EC0-350 Exam Questions
892 real EC0-350 exam questions with expert-verified answers and explanations. Page 12 of 18.
- Question #556
Based on the following extract from the log of a compromised machine, what is the hacker really trying to steal?
- Question #557
As a securing consultant, what are some of the things you would recommend to a company to ensure DNS security? Select the best answers.
- Question #558
Why would you consider sending an email to an address that you know does not exist within the company you are performing a Penetration Test for?
- Question #559
What tool can crack Windows SMB passwords simply by listening to network traffic? Select the best answer.
- Question #560
A network admin contacts you. He is concerned that ARP spoofing or poisoning might occur on his network. What are some things he can do to prevent it? Select the best answers.
- Question #561
Peter, a Network Administrator, has come to you looking for advice on a tool that would help him perform SNMP enquires over the network. Which of these tools would do the SNMP enum...
- Question #562
If a token and 4-digit personal identification number (PIN) are used to access a computer system and the token performs off-line checking for the correct PIN, what type of attack i...
- Question #563
Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm througho...
- Question #564
Study the snort rule given below: From the options below, choose the exploit against which this rule applies.
- Question #565
Which of the following algorithms can be used to guarantee the integrity of messages being sent, in transit, or stored? (Choose the best answer)
- Question #566
A user on your Windows 2000 network has discovered that he can use L0phtcrack to sniff the SMB exchanges which carry user logons. The user is plugged into a hub with 23 other syste...
- Question #567
You are attempting to crack LM Manager hashed from Windows 2000 SAM file. You will be using LM Brute force hacking tool for decryption. What encryption algorithm will you be decryp...
- Question #568
In the context of password security, a simple dictionary attack involves loading a dictionary file (a text file full of dictionary words) into a cracking application such as L0phtC...
- Question #569
What is the algorithm used by LM for Windows2000 SAM?
- Question #570
E-mail scams and mail fraud are regulated by which of the following?
- Question #571
Which of the following LM hashes represent a password of less than 8 characters? (Select 2)
- Question #572
Which of the following is the primary objective of a rootkit?
- Question #573
This kind of password cracking method uses word lists in combination with numbers and special characters:
- Question #574
_________ is a tool that can hide processes from the process list, can hide files, registry entries, and intercept keystrokes.
- Question #575
What is the BEST alternative if you discover that a rootkit has been installed on one of your computers?
- Question #576
What do Trinoo, TFN2k, WinTrinoo, T-Sight, and Stracheldraht have in common?
- Question #577
How can you determine if an LM hash you extracted contains a password that is less than 8 characters long?
- Question #578
When discussing passwords, what is considered a brute force attack?
- Question #579
Which of the following are well know password-cracking programs?(Choose all that apply.
- Question #580
Password cracking programs reverse the hashing process to recover passwords.(True/False.)
- Question #581
While examining audit logs, you discover that people are able to telnet into the SMTP server on port 25. You would like to block this, though you do not see any evidence of an atta...
- Question #582
Windows LAN Manager (LM) hashes are known to be weak. Which of the following are known weaknesses of LM? (Choose three)
- Question #583
You have retrieved the raw hash values from a Windows 2000 Domain Controller. Using social engineering, you come to know that they are enforcing strong passwords. You understand th...
- Question #584
An attacker runs netcat tool to transfer a secret file between two hosts. Machine A: netcat -l -p 1234 < secretfile Machine B: netcat 192.168.3.4 > 1234 He is worried about informa...
- Question #586
Fingerprinting an Operating System helps a cracker because:
- Question #587
In the context of Windows Security, what is a 'null' user?
- Question #588
What does the following command in netcat do? nc -l -u -p55555 < /etc/passwd
- Question #589
What hacking attack is challenge/response authentication used to prevent?
- Question #590
What file system vulnerability does the following command take advantage of? type c:\anyfile.exe > c:\winnt\system32\calc.exe:anyfile.exe
- Question #591
Attackers can potentially intercept and modify unsigned SMB packets, modify the traffic and forward it so that the server might perform undesirable actions. Alternatively, the atta...
- Question #592
LM authentication is not as strong as Windows NT authentication so you may want to disable its use, because an attacker eavesdropping on network traffic will attack the weaker prot...
- Question #593
Which of the following keyloggers cannot be detected by anti-virus or anti-spyware products?
- Question #594
_____ is the process of converting something from one representation to the simplest form. It deals with the way in which systems convert data from one form to another.
- Question #595
Which type of attack is port scanning?
- Question #596
You are a Administrator of Windows server. You want to find the port number for POP3. What file would you find the information in and where? Select the best answer.
- Question #597
One of your junior administrator is concerned with Windows LM hashes and password cracking. In your discussion with them, which of the following are true statements that you would...
- Question #598
In the following example, which of these is the "exploit"? Today, Microsoft Corporation released a security notice. It detailed how a person could bring down the Windows 2003 Serve...
- Question #599
Assuring two systems that are using IPSec to protect traffic over the internet, what type of general attack could compromise the data?
- Question #600
What is a Trojan Horse?
- Question #601
You want to use netcat to generate huge amount of useless network data continuously for various performance testing between 2 hosts. Which of the following commands accomplish this...
- Question #602
After an attacker has successfully compromised a remote computer, what would be one of the last steps that would be taken to ensure that the compromise is not traced back to the so...
- Question #603
You have hidden a Trojan file virus.exe inside another file readme.txt using NTFS streaming. Which command would you execute to extract the Trojan to a standalone file?
- Question #604
You suspect that your Windows machine has been compromised with a Trojan virus. When you run anti-virus software it does not pick of the Trojan. Next you run netstat command to loo...
- Question #605
In Linux, the three most common commands that hackers usually attempt to Trojan are:
- Question #606
John wishes to install a new application onto his Windows 2000 server. He wants to ensure that any application he uses has not been Trojaned. What can he do to help ensure this?