🔍

312-50v13 — questions

Page 4 of 16 · 308 total questions.

Topic 1 · Question 61

Richard, an attacker, aimed to hack IoT devices connected to a target network. In this process, Richard recorded the frequency required to share information between connected devices. After obtaining the frequency, he captured the original data when commands were initiated by the connected devices. Once the original data were collected, he used free tools such as URH to segregate the command sequence. Subsequently, he started injecting the segregated command sequence on the same frequency into the IoT network, which repeats the captured signals of the devices. What is the type of attack performed by Richard in the above scenario?

  • ACryptanalysis attack
  • BReconnaissance attack
  • CSide-channel attack
  • DReplay attack (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Replay attack

Topic 1 · Question 62

Which of the following allows attackers to draw a map or outline the target organization's network infrastructure to know about the actual environment that they are going to hack?

  • AVulnerability analysis
  • BMalware analysis
  • CScanning networks (correct answer)
  • DEnumeration
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Scanning networks

Topic 1 · Question 63

Your company was hired by a small healthcare provider to perform a technical assessment on the network. What is the best approach for discovering vulnerabilities on a Windows-based computer?

  • AUse the built-in Windows Update tool
  • BUse a scan tool like Nessus (correct answer)
  • CCheck MITRE.org for the latest list of CVE findings
  • DCreate a disk image of a clean Windows installation
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Use a scan tool like Nessus

Topic 1 · Question 64

Susan, a software developer, wants her web API to update other applications with the latest information. For this purpose, she uses a user-defined HTTP callback or push APIs that are raised based on trigger events; when invoked, this feature supplies data to other applications so that users can instantly receive real-time information. Which of the following techniques is employed by Susan?

  • AWeb shells
  • BWebhooks (correct answer)
  • CREST API
  • DSOAP API
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Webhooks This option meets the real-time / low-latency performance requirement.

Topic 1 · Question 65

Which IOS jailbreaking technique patches the kernel during the device boot so that it becomes jailbroken after each successive reboot?

  • ATethered jailbreaking
  • BSemi-untethered jailbreaking
  • CSemi-tethered jailbreaking
  • DUntethered jailbreaking (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Untethered jailbreaking

Topic 1 · Question 66

Stella, a professional hacker, performs an attack on web services by exploiting a vulnerability that provides additional routing information in the SOAP header to support asynchronous communication. This further allows the transmission of web-service requests and response messages using different TCP connections. Which of the following attack techniques is used by Stella to compromise the web services?

  • AWeb services parsing attacks
  • BWS-Address spoofing (correct answer)
  • CSOAPAction spoofing
  • DXML injection
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: WS-Address spoofing This option decouples the components so they scale independently and absorb load spikes.

Topic 1 · Question 67

Attacker Steve targeted an organization’s network with the aim of redirecting the company’s web traffic to another malicious website. To achieve this goal, Steve performed DNS cache poisoning by exploiting the vulnerabilities in the DNS server software and modified the original IP address of the target website to that of a fake website. What is the technique employed by Steve to gather information for identity theft?

  • APharming (correct answer)
  • BSkimming
  • CPretexting
  • DWardriving
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Pharming

Topic 1 · Question 68

What is the port to block first in case you are suspicious that an IoT device has been compromised?

  • A22
  • B48101 (correct answer)
  • C80
  • D443
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: 48101

Topic 1 · Question 69

Clark is a professional hacker. He created and configured multiple domains pointing to the same host to switch quickly between the domains and avoid detection. Identify the behavior of the adversary in the above scenario.

  • AUnspecified proxy activities (correct answer)
  • BUse of command-line interface
  • CData staging
  • DUse of DNS tunneling
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Unspecified proxy activities

Topic 1 · Question 70

What firewall evasion scanning technique make use of a zombie system that has low network activity as well as its fragment identification numbers?

  • APacket fragmentation scanning
  • BSpoof source address scanning
  • CDecoy scanning
  • DIdle scanning (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Idle scanning

Topic 1 · Question 71

By performing a penetration test, you gained access under a user account. During the test, you established a connection with your own machine via the SMB service and occasionally entered your login and password in plaintext. Which file do you have to clean to clear the password?

  • A.xsession-log
  • B.profile
  • C.bashrc
  • D.bash_history (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: .bash_history

Topic 1 · Question 72

Jack, a disgruntled ex-employee of Incalsol Ltd., decided to inject fileless malware into Incalsol's systems. To deliver the malware, he used the current employees' email IDs to send fraudulent emails embedded with malicious links that seem to be legitimate. When a victim employee clicks on the link, they are directed to a fraudulent website that automatically loads Flash and triggers the exploit. What is the technique used by Jack to launch the fileless malware on the target systems?

