312-50V9 Exam Questions
613 real 312-50V9 exam questions with expert-verified answers and explanations. Page 10 of 13.
- Question #451Vulnerability Analysis
Which of the following lists are valid data-gathering activities associated with a risk assessment?
risk assessmentthreat identificationvulnerability identificationcontrol analysis - Question #452Introduction to Ethical Hacking
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior...
black box testingpenetration testingrules of engagementexternal assessment - Question #453Introduction to Ethical Hacking
Which of the following is a detective control?
detective controlaudit trailsecurity control typesmonitoring - Question #454Vulnerability Analysis
Which of the following is a component of a risk assessment?
risk assessmentadministrative safeguardsrisk managementsecurity controls - Question #455Introduction to Ethical Hacking
Risks = Threats x Vulnerabilities is referred to as the:
risk equationthreat analysisvulnerabilityrisk formula - Question #456Evading IDS, Firewalls, and Honeypots
Which of the following is designed to identify malicious attempts to penetrate systems?
intrusion detection systemIDSmalicious trafficnetwork security - Question #457Social Engineering
Which of the following is a low-tech way of gaining unauthorized access to systems?
social engineeringunauthorized accesslow-tech attackhuman factor - Question #458Cryptography
PGP, SSL, and IKE are all examples of which type of cryptography?
public key cryptographyPGPSSLIKE - Question #459System Hacking
Which method of password cracking takes the most time and effort?
password crackingbrute forcerainbow tablesdictionary attack - Question #460Hacking Web Servers
What is the most common method to exploit the "Bash Bug" or "ShellShock" vulnerability?
ShellShockBash BugCGI exploitationweb server vulnerability - Question #461Hacking Web Servers
Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?
Niktoweb server scanningCGI testingvulnerability scanner - Question #462Sniffing
Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?
tcptracepacket capture analysispcapnetwork forensics - Question #463Hacking Wireless Networks
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?
Kismetwireless detection802.11Linux tools - Question #464Vulnerability Analysis
Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?
missing patchesWindows file serverpatch managementcommon vulnerabilities - Question #465Evading IDS, Firewalls, and Honeypots
While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handsha...
circuit-level gatewayfirewall typesOSI session layerfirewall traversal - Question #466Evading IDS, Firewalls, and Honeypots
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: Untrust (Inter...
firewall rulesDMZ configurationRDP access controlleast privilege rule - Question #467Evading IDS, Firewalls, and Honeypots
A circuit level gateway works at which of the following layers of the OSI Model?
circuit-level gatewayOSI modelLayer 4firewall types - Question #468Cryptography
Which of the following is a symmetric cryptographic standard?
symmetric encryption3DEScryptographic standardsblock cipher - Question #469Cryptography
A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new docume...
dictionary attackpassword crackingPDF securitycryptography attacks - Question #470Cryptography
Which property ensures that a hash function will not produce the same hashed value for two different messages?
collision resistancehash functionscryptographic propertiesintegrity - Question #471Hacking Web Servers
How can telnet be used to fingerprint a web server?
telnetweb server fingerprintingbanner grabbingHTTP - Question #472Introduction to Ethical Hacking
Low humidity in a data center can cause which of the following problems?
static electricitydata center physical securityhumidity controlenvironmental controls - Question #473Social Engineering
A consultant is hired to do physical penetration testing at a large financial company. In the first day of his assessment, the consultant goes to the company`s building dressed lik...
tailgatingphysical penetration testingaccess control bypasssocial engineering - Question #474Evading IDS, Firewalls, and Honeypots
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's computer to update the router confi...
false positiveIDS alertsintrusion detectionlog analysis - Question #475Hacking Web Applications
While performing data validation of web content, a security technician is required to restrict malicious input. Which of the following processes is an efficient way of restricting...
input validationdata validationmalicious input restrictionweb security controls - Question #476System Hacking
A covert channel is a channel that
covert channelsecurity policyinformation transfersteganography - Question #477System Hacking
John the Ripper is a technical assessment tool used to test the weakness of which of the following?
