Pass the ECCouncil CEH v12 312-50v12 Questions and answers with CertsForce

Viewing page 5 out of 12 pages
Viewing questions 61-75 out of questions
Questions # 61:

A hacker is an intelligent individual with excellent computer skills and the ability to explore a computer’s software and hardware without the owner’s permission. Their intention can either be to simply gain knowledge or to illegally make changes.

Which of the following class of hacker refers to an individual who works both offensively and defensively at various times?

Options:

A.

White Hat


B.

Suicide Hacker


C.

Gray Hat


D.

Black Hat


Expert Solution
Questions # 62:

An Intrusion Detection System (IDS) has alerted the network administrator to a possibly malicious sequence of packets sent to a Web server in the network’s external DMZ. The packet traffic was captured by the IDS and saved to a PCAP file. What type of network tool can be used to determine if these packets are genuinely malicious or simply a false positive?

Options:

A.

Protocol analyzer


B.

Network sniffer


C.

Intrusion Prevention System (IPS)


D.

Vulnerability scanner


Expert Solution
Questions # 63:

Based on the following extract from the log of a compromised machine, what is the hacker really trying to steal?

Options:

A.

har.txt


B.

SAM file


C.

wwwroot


D.

Repair file


Expert Solution
Questions # 64:

Why should the security analyst disable/remove unnecessary ISAPI filters?

Options:

A.

To defend against social engineering attacks


B.

To defend against webserver attacks


C.

To defend against jailbreaking


D.

To defend against wireless attacks


Expert Solution
Questions # 65:

An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections.

When users accessed any page, the applet ran and exploited many machines. Which one of the following tools the hacker probably used to inject HTML code?

Options:

A.

Wireshark


B.

Ettercap


C.

Aircrack-ng


D.

Tcpdump


Expert Solution
Questions # 66:

You just set up a security system in your network. In what kind of system would you find the following string of characters used as a rule within its configuration? alert tcp any any -> 192.168.100.0/24 21 (msg: ““FTP on the network!””;)

Options:

A.

A firewall IPTable


B.

FTP Server rule


C.

A Router IPTable


D.

An Intrusion Detection System


Expert Solution
Questions # 67:

What is the role of test automation in security testing?

Options:

A.

It is an option but it tends to be very expensive.


B.

It should be used exclusively. Manual testing is outdated because of low speed and possible test setup inconsistencies.


C.

Test automation is not usable in security due to the complexity of the tests.


D.

It can accelerate benchmark tests and repeat them with a consistent test setup. But it cannot replace manual testing completely.


Expert Solution
Questions # 68:

Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?

Options:

A.

Nikto


B.

John the Ripper


C.

Dsniff


D.

Snort


Expert Solution
Questions # 69:

The “Gray-box testing” methodology enforces what kind of restriction?

Options:

A.

Only the external operation of a system is accessible to the tester.


B.

The internal operation of a system in only partly accessible to the tester.


C.

Only the internal operation of a system is known to the tester.


D.

The internal operation of a system is completely known to the tester.


Expert Solution
Questions # 70:

Which of the following statements about a zone transfer is correct? (Choose three.)

Options:

A.

A zone transfer is accomplished with the DNS


B.

A zone transfer is accomplished with the nslookup service


C.

A zone transfer passes all zone information that a DNS server maintains


D.

A zone transfer passes all zone information that a nslookup server maintains


E.

A zone transfer can be prevented by blocking all inbound TCP port 53 connections


F.

Zone transfers cannot occur on the Internet


Expert Solution
Questions # 71:

Bob, a network administrator at BigUniversity, realized that some students are connecting their notebooks in the wired network to have Internet access. In the university campus, there are many Ethernet ports available for professors and authorized visitors but not for students.

He identified this when the IDS alerted for malware activities in the network. What should Bob do to avoid this problem?

Options:

A.

Disable unused ports in the switches


B.

Separate students in a different VLAN


C.

Use the 802.1x protocol


D.

Ask students to use the wireless network


Expert Solution
Questions # 72:

What is the known plaintext attack used against DES which gives the result that encrypting plaintext with one DES key followed by encrypting it with a second DES key is no more secure than using a single key?

Options:

A.

Man-in-the-middle attack


B.

Meet-in-the-middle attack


C.

Replay attack


D.

Traffic analysis attack


Expert Solution
Questions # 73:

Which Intrusion Detection System is the best applicable for large environments where critical assets on the network need extra scrutiny and is ideal for observing sensitive network segments?

Options:

A.

Honeypots


B.

Firewalls


C.

Network-based intrusion detection system (NIDS)


D.

Host-based intrusion detection system (HIDS)


Expert Solution
Questions # 74:

The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. Which of the following options can be useful to ensure the integrity of the data?

Options:

A.

The CFO can use a hash algorithm in the document once he approved the financial statements


B.

The CFO can use an excel file with a password


C.

The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document


D.

The document can be sent to the accountant using an exclusive USB for that document


Expert Solution
Questions # 75:

Steve, a scientist who works in a governmental security agency, developed a technological solution to identify people based on walking patterns and implemented this approach to a physical control access.

A camera captures people walking and identifies the individuals using Steve’s approach.

After that, people must approximate their RFID badges. Both the identifications are required to open the door. In this case, we can say:

Options:

A.

Although the approach has two phases, it actually implements just one authentication factor


B.

The solution implements the two authentication factors: physical object and physical characteristic


C.

The solution will have a high level of false positives


D.

Biological motion cannot be used to identify people


Expert Solution
Viewing page 5 out of 12 pages
Viewing questions 61-75 out of questions