option
Questions
ayuda
daypo
search.php

III

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
III

Description:
Testi I ok

Creation Date: 2026/08/25

Category: Others

Number of questions: 100

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

Which Nmap scan is stealthiest?. SYN. UDP. TCP Connect. Xmas.

You have gone to an organization’s website to gather information, such as employee names, email addresses, and phone numbers. Which step of the hacker’s methodology does this correspond to?. Reconnaissance. Fingerprinting. Scanning and enumeration. Gaining access.

An attacker abuses PowerShell heavily. Which log helps most?. PowerShell script block logs. Syslog. Firewall logs. DNS logs.

A digital publishing firm in Charlotte, North Carolina, noticed suspicious probing activity against its public website. To proactively assess exposure, the security team initiated a focused scan of the company's HTTP servers. The chosen tool examined server headers, identified installed web server software through file signatures and favicon analysis, checked for outdated components, and searched for potentially dangerous files and misconfigurations. The scan also supported SSL connections and generated exportable reports in multiple formats for documentation. Which vulnerability assessment tool most closely aligns with the capabilities described?. Nikto. Nessus. Qualys VM. OpenVAS.

You are part of a red team hired to assess the cybersecurity posture of a large retail chain headquartered in New York. The client wants to know whether their defenses can anticipate future attack patterns before they occur. To meet this objective, your team deploys an AI-enabled platform that analyzes previous breaches and anomaly data to forecast potential attack vectors. Which benefit of AI-driven ethical hacking is most critical in this case?. Predictive analysis. Simulation and testing. Enhanced reporting. Scalability.

A regional logistics provider in Charlotte, North Carolina, operates its shipment tracking and partner API services on an Apache web platform configured to support a modern multiplexed communication protocol to improve efficiency under concurrent load. During a controlled stress assessment, testers simulate sustained client activity that repeatedly initiates and completes numerous lightweight exchanges over persistent connections. Over time, system monitoring reveals that memory utilization steadily increases despite stable request volume and no proportional rise in active sessions. Even after the simulated clients disconnect normally, resource usage does not return to baseline levels. After several cycles, the service becomes sluggish and must be restarted to restore normal responsiveness. No unusual disk activity or database errors are observed during the test window. The behavior is only present when the multiplexed protocol mode is enabled; reverting to legacy handing eliminates the issue. Which Apache vulnerability best explains this behavior?. HTTP/2 Stream Memory Not Reclaimed on RST. Insecure Default Configuration. mod_macro Buffer Over-read. DoS in HTTR/2 with Initial Window Size 0.

You have been asked to perform a penetration test for a local company. You have had several meetings with the client and are now almost ready to begin the assessment. Which of the following is the document that would contain verbiage which describes what type of testing is allowed and when you will perform testing and limits your liabilities as a penetration tester?. Rules of engagement. Service-level agreement. Nondisclosure agreement. Project scope.

Which of the following tools is used to analyze the files produced by several packet-capture programs such as tcpdump, WinDump, Wireshark, and EtherPeek?. tcptrace. OpenVAS. tcptraceroute. Nessus.

During a red team exercise for a global insurance provider in Chicago, ethical hacker Maria tests the effectiveness of the company’s endpoint defenses. She launches an attack by injecting malicious PowerShell commands into a trusted process without dropping any executables on disk. The code executes entirely in memory, generating abnormal spikes in resource usage. After a reboot, Maria notes that the system returns to normal and traditional antivirus logs show no evidence of infection. Which type of malware technique did Maria most likely use in this test?. Fileless Malware. Ransomware. Trojan. Rootkit.

During a penetration test at a healthcare provider in Phoenix, ethical hacker Sofia crafts a stream of IP packets with manipulated offset fields and overlapping payload offsets so that the records server’s protocol stack repeatedly attempts to reconstruct the original datagrams. The repeated reconstruction attempts consume CPU and memory, causing the system to crash intermittently and disrupt patient portal access, even though overall bandwidth remains normal. Packet analysis shows deliberately malformed offsets that trigger processing errors rather than a simple flood of traffic. Which type of attack is Sofia most likely simulating?. Teardrop Attack. Fragmentation Attack. Ping of Death. ICMP Flood.

