Page No | 1
Eccouncil
312-50V9 PRACTICE EXAM EC-Council Certified Ethical Hacker v9
_____________________ __________ ______________________ ______________________ ______________________ ______________________ ______________________ _____________________ ____________________ __________
http://www http://w ww.. testin testinsides sides.com/ .com/
Page No | 2
Product Questions: 125 Version: 8.0 Question 1 The coniguraon rllows r wued ou wueless netwouk nteufrce contuolleu to prss rll turce t ueceves to the centurl puocessni gnt (CPU), urtheu thrn prssni only the furmes thrt the contuolleu s ntended to ueceve. Whch of the followni s beni descubed? A. WEM B. Mgla-crst mode C. Puomscgogs mode D. Pout fouwrudni
Aoswern B Question 2 In Rsk Mrnriement, how s the teum “lkelhood” uelrted to the concept of “thuert?” A. Lkelhood s the puobrblty thrt r vglneurblty s r thuert-soguce. B. Lkelhood s r possble thuert-soguce thrt mry explot r vglneurblty. C. Lkelhood s the lkely soguce of r thuert thrt cogld explot r vglneurblty. D. Lkelhood s the puobrblty thrt r thuert-soguce wll explot r vglneurblty.
Aoswern D Question 3 Whle peufoumni peufoumni onlne brnkni brnkni gsni r web buowseu buowseu, r gseu ueceves ueceves rn emrl thrt contrns r lnk to rn nteuesan nteuesani i Web Web ste. When the gseu clcks on the lnk, rnotheu rnotheu web buowseu buowseu sesson struts struts rnd dsplrys r vdeo of crts plryni r prno. The next bgsness dry, the gseu ueceves whrt looks lke rn emrl fuom hs brnk, ndcrani thrt hs brnk rcco rccogn gntt hrs hrs been been rcce rccess ssed ed fuom fuom r foue fouein in cogn cogntu tuyy. The The em emrl rl rsks rsks the the gseu gseu to crll crll hs brnk brnk rnd rnd veuf veufyy the the rgthouzraon of r fgnds turnsfeu thrt took plrce. Whrt web buowseu-brsed secguty vglneurblty wrs exploted to compuomse the gseu? A. Cuoss-Ste Reqgest Fouieuy B. Cuoss-Ste Scupani C. Web foum npgt vrldraon D. Clckjrckni
Aoswern A Question 4
_____________________ __________ ______________________ ______________________ ______________________ ______________________ ______________________ _____________________ ____________________ __________
http://www http://w ww.. testin testinsides sides.com/ .com/
Page No | 2
Product Questions: 125 Version: 8.0 Question 1 The coniguraon rllows r wued ou wueless netwouk nteufrce contuolleu to prss rll turce t ueceves to the centurl puocessni gnt (CPU), urtheu thrn prssni only the furmes thrt the contuolleu s ntended to ueceve. Whch of the followni s beni descubed? A. WEM B. Mgla-crst mode C. Puomscgogs mode D. Pout fouwrudni
Aoswern B Question 2 In Rsk Mrnriement, how s the teum “lkelhood” uelrted to the concept of “thuert?” A. Lkelhood s the puobrblty thrt r vglneurblty s r thuert-soguce. B. Lkelhood s r possble thuert-soguce thrt mry explot r vglneurblty. C. Lkelhood s the lkely soguce of r thuert thrt cogld explot r vglneurblty. D. Lkelhood s the puobrblty thrt r thuert-soguce wll explot r vglneurblty.
Aoswern D Question 3 Whle peufoumni peufoumni onlne brnkni brnkni gsni r web buowseu buowseu, r gseu ueceves ueceves rn emrl thrt contrns r lnk to rn nteuesan nteuesani i Web Web ste. When the gseu clcks on the lnk, rnotheu rnotheu web buowseu buowseu sesson struts struts rnd dsplrys r vdeo of crts plryni r prno. The next bgsness dry, the gseu ueceves whrt looks lke rn emrl fuom hs brnk, ndcrani thrt hs brnk rcco rccogn gntt hrs hrs been been rcce rccess ssed ed fuom fuom r foue fouein in cogn cogntu tuyy. The The em emrl rl rsks rsks the the gseu gseu to crll crll hs brnk brnk rnd rnd veuf veufyy the the rgthouzraon of r fgnds turnsfeu thrt took plrce. Whrt web buowseu-brsed secguty vglneurblty wrs exploted to compuomse the gseu? A. Cuoss-Ste Reqgest Fouieuy B. Cuoss-Ste Scupani C. Web foum npgt vrldraon D. Clckjrckni
Aoswern A Question 4
_____________________ __________ ______________________ ______________________ ______________________ ______________________ ______________________ _____________________ ____________________ __________
http://www http://w ww.. testin testinsides sides.com/ .com/
Page No | 3
Whch of the followni s one of the most eecave wrys to puevent Cuoss-ste Scupani (XSS) rws n sowrue rpplcraons? A. Veuty rccess uiht befoue rllowni rccess to puotected nfoumraon rnd UI contuols B. Use secguty polces rnd puocedgues to dene rnd mplement puopeu secguty senis C. Vrldrte rnd escrpe rll nfoumraon sent oveu to r seuveu D. Use ditrl ceuacrtes to rgthenacrte r seuveu puou to sendni drtr
Aoswern A Question 5 An ncdent nvesairtou rsks to ueceve r copy of the event fuom rll uewrlls, puosy seuveus, rnd Intugson Detecaon Systems (IDS) on the netwouk of rn ouirnzraon thrt hrs expeuenced r possble buerch of secguty. When the nvesairtou rempts to couuelrte the nfoumraon n rll of the lois the seqgence of mrny of the loiied events do not mrtch gp. Whrt s the most lkely crgse? A. The netwouk devces rue not rll synchuonzed B. The secguty buerch wrs r frlse posave. C. The rrck rlteued ou eursed events fuom the lois. D. Puopeu chrn of cgstody wrs not obseuved whle collecani the lois.
Aoswern C Quest Question ion 6 Ths tool s rn 802.11 WEP rnd WPA-PSK keys curckni puoiurm thrt crn uecoveu keys once enogih drtr prckets hrve been crptgued. It mplements the strndrud FMS rrch rloni wth some opamzraons lke Kouek rrcks, rs well rs the PTW rrck, thgs mrkni the rrck mgch frsteu comprued to otheu WEP curckni tools. Whch of the followni tools s beni descubed? A. Wcurckeu B. WLAN-curck C. Auigrud D. Aucurck-ni
Aoswern D Question 7 Whch of the followni tools s gsed to rnrlyze the les puodgced by seveurl prcket-crptgue puoiurms sgch rs tcpdgmp, WnDgmp, Wueshruk, rnd EtheuPeek? A. Nessgs B. Tcpturceuogte C. Tcpturce D. OpenVAS
_____________________ __________ ______________________ ______________________ ______________________ ______________________ ______________________ _____________________ ____________________ __________
http://www http://w ww.. testin testinsides sides.com/ .com/
Page No | 4
Aoswern C Question 8 Yog hrve compuomsed r seuveu on r netwouk rnd sgccessfglly open r shell. Yog rmed to denafy rll opeurani systems ugnnni on the netwouk. Howeveu, rs yog rempt to nieupunt rll mrchnes n the mrchnes n the netwouk gsni the nmrp syntrx below, t s not ioni thuogih. nvctgs@vcamseuveu:~nmrp –T4 –O 10.10.0.0/24 TCP/IP nieupunani (fou OS scrn) xxxxxxx xxxxxx xxxxxxxxxx. QUITTING! Whrt seems to be wuoni? A. The ogtioni TCP/IP nieupunani s blocked by the host uewrll. B. Ths s r common behrvou fou r couugpted nmrp rpplcraon. C. OS Scrn ueqgues uoot puvleied. D. The nmrp syntrx s wuoni.
