πŸ”

312-50v13 β€” questions

Page 13 of 16 Β· 308 total questions.

Topic 1 Β· Question 241

Gregory, a professional penetration tester working at Sys Security Ltd., is tasked with performing a security test of web applications used in the company. For this purpose, Gregory uses a tool to test for any security loopholes by hijacking a session between a client and server. This tool has a feature of intercepting proxy that can be used to inspect and modify the traffic between the browser and target application. This tool can also perform customized attacks and can be used to test the randomness of session tokens. Which of the following tools is used by Gregory in the above scenario?

  • AWireshark
  • BNmap
  • CBurp Suite (correct answer)
  • DCxSAST
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Burp Suite

Explanation

Burp Suite intercepts, inspects, and tests web application traffic for security weaknesses. This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 242

A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?

  • APerform a vulnerability scan of the system.
  • BDetermine the impact of enabling the audit feature. (correct answer)
  • CPerform a cost/benefit analysis of the audit feature.
  • DAllocate funds for staffing of audit log review.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Determine the impact of enabling the audit feature.

Topic 1 Β· Question 243

A penetration tester is performing the footprinting process and is reviewing publicly available information about an organization by using the Google search engine. Which of the following advanced operators would allow the pen tester to restrict the search to the organization’s web domain?

  • A[allinurl:]
  • B[location:]
  • C[site:] (correct answer)
  • D[link:]
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: [site:]

Topic 1 Β· Question 244

A security analyst uses Zenmap to perform an ICMP timestamp ping scan to acquire information related to the current time from the target host machine. Which of the following Zenmap options must the analyst use to perform the ICMP timestamp ping scan?

  • A-Pn
  • B-PU
  • C-PP (correct answer)
  • D-PY
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: -PP This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 245

An attacker decided to crack the passwords used by industrial control systems. In this process, he employed a loop strategy to recover these passwords. He used one character at a time to check whether the first character entered is correct; if so, he continued the loop for consecutive characters. If not, he terminated the loop. Furthermore, the attacker checked how much time the device took to finish one complete password authentication process, through which he deduced how many characters entered are correct. What is the attack technique employed by the attacker to crack the passwords of the industrial control systems?

  • ABuffer overflow attack
  • BSide-channel attack (correct answer)
  • CDenial-of-service attack
  • DHMI-based attack
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Side-channel attack

Topic 1 Β· Question 246

Which type of attack attempts to overflow the content-addressable memory (CAM) table in an Ethernet switch?

  • ADDoS attack
  • BEvil twin attack
  • CDNS cache flooding
  • DMAC flooding (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: MAC flooding

Topic 1 Β· Question 247

What is the following command used for?

Exhibit 1 for question 247
  • ARetrieving SQL statements being executed on the database
  • BCreating backdoors using SQL injection
  • CEnumerating the databases in the DBMS for the URL (correct answer)
  • DSearching database statements at the IP address given
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Enumerating the databases in the DBMS for the URL

Topic 1 Β· Question 248

Jane is working as a security professional at CyberSol Inc. She was tasked with ensuring the authentication and integrity of messages being transmitted in the corporate network. To encrypt the messages, she implemented a security model in which every user in the network maintains a ring of public keys. In this model, a user needs to encrypt a message using the receiver’s public key, and only the receiver can decrypt the message using their private key. What is the security model implemented by Jane to secure corporate messages?

  • AZero trust network
  • BSecure Socket Layer (SSL)
  • CTransport Layer Security (TLS)
  • DWeb of trust (WOT) (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Web of trust (WOT) This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 249

Clark, a professional hacker, attempted to perform a Btlejacking attack using an automated tool, BtleJack, and hardware tool, micro:bit. This attack allowed Clark to hijack, read, and export sensitive information shared between connected devices. To perform this attack, Clark executed various btlejack commands. Which of the following commands was used by Clark to hijack the connections?

  • Abtlejack -f 0x9c68fd30 -t -m 0x1fffffffff
  • Bbtlejack -c any
  • Cbtlejack -d /dev/ttyACM0 -d /dev/ttyACM2 -s
  • Dbtlejack -f 0x129f3244 -j (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: btlejack -f 0x129f3244 -j

Topic 1 Β· Question 250

John, a professional hacker, targeted CyberSol Inc., an MNC. He decided to discover the IoT devices connected in the target network that are using default credentials and are vulnerable to various hijacking attacks. For this purpose, he used an automated tool to scan the target network for specific types of IoT devices and detect whether they are using the default, factory-set credentials. What is the tool employed by John in the above scenario?