Upon completing a vulnerability evaluation for a financial services firm in Cincinnati, Ohio, the security team finalized its formal report for executive review. One portion of the document grouped identified weaknesses into severity tiers and highlighted systems with elevated exposure levels across the environment. This part of the report emphasized the relative impact and prioritization of identified weaknesses across affected assets. Which component of the vulnerability assessment report is represented in this scenario?. Risk Assessment. Findings. Recommendations. Assessment Overview.

An ethical hacker conducting an authorized assessment of a multinational advisory firm begins collecting intelligence exclusively from publicly accessible online platforms where employees share professional background details and engage in industry related discussions. By correlating individual role descriptions, publicly endorsed technical competencies, collaborative conversations referencing internal initiatives, and recurring terminology used to describe projects and departments, the tester develops a structured view of reporting relationships, identifies commonly deployed technologies, and infers internal naming conventions. From a reconnaissance methodology perspective, which technique is being applied?. Footprinting through Social Networking Sites. Footprinting through Internet Research Services. Footprinting through Search Engines. Footprinting through Social Engineering.

What does ATT&CK tactic “Persistence” mean?. Long-term access. Cleanup. Data theft. Initial exploit.

Which of the following best describes an attack that altered the contents of two critical files?. Integrity. Confidentially. Authentication. Availability.

Which individuals believe that hacking and defacing websites can promote social change?. Hacktivists. Gray hat hackers. Black hat hackers. Ethical hackers.

Justin Fletcher is conducting an authorized assessment for EverSafe Technologies in Las Vegas. During the active reconnaissance phase, he interacts directly with the organization's infrastructure to retrieve structural details about how its public-facing systems are logically organized. His activity generates entries within the target environment's monitoring systems. Which type of active footprinting technique is Justin performing?. DNS interrogation. Network/port scanning. Social engineering. User and service enumeration.

A healthcare analytics firm in Denver, Colorado, hosts several internal applications on an IIS web server. During an authorized security assessment, a tester evaluates a lesser-used endpoint designed for administrative operations. By sending crafted HTTP requests directly to this endpoint, the tester is able to invoke server-side management functions without interacting with the standard login workflow presented by the primary user interface. Further review indicates that certain restricted operations can be executed when accessed through alternate request paths, suggesting inconsistent enforcement of access controls within the application. Which IIS vulnerability is most accurately demonstrated in this scenario?. Authentication bypass vulnerability. CRLF cross-site scripting vulnerability. Trust boundary violation vulnerability. File and directory permissions vulnerability.

The various hping commands are as follows. During an authorized penetration test, a security analyst executes a TCP-based probe using hping without attempting to complete the three-way handshake. Packet analysis shows that closed ports return a TCP RST response, while open ports do not generate any reply. The crafted packets contain a non-standard combination of TCP control bits rather than relying on a single control flag. Which scanning technique is being performed?. FIN, PUSH and URG scan on port 80. ACK scan on port 80. ICMP ping. UDP scan on port 80.

While reviewing exposed infrastructure for a logistics company in Denver, Joe, a security analyst, identifies that one host is synchronizing time using UDP port 123. Probing further, he issues queries to extract details about peers, offsets, and delays. This allows him to gather internal hostnames and client IP addresses connected to the time server. Such information leakage could provide insight into the company’s internal network structure. Which technique was most likely used to obtain this information?. NTP Enumeration. NetBIOS Enumeration. DNS Zone Transfer Enumeration. VoIP Enumeration.

A compromised endpoint communicates with C2 using DNS queries. What system-level indicator exists?. DNS anomalies. Memory leaks. Disk usage. CPU spikes.

Which defense MOST disrupts ransomware spread?. Network segmentation. AV. IDS. Backup.

A national retail chain headquartered in Minneapolis, Minnesota operates a customer rewards portal supported by front-end delivery layers designed to improve performance during peak shopping periods. During an authorized security assessment, a tester submits a specially crafted request containing unusual header combinations and a modified query parameter while accessing a promotional page. Shortly afterward, other legitimate users requesting the same promotional page through standard browsers begin receiving altered content that differs from what the application normally generates. When the tester accesses the underlying origin system directly, the response reflects the expected legitimate version. After some time and additional routine traffic, the unexpected content is no longer served. Identify the attack technique best explains this observed behavior?. Web Cache Poisoning Attack. SQL Injection Vulnerability. DNS Rebinding Attack. DNS Server Hijacking.