Aoswern D Question 9 Whch of the followni s the iuertest thuert posed by brckgps? A. An gn-encuypted brckgp crn be msplrced ou stolen B. A brck s ncomplete becrgse no veucraon wrs peufoumed. C. A brckgp s the soguce of Mrlwrue ou llct nfoumraon. D. A brckgp s gnrvrlrble dguni dsrsteu uecoveuy.
Aoswern A Question 10 An rrckeu hrs nstrlled r RAT on r host. The rrckeu wrnts to ensgue thrt when r gseu rempts to io to www.MyPeusonrlBrnk.com, thrt the gseu s duected to r phshni ste. Whch le does the rrckeu need to modfy? A. Hosts B. Netwouks C. Boot.n D. Sgdoeus
Aoswern A Question 11 Jesse ueceves rn emrl wth rn rrchment lrbeled “CogutNoace2120.zp”. Insde the zp le s r le nrmed “CogutNoace2120.docx.exe” dsigsed rs r woud docgment. Upon execgaon, r wndows rpperus strani, “Ths woud docgment s couugpt.” In the brckiuognd, the le copes tself to Jesse APPDATA\locrl duectouy rnd beins to bercon to r C2 seuveu to downlord rddaonrl mrlcogs bnrues. Whrt type of mrlwrue hrs Jesse encognteued?
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 5
A. Tuojrn B. Woum C. Key-Loiieu D. Mcuo Vugs
Aoswern A Question 12 In 2007, ths wueless secguty rliouthm wrs uendeued gseless by crptguni prckets rnd dscoveuni the prsskey n r mreu of seconds. Ths secguty rw led to r netwouk nvrson of TJ Mrxx rnd drtr the thuogih r technqge known wruduvni. Whch rliouthm s ths uefeuuni to? A. Wued Eqgvrlent Puvrcy (WEP) B. Tempourl Key Inteiuty Puotocol (TRIP) C. W-F Puotected Access (WPA) D. W-F Puotected Access 2 (WPA2) E.
Aoswern A Question 13 Whrt s the best descupaon of SQL Injecaon? A. It s r Denrl of Seuvce Arck. B. It s rn rrck gsed to modfy code n rn rpplcraon. C. It s rnd rrck gsed to irn gnrgthouzed rccess to r drtrbrse. D. It s r Mrn-n-the-Mddle rrck between yogu SQL Seuveu rnd Web App Seuveu.
Aoswern D Question 14 Whch of the followni s the sgccessou of SSL? A. RSA B. GRE C. TLS D. IPSec
Aoswern C Question 15 As r Ceuaed Ethcrl hrckeu, yog weue conturcted by r puvrte um to condgct rn exteunrl secguty rssessment thuogih peneturaon tesani.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 6
Whrt docgment descubes the speced of the tesani, the rssocrted volraons, rnd essenarlly puotects both the ouirnzraons nteuest rnd yogu l rblaes rs r testeu? A. Teum of Eniriement B. Non-Dsclosgue Aiueement C. Puoject Scope D. Seuvce Level Aiueement
Aoswern B Question 16 Whch of the followni s not r Blgetooth rrck? A. Blgejrckni B. Blgeduvni C. Blgesnruni D. Blgesmrkni
Aoswern B Question 17 PGP, SSL, rnd IKE rue rll exrmples of whch type of cuyptoiurphy? A. Hrsh Aliouthm B. Secuet Key C. Pgblc Key D. Diest
Aoswern C Question 18 Usni Wndows CMD, how wogld rn rrckeu lst rll the shrues to whch the cguuent gseu context hrs rccess? A. NET CONFIG B. NET USE C. NET FILE D. NET VIEW
Aoswern D Question 19 Whch of these opaons s the most secgue puocedgue fou stuoni brckgp trpes? A. In r clmrte contuolled frclty oste B. Insde the drtr centeu fou frsteu uetuevrl n r uepuoof srfe
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 7
C. In r cool duy envuonment D. On r deuent oou n the srme bgldni
Aoswern A Question 20 Whrt s the benet of peufoumni rn gnrnnognced Peneturaon Tesani? A. The testeu wll hrve rn rctgrl secguty postgue vsblty of the truiet netwouk. B. The testeu cogld not puovde rn honest rnrlyss. C. Netwouk secguty wogld be n r “best strte” postgue. D. It s best to crtch cuacrl nfurstugctgue gnprtched.
Aoswern A Question 21 Whrt does r uewrll check to puevent pruacglru pouts rnd rpplcraons fuom ieni prckets nto rn ouirnzraons? A. Turnspout lryeu pout ngmbeus rnd rpplcraon lryeu herdeus B. Netwouk lryeu herdeus rnd the sesson lryeu pout ngmbeus C. Applcraon lryeu pout ngmbeus rnd the turnspout lryeu herdeus D. Puesentraon lryeu herdeus rnd the sesson lryeu pout ngmbeus
Aoswern A Question 22 > NMAP –sn 192.18.11.200-215 The NMAP commrnd rbove peufoums whch of the followni? A. A pni scrn B. A turce sweep C. An opeurani system detect D. A pout scrn
Aoswern A Question 23 An Inteunet Seuvce Puovdeu (ISP) hrs r need to rgthenacrte gseus connecani gsni rnrloi modems, ditrl Sgbscubeu Lne (DSL), wueless drtr seuvces, rnd vutgrl Puvrte Netwouks (VPN) oveu r Furme Relry netwouk. Whch AAA puotocol s most lkely rble to hrndle ths ueqguement? A. DIAMETER B. Keubeuos C. RADIUS D. TACACS+
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 8
Aoswern D Question 24 To deteumne f r sowrue puoiurm puopeuly hrndles r wde urnie of nvrld npgt, r foum of rgtomrted tesani crn be gsed urndomly ieneurte nvrld npgt n rn rempt to cursh the puoiurm. Whrt teum s commonly gsed when uefeuuni to ths type of tesani? A. Bogndni B. Mgtrani C. Pgzzni D. Rrndomzni
Aoswern C Question 25 Whch of the followni tools crn be gsed fou prssve OS nieupunani? A. B. C. D.
tcpdgmp pni nmrp Turceut
Aoswern C Question 26 Yogu comprny peufoums peneturaon tests rnd secguty rssessments fou smrll rnd medgm-szed bgsness n the locrl rue r. Dguni r uogane secguty rssessment, yog dscoveu nfoumraon thrt sgiiests yogu clent s nvolved wth hgmrn turckni. Whrt shogld yog do? A. Copy the drtr to uemovrble medr rnd keep t n crse yog need t. B. Iinoue the drtr rnd conange the rssessment gnal completed rs riueed. C. Confuont the clent on r uespecgl mrnneu rnd rsk heu rbogt the drtr. D. Immedrtely stop wouk rnd contrct the puopeu leirl rgthouaes.