  • AIoT Inspector
  • BAT&T IoT Platform
  • CIoTSeeker (correct answer)
  • DAzure IoT Central
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: IoTSeeker

Topic 1 Β· Question 251

Tony wants to integrate a 128-bit symmetric block cipher with key sizes of 128, 192, or 256 bits into a software program, which involves 32 rounds of computational operations that include substitution and permutation operations on four 32-bit word blocks using 8-variable S-boxes with 4-bit entry and 4-bit exit. Which of the following algorithms includes all the above features and can be integrated by Tony into the software program?

  • ACAST-128
  • BRC5
  • CTEA
  • DSerpent (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Serpent

Topic 1 Β· Question 252

Jacob works as a system administrator in an organization. He wants to extract the source code of a mobile application and disassemble the application to analyze its design flaws. Using this technique, he wants to fix any bugs in the application, discover underlying vulnerabilities, and improve defense strategies against attacks. What is the technique used by Jacob in the above scenario to improve the security of the mobile application?

  • AReverse engineering (correct answer)
  • BApp sandboxing
  • CJailbreaking
  • DSocial engineering
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Reverse engineering This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 253

Mirai malware targets IoT devices. After infiltration, it uses them to propagate and create botnets that are then used to launch which types of attack?

  • AMITM attack
  • BPassword attack
  • CBirthday attack
  • DDDoS attack (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: DDoS attack

Topic 1 Β· Question 254

Bill has been hired as a penetration tester and cyber security auditor for a major credit card company. Which information security standard is most applicable to his role?

  • AFISMA
  • BSarbanes-Oxley Act
  • CHITECH
  • DPCI-DSS (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: PCI-DSS This option keeps traffic private / properly secured as required.

Topic 1 Β· Question 255

Geena, a cloud architect, uses a master component in the Kubernetes cluster architecture that scans newly generated pods and allocates a node to them. This component can also assign nodes based on factors such as the overall resource requirement, data locality, software/hardware/policy restrictions, and internal workload interventions. Which of the following master components is explained in the above scenario?

  • AKube-apiserver
  • BEtcd cluster
  • CKube-controller-manager
  • DKube-scheduler (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Kube-scheduler

Topic 1 Β· Question 256

According to the NIST cloud deployment reference architecture, which of the following provides connectivity and transport services to consumers?

  • ACloud connector
  • BCloud broker
  • CCloud provider
  • DCloud carrier (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Cloud carrier

Topic 1 Β· Question 257

A group of hackers were roaming around a bank office building in a city, driving a luxury car. They were using hacking tools on their laptop with the intention to find a free-access wireless network. What is this hacking process known as?

  • AWardriving (correct answer)
  • BSpectrum analysis
  • CWireless sniffing
  • DGPS mapping
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Wardriving

Topic 1 Β· Question 258

Which among the following is the best example of the third step (delivery) in the cyber kill chain?

  • AAn intruder creates malware to be used as a malicious attachment to an email.
  • BAn intruder's malware is triggered when a target opens a malicious email attachment.
  • CAn intruder's malware is installed on a targets machine.
  • DAn intruder sends a malicious attachment via email to a target. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: An intruder sends a malicious attachment via email to a target.

Topic 1 Β· Question 259

Calvin, a grey-hat hacker, targets a web application that has design flaws in its authentication mechanism. He enumerates usernames from the login form of the web application, which requests users to feed data and specifies the incorrect field in case of invalid credentials. Later, Calvin uses this information to perform social engineering. Which of the following design flaws in the authentication mechanism is exploited by Calvin?

  • AUser impersonation
  • BInsecure transmission of credentials
  • CPassword reset mechanism
  • DVerbose failure messages (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Verbose failure messages

Topic 1 Β· Question 260

Rebecca, a security professional, wants to authenticate employees who use web services for safe and secure communication. In this process, she employs a component of the Web Service Architecture, which is an extension of SOAP, and it can maintain the integrity and confidentiality of SOAP messages. Which of the following components of the Web Service Architecture is used by Rebecca for securing the communication?

  • AWS-Work Processes
  • BWS-Security (correct answer)
  • CWS-Policy
  • DWSDL
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: WS-Security This option keeps traffic private / properly secured as required.

Showing questions 241–260 of 308 Β· Page 13 of 16