312-50V9 Practice Questions
609 real 312-50V9 exam questions with expert-verified answers and explanations. Page 2 of 13.
- Question #55
Which type of scan measures a person's external features through a digital video camera?
- Question #56
WPA2 uses AES for wireless data encryption at which of the following encryption levels?
- Question #57
An attacker uses a communication channel within an operating system that is neither designed nor intended to transfer information. What is the name of the communications channel?
- Question #58
What technique is used to perform a Connection Stream Parameter Pollution (CSPP) attack?
- Question #59
A newly discovered flaw in a software application would be considered which kind of security vulnerability?
- Question #60
During a penetration test, a tester finds that the web application being analyzed is vulnerable to Cross Site Scripting (XSS). Which of the following conditions must be met to expl...
- Question #61
The use of alert thresholding in an IDS can reduce the volume of repeated alerts, but introduces which of the following vulnerabilities?
- Question #62
What is the main advantage that a network-based IDS/IPS system has over a host-based solution?
- Question #63
The network administrator for a company is setting up a website with e-commerce capabilities. Packet sniffing is a concern because credit card information will be sent electronical...
- Question #64
When an alert rule is matched in a network-based IDS like snort, the IDS does which of the following?
- Question #65
Which type of intrusion detection system can monitor and alert on attacks, but cannot stop them?
- Question #66
An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces...
- Question #67
From the two screenshots below, which of the following is occurring? First one: 1 [10.0.0.253]# nmap -sP 10.0.0.0/24 3 Starting Nmap 5 Host 10.0.0.1 appears to be up. 6 MAC Address...
- Question #68
Pentest results indicate that voice over IP traffic is traversing a network. Which of the following tools will decode a packet capture and extract the voice conversations?
- Question #69
Which technical characteristic do Ethereal/Wireshark, TCPDump, and Snort have in common?
- Question #70
Which set of access control solutions implements two-factor authentication?
- Question #71
A security engineer has been asked to deploy a secure remote access solution that will allow employees to connect to the company's internal network. Which of the following can be i...
- Question #72
A person approaches a network administrator and wants advice on how to send encrypted email from home. The end user does not want to have to pay for any license fees or manage serv...
- Question #73
To send a PGP encrypted message, which piece of information from the recipient must the sender have before encrypting the message?
- Question #74
An engineer is learning to write exploits in C++ and is using the exploit tool Backtrack. The engineer wants to compile the newest C++ exploit and name it calc.exe. Which command w...
- Question #75
A recently hired network security associate at a local bank was given the responsibility to perform daily scans of the internal network to look for unauthorized devices. The employ...
- Question #76
A tester has been using the msadc.pl attack script to execute arbitrary commands on a Windows NT4 web server. While it is effective, the tester finds it tedious to perform extended...
- Question #77
One advantage of an application-level firewall is the ability to
- Question #78
Which of the statements concerning proxy firewalls is correct?
- Question #79
On a Linux device, which of the following commands will start the Nessus client in the background so that the Nessus server can be configured?
- Question #80
Which of the following tools will scan a network to perform vulnerability checks and compliance auditing?
- Question #81
What is the best defense against privilege escalation vulnerability?
- Question #82
How can a rootkit bypass Windows 7 operating system's kernel mode, code signing policy?
- Question #83
Which of the following items of a computer system will an anti-virus program scan for viruses?
- Question #84
Which protocol and port number might be needed in order to send log messages to a log analysis tool that resides behind a firewall?
- Question #85
A pentester is using Metasploit to exploit an FTP server and pivot to a LAN. How will the pentester pivot using Metasploit?
- Question #86
What is the outcome of the comm"nc -l -p 2222 | nc 10.1.0.43 1234"?
- Question #87
Which of the following is a client-server tool utilized to evade firewall inspection?
- Question #88
Which tool is used to automate SQL injections and exploit a database by forcing a given web application to connect to another database controlled by a hacker?
- Question #89
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see...
- Question #90
Which of the following identifies the three modes in which Snort can be configured to run?
- Question #91
When using Wireshark to acquire packet capture on a network, which device would enable the capture of all traffic on the wire?
- Question #92
Which of the following programming languages is most vulnerable to buffer overflow attacks?
- Question #93
Smart cards use which protocol to transfer the certificate in a secure manner?
- Question #94
Which of the following is a hashing algorithm?
- Question #95
Which of the following problems can be solved by using Wireshark?
- Question #96
What is the correct PCAP filter to capture all TCP traffic going to or from host 192.168.0.125 on port 25?
- Question #97
Which tool would be used to collect wireless packet data?
- Question #98
Which of the following is an example of two factor authentication?
- Question #99
Diffie-Hellman (DH) groups determine the strength of the key used in the key exchange process. Which of the following is the correct bit size of the Diffie-Hellman (DH) group 5?
- Question #100
After gaining access to the password hashes used to protect access to a web based application, knowledge of which cryptographic algorithms would be useful to gain access to the app...
- Question #101
What statement is true regarding LM hashes?
- Question #102
A developer for a company is tasked with creating a program that will allow customers to update their billing and shipping information. The billing address field used is limited to...
- Question #103
A security analyst in an insurance company is assigned to test a new web application that will be used by clients to help them choose and apply for an insurance plan. The analyst d...
- Question #104
A security administrator notices that the log file of the company's webserver contains suspicious entries: Based on source code analysis, the analyst concludes that the login.php s...