412-79V8 Exam Questions
200 real 412-79V8 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Mason is footprinting an organization to gather competitive intelligence. He visits the company's website for contact information and telephone numbers but does not find any. He kn...
- Question #2
Application security assessment is one of the activity that a pen tester performs in the attack phase. It is designed to identify and assess threats to the organization through bes...
- Question #3
Which of the following is not a characteristic of a firewall?
- Question #4
John, the penetration testing manager in a pen testing firm, needs to prepare a pen testing pricing report for a client. Which of the following factors does he need to consider whi...
- Question #5
A wireless intrusion detection system (WIDS) monitors the radio spectrum for the presence of unauthorized, rogue access points and the use of wireless attack tools. The system moni...
- Question #6
A penetration test will show you the vulnerabilities in the target system and the risks associated with it. An educated valuation of the risk will be performed so that the vulnerab...
- Question #7
Which of the following is not the SQL injection attack character?
- Question #8
Which of the following is the objective of Gramm-Leach-Bliley Act?
- Question #9
Which of the following contents of a pen testing project plan addresses the strengths, weaknesses, opportunities, and threats involved in the project?
- Question #10
In a TCP packet filtering firewall, traffic is filtered based on specified session rules, such as when a session is initiated by a recognized computer. Identify the level up to whi...
- Question #11
Which of the following are the default ports used by NetBIOS service?
- Question #12
Phishing is typically carried out by email spoofing or instant messaging and it often directs users to enter details at a fake website whose look and feel are almost identical to t...
- Question #13
What is the maximum value of a "tinyint" field in most database systems?
- Question #14
Which of the following policies states that the relevant application owner must authorize requests for additional access to specific business applications in writing to the IT Depa...
- Question #15
Black-box testing is a method of software testing that examines the functionality of an application (e.g. what the software does) without peering into its internal structures or wo...
- Question #16
Which of the following is NOT related to the Internal Security Assessment penetration testing strategy?
- Question #17
What are placeholders (or markers) in an HTML document that the web server will dynamically replace with data just before sending the requested documents to a browser?
- Question #18
Attackers create secret accounts and gain illegal access to resources using backdoor while bypassing the authentication procedures. Creating a backdoor is a where an attacker obtai...
- Question #19
Rule of Engagement (ROE) is the formal permission to conduct a pen-test. It provides top- level guidance for conducting the penetration testing. Various factors are considered whil...
- Question #20
Which of the following protocols cannot be used to filter VoIP traffic?
- Question #21
A penetration test consists of three phases: pre-attack phase, attack phase, and post- attack phase. Active reconnaissance which includes activities such as network mapping, web pr...
- Question #22
Identify the type of testing that is carried out without giving any information to the employees or administrative head of the organization.
- Question #23
Before performing the penetration testing, there will be a pre-contract discussion with different pen-testers (the team of penetration testers) to gather a quotation to perform pen...
- Question #24
Identify the transition mechanism to deploy IPv6 on the IPv4 network from the following diagram.
- Question #25
John, a penetration tester, was asked for a document that defines the project, specifies goals, objectives, deadlines, the resources required, and the approach of the project. Whic...
- Question #26
A WHERE clause in SQL specifies that a SQL Data Manipulation Language (DML) statement should only affect rows that meet specified criteria. The criteria are expressed in the form o...
- Question #27
External penetration testing is a traditional approach to penetration testing and is more focused on the servers, infrastructure and the underlying software comprising the target....
- Question #28
What information can be collected by dumpster diving?
- Question #29
In which of the following firewalls are the incoming or outgoing packets blocked from accessing services for which there is no proxy?
- Question #30
Which of the following policies helps secure data and protects the privacy of organizational information?
- Question #31
Why is a legal agreement important to have before launching a penetration test?
- Question #32
What are the 6 core concepts in IT security?
- Question #33
Which vulnerability assessment phase describes the scope of the assessment, identifies and ranks the critical assets, and creates proper information protection procedures such as e...
- Question #34
In Linux, /etc/shadow file stores the real password in encrypted format for user's account with added properties associated with the user's password. In the example of a /etc/shado...
- Question #35
What is a difference between host-based intrusion detection systems (HIDS) and network-based intrusion detection systems (NIDS)?
- Question #36
What is the difference between penetration testing and vulnerability testing?
- Question #37
Information gathering is performed to:
- Question #38
Which type of vulnerability assessment tool provides security to the IT system by testing for vulnerabilities in the applications and operation system?
- Question #39
A penetration tester performs OS fingerprinting on the target server to identify the operating system used on the target server with the help of ICMP packets. While performing ICMP...
- Question #40
Traffic on which port is unusual for both the TCP and UDP ports?
- Question #41
Which of the following statements is true about Multi-Layer Intrusion Detection Systems (mIDSs)?
- Question #42
Hackers today have anever-increasinglist of weaknesses in the web application structure at their disposal, which they can exploit to accomplish a wide variety of malicious tasks. N...
- Question #43
What sort of vulnerability assessment approach starts by building an inventory of protocols found on the machine?
- Question #44
During the process of fingerprinting a web application environment, what do you need to do in order to analyze HTTP and HTTPS request headers and the HTML source code?
- Question #45
Identify the type of firewall represented in the diagram below:
- Question #46
Due to illegal inputs, various types of TCP stacks respond in a different manner. Some IDSs do not take into account the TCP protocol's urgency feature, which could allow testers t...
- Question #47
Identify the correct formula for Return on Investment (ROI).
- Question #48
Identify the person who will lead thepenetration-testingproject and be the client point of contact.
- Question #49
A man enters a PIN number at an ATM machine, being unaware that the person next to him was watching. Which of the following social engineering techniques refers to this type of inf...
- Question #50
The Internet is a giant database where people store some of their most private information on the cloud, trusting that the service provider can keep it all safe. Trojans, Viruses,...