312-50V7 Exam Questions
519 real 312-50V7 exam questions with expert-verified answers and explanations. Page 5 of 11.
- Question #202
What is the outcome of the comm"nc -l -p 2222 | nc 10.1.0.43 1234"?
- Question #203
For messages sent through an insecure channel, a properly implemented digital signature gives the receiver reason to believe the message was sent by the claimed sender. While using...
- Question #204
Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design,...
- Question #205
When using Wireshark to acquire packet capture on a network, which device would enable the capture of all traffic on the wire?
- Question #206
How does an operating system protect the passwords used for account logins?
- Question #207
Which of the following programs is usually targeted at Microsoft Office products?
- Question #208
What is the main difference between a "Normal" SQL Injection and a "Blind" SQL Injection vulnerability?
- Question #209
Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion?
- Question #210
Data hiding analysis can be useful in
- Question #211
Smart cards use which protocol to transfer the certificate in a secure manner?
- Question #212
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: Untrust (Inter...
- Question #213
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is
- Question #214
Which of the following is a protocol that is prone to a man-in-the-middle (MITM) attack and maps a 32-bit address to a 48-bit address?
- Question #215
Which NMAP feature can a tester implement or adjust while scanning for open ports to avoid detection by the network's IDS?
- Question #216
Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?
- Question #217
Which type of access control is used on a router or firewall to limit network activity?
- Question #218
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?
- Question #219
Which types of detection methods are employed by Network Intrusion Detection Systems (NIDS)? (Choose two.)
- Question #220
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following?
- Question #221
Which command lets a tester enumerate alive systems in a class C network via ICMP using native Windows tools?
- Question #222
How can telnet be used to fingerprint a web server?
- Question #223
Which of the following problems can be solved by using Wireshark?
- Question #224
Which of the following is an example of an asymmetric encryption implementation?
- Question #225
What is the purpose of conducting security assessments on network resources?
- Question #226
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, r...
- Question #227
Which of the following is an application that requires a host application for replication?
- Question #228
Which of the following is a characteristic of Public Key Infrastructure (PKI)?
- Question #229
What statement is true regarding LM hashes?
- Question #230
What is a successful method for protecting a router from potential smurf attacks?
- Question #231
Which of the following tools will scan a network to perform vulnerability checks and compliance auditing?
- Question #232
The use of technologies like IPSec can help guarantee the followinG. authenticity, integrity, confidentiality and
- Question #233
A security administrator notices that the log file of the company`s webserver contains suspicious entries: Based on source code analysis, the analyst concludes that the login.php s...
- Question #234
Which of the following is a detective control?
- Question #235
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the test...
- Question #236
A circuit level gateway works at which of the following layers of the OSI Model?
- Question #237
Which of the following lists are valid data-gathering activities associated with a risk assessment?
- Question #238
A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the...
- Question #239
Which command line switch would be used in NMAP to perform operating system detection?
- Question #240
Bluetooth uses which digital modulation technique to exchange information between paired devices?
- Question #241
A security consultant decides to use multiple layers of anti-virus defense, such as end user desktop anti-virus and E-mail gateway. This approach can be used to mitigate which kind...
- Question #242
A security policy will be more accepted by employees if it is consistent and has the support of
- Question #243
There is a WEP encrypted wireless access point (AP) with no clients connected. In order to crack the WEP key, a fake authentication needs to be performed. What information is neede...
- Question #244
What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?
- Question #245
How do employers protect assets with security policies pertaining to employee surveillance activities?
- Question #246
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's computer to update the router confi...
- Question #247
Which of the following parameters enables NMAP's operating system detection feature?
- Question #248
Which of the following is an example of IP spoofing?
- Question #249
Which of the following processes of PKI (Public Key Infrastructure) ensures that a trust relationship exists and that a certificate is still valid for specific operations?
- Question #250
What is the correct PCAP filter to capture all TCP traffic going to or from host 192.168.0.125 on port 25?
- Question #251
When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?