During which step of the incident response process would you be tasked with building the team, identifying roles, and testing the communication system?. Preparation. Recovery. Notification. Containment.

A web app deserializes untrusted data leading to RCE. What flaw exists?. Insecure deserialization. XSS. SQLi. SSTI.

During a compliance audit at a logistics company in Columbus, Ohio, the mobile security team discovers that several field-issued Android devices are responding to remote commands from an unknown external system. The affected devices are not connected via USB, and no enterprise mobility policies were recently modified. Network monitoring reveals that the devices have remote debugging enabled and are accepting connections over the wireless network on a specific high-numbered port commonly associated with remote device communication. Investigators determine that the external system was able to capture screenshots, list installed applications, forward ports, and install additional packages without requiring physical access to the devices. Which attack technique most accurately explains this compromise?. ADB Exploitation via TCP 5555. Device Administration API Abuse. FRP Bypass. Android Rooting.

A system allows execution from /tmp directory. What risk exists?. Malware execution. SQLi. XSS. DoS.

A regional healthcare provider in Minneapolis, Minnesota, began experiencing intermittent connectivity issues across a newly activated access-layer network segment. Shortly after a contractor connected a diagnostic device to an unused switch port, multiple employee workstations failed to receive valid network configurations. System logs showed repeated address negotiation attempts from affected hosts, while monitoring tools recorded a rapid sequence of configuration requests originating from a single switch interface. Within minutes, additional clients on the segment encountered similar assignment failures. From a sniffing standpoint, which technique most accurately explains this behavior?. DHCP Starvation. MAC Spoofing. Rogue DHCP Server. IRDP Spoofing.

A cybersecurity team at a cloud infrastructure provider in San Jose, California, initiated a structured vulnerability evaluation across its production environment. The scanning process began by identifying communication protocols active on each host. Once the protocols were cataloged, the platform analyzed which services were associated with those ports and dynamically selected only the vulnerability tests relevant to those detected services. The scanning logic adjusted automatically based on discoveries made during execution. Which vulnerability assessment approach is illustrated in this scenario?. Inference-Based Assessment. Product-Based Solutions. Service-Based Solutions. Tree-Based Assessment.

As part of an internal security assessment at First Union Bank in Chicago, Rachel Morgan is evaluating whether unauthorized packet capture tools are operating within the loan processing segment of the network. During traffic observation, she notices behavior suggesting that a particular host may be processing frames beyond its intended destination scope. To verify whether the network interface is accepting traffic not explicitly addressed to it, Rachel decides to transmit specially crafted packets designed to provoke an abnormal response from a system operating in promiscuous mode. Which detection technique should Rachel use to confirm the presence of a sniffer?. Ping method by sending packets with an incorrect MAC address. DNS method by monitoring reverse DNS lookup traffic. Sniffer detection using an NSE script to check for promiscuous mode. ARP method by sending non-broadcast ARP requests.

During a strategic security briefing at Meridian Global Analytics in Washington, D.C., executives review a series of coordinated activities targeting national infrastructure. These activities include manipulating digital media to influence public perception, disrupting communication networks, and degrading critical systems to weaken institutional stability without direct conventional military engagement. What form of conflict best describes this type of coordinated activity?. Information warfare. Cyber espionage. Cyberterrorism. Hacktivism.

Your ethical hacking firm has been hired to conduct a penetration test. Which of the following documents limits the scope of your activities?. Terms of engagement. Memorandum of understanding. Nondisclosure agreement. PCI-DSS.

As part of a red team campaign against a pharmaceutical company in Boston, ethical hacker Alex begins with a successful spear-phishing attack that delivers an initial payload to a manager’s laptop. After gaining access, Alex pivots to harvesting cached credentials and using them to move laterally across the internal network. Soon, routers, printers, and several file servers are compromised, expanding the red team’s control beyond the original host. At this point, Alex has not yet targeted sensitive research data, but the team has built a broader foothold within the environment. Which phase of the Advanced Persistent Threat (APT) lifecycle is Alex simulating?. Persistence. Search & Exfiltration. Expansion. Initial Intrusion.

