Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the ECCouncil CEH v13 312-50v13 Questions and answers with CertsForce

Viewing page 6 out of 16 pages
Viewing questions 76-90 out of questions
Questions # 76:

Why is using Google Hacking justified during passive footprinting?

Options:

A.

Identifying weaknesses in website source code


B.

Locating phishing sites mimicking the organization


C.

Mapping internal network structures


D.

Discovering hidden organizational data indexed by search engines


Expert Solution
Questions # 77:

A penetration tester is assessing a company ' s executive team for vulnerability to sophisticated social engineering attacks by impersonating a trusted vendor and leveraging internal communications. What is the most effective social engineering technique to obtain sensitive executive credentials without being detected?

Options:

A.

Develop a fake social media profile to connect with executives and request private information


B.

Conduct a phone call posing as the CEO to request immediate password changes


C.

Create a targeted spear-phishing email that references recent internal projects and requests credential verification


D.

Send a mass phishing email with a malicious link disguised as a company-wide update


Expert Solution
Questions # 78:

A penetration tester discovers that a web application uses unsanitized user input to dynamically generate file paths. The tester identifies that the application is vulnerable to Remote File Inclusion (RFI). Which action should the tester take to exploit this vulnerability?

Options:

A.

Inject a SQL query into the input field to perform SQL injection


B.

Use directory traversal to access sensitive system files on the server


C.

Provide a URL pointing to a remote malicious script to include it in the web application


D.

Upload a malicious shell to the server and execute commands remotely


Expert Solution
Questions # 79:

At a cybersecurity consultancy firm in Boston, senior analyst Amanda Liu is called in to assess a malware outbreak affecting a regional healthcare provider. Despite using updated antivirus tools, the security team notices inconsistent detection across infected endpoints. Amanda discovers that while the malicious behavior is consistent, system file tampering and suspicious outbound traffic, each malware sample has a slightly different code structure and fails traditional hash-based comparison. Static analysis reveals that the underlying logic remains unchanged, but the code patterns vary unpredictably across infections. What type of virus is most likely responsible for this behavior?

Options:

A.

Cavity virus


B.

Macro virus


C.

Polymorphic virus


D.

Stealth virus


Expert Solution
Questions # 80:

During an internal investigation at a healthcare billing firm in Denver, Colorado, the security team analyzes suspicious activity involving a senior accountant’s corporate smartphone. The user reports that the device behaved normally and that no links were clicked or applications installed during the timeframe in question.

Telecom monitoring reveals that the device received several binary-formatted SMS messages shortly before the incident. These messages were not visible in the messaging application. Within minutes of receiving them, the phone began transmitting cellular location identifiers and device-related data to an unfamiliar external system. The transmissions occurred automatically and did not require any user interaction.

Which mobile attack technique most accurately explains this behavior?

Options:

A.

Call Spoofing


B.

OTP Hijacking


C.

SMiShing


D.

SIMjacker


Expert Solution
Questions # 81:

Several months prior to a confirmed compromise, security telemetry at a semiconductor manufacturer in Phoenix, Arizona showed systematic intelligence gathering focused on executive leadership, research engineers, and publicly exposed infrastructure.

Subsequent investigation determined that the adversary had assembled customized exploit frameworks, tested malware variants against commercial defensive products in isolated environments, and mapped externally accessible services associated with the organization.

These activities were part of a coordinated strategy developed well before any credential abuse or lateral movement was observed.

Determine the APT lifecycle stage represented by these actions.

Options:

A.

Persistence


B.

Expansion


C.

Preparation


D.

Initial Intrusion


Expert Solution
Questions # 82:

When referring to the domain name service, what is a zone?

Options:

A.

A collection of domains


B.

The zone namespace


C.

A collection of alias records


D.

A collection of resource records


Expert Solution
Questions # 83:

A REST API uses user-provided object IDs without authorization checks. What flaw is this?

Options:

A.

Mass assignment


B.

XSS


C.

SQLi


D.

BOLA


Expert Solution
Questions # 84:

During a penetration test at IntelliCore Systems in Raleigh, North Carolina, ethical hacker Javier directs a wave of repetitive web requests against the company ' s portal that overloads backend scripts which process search queries and form submissions. As a result, legitimate customers experience long delays and occasional timeouts while attempting to log in or complete transactions.

Which DoS/DDoS technique is Javier most likely demonstrating?

Options:

A.

Slowloris


B.

UDP Flood


C.

Peer-to-Peer Attack


D.

HTTP GET/POST Attack


Expert Solution
Questions # 85:

A penetration tester is assessing a web application that employs secure, HTTP-only cookies, regenerates session IDs upon login, and uses strict session timeout policies. To hijack a user ' s session without triggering the application ' s security defenses, which advanced technique should the tester utilize?

Options:

A.

Perform a session token prediction by analyzing session ID entropy and patterns


B.

Conduct a network-level man-in-the-middle attack to intercept and reuse session tokens


C.

Execute a Cross-Site Request Forgery (CSRF) attack to manipulate session states


D.

Implement a session fixation strategy by pre-setting a session ID before user authentication


Expert Solution
Questions # 86:

A penetration tester is tasked with assessing the security of an Android mobile application that stores sensitive user data. The tester finds that the application does not use proper encryption to secure data at rest. What is the most effective way to exploit this vulnerability?

Options:

A.

Access the local storage to retrieve sensitive data directly from the device


B.

Use SQL injection to retrieve sensitive data from the backend server


C.

Execute a Cross-Site Scripting (XSS) attack to steal session cookies


D.

Perform a brute-force attack on the application ' s login credentials


Expert Solution
Questions # 87:

A future-focused security audit discusses risks where attackers collect encrypted data now, anticipating that they can decrypt it later with quantum computers. What is this threat known as?

Options:

A.

Saving data today for future quantum decryption


B.

Replaying intercepted quantum messages


C.

Breaking RSA using quantum algorithms


D.

Flipping qubit values to corrupt the output


Expert Solution
Questions # 88:

What is CVSS used for?

Options:

A.

Auditing


B.

Encryption


C.

Severity scoring


D.

Exploitation


Expert Solution
Questions # 89:

Which advanced session hijacking technique is hardest to detect and mitigate in a remote-access environment?

Options:

A.

Session sidejacking over public Wi-Fi


B.

ARP spoofing on local networks


C.

Brute-force session guessing


D.

Cookie poisoning


Expert Solution
Questions # 90:

A fintech startup in Austin, Texas deploys several virtual machines within a public cloud environment. During an authorized cloud security assessment, a tester uploads a small script to one of the instances through a web application vulnerability. After executing the script locally on the instance, the tester retrieves temporary access credentials associated with the instance ' s assigned role. These credentials are then used to enumerate storage resources and access additional cloud services within the same account. Which cloud attack technique best corresponds to this activity?

Options:

A.

Cloud Snooper Attack


B.

Wrapping Attack


C.

IMDS Attack


D.

CP DoS Attack


Expert Solution
Viewing page 6 out of 16 pages
Viewing questions 76-90 out of questions