John the Ripperpassword crackingpassword weaknessoffline attack - Question #478Introduction to Ethical Hacking
Least privilege is a security concept that requires that a user is
least privilegeaccess controlsecurity principlesuser permissions - Question #479Introduction to Ethical Hacking
If the final set of security controls does not eliminate all risk in a system, what could be done next?
residual riskrisk acceptancerisk managementsecurity controls - Question #480System Hacking
What is one thing a tester can do to ensure that the software is trusted and is not changing or tampering with critical data on the back end of a system it is loaded on?
software integrityinterrupt analysistrusted softwaresystem tampering detection - Question #481Introduction to Ethical Hacking
Which of the following examples best represents a logical or technical control?
security controlslogical controlstechnical controlsaccess control - Question #482Introduction to Ethical Hacking
It is an entity or event with the potential to adversely impact a system through unauthorized access, destruction, disclosure, denial of service or modification of data. Which of t...
threat definitionsecurity conceptsrisk terminologyvulnerability - Question #483Introduction to Ethical Hacking
As a Certified Ethical Hacker, you were contracted by a private firm to conduct an external security assessment through penetration testing. What document describes the specifics o...
terms of engagementpenetration testinglegal agreementsproject scope - Question #484Social Engineering
Initiating an attack against targeted businesses and organizations, threat actors compromise a carefully selected website by inserting an exploit resulting in malware infection. Th...
watering hole attackzero-day exploittargeted attackmalware infection - Question #485Scanning Networks
You have successfully gained access to your client's internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Mic...
SMBport 445Windows file sharingnetwork ports - Question #486Hacking Wireless Networks
It is a short-range wireless communication technology intended to replace the cables connecting portable of fixed devices while maintaining high levels of security. It allows mobil...
Bluetoothshort-range wirelesswireless technologymobile devices - Question #487Malware Threats
A hacker has successfully infected an internet-facing server which he will then use to send junk mail, take part in coordinated attacks, or host junk email content. Which sort of t...
botnet trojanmalware typesspam relaycoordinated attacks - Question #488Evading IDS, Firewalls, and Honeypots
You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection Syste...
CryptcatIDS evasiontraffic encryptionpivoting - Question #489Malware Threats
It is a kind of malware (malicious software) that criminals install on your computer so they can lock it from a remote location. This malware generates a pop-up window, webpage, or...
ransomwaremalware definitionextortionpop-up warning - Question #490Scanning Networks
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?
NMAPTCP scanOS fingerprintingservice detection - Question #491Scanning Networks
While checking the settings on the internet browser, a technician finds that the proxy server settings have been checked and a computer is trying to use itself as a proxy server. W...
loopback address127.0.0.1proxy servernetwork addressing - Question #492Scanning Networks
A company has five different subnets: 192.168.1.0, 192.168.2.0, 192.168.3.0, 192.168.4.0 and 192.168.5.0. How can NMAP be used to scan these adjacent Class C networks?
NMAPsubnet scanningClass C networknetwork range - Question #493Evading IDS, Firewalls, and Honeypots
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the test...
SSH tunnelingstealth scanningIDS evasionborder sensor - Question #494Scanning Networks
A hacker is attempting to see which ports have been left open on a network. Which NMAP switch would the hacker use?
NMAP switchesport scanningnetwork reconnaissanceopen ports - Question #495Scanning Networks
ICMP ping and ping sweeps are used to check for active systems and to check
ICMPping sweepfirewall traversalactive host discovery - Question #496Scanning Networks
Which command line switch would be used in NMAP to perform operating system detection?
NMAPOS detection-O flagfingerprinting - Question #497Footprinting and Reconnaissance
A hacker is attempting to use nslookup to query Domain Name Service (DNS). The hacker uses the nslookup interactive mode for the search. Which command should the hacker type into t...
nslookupDNS enumerationNS recordsDNS query - Question #498Footprinting and Reconnaissance
A hacker searches in Google for filetype:pcf to find Cisco VPN config files. Those files may contain connectivity passwords that can be decoded with which of the following?
Google hackingCisco VPNPCF filesCain and Abel - Question #499Scanning Networks
An NMAP scan of a server shows port 25 is open. What risk could this pose?
port 25SMTPopen mail relayservice identification - Question #500Social Engineering
When utilizing technical assessment methods to assess the security posture of a network, which of the following techniques would be most effective in determining whether end-user s...
social engineeringsecurity awareness trainingend-user testingpenetration testing