A multinational healthcare provider headquartered in Boston, Massachusetts, relies on federated authentication to allow employees to access multiple cloud- hosted applications using a single sign-on portal. During an authorized red team engagement, a security consultant gains access to the organization's identity infrastructure and extracts signing material used in trust relationships between the internal identity provider and external cloud services. Using this material, the constant generates authentication responses that grant administrative-level access to several cloud applications without interacting with user credential or triggering multifactor authentication challenges. The access appears legitimate within the cloud service logs. Which cloud attack technique best aligns with this behavior?. Golden SAML Attack. Man-in-the-Cloud (MITC) Attack. Living off the Cloud (LotC) Attack. Cloud Hopper Attack.

A system’s audit logs are not centralized. Which attack phase is hardest to detect?. Initial access. Lateral movement. Delivery. Recon.

A fintech startup in Austin, Texas, deploys several virtual machines within a public cloud environment. During an authorized cloud security assessment, a tester uploads a small script to one of the instances through web application vulnerability. After executing the script locally on the instance, the tester retrieves temporary access credentials associated with the instance's assigned role. These credentials are then used to enumerate storage resources and access additional cloud services within the same account. Which cloud attack technique best corresponds to this activity?. IMDS Attack. Cloud Snooper Attack. CPDoS Attack. Wrapping Attack.

A technology consulting firm in Denver, Colorado, recently experienced a wave of suspicious account compromise incidents. Several employees reported receiving an email that appeared identical to a legitimate cloud storage notification they had received earlier that week. The message reused the original branding, formatting, sender display name, and subject line. However, it informed recipients that the previously shared document had been "updated due to synchronization errors" and instructed them to reauthenticate using the embedded link. The link directed users to a convincing replica of the organization's authentication portal. Investigation revealed that the attacker had reused content from a genuine prior communication and modified only the embedded hyperlink. Which type of social engineering attack does this scenario most accurately represent?. Clone Phishing. Search Engine Phishing. Tabnabbing. Consent Phishing.

Which protocol is insecure by default?. Telnet. SSH. SFTP. HTTPS.

Which of the following addresses the secrecy and privacy of information?. Confidentiality. Authentication. Integrity. Availability.

What does TTL manipulation help evade?. IDS. Encryption. Router. Firewall.

A digital media company in Seattle, Washington deploys an Nginx-based infrastructure to support its internal analytics dashboard and content publishing portal. During an authorized red team engagement, a tester evaluates the web-based administrative interface used to upload configuration bundles and manage application components. While analyzing a file-upload feature, the tester observes that certain user-supplied parameters submitted with uploaded content are incorporated into backend processing routines with limited validation. By adjusting specific values in the request, he alters how the server-side component interprets those inputs. Subsequent log analysis shows that the modified input affected system-level operations executed under the web service context, despite no direct shell access being obtained. Which Nginx-related vulnerability best describes the weakness identified in this scenario?. OS command injection in nginxWebUI. Server-side request forgery (SSRF) vulnerability. Improper certificate validation. NULL pointer dereference in HTTP/3.

At a digital marketing firm in Atlanta, Georgia, employees began reporting that access to a widely used cloud collaboration portal was intermittently redirecting them to a counterfeit interface hosted on an unfamiliar IP address. Security engineers observed that when multiple users across different departments attempted to access the legitimate domain, they consistently received the same incorrect IP resolution. The anomalous behavior persisted across sessions and affected numerous internal clients until the organization's name resolution service was restarted, after which normal resolution resumed. What DNS manipulation technique best explains this scenario?. Injecting malicious records through DNS Cache Poisoning. Performing Intranet DNS Spoofing within the local network. Executing Proxy Server DNS Poisoning to alter resolution paths. Conducting Internet DNS Spoofing from a remote network.

At a private aerospace research facility in Mesa, Arizona, an executive raises concerns after sensitive discussion points from speakerphone meetings begin surfacing externally. The device shows no indicators of active audio recording, and application permission history does not reflect recent camera or microphone authorization changes. A forensic mobile analysis identifies that an installed application has been continuously reading motion sensor output while the phone's loudspeaker is active. The collected sensor data was later transmitted to a remote server, where acoustic characteristics were reconstructed from the recorded measurements. Identify the attack technique responsible for this compromise. Spearphone Attack. Android Camera Hijack Attack. Camfecting. StormBreaker Abuse.