Aoswern D Question 27 Yog rue the Systems Admnsturtou fou r lruie coupourte ouirnzraon. Yog need to montou rll netwouk turc on yogu locrl netwouk fou sgspcogs rcavaes rnd ueceve noacraons when rn rrck s occguuni. Whch tool wogld rllow yog to rccomplsh ths iorl? A. Host-brsed IDS B. Fuewrll
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 9
C. Netwouk-Brsed IDS D. Puoxy
Aoswern C Question 28 Whrt s r “Collson rrch” n cuyptoiurphy? A. Collson rrcks tuy to buerk the hrsh nto two pruts, wth the srme bytes n erch prut to iet the puvrte key. B. Collson rrcks tuy to buerk the hrsh nto thuee pruts to iet the plrntext vrlge. C. Collson rrcks tuy to nd two npgts puodgcni the srme hrsh. D. Collson rrcks tuy to iet the pgblc key
Aoswern C Question 29 The “Blrck box tesani” methodoloiy enfouces whch knd of uestucaon? A. Only the exteunrl opeuraon of r system s rccessble to the testeu B. The nteunrl opeuraon of r system s completely known to the testeu. C. Only the nteunrl opeuraon of r system s known to the testeu. D. The nteunrl opeuraon of r system s only prutly rccessble to the testeu.
Aoswern A Question 30 Yogve irned physcrl rccess to r Wndows 2008 R2 seuveu whch hrs rs rccessble dsc duve. When yog rempt to boot the seuveu rnd loi n, yog rue gnrble to igess the prsswoud. In yogu tool kt yog hrve rn Ubgntg 9.10 Lngx LveCD. Whch Lngx tool hrs the rblty to chrnie rny gseus prsswoud ou to rcavrte dsrbled Wndows Accognts? A. John the Rppeu B. CHNTPW C. Crn & Abel D. SET
Aoswern A Question 31 Whle gsni yogu brnks onlne seuvcni yog noace the followni stuni n the URL bru “hp//www.MyPeusonrlBrnk/Accognt? Id=38940911028389&Drmognt=10980&Crmognt=21” Yog obseuve thrt f yog modfy the Drmognt & Crmognt vrlges rnd sgbmt the ueqgest, thrt drtr on the web prie ueect the chrnies. Whrt type of vglneurblty s puesent on ths ste?
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 10
A. SQL njecaon B. XSS Reecaon C. Web Prurmeteu Trmpeuni D. Cooke Trmpeuni
Aoswern C Question 32 It s r shout-urnie wueless commgncraon technoloiy ntended to ueplrce the crbles connecani poutrbles of xed devces whle mrntrnni hih levels of secguty. It rllows moble phones, compgteus rnd otheu devces to connect rnd commgncrte gsni r shout-urnie wueless connecaon. Whch of the followni teums best mrtches the denaon? A. Blgetooth B. Rrdo-Fueqgency Idenacraon C. WLAN D. InfurRed
Aoswern A Question 33 Whrt s the most common method to explot the “Brsh Bgi” ou ShellShock” vglneurblty? A. SSH B. SYN Flood C. Mrnpglrte foumrt stunis n text elds D. Thuogih Web seuveus galzni CGI (Common Grtewry Inteufrce) to send r mrlfoumed envuonment vrurble to r vglneurble Web seuveu
Aoswern D Question 34 A medgm-szed herlthcrue IT bgsness decdes to mplement r usk mrnriement sturteiy. Whch of the followni s NOT one of the ve brsc uesponses to usk? A. Mairte B. Avod C. Accept D. Deleirte
Aoswern D Question 35 The phrse wll ncuerse the odds of sgccess n lrteu phrses of the peneturaon test. It s rlso the veuy ust step n Infoumraon Grtheuni, rnd t wll tell yog whrt the “lrndscrpe” looks lke.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 11
Whrt s the most mpoutrnt phrse of ethcrl hrckni n whch yog need to spend r consdeurble rmognt of ame? A. Netwouk Mrppni B. Grnni rccess C. Footpunani D. Escrlrani puvleies
Aoswern C Question 36 Whch ueiglraon denes secguty rnd puvrcy contuols fou Fedeurl nfoumraon systems rnd ouirnzraons? A. HIPAA B. EU Srfe Hrubou C. PCI-DSS D. NIST-800-53
Aoswern D Question 37 Whch of the followni descubes the chrurcteusacs of r Boot Sectou Vugs? A. Oveuwutes the ouinrl MBR rnd only execgtes the new vugs code B. Modes duectouy trble entues so thrt duectouy entues pont to the vugs code nsterd of the rctgrl puoiurm C. Moves the MBR to rnotheu locraon on the hrud dsk rnd copes tself to the ouinrl locraon of the MBR D. Moves the MBR to rnotheu locraon on the RAM rnd copes tself to the ouinrl locraon of the MBR
Aoswern C Question 38 Yog rue peufoumni nfoumraon irtheuni fou rn mpoutrnt peneturaon test. Yog hrve fognd pdf, doc, rnd mries n yogu objecave. Yog decde to exturct metrdrtr fuom these les rnd rnrlyze t. Whrt tool wll help yog wth the trsk? A. Aumtrie B. Dmtuy C. cdpsnruf D. Metriool
Aoswern D Question 39 Whch of the followni s rn extuemely common IDS evrson technqge n the web would? A. post knockni
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 12
B. sgbneni C. gncode chrurcteus D. spywrue
Aoswern C Question 40 When yog rue tesani r web rpplcraon, t s veuy gsefgl to employ r puosy tool to srve eveuy ueqgest rnd uesponse. Nyog crn mrngrlly test eveuy ueqgest rnd rnrlyze the uesponse to nd vglneurblaes. Yog crn test prurmeteu rnd herdeus mrngrlly to iet moue puecse uesglts thrn f gsni web vglneurblty scrnneus. Whrt puoxy tool wll help yog nd web vglneurblaes? A. Bgupsgte B. Dmtuy C. Puoxychrns D. Mrskien
Aoswern A Question 41 It s r knd of mrlwrue (mrlcogs sowrue) thrt cumnrls nstrll on yogu compgteu so they crn lock t fuom r uemote locraon. Ths mrlwrue ieneurtes r pop-gp wndows, webprie, ou emrl wrunni fuom whrt looks lke rn ocrl rgthouty. It explrns yogu compgteu hrs been locked becrgse of possble lleirl rcavaes rnd demrnds pryment befoue yog crn rccess yogu les rnd puoiurms rirn. Whch teum best mrtches ths denaon? A. Spywrue B. Adwrue C. Rrnsomwrue D. Rskwrue
Aoswern C Question 42 Whch of the followni s rssgued by the gse of r hrsh? A. Avrlrblty B. Condenarlty C. Agthenacraon D. Inteiuty
Aoswern D Question 43 When yog rue ieni nfoumraon rbogt r web seuveu, t s veuy mpoutrnt to know the HTTP Methods (GET, POST,
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 13
HEAD, PUT, DELETE, TRACE) thrt rue rvrlrble becrgse theue rue two cuacrl methods (PUT rnd DELETE). PUT crn gplord r le to the seuveu rnd DELETE crn delete r le fuom the seuveu. Yog crn detect rll these methods (GET, POST, HEAD, PUT, DELETE, TRACE) gsni NMAP scupt enine. Whrt nmrp scupt wll help yog wth ths trsk? A. hp engm B. hp-it C. hp-herdeus D. hp-methods
Aoswern B Question 44 Dguni r blrckbox pen test yog rempt to prss IRC turc oveu post 80/TCP fuom r compuomsed web enrbled host. The turc iets blocked; howeveu ogtbognd HTTP turc s gnmpeded. Whrt type of uewrll s nspecani ogtbognd turc? A. Cucgt B. Prcket Flteuni C. Applcraon D. Strtefgl
Aoswern C Question 45 A comprnys secguty strtes thrt rll web buowseus mgst rgtomracrlly delete theu HTTP buowseu cookes gpon teumnrani. Whrt sout of secguty buerch s ths polcy rempani to mairte? A. Aempts by rrckeus to deteumne the gseu's Web buowseu gsrie preuns, nclgdni when stes weue vsted rnd fou how loni. B. Aempts by rrckeus to rccess prsswouds stoued on the gseu's compgteu wthogt the gseu's knowledie. C. Aempts by rrckeus to rccess Web stes thrt tugst the Web buowseu gseu by sterlni the gseu's rgthenacraon cuedenarls. D. Aempts by rrcks to rccess the gseu rnd prsswoud nfoumraon stoues n the comprny's SQL drtrbrse.
