312-50V11 Practice Questions
1,039 real 312-50V11 exam questions with expert-verified answers and explanations. Page 19 of 21.
- Question #903Enumeration
Garry is a network administrator in an organization. He uses SNMP to manage networked devices from a remote location. To manage nodes in the network, he uses MIB. which contains fo...
SNMPMIB typesnetwork enumerationworkstation services - Question #904Information Security and Ethical Hacking Fundamentals
Nicolas just found a vulnerability on a public-facing system that is considered a zero-day vulnerability. He sent an email to the owner of the public system describing the problem...
hacker typesresponsible disclosurewhite hat hackerethical hacking - Question #905System Hacking
Which of the following are well known password-cracking programs?
password crackingL0phtcrackJohn the Rippercracking tools - Question #906System Hacking
What is the Shellshock bash vulnerability attempting to do on a vulnerable Linux host? env x='(){ :;};echo exploit' bash 璫 `cat/etc/passwd'
Shellshockbash vulnerabilitycommand injection/etc/passwd - Question #907Cloud Computing
joe works as an it administrator in an organization and has recently set up a cloud computing service for the organization. To implement this service, he reached out to a telecom c...
NIST cloud architecturecloud carriercloud deployment rolescloud service provider - Question #908Vulnerability Analysis
David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vul...
vulnerability management lifecycleremediationpatch managementrisk mitigation - Question #909Malware Threats
Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfilltrated by an...
fileless malwareapplication whitelisting bypassAV evasionliving off the land - Question #910Social Engineering
While browsing his Facebook teed, Matt sees a picture one of his friends posted with the caption. "Learn more about your friends!", as well as a number of personal questions. Matt...
social engineeringsecurity questionsinformation disclosurepretexting - Question #911Scanning Networks
Andrew is an Ethical Hacker who was assigned the task of discovering all the active devices hidden by a restrictive firewall in the IPv4 range in a given target network. Which of t...
host discoveryARP ping scanfirewall evasionIPv4 scanning - Question #912Vulnerability Analysis
Mary found a high vulnerability during a vulnerability scan and notified her server team. After analysis, they sent her proof that a fix to that issue had already been applied. The...
false positivevulnerability scanningscan accuracyvulnerability assessment - Question #913Enumeration
Which of the following protocols can be used to secure an LDAP service against anonymous queries?
LDAP securityNTLM authenticationanonymous queriesdirectory services - Question #914Vulnerability Analysis
Why is a penetration test considered to be more thorough than vulnerability scan?
penetration testingvulnerability scanningactive exploitationsecurity assessment methodology - Question #915Cryptography
Alice needs to send a confidential document to her coworker. Bryan. Their company has public key infrastructure set up. Therefore. Alice both encrypts the message and digitally sig...
PKIasymmetric encryptionpublic key encryptiondigital signatures - Question #916Cryptography
Dorian Is sending a digitally signed email to Polly, with which key is Dorian signing this message and how is Poly validating It?
digital signaturesprivate key signingpublic key verificationasymmetric cryptography - Question #917IoT and OT Hacking
An organization has automated the operation of critical infrastructure from a remote location. For this purpose, all the industrial control systems are connected to the Internet. T...
OT securityICS protectionindustrial control systemsFlowmon - Question #918Hacking Web Applications
John is investigating web-application firewall logs and observers that someone is attempting to inject the following: char buff[10]; buff[>o] - 'a': What type of attack is this?
buffer overflowmemory corruptionweb application attacksWAF log analysis - Question #919Hacking Mobile Platforms
Don, a student, came across a gaming app in a third-party app store and Installed it. Subsequently, all the legitimate apps in his smartphone were replaced by deceptive application...
Agent Smith attackmobile malwareAndroid securityapp replacement - Question #920Sniffing
A pen tester is configuring a Windows laptop for a test. In setting up Wireshark, what river and library are required to allow the NIC to work in promiscuous mode?
WiresharkWinPcappromiscuous modepacket capture - Question #921Footprinting and Reconnaissance
You start performing a penetration test against a specific website and have decided to start from grabbing all the links from the main page. What Is the best Linux pipe to achieve...
web scrapinglink extractionLinux reconnaissance commandswget - Question #922Session Hijacking
Scenario: Joe turns on his home computer to access personal online banking. When he enters as if he has never visited the site before. When he examines the website URL closer, he f...
DNS hijackingURL spoofingweb spoofingnetwork redirection - Question #923Cryptography
This form of encryption algorithm is asymmetric key block cipher that is characterized by a 128-bit block size, and its key size can be up to 256 bits. Which among the following is...
Twofishblock ciphersymmetric encryptionkey size - Question #924Information Security and Ethical Hacking Fundamentals
At what stage of the cyber kill chain theory model does data exfiltration occur?
cyber kill chaindata exfiltrationattack phasesactions on objectives - Question #925Hacking Web Applications
Jason, an attacker, targeted an organization to perform an attack on its Internet-facing web server with the intention of gaining access to backend servers, which are protected by...
SSRFserver-side request forgeryURL manipulationweb application attack - Question #926Information Security and Ethical Hacking Fundamentals
infecting a system with malware and using phishing to gain credentials to a system or web application are examples of which phase of the ethical hacking methodology?
ethical hacking methodologygaining accessphishingmalware - Question #927Cryptography
John wants to send Marie an email that includes sensitive information, and he does not trust the network that he is connected to. Marie gives him the idea of using PGP. What should...
