412-79V10 Exam Questions
319 real 412-79V10 exam questions with expert-verified answers and explanations. Page 4 of 7.
- Question #151
What is the difference between host-based intrusion detection systems (HIDS) and network-based intrusion detection systems (NIDS)?
- Question #152
A chip-set is a group of integrated circuits that are designed to work together and are usually marketed as a single product." It is generally the motherboard chips or (the logic g...
- Question #153
In the process of hacking a web application, attackers manipulate the HTTP requests to subvert the application authorization schemes by modifying input fields and parameters that a...
- Question #154
Which of the following IDS evasion techniques does IDS reject the packets that an end system accepts?
- Question #155
Besides the policy implications of chat rooms, Internet Relay Chat (IRC) is frequented by attackers and used as a command and control mechanism. IRC normally uses which one of the...
- Question #156
Internet Control Message Protocol (ICMP) messages occur in many situations, such as whenever a datagram cannot reach the destination or the gateway does not have the buffering capa...
- Question #157
John and Hillary works at the same department in the company. John wants to find out Hillary's network password so he can take a look at her documents on the network. He decides to...
- Question #158
Harold is a security analyst who has just run the rdisk /s command to grab the backup SAM file on a computer. Where should Harold navigate on the computer to find the file?
- Question #159
Which of the following log analysis tools is a Cisco Router Log Format log analyzer and it parses logs, imports them into a SQL database (or its own built-in database), aggregates...
- Question #160
Identify the policy that defines the standards for the organizational network connectivity and security standards for computers that are connected in the organization's network?
- Question #161
System/service FTP server listens on UDP port 69. Which of the following utility reports the port status of target TCP and UDP ports on a local or a remote computer and is used to...
- Question #162
Traffic on which port is unusual for both the TCP and UDP ports?
- Question #163
Identify the type of testing that is carried out without giving any information to the employees or administrative head of the organization.
- Question #164
Identify the person who will lead the penetration-testing project and be the client point of contact.
- Question #165
ARP spoofing is a technique whereby an attacker sends fake ("spoofed") Address Resolution Protocol (ARP) messages onto a Local Area Network. Generally, the attacker spoofs the MAC...
- Question #166
Which of the following password hashing algorithms is used in the NTLMv2 authentication mechanism?
- Question #167
Which of the following will not handle routing protocols properly?
- Question #168
TCP/IP provides a broad range of communication protocols for the various applications on the network. The TCP/IP model has four layers with major protocols included with each layer...
- Question #169
What is the maximum value of a "tinyint" field in most database systems?
- Question #170
After passing her CEH exam, Carol wants to ensure that her network is completely secure. She implements a DMZ, statefull firewall, NAT, IPSEC, and a packet filtering firewall. Sinc...
- Question #171
What are the 6 core concepts in IT security?
- Question #172
What are the scanning techniques that are used to bypass firewall rules and logging mechanisms and disguise themselves as usual network traffic?
- Question #173
What is the difference between penetration testing and vulnerability testing?
- Question #174
Which of the following defines the details of services to be provided for the client's organization and the list of services required for performing the test in the organization?
- Question #175
You are a security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. You ha...
- Question #176
Which of the following attributes has a LM and NTLMv1 value as 64bit + 64bit + 64bit and NTLMv2 value as 128 bits?
- Question #177
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
- Question #178
Which of the following acts makes reputational risk of poor security a reality because it requires public disclosure of any security breach that involves personal information if it...
- Question #179
A wireless intrusion detection system (WIDS) monitors the radio spectrum for the presence of unauthorized, rogue access points and the use of wireless attack tools. The system moni...
- Question #180
Which is the first step in preparing a Rules of Engagement (ROE) document?
- Question #181
When setting up a wireless network with multiple access points, why is it important to set each access point on a different channel?
- Question #182
Which of the following is developed to address security concerns on time and reduce the misuse or threat of attacks in an organization?
- Question #183
Which one of the following log analysis tools is used for analyzing the server's log files?
- Question #184
Which one of the following attacks does a hacker perform in order to obtain UDDI information such as businessEntity, businessService, bindingTemplate, and tModel?
- Question #185
Which one of the following Snort logger mode commands is associated to run a binary log file through Snort in sniffer mode to dump the packets to the screen?
- Question #186
Which of the following approaches to vulnerability assessment relies on the administrator providing baseline of system configuration and then scanning continuously without incorpor...
- Question #187
You work in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes...
- Question #188
Choose the correct option to define the Prefix Length.
- Question #189
Security auditors determine the use of WAPs on their networks with Nessus vulnerability scanner which identifies the commonly used WAPs. This information is not always accurate eno...
- Question #190
You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have successfully found...
- Question #191
Identify the correct formula for Return on Investment (ROI).
- Question #192
What is the biggest source of data leaks in organizations today?
- Question #193
Which of the following is a command line tool used for capturing data from the live network and copying those packets to a file?
- Question #194
Which of the following reports provides a summary of the complete pen testing process, its outcomes, and recommendations?
- Question #195
Penetration testing engagement (ROE) is the formal permission to conduct a pen-test. It provides top-level guidance for conducting the penetration testing. Various factors are cons...
- Question #196
Which is a security method to prevent unauthorized users from "tailgating"?
- Question #197
Which of the following device that is designed to transmit and receive the electromagnetic waves that are generally called radio waves. Which one of the following types of antenna...
- Question #198
Software firewalls work at which layer of the OSI model?
- Question #199
If a web application sends HTTP cookies as its method for transmitting session tokens, it may be vulnerable which of the following attacks?
- Question #200
How many bits is Source Port Number in TCP Header packet?