312-50V9 Exam Questions
613 real 312-50V9 exam questions with expert-verified answers and explanations. Page 9 of 13.
- Question #401Malware Threats
Which of the following is an application that requires a host application for replication?
virusmalware typeshost dependencyreplication - Question #402Hacking Mobile Platforms
A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. The analyst will use the Blackjacking att...
BlackjackingBBProxyBlackberrymobile attack tools - Question #403Introduction to Ethical Hacking
Which of the following can the administrator do to verify that a tape backup can be recovered in its entirety?
backup verificationtape restoredata recoveryintegrity validation - Question #404Malware Threats
Which of the following describes the characteristics of a Boot Sector Virus?
boot sector virusMBRvirus typesdisk infection - Question #405Hacking Web Applications
Which statement is TRUE regarding network firewalls preventing Web Application attacks?
network firewallweb application attacksport 80port 443 - Question #406Malware Threats
Which of the following programs is usually targeted at Microsoft Office products?
macro virusMicrosoft Officevirus typesdocument infection - Question #407Hacking Wireless Networks
Bluetooth uses which digital modulation technique to exchange information between paired devices?
BluetoothPSKmodulationwireless protocols - Question #408Introduction to Ethical Hacking
In order to show improvement of security over time, what must be developed?
security metricssecurity improvementmeasurementreporting - Question #409Footprinting and Reconnaissance
Passive reconnaissance involves collecting information through which of the following?
passive reconnaissanceOSINTpublicly accessible sourcesinformation gathering - Question #410System Hacking
How can rainbow tables be defeated?
rainbow tablespassword saltingpassword crackinghash attacks - Question #411System Hacking
The following is a sample of output from a penetration tester's machine targeting a machine with the IP address of 192.168.1.106: What is most likely taking place?
brute forceremote service attackpenetration testingcredential attack - Question #412Hacking Web Applications
Which statement best describes a server type under an N-tier architecture?
N-tier architectureweb architectureserver rolesapplication tiers - Question #413System Hacking
If an e-commerce site was put into a live environment and the programmers failed to remove the secret entry point that was used during the application development, what is this sec...
trap doorbackdoorSDLCweb application security - Question #414Scanning Networks
A technician is resolving an issue where a computer is unable to connect to the Internet using a wireless access point. The computer is able to transfer files locally to other mach...
default gatewayIP addressingnetwork troubleshootingrouting - Question #415Denial of Service
Which of the following network attacks relies on sending an abnormally large packet size that exceeds TCP/ IP specifications?
ping of deathoversized packetsDoS attack typesTCP/IP - Question #416Evading IDS, Firewalls, and Honeypots
Which NMAP feature can a tester implement or adjust while scanning for open ports to avoid detection by the network's IDS?
NMAPtiming optionsIDS evasionstealth scanning - Question #417Introduction to Ethical Hacking
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is
OWASPOSSTMMtesting methodologysecurity controls - Question #418Hacking Web Applications
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?
OWASPWebGoatvulnerable applicationsecurity training - Question #419Introduction to Ethical Hacking
What are the three types of compliance that the Open Source Security Testing Methodology Manual (OSSTMM) recognizes?
OSSTMMcompliance typeslegislativecontractual - Question #420Cryptography
Which of the following algorithms provides better protection against brute force attacks by using a 160-bit message digest?
SHA-1message digestbrute force protectionhashing algorithms - Question #421Cryptography
Which cipher encrypts the plain text digit (bit or byte) one by one?
stream ciphersymmetric encryptioncipher typesbit-by-bit encryption - Question #422Evading IDS, Firewalls, and Honeypots
Which of the following types of firewall inspects only header information in network traffic?
packet filterfirewall typesheader inspectionnetwork traffic filtering - Question #423Evading IDS, Firewalls, and Honeypots
During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this res...
ACK scanstateless inspectionNMAPfirewall behavior - Question #424Evading IDS, Firewalls, and Honeypots
Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drawn based on these scan results? TCP p...
FirewalkTTL exceededfirewall port filteringpacket gateway analysis - Question #425Cryptography
Which of the following is an example of an asymmetric encryption implementation?
asymmetric encryptionPGPpublic key cryptographyencryption types - Question #426Cryptography
A hacker was able to sniff packets on a company's wireless network. The following information was discovered: The Key 10110010 01001011 The Cyphertext 01100101 01011010 Using the E...