PGPpublic key encryptionasymmetric encryptionemail security - Question #928Vulnerability Analysis
A newly joined employee. Janet, has been allocated an existing system used by a previous employee. Before issuing the system to Janet, it was assessed by Martin, the administrator....
host-based assessmentvulnerability assessmentregistry analysisconfiguration errors - Question #929Enumeration
Allen, a professional pen tester, was hired by xpertTech solutWns to perform an attack simulation on the organization's network resources. To perform the attack, he took advantage...
NetBIOSenumerationport 139NetBIOS codes - Question #930Cryptography
What piece of hardware on a computer's motherboard generates encryption keys and only releases a part of the key so that decrypting a disk on a new piece of hardware is not possibl...
TPMdisk encryptionhardware security modulekey management - Question #931Sniffing
Bill is a network administrator. He wants to eliminate unencrypted traffic inside his company's network. He decides to setup a SPAN port and capture all traffic to the datacenter....
SNMPUDP 161SNMPv3network protocol security - Question #932Scanning Networks
In order to tailor your tests during a web-application scan, you decide to determine which web- server version is hosting the application. On using the sV flag with Nmap. you obtai...
banner grabbingNmapservice version detectioninformation gathering - Question #933Sniffing
Robin, a professional hacker, targeted an organization's network to sniff all the traffic. During this process, Robin plugged in a rogue switch to an unused port in the LAN with a...
STP attackspanning tree protocolrogue switchroot bridge manipulation - Question #934Information Security and Ethical Hacking Fundamentals
Widespread fraud ac Enron. WorldCom, and Tyco led to the creation of a law that was designed to improve the accuracy and accountability of corporate disclosures. It covers accounti...
SOXSarbanes-Oxleycompliancecorporate governance - Question #935Cloud Computing
Annie, a cloud security engineer, uses the Docker architecture to employ a client/server model in the application she is working on. She utilizes a component that can process API r...
Docker daemonDocker architecturecontainer managementcloud security - Question #936Hacking Mobile Platforms
Which ios jailbreaking technique patches the kernel during the device boot so that it becomes jailbroken after each successive reboot?
iOS jailbreakinguntethered jailbreakkernel patchingmobile security - Question #937Hacking Mobile Platforms
What is the file that determines the basic configuration (specifically activities, services, broadcast receivers, etc.) in an Android application?
AndroidManifest.xmlAndroid application structureAPK componentsmobile app configuration - Question #938Denial of Service
A DDOS attack is performed at layer 7 to take down web infrastructure. Partial HTTP requests are sent to the web infrastructure or applications. Upon receiving a partial request, t...
Slowlorislayer 7 DDoSpartial HTTP requestsapplication layer attack - Question #939Social Engineering
Ralph, a professional hacker, targeted Jane, who had recently bought new systems for her company. After a few days, Ralph contacted Jane while masquerading as a legitimate customer...
impersonationsocial engineeringpretextingphysical access - Question #940Cryptography
Internet Protocol Security IPsec is actually a suite pf protocols. Each protocol within the suite provides different functionality. Collective IPsec does everything except.
IPsecnetwork layerprotocol suiteVPN security - Question #941Scanning Networks
Consider the following Nmap output: What command-line parameter could you use to determine the type and version number of the web server?
Nmapservice version detectionbanner grabbingweb server fingerprinting - Question #942Evading IDS, Firewalls, and Honeypots
John, a professional hacker, decided to use DNS to perform data exfiltration on a target network, in this process, he embedded malicious data into the DNS protocol packets that eve...
DNS tunnelingfirewall bypassdata exfiltrationC&C communication - Question #943Malware Threats
Which type of virus can change its own code and then cipher itself multiple times as it replicates?
stealth viruspolymorphic virusself-modifying codevirus types - Question #944Information Security and Ethical Hacking Fundamentals
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?
bug bountyvulnerability disclosureHackerOneethical hacking programs - Question #945Social Engineering
An attacker redirects the victim to malicious websites by sending them a malicious link by email. The link appears authentic but redirects the victim to a malicious web page, which...
phishingmalicious linkcredential theftsocial engineering - Question #946Cloud Computing
Geena, a cloud architect, uses a master component in the Kubernetes cluster architecture that scans newly generated pods and allocates a node to them. This component can also assig...
Kuberneteskube-schedulerpod schedulingcontainer orchestration - Question #947Social Engineering
_________ is a type of phishing that targets high-profile executives such as CEOs, CFOs, politicians, and celebrities who have access to confidential and highly valuable informatio...
whalingexecutive targetingspear phishingsocial engineering - Question #948Session Hijacking
Peter, a system administrator working at a reputed IT firm, decided to work from his home and login remotely. Later, he anticipated that the remote connection could be exposed to s...
VPNencrypted tunnelsession hijacking preventionremote access - Question #949Social Engineering
An attacker can employ many methods to perform social engineering against unsuspecting employees, including scareware. What is the best example of a scareware attack?
scarewaresocial engineeringmalware pop-upuser manipulation - Question #950Information Security and Ethical Hacking Fundamentals
Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?
PCI-DSScompliance standardspayment card securityregulatory frameworks - Question #951Cryptography
Tony wants to integrate a 128-bit symmetric block cipher with key sizes of 128,192, or 256 bits into a software program, which involves 32 rounds of computational operations that i...
Serpent cipherblock ciphersymmetric encryptionS-boxes - Question #952Hacking Wireless Networks
Morris, an attacker, wanted to check whether the target AP is in a locked state. He attempted using different utilities to identify WPS-enabled APs in the target wireless network....
WPSwash toolwireless AP discoveryWi-Fi hacking tools