312-50V7 Exam Questions
519 real 312-50V7 exam questions with expert-verified answers and explanations. Page 6 of 11.
- Question #252
Which element of Public Key Infrastructure (PKI) verifies the applicant?
- Question #253
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?
- Question #254
A hacker is attempting to use nslookup to query Domain Name Service (DNS). The hacker uses the nslookup interactive mode for the search. Which command should the hacker type into t...
- Question #255
After gaining access to the password hashes used to protect access to a web based application, knowledge of which cryptographic algorithms would be useful to gain access to the app...
- Question #256
To send a PGP encrypted message, which piece of information from the recipient must the sender have before encrypting the message?
- Question #257
An attacker has been successfully modifying the purchase price of items purchased on the company's web site. The security administrators verify the web server and Oracle database h...
- Question #258
Which of the following items is unique to the N-tier architecture method of designing software applications?
- Question #259
A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer...
- Question #260
To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settin...
- Question #261
While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handsha...
- Question #262
Which type of scan is used on the eye to measure the layer of blood vessels?
- Question #263
A security analyst in an insurance company is assigned to test a new web application that will be used by clients to help them choose and apply for an insurance plan. The analyst d...
- Question #264
While testing the company's web applications, a tester attempts to insert the following test script into the search area on the company's web sitE. <script>alert(" Testing Testing...
- Question #265
A hacker was able to sniff packets on a company's wireless network. The following information was discovereD. The Key 10110010 01001011 The Cyphertext 01100101 01011010 Using the E...
- Question #266
International Organization for Standardization (ISO) standard 27002 provides guidance for compliance by outlining
- Question #267
Which solution can be used to emulate computer services, such as mail and ftp, and to capture information related to logins or actions?
- Question #268
A network administrator received an administrative alert at 3:00 a.m. from the intrusion detection system. The alert was generated because a large number of packets were coming int...
- Question #269
The following is part of a log file taken from the machine on the network with the IP address of 192.168.1.106: Time:Mar 13 17:30:15 Port:20 Source:192.168.1.103 Destination:192.16...
- Question #270
Which type of intrusion detection system can monitor and alert on attacks, but cannot stop them?
- Question #271
Which of the following settings enables Nessus to detect when it is sending too many packets and the network pipe is approaching capacity?
- Question #272
Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. Which of the following is the correct bit size of the Diffie-Hellman (DH) group 5?
- Question #273
Which results will be returned with the following Google search query? site:target.com - site:Marketing.target.com accounting
- Question #274
One advantage of an application-level firewall is the ability to
- Question #275
Which type of security document is written with specific step-by-step details?
- Question #276
A certified ethical hacker (CEH) completed a penetration test of the main headquarters of a company almost two months ago, but has yet to get paid. The customer is suffering from f...
- Question #277
If a tester is attempting to ping a target that exists but receives no response or a response that states the destination is unreachable, ICMP may be disabled and the network may b...
- Question #278
How can rainbow tables be defeated?
- Question #279
Which of the following is an advantage of utilizing security testing methodologies to conduct a security audit?
- Question #280
A developer for a company is tasked with creating a program that will allow customers to update their billing and shipping information. The billing address field used is limited to...
- Question #281
If the final set of security controls does not eliminate all risk in a system, what could be done next?
- Question #282
In keeping with the best practices of layered security, where are the best places to place intrusion detection/intrusion prevention systems? (Choose two.)
- Question #283
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?
- Question #284
Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest?
- Question #285
Company A and Company B have just merged and each has its own Public Key Infrastructure (PKI). What must the Certificate Authorities (CAs) establish so that the private PKIs for Co...
- Question #286
What is the best defense against privilege escalation vulnerability?
- Question #287
Fingerprinting VPN firewalls is possible with which of the following tools?
- Question #288
A company has publicly hosted web applications and an internal Intranet protected by a firewall. Which technique will help protect against enumeration?
- Question #289
Which of the following is a primary service of the U.S. Computer Security Incident Response Team (CSIRT)?
- Question #290
Which of the following is a client-server tool utilized to evade firewall inspection?
- Question #291
Which of the following is a symmetric cryptographic standard?
- Question #292
Which of the following cryptography attack methods is usually performed without the use of a computer?
- Question #293
What technique is used to perform a Connection Stream Parameter Pollution (CSPP) attack?
- Question #294
Which of the following open source tools would be the best choice to scan a network for potential targets?
- Question #295
Which of the following levels of algorithms does Public Key Infrastructure (PKI) use?
- Question #296
Which cipher encrypts the plain text digit (bit or byte) one by one?
- Question #297
WPA2 uses AES for wireless data encryption at which of the following encryption levels?
- Question #298
Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/IP specifications?
- Question #299
Which of the following viruses tries to hide from anti-virus programs by actively altering and corrupting the chosen service call interruptions when they are being run?
- Question #300
The Open Web Application Security Project (OWASP) testing methodology addresses the need to secure web applications by providing which one of the following services?
- Question #301
Which of the following techniques does a vulnerability scanner use in order to detect vulnerability on a target service?