問題1
A penetration tester discovers that a web application is vulnerable to Local File Inclusion (LFI) due to improper input validation in a URL parameter. Which approach should the tester take to exploit this vulnerability?
A penetration tester discovers that a web application is vulnerable to Local File Inclusion (LFI) due to improper input validation in a URL parameter. Which approach should the tester take to exploit this vulnerability?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題2
After installing a backdoor on a web server, what action best ensures it remains undetected?
After installing a backdoor on a web server, what action best ensures it remains undetected?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題3
A network administrator reviews logs and observes that an attacker sends packets requesting the target system' s internal clock value. The response includes timing information that can be used to calculate round-trip delay and analyze host characteristics.
What host discovery technique is being used in this scenario?
A network administrator reviews logs and observes that an attacker sends packets requesting the target system' s internal clock value. The response includes timing information that can be used to calculate round-trip delay and analyze host characteristics.
What host discovery technique is being used in this scenario?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題4
During a high-stakes engagement, a penetration tester abuses MS-EFSRPC to force a domain controller to authenticate to an attacker-controlled server. The tester captures the NTLM hash and relays it to AD CS to obtain a certificate granting domain admin privileges. Which network-level hijacking technique is illustrated?
During a high-stakes engagement, a penetration tester abuses MS-EFSRPC to force a domain controller to authenticate to an attacker-controlled server. The tester captures the NTLM hash and relays it to AD CS to obtain a certificate granting domain admin privileges. Which network-level hijacking technique is illustrated?
正確答案: D
說明:(僅 NewDumps 成員可見)
問題5
In an ethical hacking methodology and framework, which of the following step is known for "active and passive information gathering"?
In an ethical hacking methodology and framework, which of the following step is known for "active and passive information gathering"?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題6
Which vulnerability exploits memory corruption?
Which vulnerability exploits memory corruption?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題7
In a recent cybersecurity incident, Google's response team in the United States investigated a severe attack that briefly disrupted services and customer-facing platforms for approximately 2-3 minutes. Server logs recorded a sudden surge in traffic, peaking at 398 million requests per second, which caused active connections to drop unexpectedly. The attack was traced to numerous compromised devices, likely orchestrated through malicious tools promoted on social media. Based on this information, what type of attack was most likely executed against Google's infrastructure?
In a recent cybersecurity incident, Google's response team in the United States investigated a severe attack that briefly disrupted services and customer-facing platforms for approximately 2-3 minutes. Server logs recorded a sudden surge in traffic, peaking at 398 million requests per second, which caused active connections to drop unexpectedly. The attack was traced to numerous compromised devices, likely orchestrated through malicious tools promoted on social media. Based on this information, what type of attack was most likely executed against Google's infrastructure?
正確答案: C
說明:(僅 NewDumps 成員可見)
問題8
In the heart of Silicon Valley, California, network administrator Jake Henderson oversees the web infrastructure for TechTrend Innovations, a startup specializing in cloud solutions. During a routine architecture review, Jake evaluates the setup of their web server, which handles high-traffic API requests. He notes that the server's primary module processes incoming requests and works with additional modules to manage encryption, URL rewriting, and authentication. Curious about the server's design, Jake consults the documentation to ensure optimal performance and security.
Which web server component is Jake analyzing as part of TechTrend Innovations' architecture?
In the heart of Silicon Valley, California, network administrator Jake Henderson oversees the web infrastructure for TechTrend Innovations, a startup specializing in cloud solutions. During a routine architecture review, Jake evaluates the setup of their web server, which handles high-traffic API requests. He notes that the server's primary module processes incoming requests and works with additional modules to manage encryption, URL rewriting, and authentication. Curious about the server's design, Jake consults the documentation to ensure optimal performance and security.
Which web server component is Jake analyzing as part of TechTrend Innovations' architecture?
正確答案: B
說明:(僅 NewDumps 成員可見)
問題9
Which advanced session-hijacking technique is hardest to detect and mitigate?
Which advanced session-hijacking technique is hardest to detect and mitigate?
正確答案: A
說明:(僅 NewDumps 成員可見)
問題10
During a red team simu-lation at a bank in Chicago, Illinois, the SOC team suspects that some of the incoming traffic may be spoofed. To verify this, an analyst begins monitoring the sequence values assigned to packets, looking for irregularities that indicate they were not generated by the legitimate source. Which spoofing detection technique is the analyst using?
During a red team simu-lation at a bank in Chicago, Illinois, the SOC team suspects that some of the incoming traffic may be spoofed. To verify this, an analyst begins monitoring the sequence values assigned to packets, looking for irregularities that indicate they were not generated by the legitimate source. Which spoofing detection technique is the analyst using?
正確答案: B
說明:(僅 NewDumps 成員可見)