412-79V9 Exam Questions
184 real 412-79V9 exam questions with expert-verified answers and explanations. Page 1 of 4.
- Question #1
Which of the following password cracking techniques is used when the attacker has some information about the password?
- Question #2
Which of the following is an application alert returned by a web application that helps an attacker guess a valid username?
- Question #3
When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
- Question #4
HTTP protocol specifies that arbitrary binary characters can be passed within the URL by using %xx notation, where 'xx' is the
- Question #5
Which of the following is a framework of open standards developed by the Internet Engineering Task Force (IETF) that provides secure transmission of the sensitive data over an unpr...
- Question #6
An external intrusion test and analysis identify security weaknesses and strengths of the client's systems and networks as they appear from outside the client's security perimeter,...
- Question #7
Passwords protect computer resources and files from unauthorized access by malicious users. Using passwords is the most capable and effective way to protect information and to incr...
- Question #8
Rules of Engagement (ROE) document provides certain rights and restriction to the test team for performing the test and helps testers to overcome legal, federal, and policy-related...
- Question #9
Mason is footprinting an organization to gather competitive intelligence. He visits the company's website for contact information and telephone numbers but does not find any. He kn...
- Question #10
Application security assessment is one of the activity that a pen tester performs in the attack phase. It is designed to identify and assess threats to the organization through bes...
- Question #11
Which of the following is not a characteristic of a firewall?
- Question #12
The IP protocol was designed for use on a wide variety of transmission links. Although the maximum length of an IP datagram is 64K, most transmission links enforce a smaller maximu...
- Question #13
From where can clues about the underlying application environment can be collected?
- Question #14
Which of the following information gathering techniques collects information from an organization's web-based calendar and email services?
- Question #15
Which Wireshark filter displays all the packets where the IP address of the source host is 10.0.0.7?
- Question #16
Which of the following statements is true about the LM hash?
- Question #17
Which of the following statements holds true for TCP Operation?
- Question #18
Which of the following will not handle routing protocols properly?
- Question #19
What is a goal of the penetration testing report?
- Question #20
What type of attack would you launch after successfully deploying ARP spoofing?
- Question #21
Which agreement requires a signature from both the parties (the penetration tester and the company)?
- Question #22
John, the penetration testing manager in a pen testing firm, needs to prepare a pen testing pricing report for a client. Which of the following factors does he need to consider whi...
- Question #23
A wireless intrusion detection system (WIDS) monitors the radio spectrum for the presence of unauthorized, rogue access points and the use of wireless attack tools. The system moni...
- Question #24
What are the two types of 'white-box' penetration testing?
- Question #25
Which of the following is not the SQL injection attack character?
- Question #26
Which of the following is the objective of Gramm-Leach-Bliley Act?
- Question #27
In a TCP packet filtering firewall, traffic is filtered based on specified session rules, such as when a session is initiated by a recognized computer. Identify the level up to whi...
- Question #28
Phishing is typically carried out by email spoofing or instant messaging and it often directs users to enter details at a fake website whose look and feel are almost identical to t...
- Question #29
Which of the following are the default ports used by NetBIOS service?
- Question #30
What is the maximum value of a "tinyint" field in most database systems?
- Question #31
Which of the following policies states that the relevant application owner must authorize requests for additional access to specific business applications in writing to the IT Depa...
- Question #32
Most commonly, SQL injection vulnerabilities are a result of coding vulnerabilities during the Implementation/Development phase and will likely require code changes. Pen testers ne...
- Question #33
Which of the following is NOT related to the Internal Security Assessment penetration testing strategy?
- Question #34
What are placeholders (or markers) in an HTML document that the web server will dynamically replace with data just before sending the requested documents to a browser?
- Question #35
Attackers create secret accounts and gain illegal access to resources using backdoor while bypassing the authentication procedures. Creating a backdoor is a where an attacker obtai...
- Question #36
Which of the following factors is NOT considered while preparing the scope of the Rules of Engagment (ROE)?
- Question #37
Which of the following protocols cannot be used to filter VoIP traffic?
- Question #38
Active reconnaissance which includes activities such as network mapping, web profiling, and perimeter mapping is a part which phase(s)?
- Question #39
Identify the type of testing that is carried out without giving any information to the employees or administrative head of the organization.
- Question #40
Which of the following factors is NOT considered while preparing a price quote to perform pen testing?
- Question #41
Identify the transition mechanism to deploy IPv6 on the IPv4 network from the following diagram.
- Question #42
John, a penetration tester, was asked for a document that defines the project, specifies goals, objectives, deadlines, the resources required, and the approach of the project. Whic...
- Question #43
A WHERE clause in SQL specifies that a SQL Data Manipulation Language (DML) statement should only affect rows that meet specified criteri a. The criteria are expressed in the form...
- Question #44
Which of the following types of penetration testing is performed with no prior knowledge of the site?
- Question #45
Which of the following pen testing tests yields information about a company's technology infrastructure?
- Question #46
While performing ICMP scanning using Nmap tool, message received/type displays "3 - Destination Unreachable[S!]" and code 3. Which of the following is an appropriate description of...
- Question #47
What is the difference between penetration testing and vulnerability testing?
- Question #48
Which type of vulnerability assessment tool provides security to the IT system by testing for vulnerabilities in the applications and operation system?
- Question #49
Traffic on which unusual for both the TCP and UDP ports?
- Question #50
Which of the following statements is true about Multi-Layer Intrusion Detection Systems (mlDSs)?