  • AIn-memory exploits
  • BLegitimate applications
  • CScript-based injection
  • DPhishing (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Phishing

Explanation

Phishing uses deceptive communication to obtain credentials, money, or execution of malicious content.

Topic 1 · Question 73

Wilson, a professional hacker, targets an organization for financial benefit and plans to compromise its systems by sending malicious emails. For this purpose, he uses a tool to track the emails of the target and extracts information such as sender identities, mail servers, sender IP addresses, and sender locations from different public sources. He also checks if an email address was leaked using the haveibeenpwned.com API. Which of the following tools is used by Wilson in the above scenario?

  • AFactiva
  • BZoomInfo
  • CNetcraft
  • DInfoga (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Infoga

Topic 1 · Question 74

David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vulnerabilities in its IT infrastructure. He is currently executing the process of applying fixes on vulnerable systems to reduce the impact and severity of vulnerabilities. Which phase of the vulnerability-management life cycle is David currently in?

  • ARemediation (correct answer)
  • BVerification
  • CRisk assessment
  • DVulnerability scan
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Remediation This option keeps traffic private / properly secured as required.

Topic 1 · Question 75

Alice, a professional hacker, targeted an organization’s cloud services. She infiltrated the target’s MSP provider by sending spear-phishing emails and distributed custom-made malware to compromise user accounts and gain remote access to the cloud service. Further, she accessed the target customer profiles with her MSP account, compressed the customer data, and stored them in the MSP. Then, she used this information to launch further attacks on the target organization. Which of the following cloud attacks did Alice perform in the above scenario?

  • ACloud cryptojacking
  • BMan-in-the-cloud (MITC) attack
  • CCloud hopper attack (correct answer)
  • DCloudborne attack
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Cloud hopper attack

Topic 1 · Question 76

Judy created a forum. One day, she discovers that a user is posting strange images without writing comments. She immediately calls a security expert, who discovers that the following code is hidden behind those images: What issue occurred for the users who clicked on the image?

Exhibit 1 for question 76
  • AThis php file silently executes the code and grabs the user’s session cookie and session ID. (correct answer)
  • BThe code redirects the user to another site.
  • CThe code injects a new cookie to the browser.
  • DThe code is a virus that is attempting to gather the user’s username and password.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: This php file silently executes the code and grabs the user’s session cookie and session ID. This option keeps traffic private / properly secured as required.

Topic 1 · Question 77

Ethical hacker Jane Smith is attempting to perform an SQL injection attack. She wants to test the response time of a true or false response and wants to use a second command to determine whether the database will return true or false results for user IDs. Which two SQL injection types would give her the results she is looking for?

  • AOut of band and boolean-based
  • BUnion-based and error-based
  • CTime-based and union-based
  • DTime-based and boolean-based (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Time-based and boolean-based

Topic 1 · Question 78

Jason, an attacker, targeted an organization to perform an attack on its Internet-facing web server with the intention of gaining access to backend servers, which are protected by a firewall. In this process, he used a URL https://xyz.com/feed.php?url=externalsite.com/feed/to to obtain a remote feed and altered the URL input to the local host to view all the local resources on the target server. What is the type of attack Jason performed in the above scenario?

  • AWeb server misconfiguration
  • BServer-side request forgery (SSRF) attack (correct answer)
  • CWeb cache poisoning attack
  • DWebsite defacement
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Server-side request forgery (SSRF) attack

Topic 1 · Question 79

George is a security professional working for iTech Solutions. He was tasked with securely transferring sensitive data of the organization between industrial systems. In this process, he used a short-range communication protocol based on the IEEE 203.15.4 standard. This protocol is used in devices that transfer data infrequently at a low rate in a restricted area, within a range of 10-100 m. What is the short-range wireless communication technology George employed in the above scenario?

  • ALPWAN
  • BMQTT
  • CNB-IoT
  • DZigbee (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Zigbee This option keeps traffic private / properly secured as required.

Topic 1 · Question 80

Eric, a cloud security engineer, implements a technique for securing the cloud resources used by his organization. This technique assumes by default that a user attempting to access the network is not an authentic entity and verifies every incoming connection before allowing access to the network. Using this technique, he also imposed conditions such that employees can access only the resources required for their role. What is the technique employed by Eric to secure cloud resources?

  • ADemilitarized zone
  • BZero trust network (correct answer)
  • CServerless computing
  • DContainer technology
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Zero trust network

Explanation

Zero trust continuously verifies identity, device, and context instead of trusting traffic based on network location. This option keeps traffic private / properly secured as required.

Showing questions 6180 of 308 · Page 4 of 16