EC0-350 Exam Questions
892 real EC0-350 exam questions with expert-verified answers and explanations. Page 13 of 18.
- Question #607
Jason's Web server was attacked by a trojan virus. He runs protocol analyzer and notices that the trojan communicates to a remote server on the Internet. Shown below is the standar...
- Question #608
Which of the following Netcat commands would be used to perform a UDP scan of the lower 1024 ports?
- Question #609
Sniffing is considered an active attack.
- Question #610
A file integrity program such as Tripwire protects against Trojan horse attacks by:
- Question #611
Erik notices a big increase in UDP packets sent to port 1026 and 1027 occasionally. He enters the following at the command prompt. $ nc -l -p 1026 -u -v In response, he sees the fo...
- Question #612
What does the command in the exhibit do in "Ettercap"? ettercap -NCLzs --quiet
- Question #613
A remote user tries to login to a secure network using Telnet, but accidently types in an invalid user name or password. Which responses would NOT be preferred by an experienced Se...
- Question #614
A POP3 client contacts the POP3 server:
- Question #615
Samantha was hired to perform an internal security test of XYZ. She quickly realized that all networks are making use of switches instead of traditional hubs. This greatly limits h...
- Question #616
Ethereal works best on ____________.
- Question #617
The follows is an email header. What address is that of the true originator of the message?
- Question #618
Bob wants to prevent attackers from sniffing his passwords on the wired network. Which of the following lists the best options?
- Question #619
Which tool/utility can help you extract the application layer data from each TCP connection from a log file into separate files?
- Question #620
Which of the following display filters will you enable in Ethereal to view the three-way handshake for a connection from host 192.168.0.1?
- Question #621
When Jason moves a file via NFS over the company's network, you want to grab a copy of it by sniffing. Which of the following tool accomplishes this?
- Question #622
Which of the following is not considered to be a part of active sniffing?
- Question #623
ARP poisoning is achieved in _____ steps
- Question #624
How would you describe a simple yet very effective mechanism for sending and receiving unauthorized information or data between machines without alerting any firewalls and IDS's on...
- Question #625
You have captured some packets in Ethereal. You want to view only packets sent from 10.0.0.22. What filter will you apply?
- Question #626
Tess King, the evil hacker, is purposely sending fragmented ICMP packets to a remote target. The total size of this ICMP packet once reconstructed is over 65, 536 bytes. From the i...
- Question #627
Which one of the following instigates a SYN flood attack?
- Question #628
Global deployment of RFC 2827 would help mitigate what classification of attack?
- Question #629
What happens when one experiences a ping of death?
- Question #630
Which one of the following network attacks takes advantages of weaknesses in the fragment reassembly functionality of the TCP/IP protocol stack?
- Question #631
A denial of Service (DoS) attack works on the following principle:
- Question #632
What happens during a SYN flood attack?
- Question #633
What is the term 8 to describe an attack that falsifies a broadcast ICMP echo request and includes a primary and secondary victim?
- Question #634
What is the goal of a Denial of Service Attack?
- Question #635
What do you call a system where users need to remember only one username and password, and be authenticated for multiple services?
- Question #636
Clive has been monitoring his IDS and sees that there are a huge number of ICMP Echo Reply packets that are being received on the external gateway interface. Further inspection rev...
- Question #637
What would best be defined as a security test on services against a known vulnerability database using an automated tool?
- Question #638
A Buffer Overflow attack involves:
- Question #639
When working with Windows systems, what is the RID of the true administrator account?
- Question #640
If you send a SYN to an open port, what is the correct response?(Choose all correct answers.
- Question #641
When working with Windows systems, what is the RID of the true administrator account?
- Question #642
You have been called to investigate a sudden increase in network traffic at XYZ. It seems that the traffic generated was too heavy that normal business functions could no longer be...
- Question #643
Henry is an attacker and wants to gain control of a system and use it to flood a target system with requests, so as to prevent legitimate users from gaining access. What type of at...
- Question #644
Eve decides to get her hands dirty and tries out a Denial of Service attack that is relatively new to her. This time she envisages using a different kind of method to attack Browni...
- Question #645
Peter is a Network Admin. He is concerned that his network is vulnerable to a smurf attack. What should Peter do to prevent a smurf attack? Select the best answer.
- Question #646
John is using tokens for the purpose of strong authentication. He is not confident that his security is considerably strong. In the context of Session hijacking why would you consi...
- Question #647
What is the key advantage of Session Hijacking?
- Question #648
What type of cookies can be generated while visiting different web sites on the Internet?
- Question #649
Which is the right sequence of packets sent during the initial TCP three way handshake?
- Question #650
What is Hunt used for?
- Question #651
You want to carry out session hijacking on a remote server. The server and the client are communicating via TCP after a successful TCP three way handshake. The server has just rece...
- Question #652
How would you prevent session hijacking attacks?
- Question #653
Which of the following attacks takes best advantage of an existing authenticated connection?
- Question #654
Tess King is making use of Digest Authentication for her Web site. Why is this considered to be more secure than Basic authentication?
- Question #655
You have successfully run a buffer overflow attack against a default IIS installation running on a Windows 2000 Server. The server allows you to spawn a shell. In order to perform...
- Question #656
You wish to determine the operating system and type of web server being used. At the same time you wish to arouse no suspicion within the target organization. While some of the met...