TLS vulnerabilitycryptographic flaw - Question #472Information Security and Ethical Hacking Fundamentals
One of the Forbes 500 companies has been subjected to a large scale attack. You are one of the shortlisted pen testers that they may hire. During the interview with the CIO, he emp...
risk managementpenetration testing scoperisk reductionethics - Question #473Scanning Networks
Which of the following is an NMAP script that could help detect HTTP Methods such as GET, POST, HEAD, PUT, DELETE, TRACE?
nmap scriptsHTTP methodsweb enumerationhttp-methods - Question #474Footprinting and Reconnaissance
Which of the following is the most important phase of ethical hacking wherein you need to spend considerable amount of time?
footprintingethical hacking phasesreconnaissancemethodology - Question #475Hacking Wireless Networks
It is a short-range wireless communication technology that allows mobile phones, computers and other devices to connect and communicate. This technology intends to replace cables c...
Bluetoothshort-range wirelessmobile communicationwireless technology - Question #476Malware Threats
Matthew received an email with an attachment named "YouWon$10Grand.zip." The zip file contains a file named "HowToClaimYourPrize.docx.exe." Out of excitement and curiosity, Matthew...
Trojancommand and controlmalware behaviordisguised executable - Question #477Enumeration
Which among the following is a Windows command that a hacker can use to list all the shares to which the current user context has access?
NET USEWindows enumerationnetwork sharesSMB - Question #478Information Security and Ethical Hacking Fundamentals
What is the approximate cost of replacement and recovery operation per year of a hard drive that has a value of $300 given that the technician who charges $10/hr would need 10 hour...
SLEAROALErisk quantification - Question #479Information Security and Ethical Hacking Fundamentals
Knowing the nature of backup tapes, which of the following is the MOST RECOMMENDED way of storing backup tapes?
backup securityoffsite storagedata protectionbusiness continuity - Question #480Vulnerability Analysis
Which of the following tools would MOST LIKELY be used to perform security audit on various of forms of network systems?
vulnerability scannersecurity auditnetwork assessmentMBSA - Question #481Information Security and Ethical Hacking Fundamentals
A big company, who wanted to test their security infrastructure, wants to hire elite pen testers like you. During the interview, they asked you to show sample reports from previous...
pen test ethicsreport handlingconfidentialityNDA - Question #482Information Security and Ethical Hacking Fundamentals
You are about to be hired by a well known Bank to perform penetration tests. Which of the following documents describes the specifics of the testing, the associated violations, and...
terms of engagementpen test documentationlegal agreementsscope - Question #483Information Security and Ethical Hacking Fundamentals
The practical realities facing organizations today make risk response strategies essential. Which of the following is NOT one of the five basic responses to risk?
risk responserisk managementrisk strategiesrisk treatment - Question #484Footprinting and Reconnaissance
A company recently hired your team of Ethical Hackers to test the security of their network systems. The company wants to have the attack be as realistic as possible. They did not...
black-box testingpen test phasesreconnaissanceinformation gathering - Question #485Scanning Networks
TCP/IP stack fingerprinting is the passive collection of configuration attributes from a remote device during standard layer 4 network communications. Which of the following tools...
OS fingerprintingpassive fingerprintingTCP/IP stacktcpdump - Question #486Information Security and Ethical Hacking Fundamentals
The chance of a hard drive failure is known to be once every four years. The cost of a new hard drive is $500. EF (Exposure Factor) is about 0.5. Calculate for the Annualized Loss...
ALE calculationAROSLEquantitative risk analysis - Question #487Information Security and Ethical Hacking Fundamentals
Backing up data is a security must. However, it also have certain level of risks when mishandled. Which of the following is the greatest threat posed by backups?
backup securitydata protectionencryptionphysical security - Question #488Information Security and Ethical Hacking Fundamentals
What kind of risk will remain even if all theoretically possible safety measures would be applied?
residual riskrisk managementrisk terminologysecurity controls - Question #489Evading IDS, Firewalls, and Honeypots
While doing a Black box pen test via the TCP port (80), you noticed that the traffic gets blocked when you tried to pass IRC traffic from a web enabled host. However, you also noti...
stateful firewalltraffic inspectionpacket filteringfirewall types - Question #490Information Security and Ethical Hacking Fundamentals
It is a widely used standard for message logging. It permits separation of the software that generates messages, the system that stores them, and the software that reports and anal...
syslogevent logginglog managementnetwork protocols - Question #491Scanning Networks
While doing a technical assessment to determine network vulnerabilities, you used the TCP XMAS scan. What would be the response of all open ports?
TCP XMAS scanport scanningopen port responsestealth scanning - Question #492Footprinting and Reconnaissance
Which of the following tools is used by pen testers and analysts specifically to analyze links between data using link analysis and graphs?
Maltegolink analysisOSINT toolsreconnaissance tools - Question #493Vulnerability Analysis
If you are to determine the attack surface of an organization, which of the following is the BEST thing to do?
attack surfacenetwork scanningDMZvulnerability assessment - Question #494Scanning Networks
What is the best Nmap command to use when you want to list all devices in the same network quickly after you successfully identified a server whose IP address is 10.10.0.5?
nmapfast scannetwork discoveryhost enumeration - Question #495Scanning Networks
You've just discovered a server that is currently active within the same network with the machine you recently compromised. You ping it but it did not respond. What could be the ca...
ICMPpingfirewall filteringnetwork troubleshooting - Question #496Footprinting and Reconnaissance
What tool should you use when you need to analyze extracted metadata from files you collected when you were in the initial stage of penetration test (information gathering)?
metadata analysisMetagoofilOSINTinformation gathering - Question #497Information Security and Ethical Hacking Fundamentals
Which of the following is NOT an ideal choice for biometric controls?
biometricsauthentication factorsphysical securityaccess control - Question #498Information Security and Ethical Hacking Fundamentals
While you were gathering information as part of security assessments for one of your clients, you were able to gather data that show your client is involved with fraudulent activit...
ethical hacking ethicslegal obligationsincident reportingprofessional conduct - Question #499Enumeration
Suppose you've gained access to your client's hybrid network. On which port should you listen to in order to know which Microsoft Windows workstations has its file sharing enabled?
SMBport 445file sharingWindows enumeration - Question #500Malware Threats
Which of the following BEST describes the mechanism of a Boot Sector Virus?
boot sector virusMBRmalware mechanismvirus types