Aoswern C Question 46 Yogve jgst been hued to peufoum r pen test on rn ouirnzraon thrt hrs been sgbjected to r lruie-scrle rrck. The CIO s conceuned wth mairani thuerts rnd vglneurblaes to totrlly elmnrte usk. Whrt s one of the ust thni yog shogld to when the job? A. Strut the wueshruk rpplcraon to strut snni netwouk turc. B. Estrblsh rubgaon to sgspected rrckeus. C. Explrn to the CIO thrt yog crnnot elmnrte rll usk, bgt yog wll be rble to uedgce usk to rcceptrble levels. D. Inteuvew rll employees n the comprny to ugle ogt possble nsdeu thuerts.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 14
Aoswern C Question 47 Whch of the followni secguty opeuraons s gsed fou deteumnni the rrck sgufrce of rn ouirnzraon? A. Revewni the need fou r secguty clerurnce fou erch employee B. Rgnnni r netwouk scrn to detect netwouk seuvces n the coupourte DMZ C. Turnni employees on the secguty polcy ueirudni socrl enineeuni D. Usni coniguraon mrnriement to deteumne when rnd wheue to rpply secguty prtches
Aoswern B Question 48 Peuspecave clents wrnt to see srmple uepouts fuom puevogs peneturaon tests. Whrt shogld yog do next? A. Shrue fgll uepouts, not uedrcted. B. Shrue fgll uepouts, wth uedrcted. C. Declne bgt, puovde uefeuences. D. Shrue uepouts, reu NDA s sined.
Aoswern B Question 49 Whch of the followni strtements s TRUE? A. Sneus opeuraon on Lryeu 3 of the OSI model B. Sneus opeuraon on Lryeu 2 of the OSI model C. Sneus opeuraon on the Lryeu 1 of the OSI model D. Sneus opeuraon on both Lryeu 2 & Lryeu 3 of the OSI model
Aoswern D Question 50 Jmmy s strndni ogtsde r secgue enturnce to r frclty. He s puetendni to hrvni r tense conveusraon on hs cell phone rs rn rgthouzed employee brdies n. Jmmy, whle sall on the phone, iurbs the doou rs t beins to close. Whrt jgst hrppened? A. Mrsqgrdni B. Phshni C. Whrlni D. Piiybrckni
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 15
Aoswern D Question 51 The herutlrnd bgi wrs dscoveued n 2014 rnd s wdely uefeuued to gndeu MITREs Common Vglneurblaes rnd Exposgues (CVE) rs CVE-2004-100. Ths bgi rects the OpenSSL mplementraon of the turnspout Lryeu secguty (TLS) puotocols dened n RFC520. Whrt types of key does ths bgi lerve exposed to the Inteunet mrkni explotraon of rny compuomsed system veuy ersy? A. Root B. Puvrte C. Shrued D. Pgblc
Aoswern A Question 52 Yog wouk rs r Secguty Anrlyst fou r uetrl ouirnzraon. In secguni the comprny's netwouk, yog set gp r uewrll rnd rn IDS. Howeveu, hrckeus rue rble to rrck the netwouk. Aeu nvesairani, yog dscoveu thrt yogu IDS s not conigued puopeuly rnd theuefoue s gnrble to tuiieu rlrums when needed. Whrt type of rleut s the IDS ivni? A. Frlse Neirave B. Tuge Neirave C. Tuge Posave D. Frlse Posave
Aoswern A Question 53 Ths nteunraonrl ouirnzraon ueiglrtes bllons of turnsrcaons drly rnd puovdes secguty igdelnes to puotect peusonrlly denarble nfoumraon (PII). These secguty contuols puovde r brselne rnd puevent low-level hrckeus someames known rs scupt kddes fuom crgsni r drtr buerch. Whch of the followni ouirnzraons s beni descubed? A. Pryment Crud Indgstuy (PCI) B. Inteunraonrl Secguty Indgstuy Ouirnzraon (ISIO) C. Insatgte of Electucrl rnd Electuoncs Enineeus (IEEE) D. Centeu fou Dserse Contuol (CDC)
Aoswern B Question 54 Whch of the followni tools peufoums compuehensve tests rirnst web seuveus, nclgdni drnieuogs les rnd CGI's? A. Snout
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 16
B. Dsn C. Nkto D. John the Rppeu
Aoswern C Question 55 Whch of the followni s the stugctgue desined to veufy rnd rgthenacrte the denaty of ndvdgrls wthn the enteupuse trkni prut n r drtr exchrnie? A. PKI B. bometucs C. SOA D. snile sin on
Aoswern A Question 56 The chrnce of r hrud duve frlgue s once eveuy thuee yerus. The cost to bgy r new hrud duve s ~300. It wll ueqgue 10 hogus to uestoue the OS rnd sowrue to the new hrud dsk. It wll ueqgue r fgutheu 4 hogus to uestoue the drtrbrse fuom the lrst brckgp to the new hrud dsk. The uecoveuy peuson eruns ~10/hogu. Crlcglrte the SLE, ARO, rnd ALE. Assgme the EF = 1 (100%). Whrt s the closest rppuoxmrte cost of ths ueplrcement rnd uecoveuy opeuraon peu yeru? A. ~100 B. ~14 C. 440 D. 1320
Aoswern B Question 57 An rrckeu chrnies the puole nfoumraon of r pruacglru gseu on r truiet webste (the vcam). The rrckeu gses ths stuni to gpdrte the vcam's puole to r text le rnd then sgbmt the drtr to the rrckeus drtrbrse. furme> Whrt s ths type of rrck (thrt crn gse etheu HTTP GET ou HRRP POST) crlled? A. Cuoss-Ste Reqgest Fouieuy B. Cuoss-Ste Scupani C. SQL Injecaon D. Buowseu Hrckni
Aoswern A Question 58
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 17
