ML0-320 Exam Questions
238 real ML0-320 exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #158
System administrators need to be aware of what tool that adds while-bytes of executable code to an existing malicious binary with the goal of evading anti-trojan software using MD5...
- Question #159
Which of the following would best describe the meaning of steganography?
- Question #160
In symmetric cryptosystem, how many keys are needed to communicate securely between 10 different people who all wish to have a key pair to talk to each other?
- Question #161
What technology has made trojans easy to distribute? Choose the best Answer:.
- Question #162
It is common knowledge that a Penetration Test relies on a testers ability to collect information from different sources. Only about 35% to 40% of the information collected will be...
- Question #163
One of your clients has been the victim of a brute force attack against their SSH server. They ask you what could be done to protect their Linux servers. You propose the use of IP...
- Question #164
Which of the following best describes a Script Kiddie?
- Question #165
Assuming SNMP Agent devices are IPSec-capable, why would implementing IPSec help protect SNMP Agents? Choose three.
- Question #166
Which tools and or techniques can be used to remove an Alternative Data Stream on an NTFS file? Choose two.
- Question #168
Bob is working as an Instrusion Detection System administrator for a company called CCCure. Being a keen analyst he has noted a very large amount of SYN packet being sent to some o...
- Question #169
An administrator has just completed the installation of Nessus on a Linux System that will only have physical space for the server and no monitor.The administrator was told that Ne...
- Question #170
When doing an ACK flag scanning the target host is sent TCP packets with the ACK flag set and the reply is then analyzed. Which of the following items within the response packets w...
- Question #171
There are multiples ways that passwords could be cracked. Which of the following is not a password cracking method?
- Question #172
When referring to database, what would you call the number of rows within a table?
- Question #173
If an attacker gets Adminsitrative-level access, why cant the entries in the Event log be trusted with certainty? Choose two.
- Question #174
Jhezza has just arrived at her office and she is checking her stock portfolio as she does every day. She connects to her broker web site and decides to buy some stocks that are hig...
- Question #176
Which of the following SQL injection scripts would attempt to discover all usernames on the table users beginning with Ad?
- Question #177
Why wouldn't it be surprising to find netcat on a trojaned-computer? Choose three.
- Question #178
Which of the following techniques would be effective to get around some of the blocking rules on certain firewalls? The same technique could be used to avoid detection by intrusion...
- Question #179
When a digital certificate has been revoked before its expiry date, how will the Certification Authority (CA) that issued the certificate inform other CAs that the specific certifi...
- Question #180
Examining all web pages from a site might be a tedious task. In order to facilitate such as task you can make use of a web crawler. Which of the choices presented below would best...
- Question #181
While performing a penetration test you discover that the system being tested is already compromised by an intruder. Further examination shows the intruder being currently on the s...
- Question #182
Why is it often recommended to rename the built-in Administrator account on a Windows 2000 domain? Choose the best Answer:.
- Question #183
Which of the following pieces of information can be obtained from a Whois query? Choose all that apply.
- Question #184
A Denial of Service (DoS) attack can have severe effect on a company network or systems.What is the main purpose of a DoS attack? Choose the best response.
- Question #185
John is attempting to reduce the likelihood that his Linux server could be compromised through exploitation of ports and services that are not necessary or through the use of packe...
- Question #186
Password attack fall within two main categoriesSocial Attacks and Digital Attacks. Which of the following would not be considered a Social Attack on passwords?
- Question #187
proactive in their security approach. Most likely there are some Intrusion Detection Systems (IDS) in place that would quickly identify Julius IP address and he would then be block...
- Question #188
Bob has accessed a nice site that sells high end wireless network equipment. However, after looking around for a while it was obvious that most items were too expensive for his low...
- Question #189
BASIC authentication for HTTP authentication is universally understood but has the disadvantage of passing username and password in BASE64 encoding. What technology could be used t...
- Question #190
security test on some of their servers. Over the past few days Joshua has been collecting tons of information about his target. He did so by accessing public database and never sen...
- Question #191
The process of flooding a local segment with thousands of random MAC addresses can result in some switches behaving like a hub. The goal of the hacker is to accomplish what? Choose...
- Question #192
What is one possible method that hackers can use to sniff SSL connections? Choose the best Answer:.
- Question #193
You have noticed that one of your users has installed a tool named KerbCrack as well as another tool named KerbSniff on his machine withou your authroization. The company is making...
- Question #194
The Advanced Encryption Standard (AES) was released to protect sensitive data used by US.Government organizations. Up to what classification level was AES built for?
- Question #195
Vulnerabilities Scanners have large databases of known vulnerabilities and exposures that exist within a very large number of operating systems and applications. Most scanners are...
- Question #196
What technology is often used by employees to get access to web sites that are blocked by their corporate proxy server? Choose the best Answer:.
- Question #197
Cracking encryption is often impossible due to time constraints whereby it would take hundreds of years in some cases. Great advancement has taken place lately regarding the cracki...
- Question #198
Which of these methods would be considered examples of active reconnaissance? (Choose three.)
- Question #199
Bob has just produced a very detailed penetration testing report for his client.Bob wishes to ensure that the report will not be changed in storage or in transit. What would be the...
- Question #200
Which of the following is the best method to counteract offline password cracking? Choose the best Answer:.
- Question #201
Which of the following could be countermeasures to scanning? Choose all that apply.
- Question #202
Which of the following are reasons why LAN Manager hashes stored in the SAM file are considered relatively easy to crack? Choose two.
- Question #203
A null session allows users to connect remotely to other Windows computers on the network.According to the implementation of NULL Session on Windows platforms, how long would the p...
- Question #204
Todays security infrastructures are composed of firewall, instrusion detection systems, content screening, certificates, tokens, and a lot more. Howeve, there is still one aspect t...
- Question #205
You have successfully exploited a remote computer. You now have limited privilege on the remote computer. You tests have revealed that it is possible to download files from the int...
- Question #206
Keen administrators (the enemy of penetration testers)will take great steps in order to collect logs on different servers.By having a detailed log of activities they may be able to...
- Question #207
What is the most secure method of implementing Software Restriction Policies to prevent users from running both unauthorized and undesirable software? Choose the best Answer:.
- Question #208
One of the challenges when doing large scale security tests is the time required. If you have to scan a class B network it might take you a very long time. Scanrand is a tool that...
- Question #209
When talking about databases search query languages, commands such as Select, Update, Insert, Grant, and Revoke would all the part of what language?