🔍

312-50v13 — questions

Page 16 of 16 · 308 total questions.

Topic 1 · Question 301

A penetration tester is tasked with enumerating user accounts and network resources in a highly secured Windows environment where standard methods like SMB null sessions are blocked. The network employs strict firewall rules and intrusion detection systems to prevent unauthorized access. Which technique should the tester use to discreetly gather the required information without triggering security alarms?

  • AExploit a misconfigured LDAP service to perform anonymous searches
  • BConduct a zone transfer by querying the organization’s DNS servers (correct answer)
  • CUtilize NetBIOS over TCP/IP to list shared resources anonymously
  • DLeverage Active Directory Web Services for unauthorized queries
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Conduct a zone transfer by querying the organization’s DNS servers

Explanation

DNS resolves host names to records such as IP addresses and service locations. This option keeps traffic private / properly secured as required.

Topic 1 · Question 302

A penetration tester is tasked with scanning a network protected by an IDS and firewall that actively blocks connection attempts on non-standard ports. The tester needs to gather information on the target system without triggering alarms. Which technique should the tester use to evade detection?

  • AConduct a full TCP Connect scan to confirm open ports
  • BExecute a TCP ACK scan to map firewall rules and bypass the IDS
  • CPerform a SYN flood attack to overwhelm the firewall
  • DUse a low-and-slow scan to reduce detection by the IDS (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Use a low-and-slow scan to reduce detection by the IDS

Explanation

An intrusion detection system identifies and alerts on suspicious activity without normally blocking it.

Topic 1 · Question 303

In the neon-lit sprawl of Las Vegas, Nevada, a luxury hotel’s smart room control system suffered a breach, allowing an intruder to manipulate guest room settings. The incident investigation revealed that the IoT devices lacked any mechanism to verify the integrity or authenticity of software prior to execution, allowing tampered instructions to run unchecked. As Emma Ruiz, a cybersecurity consultant brought in to assess the breach, you recommend a solution that ensures only authorized, validated code is executed on the devices. Which secure development practice are you advising the hotel to implement?

  • AAllow code signing (correct answer)
  • BEnsure secure boot
  • CSecure firmware or software updates
  • DUtilize secure communication protocols
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Allow code signing This option keeps traffic private / properly secured as required.

Topic 1 · Question 304

You are Sophia Bennett, an ethical hacker at Nexus Cyber Defense, tasked with evaluating the security of a smart retail store’s IoT network in San Francisco, California. During your assessment, you uncover a vulnerability in the store’s smart inventory sensors that could allow an attacker to gain unauthorized access. The flaw lies in a cloud-based communication process that lacks authentication and encryption and fails to properly validate data exchange between the sensors and the cloud management platform. Based on the described vulnerability, which IoT attack surface area are you addressing in your findings?

  • AInsecure ecosystem interfaces
  • BInsecure data transfer and storage (correct answer)
  • CInsecure default settings
  • DInsecure network services
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Insecure data transfer and storage This option keeps traffic private / properly secured as required.

Topic 1 · Question 305

Michael, an ethical hacker at a New York-based e-commerce company, is evaluating the security of their online payment system after a recent incident where fraudulent transactions went undetected. His investigation reveals that the system uses an asymmetric encryption algorithm to ensure the authenticity of payment confirmations. He finds that the algorithm employs a public-key cryptosystem, where the sender signs the transaction with a private key, and the recipient verifies it using a corresponding public key located in a directory. During his test, Michael intercepts a signed message and notices that the algorithm supports modular exponentiation for generating digital signatures, a process critical to verifying the identity of the signatory. He aims to assess if the algorithm’s configuration could be vulnerable to a meet-in-the-middle attack due to its key structure. Which asymmetric encryption algorithm should Michael identify as the one used by the payment system?

  • ADiffie-Hellman
  • BRSA
  • CElGamal
  • DDSA (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: DSA This option keeps traffic private / properly secured as required.

Topic 1 · Question 306

During a quarterly security audit at a financial services company in Charlotte, North Carolina, you are tasked with reviewing exposed services on legacy servers inherited from a third-party vendor. While scanning, you discover that TCP port 1434 is open on a database node that is not listed in the company’s active inventory. The IT team has no records explaining why this service is running, and you are asked to determine whether the exposure of this port could indicate an unnecessary database-related risk. Based on standardized port assignments, which service is most likely running on this port and requires further review?

  • Asql*net
  • Bms-sql-m (correct answer)
  • Cms-sql-s
  • Dsqlsrv
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: ms-sql-m This option keeps traffic private / properly secured as required.

Topic 1 · Question 307

During a quarterly vulnerability management review at RedCore Motors, Priya finalizes the deployment of Nessus Essentials across the company’s IT infrastructure. The solution is selected for its ability to support diverse technologies including operating systems, databases, web servers, and virtual environments. While preparing a training session for junior analysts, Priya asks them to identify a capability that Nessus Essentials is specifically designed to provide as part of its scanning process.

  • AHigh-speed asset discovery (correct answer)
  • BAgent-based detection
  • CChecks for outdated versions of over 1250 servers
  • DPatch management for operating systems and third-party applications
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: High-speed asset discovery

Topic 1 · Question 308

You are Jordan, a cryptographic assessor at Cascade Data in Portland, Oregon, reviewing the protection applied to telemetry logs. Your review finds an algorithm that operates on 128-bit blocks, accepts keys up to 256 bits, and the documentation notes it was one of the finalists in the AES selection process that aimed to replace legacy DES. Which symmetric encryption algorithm should you identify as being used?

  • ABlowfish
  • BRC4
  • CAES
  • DTwofish (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Twofish This option keeps traffic private / properly secured as required.

Showing questions 301308 of 308 · Page 16 of 16