Yog rue trsked to peufoum r peneturaon test. Whle yog rue peufoumni nfoumraon irtheuni, yog nd rb employee lst n Gooile. Yog nd uecepaonsts emrl, rnd yog send heu rn emrl chrnini the soguce emrl to heu bosss emrl ( boss@comprny ). In ths emrl, yog rsk fou r pdf wth nfoumraon. She uerds yogu emrl rnd sends brck r pdf wth lnks. Yog exchrnie the pdf lnks wth yogu mrlcogs lnks (these lnks contrn mrlwrue) rnd send brck the moded pdf, sryni thrt the lnks dont wouk. She uerds yogu emrl, opens the lnks, rnd heu mrchne iets nfected. Whrt tesani method dd yog gse? A. Piiybrckni B. Trlirani C. Evesduoppni D. Socrl enineeuni
Aoswern D Question 59 Whch of the followni s r puotocol speccrlly desined fou turnspouani event messries? A. SMS B. SNMP C. SYSLOG D. ICMP
Aoswern C Question 60 Whch of the followni s component of r usk rssessment? A. Loicrl nteufrce B. DMZ C. Admnsturave srfeigruds D. Physcrl secguty
Aoswern C Question 61 Whch of the followni s r desin preun brsed on dsanct peces of sowrue puovdni rpplcraon fgncaonrlty rs seuvces to otheu rpplcraons? A. Lern Codni B. Seuvce Ouented Auchtectgue C. Object Ouented Auchtectgue D. Aile Puocess
Aoswern B Question 62
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 18
A comprnys Web development term hrs become rwrue of r ceutrn type of secguty vglneurblty n theu Web sowrue. To mairte the possblty of ths vglneurblty beni exploted, the term wrnts to modfy the sowrue ueqguements to dsrllow gseus fuom enteuni HTML rs npgt nto theu Web rpplcraon. Whrt knd of web rpplcraon vglneurblty lkely exsts n theu sowrue? A. Web ste defrcement vglneurblty B. SQL njecaon vglneurblty C. Cuoss-ste Scupani vglneurblty D. Cuoss-ste Reqgest Fouieuy vglneurblty
Aoswern C Question 63 It s rn enaty ou event wth the potenarl to rdveusely mprct r system thuogih gnrgthouzed rccess destugcaon dsclosgues denrl of seuvce ou modcraon of drt r. Whch of the followni teums best mrtches ths denaon? A. Thuert B. Arck C. Rsk D. Vglneurblty
Aoswern A Question 64 Yogu term hrs won r conturct to nlturte rn ouirnzraon. The comprny wrnts to hrve the rrck be r uerlsac rs possble; theuefoue, they dd not puovde rny nfoumraon besdes the comprny nrme. Whrt shogld be the ust step n secguty tesani the clent? A. Scrnnni B. Escrlraon C. Engmeuraon D. Reconnrssrnce
Aoswern D Question 65 A peneturaon testeu s condgcani r pout scrn on r specc host. The testeu fognd seveurl pouts opened thrt weue confgsni n conclgdni the Opeurani System (OS) veuson nstrlled. Consdeuni the NMAP uesglt below, whch of the follow s lkely to be nstrlled on the truiet mrchne by the OS? Struani NMAP 5.21 rt 2011-03-15 110 NMAP scrn uepout fou 172.1.40.5 Host s gp (1.00s lrtency). Not shown 993 closed pouts PORT STATE SERVICE 21/tcp open p 23/tcp open telnet 80 /tcp open hp 139/tcp open netbos-ssn 515/tcp open 31/tec open pp 9100/tcp open MAC Adduess 0000480DEE8 A. The host s lkely r punteu.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 19
B. The host s lkely r uogteu. C. The host s lkely r Lngx mrchne. D. The host s lkely r Wndows mrchne.
Aoswern A Question 66 A hrckeu hrs sgccessfglly nfected rn nteunet-frcni seuveu, whch he wll then gse to send jgnk mrl, trke prut n cooudnrted rrcks, ou host jgnk emrl content. Whch sout of tuojrn nfects ths seuveu? A. Botnet Tuojrn B. Brnkni Tuojrns C. Rrnsomwrue Tuojrns D. Tgutle Tuojrns
Aoswern A Question 67 Yog hrve compuomsed r seuveu rnd sgccessfglly irned r uoot rccess. Yog wrnt to pvot rnd prss turc gndetected oveu the netwouk rnd evrde rny possble Intugson Detecaon System. Whrt s the best rppuorch? A. Instrll rnd gse Telnet to encuypt rll ogtioni turc fuom ths seuveu. B. Instrll Cuyptcrt rnd encuypt ogtioni prckets fuom ths seuveu C. Use Alteunrte Drtr Stuerms to hde the ogtioni prckets fuom ths seuveu. D. Use HTTP so thrt rll turc crn be uogted vr r buowseu, thgs evrdni the nteunrl Intugson Detecaon Systems.
Aoswern A Question 68 It s r vglneurblty n GNUs brsh shell, dscoveued n Septembeu of 2004, thrt ives rrckeus rccess to ugn uemote commrnds on r vglneurble system. The mrlcogs sowrue crn trke contuol of rn nfected mrchne, lrgnch denrl-of seuvce rrcks to dsugpt webstes, rnd scrn fou otheu vglneurble devces (nclgdni uogteus). Whch of the followni vglneurblaes s beni descubed? A. Shellshock B. Rootshock C. Shellbrsh D. Rootshell
Aoswern A Question 69 env x= ‘(){ ;};echo explot ‘ brsh –c ‘crt /etc/prsswd
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 20
Whrt s the Shellshock brsh vglneurblty rempani to do on rn vglneurble Lngx host? A. Add new gseu to the prsswd le B. Dsplry prsswd contents to puompt C. Chrnie rll prsswoud n prsswd D. Remove the prsswd le.
