312-50V9 Exam Questions
613 real 312-50V9 exam questions with expert-verified answers and explanations. Page 11 of 13.
- Question #501Enumeration
A company has publicly hosted web applications and an internal Intranet protected by a firewall. Which technique will help protect against enumeration?
DNS A recordsenumeration protectioninternal host exposurefirewall architecture - Question #502System Hacking
Which of the following techniques will identify if computer files have been changed?
file integritycryptographic hashingchange detectionhost-based security - Question #503Scanning Networks
What are two things that are possible when scanning UDP ports? (Choose two)
UDP scanningICMP responseopen port behaviorport scanning - Question #504Scanning Networks
What does a type 3 code 13 represent?(Choose two.
ICMP type 3 code 13destination unreachableadministratively prohibitedICMP codes - Question #505Scanning Networks
Destination unreachable administratively prohibited messages can inform the hacker to what?
ICMP unreachablepacket filteringfirewall detectionrouter ACL - Question #506Scanning Networks
Which of the following Nmap commands would be used to perform a stack fingerprinting?
OS fingerprintingnmap -O flagTCP/IP stack fingerprintingnmap syntax - Question #507Scanning Networks
(Note: the student is being tested on concepts learnt during passive OS fingerprinting, basic TCP/IP connection concepts and the ability to read packet signatures from a sniff dump...
Back Orificeport 31337packet signature analysismalware port - Question #508Scanning Networks
Which type of Nmap scan is the most reliable, but also the most visible, and likely to be picked up by and IDS?
TCP connect scanIDS visibilitynmap scan typesfull handshake - Question #509Scanning Networks
Name two software tools used for OS guessing? (Choose two.
OS fingerprinting toolsNmapQuesoactive fingerprinting - Question #510Introduction to Ethical Hacking
Sandra is the security administrator of XYZ.com. One day she notices that the XYZ.com Oracle database server has been compromised and customer information along with financial data...
computer crime reportinglaw enforcement agenciesincident responseUS cybercrime organizations - Question #511Enumeration
While reviewing the result of scanning run against a target network you come across the following: Which among the following can be used to get this output?
SNMP walkenumeration outputSNMP protocolnetwork management enumeration - Question #512Scanning Networks
You are manually conducting Idle Scanning using Hping2. During your scanning you notice that almost every query increments the IPID regardless of the port being queried. One or two...
idle scanningIPID incrementzombie hosthping2 - Question #513Scanning Networks
While performing ping scans into a target network you get a frantic call from the organization's security team. They report that they are under a denial of service attack. When you...
ping scanbroadcast IPsmurf attackIDS evasion - Question #514Scanning Networks
Neil notices that a single address is generating traffic from its port 500 to port 500 of several other machines on the network. This scan is eating up most of the network bandwidt...
port 500IPSecVPN fingerprintingtraffic analysis - Question #515Scanning Networks
A distributed port scan operates by:
distributed port scancoordinated scanningscan correlation - Question #516Scanning Networks
An nmap command that includes the host specification of 202.176.56-57.* will scan _______ number of hosts.
nmap host specificationIP range syntaxhost count calculationwildcard notation - Question #517Scanning Networks
A specific site received 91 ICMP_ECHO packets within 90 minutes from 47 different sites. 77 of the ICMP_ECHO packets had an ICMP ID:39612 and Seq:57072. 13 of the ICMP_ECHO packets...
ICMP echo analysisICMP ID and sequencescanning tool artifactspacket forensics - Question #518Sniffing
Which of the following commands runs snort in packet logger mode?
snortpacket logger modeIDS command syntaxnetwork monitoring - Question #519Scanning Networks
You have initiated an active operating system fingerprinting attempt with nmap against a target system: What operating system is the target host running based on the open ports sho...
OS fingerprintingnmap output interpretationopen portsWindows OS detection - Question #520Scanning Networks
Study the log below and identify the scan type.
nmap -sOIP protocol scanscan log analysisscan type identification - Question #521Scanning Networks
Which of the following command line switch would you use for OS detection in Nmap?
NmapOS detectioncommand flagsport scanning - Question #522Enumeration
Why would an attacker want to perform a scan on port 137?
NetBIOSNBTSTATport 137network enumeration - Question #523Scanning Networks
Which Type of scan sends a packets with no flags set? Select the Answer
NULL scanTCP flagsstealth scanningport scanning techniques - Question #524Scanning Networks
Sandra has been actively scanning the client network on which she is doing a vulnerability assessment test. While conducting a port scan she notices open ports in the range of 135...
SMBNetBIOSports 135-139Windows services - Question #525Enumeration
SNMP is a protocol used to query hosts, servers, and devices about performance or health status data. This protocol has long been used by hackers to gather great amount of informat...
