EC0-350 Exam Questions
892 real EC0-350 exam questions with expert-verified answers and explanations. Page 6 of 18.
- Question #256
Which method can provide a better return on IT security investment and provide a thorough and comprehensive assessment of organizational security covering policy, procedure design,...
- Question #257
When using Wireshark to acquire packet capture on a network, which device would enable the capture of all traffic on the wire?
- Question #258
How does an operating system protect the passwords used for account logins?
- Question #259
Which of the following programs is usually targeted at Microsoft Office products?
- Question #260
What is the main difference between a "Normal" SQL Injection and a "Blind" SQL Injection vulnerability?
- Question #261
Which of the following ensures that updates to policies, procedures, and configurations are made in a controlled and documented fashion?
- Question #262
Data hiding analysis can be useful in
- Question #263
Smart cards use which protocol to transfer the certificate in a secure manner?
- Question #264
A company firewall engineer has configured a new DMZ to allow public systems to be located away from the internal network. The engineer has three security zones set: Untrust (Inter...
- Question #265
When comparing the testing methodologies of Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM) the main difference is
- Question #266
Which of the following is a protocol that is prone to a man-in-the-middle (MITM) attack and maps a 32-bit address to a 48-bit address?
- Question #267
Which NMAP feature can a tester implement or adjust while scanning for open ports to avoid detection by the network's IDS?
- Question #268
Windows file servers commonly hold sensitive files, databases, passwords and more. Which of the following choices would be a common vulnerability that usually exposes them?
- Question #269
Which type of access control is used on a router or firewall to limit network activity?
- Question #270
Which NMAP command combination would let a tester scan every TCP port from a class C network that is blocking ICMP with fingerprinting and service detection?
- Question #271
Which types of detection methods are employed by Network Intrusion Detection Systems (NIDS)? (Choose two.)
- Question #272
The fundamental difference between symmetric and asymmetric key cryptographic systems is that symmetric key cryptography uses which of the following?
- Question #273
Which command lets a tester enumerate alive systems in a class C network via ICMP using native Windows tools?
- Question #274
How can telnet be used to fingerprint a web server?
- Question #275
Which of the following problems can be solved by using Wireshark?
- Question #276
Which of the following is an example of an asymmetric encryption implementation?
- Question #277
What is the purpose of conducting security assessments on network resources?
- Question #278
A penetration tester was hired to perform a penetration test for a bank. The tester began searching for IP ranges owned by the bank, performing lookups on the bank's DNS servers, r...
- Question #279
Which of the following is an application that requires a host application for replication?
- Question #280
Which of the following is a characteristic of Public Key Infrastructure (PKI)?
- Question #281
What statement is true regarding LM hashes?
- Question #282
What is a successful method for protecting a router from potential smurf attacks?
- Question #283
Which of the following tools will scan a network to perform vulnerability checks and compliance auditing?
- Question #284
The use of technologies like IPSec can help guarantee the followinG. authenticity, integrity, confidentiality and
- Question #285
A security administrator notices that the log file of the company`s webserver contains suspicious entries: Based on source code analysis, the analyst concludes that the login.php s...
- Question #286
Which of the following is a detective control?
- Question #287
A penetration tester is attempting to scan an internal corporate network from the internet without alerting the border sensor. Which is the most efficient technique should the test...
- Question #288
A circuit level gateway works at which of the following layers of the OSI Model?
- Question #289
Which of the following lists are valid data-gathering activities associated with a risk assessment?
- Question #290
A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate web site from their workstations. Which of the following is the...
- Question #291
Which command line switch would be used in NMAP to perform operating system detection?
- Question #292
Bluetooth uses which digital modulation technique to exchange information between paired devices?
- Question #293
A security consultant decides to use multiple layers of anti-virus defense, such as end user desktop anti-virus and E-mail gateway. This approach can be used to mitigate which kind...
- Question #294
A security policy will be more accepted by employees if it is consistent and has the support of
- Question #295
There is a WEP encrypted wireless access point (AP) with no clients connected. In order to crack the WEP key, a fake authentication needs to be performed. What information is neede...
- Question #296
What type of OS fingerprinting technique sends specially crafted packets to the remote OS and analyzes the received response?
- Question #297
How do employers protect assets with security policies pertaining to employee surveillance activities?
- Question #298
When analyzing the IDS logs, the system administrator noticed an alert was logged when the external router was accessed from the administrator's computer to update the router confi...
- Question #299
Which of the following parameters enables NMAP's operating system detection feature?
- Question #300
Which of the following is an example of IP spoofing?
- Question #301
Which of the following processes of PKI (Public Key Infrastructure) ensures that a trust relationship exists and that a certificate is still valid for specific operations?
- Question #302
What is the correct PCAP filter to capture all TCP traffic going to or from host 192.168.0.125 on port 25?
- Question #303
When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?
- Question #304
Which element of Public Key Infrastructure (PKI) verifies the applicant?
- Question #305
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?