🔍

312-50v13 — questions

Page 2 of 16 · 308 total questions.

Topic 1 · Question 21

Joe works as an IT administrator in an organization and has recently set up a cloud computing service for the organization. To implement this service, he reached out to a telecom company for providing Internet connectivity and transport services between the organization and the cloud service provider. In the NIST cloud deployment reference architecture, under which category does the telecom company fall in the above scenario?

  • ACloud consumer
  • BCloud broker
  • CCloud auditor
  • DCloud carrier (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Cloud carrier

Topic 1 · Question 22

Bobby, an attacker, targeted a user and decided to hijack and intercept all their wireless communications. He installed a fake communication tower between two authentic endpoints to mislead the victim. Bobby used this virtual tower to interrupt the data transmission between the user and real tower, attempting to hijack an active session. Upon receiving the user’s request, Bobby manipulated the traffic with the virtual tower and redirected the victim to a malicious website. What is the attack performed by Bobby in the above scenario?

  • AaLTEr attack (correct answer)
  • BJamming signal attack
  • CWardriving
  • DKRACK attack
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: aLTEr attack

Topic 1 · Question 23

John, a professional hacker, targeted an organization that uses LDAP for accessing distributed directory services. He used an automated tool to anonymously query the LDAP service for sensitive information such as usernames, addresses, departmental details, and server names to launch further attacks on the target organization. What is the tool employed by John to gather information from the LDAP service?

  • Aike-scan
  • BZabasearch
  • CJXplorer (correct answer)
  • DEarthExplorer
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: JXplorer

Topic 1 · Question 24

Annie, a cloud security engineer, uses the Docker architecture to employ a client/server model in the application she is working on. She utilizes a component that can process API requests and handle various Docker objects, such as containers, volumes, images, and networks. What is the component of the Docker architecture used by Annie in the above scenario?

  • ADocker objects
  • BDocker daemon (correct answer)
  • CDocker client
  • DDocker registries
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Docker daemon This option keeps traffic private / properly secured as required.

Topic 1 · Question 25

Bob, an attacker, has managed to access a target IoT device. He employed an online tool to gather information related to the model of the IoT device and the certifications granted to it. Which of the following tools did Bob employ to gather the above information?

  • AFCC ID search (correct answer)
  • BGoogle image search
  • Csearch.com
  • DEarthExplorer
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: FCC ID search

Topic 1 · Question 26

What piece of hardware on a computer’s motherboard generates encryption keys and only releases a part of the key so that decrypting a disk on a new piece of hardware is not possible?

  • ACPU
  • BUEFI
  • CGPU
  • DTPM (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: TPM This option keeps traffic private / properly secured as required.

Topic 1 · Question 27

Gilbert, a web developer, uses a centralized web API to reduce complexity and increase the integrity of updating and changing data. For this purpose, he uses a web service that uses HTTP methods such as PUT, POST, GET, and DELETE and can improve the overall performance, visibility, scalability, reliability, and portability of an application. What is the type of web-service API mentioned in the above scenario?

  • ARESTful API (correct answer)
  • BJSON-RPC
  • CSOAP API
  • DREST API
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: RESTful API This option scales automatically to match demand.

Topic 1 · Question 28

To create a botnet, the attacker can use several techniques to scan vulnerable machines. The attacker first collects information about a large number of vulnerable machines to create a list. Subsequently, they infect the machines. The list is divided by assigning half of the list to the newly compromised machines. The scanning process runs simultaneously. This technique ensures the spreading and installation of malicious code in little time. Which technique is discussed here?

  • ASubnet scanning technique
  • BPermutation scanning technique
  • CHit-list scanning technique. (correct answer)
  • DTopological scanning technique
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Hit-list scanning technique.

Topic 1 · Question 29

Nicolas just found a vulnerability on a public-facing system that is considered a zero-day vulnerability. He sent an email to the owner of the public system describing the problem and how the owner can protect themselves from that vulnerability. He also sent an email to Microsoft informing them of the problem that their systems are exposed to. What type of hacker is Nicolas?

  • ABlack hat
  • BWhite hat
  • CGray hat (correct answer)
  • DRed hat
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Gray hat

Topic 1 · Question 30

Sophia is a shopping enthusiast who spends significant time searching for trendy outfits online. Clark, an attacker, noticed her activities several times and sent a fake email containing a deceptive page link to her social media page displaying all-new and trendy outfits. In excitement, Sophia clicked on the malicious link and logged in to that page using her valid credentials. Which of the following tools is employed by Clark to create the spoofed email?

  • AEvilginx (correct answer)
  • BSlowloris
  • CPLCinject
  • DPyLoris
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Evilginx

Topic 1 · Question 31

John, a disgruntled ex-employee of an organization, contacted a professional hacker to exploit the organization. In the attack process, the professional hacker installed a scanner on a machine belonging to one of the victims and scanned several machines on the same network to identify vulnerabilities to perform further exploitation. What is the type of vulnerability assessment tool employed by John in the above scenario?

