312-50V9 Practice Questions
609 real 312-50V9 exam questions with expert-verified answers and explanations. Page 10 of 13.
- Question #455
Risks = Threats x Vulnerabilities is referred to as the:
- Question #456
Which of the following is designed to identify malicious attempts to penetrate systems?
- Question #457
Which of the following is a low-tech way of gaining unauthorized access to systems?
- Question #458
PGP, SSL, and IKE are all examples of which type of cryptography?
- Question #459
Which method of password cracking takes the most time and effort?
- Question #460
What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?
- Question #461
Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?
- Question #462
Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?
- Question #463
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?
- Question #464
Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?
- Question #465
While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handsha...
- Question #466
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: Untrust (Inter...
- Question #467
A circuit level gateway works at which of the following layers of the OSI Model?
- Question #468
Which of the following is a symmetric cryptographic standard?
- Question #469
A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new docume...
- Question #470
Which property ensures that a hash function will not produce the same hashed value for two different messages?
- Question #471
How can telnet be used to fingerprint a web server?
- Question #472
Low humidity in a data center can cause which of the following problems?
- Question #473
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company`s building dressed lik...
- Question #474
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's computer to update the router confi...
- Question #475
While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting...
- Question #476
A covert channel is a channel that
- Question #477
John the Ripper is a technical assessment tool used to test the weakness of which of the following?
- Question #478
Least privilege is a security concept that requires that a user is
- Question #479
If the final set of security controls does not eliminate all risk in a system, what could be done next?
- Question #480
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?
- Question #481
Which of the following examples best represents a logical or technical control?
- Question #482
It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of t...
- Question #483
As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics o...
- Question #484
Initiating an attack against targeted businesses and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in malware infection. Th...
- Question #485
You have successfully gained access to your client's internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Mic...
- Question #486
It is a short-range wireless communication technology intended to replace the cables connecting portable of fixed devices while maintaining high levels of security. It allows mobil...
- Question #487
A hacker has successfully infected an internet-facing server which he will then use to send junk mail, take part in coordinated attacks, or host junk email content. Which sort of t...
- Question #488
You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection Syste...
- Question #489
It is a kind of malware (malicious software) that criminals install on your computer so they can lock it from a remote location. This malware generates a pop-up window, webpage, or...
- Question #490
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?
- Question #491
While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. W...
- Question #492
A company has five different subnets: 192.168.1.0, 192.168.2.0, 192.168.3.0, 192.168.4.0 and 192.168.5.0. How can NMAP be used to scan these adjacent Class C networks?
- Question #493
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the test...
- Question #494
A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?
- Question #495
ICMP ping and ping sweeps are used to check for active systems and to check
- Question #496
Which command line switch would be used in NMAP to perform operating system detection?
- Question #497
A hacker is attempting to use nslookup to query Domain Name Service (DNS). The hacker uses the nslookup interactive mode for the search. Which command should the hacker type into t...
- Question #498
A hacker searches in Google for filetype:pcf to find Cisco VPN config files. Those files may contain connectivity passwords that can be decoded with which of the following?
- Question #499
An NMAP scan of a server shows port 25 is open. What risk could this pose?
- Question #500
When utilizing technical assessment methods to assess the security posture of a network, which of the following techniques would be most effective in determining whether end-user s...
- Question #501
A company has publicly hosted web applications and an internal Intranet protected by a firewall. Which technique will help protect against enumeration?
- Question #502
Which of the following techniques will identify if computer files have been changed?
- Question #503
What are two things that are possible when scanning UDP ports? (Choose two)
- Question #504
What does a type 3 code 13 represent?(Choose two.