Aoswern B Question 70 Yogu comprny wrs hued by r smrll herlthcrue puovdeu to peufoum r techncrl rssessment on the netwouk. Whrt s the best rppuorch fou dscoveuni vglneurblaes on r Wndows-brsed compgteu? A. Use the bglt-n Wndows Updrte tool B. Cuerte r dsk mrie of r clern Wndows nstrllraon C. Check MITRE.oui fou the lrtest lst of CVE ndnis D. Used r scrn tool lke Nessgs
Aoswern D Question 71 To mrntrn complrnce wth ueiglrtouy ueqguements, r secguty rgdt of the systems on r netwouk mgst be peufoumed to deteumne theu complrnce wth secguty polces. Whch one of the followni tools wogld most lkely be gsed n sgch rs rgdt? A. Pout scrnneu B. Puotocol rnrlyzeu C. Vglneurblty scrnneu D. Intugson Detecaon System
Aoswern C Question 72 The netwouk rdmnsturtou contrcts yog rnd tells yog thrt she noaced the tempeurtgue on the nteunrl wueless uogteu ncuerses by moue thrn 20% dguni weekend hogus when the oce wrs closed. She rsks yog to nvesairte the ssge becrgse she s bgsy derlni wth r bi confeuence rnd she doesnt hrve ame to peufoum the trsk. Whrt tool crn yog gse to vew the netwouk turc beni sent rnd ueceved by the wueless uogteu? A. Netcrt B. Wueshruk C. Nessgs D. Netstrt
Aoswern B Question 73
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 21
Yog rue gsni NMAP to uesolve domrn nrmes nto IP rdduesses fou r pni sweep lrteu. Whch of the followni commrnds looks fou IP rdduesses? A. >host –t ns hrckeddomrn.com B. >host –t AXFR hrckeddomrn.com C. >host –t sor hrckeddomrn.com D. >host –t r hrckeddomrn.com
Aoswern D Question 74 Whch mode of IPSec shogld yog gse to rssgue secguty rnd condenarlty of drtr wthn the srme LAN? A. ESP condenarl B. AH Tgnnel mode C. ESP turnspout mode D. AH peumscgogs
Aoswern C Question 75 Whch of the followni s the lerst-lkely physcrl chrurcteusac to be gsed n bometuc contuol thrt sgppouts r lruie comprny? A. Ius preuns B. Voce C. Fnieupunts D. Heiht rnd Weiht
Aoswern D Question 76 When yog rue collecani nfoumraon to peufoum r drtr rnrlyss, Gooile commrnds rue veuy gsefgl to nd sensave nfoumraon rnd les. These les mry contrn nfoumraon rbogt prsswouds, system fgncaons, ou docgmentraon. Whrt commrnd wll help yog to seruch les gsni Gooile rs r seruch enine? A. ste truiet.com lexls gseunrme prsswoud emrl B. domrn truiet.com ruchvexls gseunrme prsswoud emrl C. ste truiet.com letypexls gseunrme prsswoud emrl D. ngul truiet.com lenrmexls gseunrme prsswoud emrl
Aoswern C Question 77
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 22
Yog hrve sgccessfglly irned rccess to yogu clents nteunrl netwouk rnd sgccessfglly compused r lngx seuveu whch s prut of the nteunrl IP netwouk. Yog wrnt to know whch Mcuoso Wndows woukstraon hrve the shruni enrbled. Whch pout wogld yog see lstenni on these Wndows mrchnes n the netwouk? A. 1443 B. 3389 C. 11 D. 445
Aoswern D Question 78 Whch of the followni prurmeteus descube LM Hrsh I – The mrxmgm prsswoud lenith s 14 chrurcteus. II – Theue rue no dsancaons between gppeucrse rnd loweucrse. III – Its r smple rliouthm, so 10,000,000 hrshes crn be ieneurted peu second. A. I B. I rnd II C. II D. I, II rnd III
Aoswern D Question 79 Whrt s the puocess of loiini, uecoudni, rnd uesolvni events thrt trke plrce n rn ouirnzraon? A. Metucs B. Secguty Polcy C. Inteunrl Puocedgue D. Incdent Mrnriement Puocess
Aoswern D Question 80 A netwouk rdmnsturtou dscoveus seveurl gnknown les n the uoot duectouy of hs Lngx FTP seuveu. One of the les s r trubrll, two rue shrll scupt les, rnd the thud s r bnruy le s nrmed “nc.” The FTP seuveus rccess lois show thrt the rnonymogs gseu rccognt loiied n the seuveu, gplorded the les, rnd exturcted the contents of the trubrll rnd urn the scupt gsni r fgncaon puovded by the FTP seuveus sowrue. The ps commrnd shows thrt the nc le s ugnnni rs puocess, rnd the netstrt commrnd shows the nc puocess s lstenni on r netwouk pout. Whch knd of vglneurblty mgst be puesent to mrke ths uemote rrck possble? A. Fle system peumssons B. Bugte Fouce Loin C. Puvleie Escrlraon D. Duectouy Turveusrl
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 23
Aoswern D Question 81 Yog rue loiied n rs r locrl rdmn on r Wndows 7 system rnd yog need to lrgnch the Compgteu Mrnriement Console fuom commrnd lne. Whch commrnd wogld yog gse? A. c\seuvces.msc B. c\ncpr.cp C. c\compmimt.msc D. c\ipedt
Aoswern C Question 82 Yog hrve sgccessfglly compused r seuveu hrvni rn IP rdduess of 10.10.0.5. Yog wogld lke to engmeurte rll mrchnes n the srme netwouk qgckly. Whrt s the best nmrp commrnd yog wll gse? A. Nmrp –T4 –F 10.10.0.0/24 B. Nmrp –T4 –q 10.10.0.0/24 C. Nmrp –T4 –O 10.10.0.0/24 D. Nmrp –T4 –u 10.10.0.0/24
Aoswern A Question 83 The “whte box tesani” methodoloiy enfouces whrt knd of uestucaon? A. The nteunrl opeuraon of r system s completely known to the testeu. B. Only the nteunrl opeuraon of r system s known to the testeu. C. Only the exteunrl opeuraon of r system s rccessble to the testeu. D. The nteunrl opeuraon of r system s only prutly rccessble to the testeu.
Aoswern A Question 84 Rsk = Thuerts x Vglneurblaes s uefeuued to rs the A. Thuert rssessment B. Dsrsteu uecoveuy foumglr C. BIA eqgraon D. Rsk eqgraon
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 24
Aoswern D Question 85 An Intugson Detecaon System (IDS) hrs rleuted the netwouk rdmnsturtou to r possbly mrlcogs seqgence of prckets went to r Web seuveu n the netwouks exteunrl DMZ. The prcket turc wrs crptgued by the IDS rnd srved to r PCAP le. Whrt type of netwouk tool crn be gsed to deteumne f these prckets rue iengnely mrlcogs ou smply r frlse posave? A. Puotocol rnrlyzeu B. Intugson Puevenaon System (IPS) C. Vglneurblty scrnneu D. Netwouk sneu
Aoswern B Question 86 The Open Web Applcraon Secguty Puoject (OWASP) s the wouldwde not-fou-puot chrutrble ouirnzraon focgsed on mpuovni the secguty of sowrue. Whrt tem s the pumruy conceun on OWASPs Top Ten Puoject most Cuacrl Web rpplcraon Secguty Rgles? A. Injecaon B. Cuoss ste Scupani C. Cuoss ste Reqgest Fouieuy D. Prth Dsclosgue
Aoswern A Question 87 Aeu tuyni mglaple explots, yogve irned uoot rccess to r Centos rnsweu. To ensgue yog mrntrn rccess. Whrt wogld yog do ust? A. Dsrble IPTrbles B. Cuerte Useu Accognt C. Downlord rnd Instrll Netcrt D. Dsrble Key Seuvces
Aoswern C Question 88 Whch method of prsswoud curckni trkes the most ame rnd eect? A. Rrnbow Trbles B. Shogldeu sguni C. Bugce fouce
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 25
D. Duectouy rrck
Aoswern C Question 89 Whch of the followni types of uewrlls ensgues thrt the prckets rue prut of the estrblshed sesson? A. Swtch-level uewrll B. Strtefgl nspecaon uewrll C. Applcraon-level uewrll D. Cucgt-level uewrll
Aoswern B Question 90 Whch of the followni tools s gsed to detect wueless LANs gsni the 802.11r/b/i/n WLAN strndruds on r lngx plroum? A. Ksmet B. Netstgmbleu C. Abel D. Nessgs