XOR cipherstream cipherwireless encryptionciphertext decryption - Question #427Cryptography
Which of the following cryptography attack methods is usually performed without the use of a computer?
rubber hose attackcryptanalysisphysical coercionnon-technical attack - Question #428Introduction to Ethical Hacking
Which of the following is a strong post designed to stop a car?
bollardphysical securityperimeter securityvehicle barrier - Question #429Introduction to Ethical Hacking
A Network Administrator was recently promoted to Chief Security Officer at a local university. One of employee's new responsibilities is to manage the implementation of an RFID car...
segregation of dutiesRFID access controlsecurity controlsprivilege management - Question #430Cryptography
What is the most secure way to mitigate the theft of corporate information from a laptop that was left in a hotel room?
disk encryptiondata protectionlaptop securitydata theft mitigation - Question #431Footprinting and Reconnaissance
Which system consists of a publicly available set of databases that contain domain name registration contact information?
WHOISdomain registrationpublic databaseDNS information - Question #432Footprinting and Reconnaissance
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, r...
passive reconnaissanceOSINTDNS lookupdumpster diving - Question #433Scanning Networks
The following is part of a log file taken from the machine on the network with the IP address of 192.168.1.106: Time:Mar 13 17:30:15 Port:20 Source:192.168.1.103 Destination:192.16...
port scansequential scanninglog analysisTCP scanning - Question #434Enumeration
A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer...
banner grabbingnetcatHTTP headersweb server fingerprinting - Question #435Enumeration
An NMAP scan of a server shows port 69 is open. What risk could this pose?
TFTPport 69unauthenticated accessUDP services - Question #436Introduction to Ethical Hacking
What information should an IT system analysis provide to the risk assessor?
security architecturerisk assessmentIT system analysisinformation security management - Question #437Footprinting and Reconnaissance
Which results will be returned with the following Google search query? site:target.com -site:Marketing.target.com accounting
Google dorkingsite operatorOSINTsearch engine reconnaissance - Question #438Introduction to Ethical Hacking
A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should...
impact analysisaudit controlsrisk managementsecurity policy - Question #439Introduction to Ethical Hacking
Which of the following is a preventive control?
preventive controlsmart card authenticationaccess control typessecurity controls - Question #440Hacking Wireless Networks
A new wireless client is configured to join a 802.11 network. This client uses the same hardware and software as many of the other clients on the network. The client can see the ne...
MAC filteringWAP association802.11wireless access control - Question #441Evading IDS, Firewalls, and Honeypots
An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network's external DMZ. The packet...
IDS alertsPCAP analysisprotocol analyzerfalse positive detection - Question #442Hacking Web Applications
An attacker gains access to a Web server's database and displays the contents of the table that holds all of the names, passwords, and other user information. The attacker did this...
input validationSQL injectionweb application securitydatabase access - Question #443Introduction to Ethical Hacking
Which of the following is a protocol specifically designed for transporting event messages?
SYSLOGevent messaginglogging protocolnetwork protocols - Question #444Scanning Networks
Which of the following security operations is used for determining the attack surface of an organization?
attack surfacenetwork scanningDMZreconnaissance - Question #445Introduction to Ethical Hacking
The security concept of "separation of duties" is most similar to the operation of which type of security device?
separation of dutiesfirewallsecurity controlsaccess control - Question #446Introduction to Ethical Hacking
The "black box testing" methodology enforces which kind of restriction?
black box testingpenetration testing methodologyexternal testingno prior knowledge - Question #447Introduction to Ethical Hacking
The "gray box testing" methodology enforces what kind of restriction?
gray box testingpenetration testing methodologypartial knowledgetesting restrictions - Question #448Introduction to Ethical Hacking
The "white box testing" methodology enforces what kind of restriction?
white box testingpenetration testing methodologyfull knowledgeinternal access - Question #449Scanning Networks
A penetration tester is conducting a port scan on a specific host. The tester found several ports opened that were confusing in concluding the Operating System (OS) version install...
NMAPport scanningservice identificationOS fingerprinting - Question #450Scanning Networks
What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?
OS fingerprintingactive scanningpacket craftingnetwork probing