SNMPcommunity stringsclear text protocolnetwork enumeration - Question #526Introduction to Ethical Hacking
Bob is acknowledged as a hacker of repute and is popular among visitors of "underground" sites. Bob is willing to share his knowledge with those who are willing to learn, and many...
ethical hackingblack hat vs white hatsecurity educationknowledge sharing - Question #527Enumeration
Peter extracts the SIDs list from Windows 2000 Server machine using the hacking tool "SIDExtractor". Here is the output of the SIDs: From the above list identify the user account w...
SIDWindows security identifiersadministrator privilegesuser enumeration - Question #528Scanning Networks
Which address translation scheme would allow a single public IP address to always correspond to a single machine on an internal network, allowing "server publishing"?
static NATIP address translationserver publishingnetwork topology - Question #529Enumeration
What is the following command used for? net use \targetipc$ "" /u:""
null sessionIPC$Windows enumerationnet use command - Question #530Scanning Networks
What is the proper response for a NULL scan if the port is closed?
NULL scanTCP RSTclosed port responseport scanning - Question #531Footprinting and Reconnaissance
One of your team members has asked you to analyze the following SOA record. What is the TTL? Rutgers.edu.SOA NS1.Rutgers.edu ipad.college.edu (200302028 3600 3600 604800 2400.
SOA recordDNS TTLzone informationDNS records - Question #532Footprinting and Reconnaissance
One of your team members has asked you to analyze the following SOA record. What is the version? Rutgers.edu.SOA NS1.Rutgers.edu ipad.college.edu (200302028 3600 3600 604800 2400.
SOA recordDNS serial numberzone versionDNS records - Question #533Footprinting and Reconnaissance
MX record priority increases as the number increases. (True/False.)
MX recordDNS prioritymail exchangeDNS records - Question #534Footprinting and Reconnaissance
Which of the following tools can be used to perform a zone transfer?
zone transferDNS toolsNSLookupDNS enumeration - Question #535Footprinting and Reconnaissance
Under what conditions does a secondary name server request a zone transfer from a primary name server?
zone transferSOA comparisonprimary secondary DNSDNS synchronization - Question #536Enumeration
What ports should be blocked on the firewall to prevent NetBIOS traffic from not coming through the firewall if your network is comprised of Windows NT, 2000, and XP?(Choose all th...
NetBIOSfirewall port blockingport 135 139 445Windows network security - Question #537Scanning Networks
What is a NULL scan?
NULL scanTCP flagsstealth scanningport scanning techniques - Question #538Scanning Networks
What is the proper response for a NULL scan if the port is open?
NULL scanopen port responseTCP behaviorport scanning - Question #539Footprinting and Reconnaissance
Which of the following statements about a zone transfer correct?(Choose three.
zone transferDNS securityTCP port 53DNS enumeration - Question #540Footprinting and Reconnaissance
You have the SOA presented below in your Zone. Your secondary servers have not been able to contact your primary server to synchronize information. How long will the secondary serv...
SOA recordzone expiryDNS synchronizationsecondary name server - Question #541Footprinting and Reconnaissance
Tess King is using the nslookup command to craft queries to list all DNS information (such as Name Servers, host names, MX records, CNAME records, glue records (delegation for chil...
DNS zone transfernslookupDNS enumerationMX records - Question #542Footprinting and Reconnaissance
A zone file consists of which of the following Resource Records (RRs)?
DNS resource recordszone fileSOA recordMX records - Question #543Sniffing
Let's imagine three companies (A, B and C), all competing in a challenging global environment. Company A and B are working together in developing a product that will generate a maj...
DNS spoofingDNS anti-spoofingzone transferDNS security - Question #544Footprinting and Reconnaissance
Which DNS resource record can indicate how long any "DNS poisoning" could last?
DNS poisoningTTLSOA recordDNS cache - Question #545Sniffing
Joseph was the Web site administrator for the Mason Insurance in New York, who's main Web the Web site. One night, Joseph received an urgent phone call from his friend, Smith. Acco...
DNS cache poisoningDNS spoofingweb defacementtraffic analysis - Question #546Enumeration
Which of the following tools are used for enumeration? (Choose three.)
enumeration toolsSID enumerationWindows enumerationDumpSec - Question #547Enumeration
What did the following commands determine? C: user2sid \earth guest S-1-5-21-343818398-789336058-1343024091-501 C:sid2user 5 21 343818398 789336058 1343024091 500 Name is Joe Domai...
SID enumerationSID 500Windows administratoruser2sid - Question #548Evading IDS, Firewalls, and Honeypots
Which definition among those given below best describes a covert channel?
covert channelprotocol misusetraffic tunnelingevasion techniques - Question #549Session Hijacking
Susan has attached to her company's network. She has managed to synchronize her boss's sessions with that of the file server. She then intercepted his traffic destined for the serv...
man-in-the-middlesession hijackingtraffic interceptionsession synchronization - Question #550Sniffing
Eric has discovered a fantastic package of tools named Dsniff on the Internet. He has learnt to use these tools in his lab and is now ready for real world exploitation. He was able...
man-in-the-middleDsniffcredential interceptionnetwork sniffing