  • AAgent-based scanner
  • BNetwork-based scanner (correct answer)
  • CCluster scanner
  • DProxy scanner
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Network-based scanner

Topic 1 · Question 32

Joel, a professional hacker, targeted a company and identified the types of websites frequently visited by its employees. Using this information, he searched for possible loopholes in these websites and injected a malicious script that can redirect users from the web page and download malware onto a victim's machine. Joel waits for the victim to access the infected web application so as to compromise the victim's machine. Which of the following techniques is used by Joel in the above scenario?

  • AWatering hole attack (correct answer)
  • BDNS rebinding attack
  • CMarioNet attack
  • DClickjacking attack
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Watering hole attack

Topic 1 · Question 33

Security administrator John Smith has noticed abnormal amounts of traffic coming from local computers at night. Upon reviewing, he finds that user data have been exfiltrated by an attacker. AV tools are unable to find any malicious software, and the IDS/IPS has not reported on any non-whitelisted programs. What type of malware did the attacker use to bypass the company’s application whitelisting?

  • AFile-less malware (correct answer)
  • BZero-day malware
  • CPhishing malware
  • DLogic bomb malware
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: File-less malware This option keeps traffic private / properly secured as required.

Topic 1 · Question 34

Dorian is sending a digitally signed email to Poly. With which key is Dorian signing this message and how is Poly validating it?

  • ADorian is signing the message with his public key, and Poly will verify that the message came from Dorian by using Dorian’s private key.
  • BDorian is signing the message with Poly’s private key, and Poly will verify that the message came from Dorian by using Dorian’s public key.
  • CDorian is signing the message with his private key, and Poly will verify that the message came from Dorian by using Dorian’s public key. (correct answer)
  • DDorian is signing the message with Poly’s public key, and Poly will verify that the message came from Dorian by using Dorian’s public key.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Dorian is signing the message with his private key, and Poly will verify that the message came from Dorian by using Dorian’s public key.

Topic 1 · Question 35

Scenario: Joe turns on his home computer to access personal online banking. When he enters the URL www.bank.com, the website is displayed, but it prompts him to re-enter his credentials as if he has never visited the site before. When he examines the website URL closer, he finds that the site is not secure and the web address appears different. What type of attack he is experiencing?

  • ADHCP spoofing
  • BDoS attack
  • CARP cache poisoning
  • DDNS hijacking (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: DNS hijacking

Explanation

DNS resolves host names to records such as IP addresses and service locations. This option keeps traffic private / properly secured as required.

Topic 1 · Question 36

Boney, a professional hacker, targets an organization for financial benefits. He performs an attack by sending his session ID using an MITM attack technique. Boney first obtains a valid session ID by logging into a service and later feeds the same session ID to the target employee. The session ID links the target employee to Boney’s account page without disclosing any information to the victim. When the target employee clicks on the link, all the sensitive payment details entered in a form are linked to Boney’s account. What is the attack performed by Boney in the above scenario?

  • AForbidden attack
  • BCRIME attack
  • CSession donation attack
  • DSession fixation attack (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Session fixation attack

Topic 1 · Question 37

Kevin, a professional hacker, wants to penetrate CyberTech Inc’s network. He employed a technique, using which he encoded packets with Unicode characters. The company’s IDS cannot recognize the packets, but the target web server can decode them. What is the technique used by Kevin to evade the IDS system?

  • ASession splicing
  • BUrgency flag
  • CObfuscating (correct answer)
  • DDesynchronization
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Obfuscating

Topic 1 · Question 38

Suppose that you test an application for the SQL injection vulnerability. You know that the backend database is based on Microsoft SQL Server. In the login/password form, you enter the following credentials: Based on the above credentials, which of the following SQL commands are you expecting to be executed by the server, if there is indeed an SQL injection vulnerability?

Exhibit 1 for question 38
  • Aselect * from Users where UserName = ‘attack’ ’ or 1=1 -- and UserPassword = ‘123456’
  • Bselect * from Users where UserName = ‘attack’ or 1=1 -- and UserPassword = ‘123456’ (correct answer)
  • Cselect * from Users where UserName = ‘attack or 1=1 -- and UserPassword = ‘123456’
  • Dselect * from Users where UserName = ‘attack’ or 1=1 --’ and UserPassword = ‘123456’
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: select * from Users where UserName = ‘attack’ or 1=1 -- and UserPassword = ‘123456’

Topic 1 · Question 39

Which of the following commands checks for valid users on an SMTP server?

  • ARCPT
  • BCHK
  • CVRFY (correct answer)
  • DEXPN
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: VRFY

Topic 1 · Question 40

Bella, a security professional working at an IT firm, finds that a security breach has occurred while transferring important files. Sensitive data, employee usernames, and passwords are shared in plaintext, paving the way for hackers to perform successful session hijacking. To address this situation, Bella implemented a protocol that sends data using encryption and digital certificates. Which of the following protocols is used by Bella?

  • AFTPS (correct answer)
  • BFTP
  • CHTTPS
  • DIP
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: FTPS This option keeps traffic private / properly secured as required.

Showing questions 2140 of 308 · Page 2 of 16