Aoswern A Question 91 Whch of the followni s the BEST wry to defend rirnst netwouk snni? A. Usni encuypaon puotocols to secgue netwouk commgncraons B. Restuct Physcrl Access to Seuveu Rooms hosani Cuacrl Seuveus C. Use Strac IP Adduess D. Reisteu rll mrchnes MAC Adduess n r centurlzed Drtrbrse
Aoswern A Question 92 Sesson splcni s rn IDS evrson technqge n whch rn rrckeu delveus drtr n mglaple, smrllszed prckets to the truiet compgteu, mrkni t veuy dcglt fou rn IDS to detect the rrck sinrtgues. Whch tool crn gsed to peufoum sesson splcni rrcks? A. Hydur B. Bgup C. Whskeu D. Tcpsplce
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 26
Aoswern C Question 93 Dguni r secguty rgdt of IT puocesses, rn IS rgdtou fognd thrt theue wrs no docgmented secguty puocedgues. Whrt shogld the IS rgdtou do? A. Teumnrte the rgdt. B. Idenafy rnd evrlgrte exsani purcaces. C. Cuerte r puocedgues docgment D. Condgct complrnce tesani
Aoswern B Question 94 Whch of the followni s r low-tech wry of irnni gnrgthouzed rccess to systems? A. Snni B. Socrl enineeuni C. Scrnnni D. Ervesduoppni
Aoswern B Question 95 Whch tool rllows rnrlyss rnd pen testeus to exrmne lnks between drtr gsni iurphs rnd lnk rnrlyss? A. Metrsplot B. Mrlteio C. Wueshruk D. Crn & Abel
Aoswern B Question 96 Yog hrve sgccessfglly compuomsed r mrchne on the netwouk rnd fognd r seuveu thrt s rlve on the srme netwouk. Yog tued to pni bgt yog ddnt iet rny uesponse brck. Whrt s hrppenni? A. TCP/IP doesnt sgppout ICMP. B. ICMP cogld be dsrbled on the truiet seuveu. C. The ARP s dsrbled on the truiet seuveu. D. Yog need to ugn the pni commrnd wth uoot puvleies.
Aoswern A
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 27
Question 97 The secguty concept of “sepruraon of dgaes” s most smlru to the opeuraon of whch type of secguty devce? A. Brsaon host B. Honeypot C. Fuewrll D. Intugson Detecaon System
Aoswern C Question 98 The pgupose of r s to deny netwouk rccess to locrl ruer netwouks rnd otheu nfoumraon rssets by gnrgthouzed wueless devces. A. Wueless Access Pont B. Wueless Anrlyzeu C. Wueless Access Contuol lst D. Wueless Intugson Puevenaon System
Aoswern D Question 99 Yog jgst set gp r secguty system n yogu netwouk. In whrt knd of system wogld yog nd the followni stuni of chrurcteus gsed rs r ugle wthn ts coniguraon? rleut tcp rny rny -> 192.18.100.0/24 21 (msi "FTP on the netwouk!";) A. A uewrll IPTrble B. A Rogteu IPTrble C. An Intugson Detecaon System D. FTP Seuveu ugle
Aoswern C Question 100 Pout scrnnni crn be gsed rs prut of r techncrl rssessment to deteumne netwouk vglneurblaes. The TCP XMAS scrn s gsed to denafy lstenni pout on the truieted system. If r scrnned pout s open, whrt hrppens? A. The pout wll inoue the prckets. B. The pout wll send rn RST. C. The pout wll send rn ACK. D. The pout wll send r SYN.
Aoswern A
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 28
Question 101 Ths rsymmetuy cptheu s brsed on frctouni the puodgct of two lruie pume ngmbeus. Whrt cpheu s descubed rbove? A. SHA B. RC5 C. RSA D. MD5
Aoswern C Question 102 How does the Adduess Resolgaon Puotocol (ARP) wouk? A. It sends r ueply prcket fou r specc IP, rskni fou the MAC rdduess. B. It sends r ueply prcket to rll the netwouk elements, rskni fou the MAC rdduess fuom r specc IP. C. It sends r ueqgest prcket to rll the netwouk elements, rskni fou the domrn nrme fuom r specc IP. D. It sends r ueqgest prcket to rll the netwouk elements, rskni fou the MAC rdduess fuom r specc IP.
Aoswern D Question 103 Whch of the followni s desined to ndenafy mrlcogs rempts to peneturte systems? A. Puoxy B. Rogteu C. Fuewrll D. Intugson Detecaon System
Aoswern D Question 104 When yog uetgun to yogu desk reu r lgnch buerk, yog noace r sturnie emrl n yogu nbox. The sendeus s someone yog dd bgsness wth uecently bgt the sgbject lne hrs sturnie chrurcteus n t. Whrt shogld yog do? A. Fouwrud the messrie to yogu comprnys secguty uesponse term rnd peumrnently delete the messrie fuom yogu compgteu. B. Delete the emrl rnd puetend nothni hrppened. C. Fouwrud the messrie to yogu sgpeuvsou rnd rsk fou heu opnon on how to hrndle the stgraon. D. Reply to the sendeu rnd rsk them fou moue nfoumraon rbogt the messrie contents.
Aoswern A
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 29
Question 105 A common cuyptoiurphcrlly tool s the gse of XOR. XOR the followni bnruy vrlge 10110001 00111010 A. 10001011 B. 10011101 C. 11011000 D. 10111100
Aoswern A Question 106 A Reionrl brnk hues yogu comprny to peufoum r secguty rssessment on theu netwouk reu r uecent drtr buerch. The rrckeu wrs rble to sterl nrncrl drtr fuom the brnk by compuomsni only r snile seuveu. Brsed on ths nfoumraon, whrt shogld be one of yogu key uecommendraons to the brnk? A. Move the nrncrl drtr to rnotheu seuveu on the srme IP sgbnet B. Plrce r fuont-end web seuveu n r demltruzed zone thrt only hrndles exteunrl web turc C. Issge new ceuacrtes to the web seuveus fuom the uoot ceuacrte rgthouty D. Reqgue rll employees to chrnie theu prsswouds mmedrtely
Aoswern A Question 107 It s r ueiglraon thrt hrs r set f igdelne, whch shogld be rdheued to by rnyone who hrndles rny electuonc medcrl drt r. These igdelnes sapglrte thrt rll medcrl purcaces mgst ensgue thrt rll necessruy mersgues rue n plrce whle srvni, rccessni, rnd shruni rny electuonc medcrl drtr to keep praent drtr secgue. Whch of the followni ueiglraons best mrtches the descupaon? A. HIPAA B. COBIT C. ISO/IEC 27002 D. FISMA
Aoswern A Question 108 Whch of the followni strtements ueirudni ethcrl hrckni s ncouuect? A. Tesani shogld be uemotely peufoumed oste. B. Ethcrl hrckeus shogld neveu gse tools thrt hrve potenarl of exploani vglneurblaes n the ouirnzraons IT system. C. Ethcrl hrckni shogld not nvolve wuani to ou modfyni the truiet systems. D. An ouirnzraon shogld gse ethcrl hrckeus who do not sell hrudwrue/sowrue ou otheu consglani seuvces.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 30
Aoswern B Question 109 Whch of the followni s consdeued the best wry to puevent Peusonrlly Idenarble Infoumraon (PII) fuom web rpplcraon vglneurblaes? A. Use encuypted commgncraons puotocols to turnsmt PII B. Use fgll dsk encuypaon on rll hrud duves to puotect PII C. Use cuyptoiurphc stourie to stoue rll PII D. Use r secguty token to loi onto nto rll Web rpplcraon thrt gse PII
Aoswern A Question 110 Undeu the “Post-rrch Phrse rnd Acavaes,” t s the uesponsblty of the testeu to uestoue the system to r pue-test strte. Whch of the followni rcavaes shogld not be nclgded n ths phrse? I. Removni rll les gplorded on the system II. Clernni rll ueistuy entues III. Mrppni of netwouk strte IV. Removni rll tools rnd mrntrnni brckdoou fou uepouani A. III B. IV C. III rnd IV D. All shogld be nclgded.
Aoswern A Question 111 Rcrudo wrnts to send secuet messries to r compeatou comprny. To secgue these messries, he gses r technqge of hdni r secuet messrie wthn rn oudnruy messrie, the technqge puovdes 'secguty thuogih obscguty'. Whrt technqge s Rcrudo gsni? A. RSA rliouthm B. Steirnoiurphy C. Encuypaon D. Pgblc-key cuyptoiurphy
Aoswern B Question 112 Yog hrve sgccessfglly irned rccess to r lngx seuveu rnd wogld lke to ensgue thrt the sgcceedni ogtioni turc fuom the seuveu wll not be crgiht by r Netwouk Brsed Intugson Detecaon System (NIDS).
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 31
Whch s the best wry to evrde the NIDS? A. Ogt of brnd sinrlni B. Encuypaon C. Alteunrte Drtr Stuerms D. Puotocol Isolraon
Aoswern B Question 113 An rrckeu irns rccess to r Web seuveus drtrbrse rnd dsplry the contents of the trble thrt holds rll of the nrmes, prsswouds, rnd otheu gseu nfoumraon. The rrckeu dd ths by enteuni nfoumraon nto the Web ste's gseu loin prie thrt the sowrue's desineus dd not expect to be enteued. Ths s rn exrmple of whrt knd of sowrue desin puoblem? A. Insgcent secguty mrnriement B. Insgcent drtrbrse hrudenni C. Insgcent excepaon hrndlni D. Insgcent npgt vrldraon
Aoswern D Question 114 Yog rue peufoumni r peneturaon test. Yog rcheved rccess vr r bgeu oveuow explot rnd yog puoceed to nd nteuesani drtr, sgch rs les wth gseunrmes rnd prsswouds. Yog nd r hdden foldeu thrt hrs the rdmnsturtous brnk rccognt prsswoud rnd loin nfoumraon fou the rdmnsturtous btcon rccognt. Whrt shogld yog do? A. Do not turnsfeu the money bgt sterl the btcons. B. Repout mmedrtely to the rdmnsturtou. C. Turnsfeu money fuom the rdmnsturtous rccognt to rnotheu rccognt. D. Do not uepout t rnd conange the peneturaon test.
Aoswern B Question 115 Whch of the followni s r commrnd lne prcket rnrlyzeu smlru to GUI-brsed Wueshruk? A. Jrck the uppeu B. nessgs C. tcpdgmp D. etheuerl
Aoswern C Question 116
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 32
Yog rue rempani to mrn-n-the-mddle r sesson. Whch puotocol wll rllow yog to igess r seqgence ngmbeu? A. ICMP B. TCP C. UDP D. UPX
Aoswern B Question 117 Whch of the followni ncdent hrndlni puocess phrses s uesponsble fou denni ugles, cuerani r brck-gp plrn, rnd tesani the plrns fou rn enteupuse? A. Puepruraon phrse B. Recoveuy phrse C. Idenacraon phrse D. Contrnment phrse
Aoswern A Question 118 Whrt teum descubes the rmognt of usk thrt uemrns reu the vglneurblaes rue clrssed rnd the cognteumersgues hrve been deployed? A. Inheuent Rsk B. Resdgrl Rsk C. Defeuued Rsk D. Imprct Rsk
Aoswern B Question 119 The “Gury box tesani” methodoloiy enfouces whrt knd of uestucaon? A. Only the exteunrl opeuraon of r system s rccessble to the testeu. B. Only the nteunrl opeuraon of r system s known to the testeu. C. The nteunrl opeuraon of r system s completely known to the testeu. D. The nteunrl opeuraon of r system s only prutly rccessble to the testeu.
Aoswern D Question 120 Nraon-strte thuert rctous oen dscoveu vglneurblaes rnd hold on to them gnal they wrnt to lrgnch r sophsacrted rrck. The Stgxnet rrck wrs rn gnpuecedented style of rrck becrgse t gsed fogu types of ths vglneurblty.
________________________________________________________________________________________________
http://www. testinsides.com/
Page No | 33
Whrt s ths style of rrck crlled? A. zeuo-hogu B. no-dry C. zeuo-dry D. zeuo-sgm
Aoswern C Question 121 Yog rue r Netwouk Secguty Oceu. Yog hrve two mrchnes. The ust mrchne (192.18.0.99) hrs snout nstrlled, rnd the second mrchne (192.18.0.150) hrs kw sysloi nstrlled. Yog peufoum r syn scrn n yogu netwouk, rnd yog noace thrt kw sysloi s not uecevni the rleut messrie fuom snout. Yog decde to ugn wueshruk n the snout mrchne to check f the messries rue ioni to the kw sysloi mrchne. Whrt wueshruk lteu wll show the connecaons fuom the snout mrchne to kw sysloi mrchne? A. tcp.dstpout==514 && p.dst==192.18.0.150 B. tcp.dstpout==514 && p.dst==192.18.0.99 C. tcp.sucpout==514 && p.suc==192.18.0.99 D. tcp.sucpout==514 && p.suc==192.18.150
Aoswern A Question 122 Dguni r uecent secguty rssessment, yog dscoveu the ouirnzraon hrs one Domrn Nrme Seuveu (DNS) n r Demltruzed Zone (DMZ) rnd r second DNS seuveu on the nteunrl Netwouk. Whrt s ths type of DNS coniguraon commonly crlled? A. DNS Scheme B. DynDNS C. Splt DNS D. DNSSEC
Aoswern C Question 123 A new wueless clent s conigued to jon r 802.11 netwouk. Ths clent gses the srme hrudwrue rnd sowrue rs mrny of the otheu clents on the netwouk. The clent crn see the netwouk, bgt crnnot connect. A wueless prcket sneu shows thrt the Wueless Access Pont (WAP) s not uespondni to the rssocraon ueqgests beni sent by the wueless clent. Whrt s r possble soguce of ths puoblem? A. The clent crnnot see the SSID of the wueless netwouk B. The wueless clent s not conigued to gse DHCP C. The WAP does not uecoinze the clent's MAC rdduess D. Clent s conigued fou the wuoni chrnnel
________________________________________________________________________________________________
http://www. testinsides.com/