A digital forensics consultant in Portland, Oregon examines an iPhone seized as part of a corporate data leakage investigation. The device contains third-party extensions and system modifications not typically permitted by the operating system vendor. The owner explains that whenever the device is powered off and restarted, it boots normally and remains fully functional for everyday tasks such as calls and messaging. However, the custom extensions and system-level tweaks do not function until a specific jailbreak application installed on the device is manually executed. No external computer is required during this reactivation process. Determine the type of jailbreaking technique implemented on this device. Semi-Untethered Jailbreaking. Tethered Jailbreaking. Untethered Jailbreaking. Semi-Tethered Jailbreaking.

During an authorized wireless security assessment, an ethical hacker captures traffic between client devices and a corporate access point to evaluate the strength of the implemented encryption mechanism. Packet analysis reveals that before protected data exchange begins, the client and access point complete a structured four-message key negotiation process. Subsequent traffic is encrypted using an AES-based counter mode protocol that integrates message authentication for integrity protection. Based on these observations, identify the wireless encryption standard deployed on the network. WPA2. WPA3. WEP. WPA.

During a red team exercise at a financial services firm in Phoenix, Arizona, an ethical hacker sends a phishing email with a disguised attachment to employees. The purpose is to transmit the payload into the environment so later attack steps can proceed. In the cyber kill chain model, which phase does this represent?. Delivery. Reconnaissance. Exploitation. Weaponization.

What is sandbox evasion?. Malware hiding. Firewall bypass. Encryption. IDS bypass.

A large-scale inventory management platform implements a pattern-based inspection layer to prevent malicious database interactions. During authorized testing, repeated payloads containing recognizable structural sequences are denied before reaching the application logic. While analyzing the inspection behavior, the tester observes that blocked requests share a consistent textual arrangement of components. The tester then alters how those components are presented within the payload while preserving the intended database operation. After this adjustment, the request bypasses the inspection layer and executes successfully, producing results consistent with earlier attempts. Determine the evasion method that best accounts for this behavior. Modifying spacing and delimiter placement to disrupt detection patterns. Transforming literal parameters using alternate character encoding schemes. Constructing the payload dynamically through segmented string operations. Introducing inline comment delimiters to fragment instruction sequences.

A Linux system allows SSH login using deprecated ciphers. What risk exists?. Downgrade attacks. SQLi. XSS. DoS.

What indicates advanced persistent threat behavior?. Long dwell time. Malware spam. One-time exploit. Brute force.

After the completion of the pen test, you have provided the client with a list of controls to implement to reduce the identified risk. What term best describes the risk that remains after the controls have been implemented?. Residual risk. Gap analysis. Total risk. Inherent risk.

Which tool dumps Windows hashes?. Mimikatz. Aircrack-ng. Hydra. John.

What is data exfiltration?. Extraction. Deletion. Encryption. Corruption.

Which vulnerability exploits memory corruption?. Buffer overflow. XSS. CSRF. SQLi.

A regional healthcare provider in Portland, Oregon, recently migrated its patient scheduling portal to a new cloud platform. Within days, multiple patients reported that when searching online for the clinic's appointment system, they were directed to a website that looked identical to the official portal. The fraudulent page appeared prominently in search engine results and prompted users to log in using their patient credentials. The URL closely resembled the legitimate domain name, and no internal DNS servers had been altered within the organization's infrastructure. Security analysts later determined that the attacker had created a convincing replica of the portal and manipulated search visibility so that unsuspecting users would voluntarily navigate to the malicious site. Which type of social engineering technique best explains this attack?. Pharming. Spear Phishing. Spimming. Whaling.

Kevin and his friends are going through a local IT firm’s garbage. Which of the following best describes this activity?. Dumpster diving. Social engineering. Reconnaissance. Intelligence gathering.

You’ve just performed a port scan against an internal device during a routine pen test. Nmap returned the following response: Starting NMAP 7.30 at 2021-10-10 11:06 NMAP scan report for 192.168.123.100 Host is up (1.00s latency). Not shown: 993 closed ports PORT STATE SERVICE 80/tcp open http 161/tcp open snmp 515/tcp open Ipd MAC Address: 00:1B:A9:01:3a:21 Based on this scan result, which of the following is most likely correct?. The host is a printer. The host is most likely a Windows computer. The host is a Cisco router. The host is most likely a Linux computer.

Which of the following is one primary difference between a malicious hacker and an ethical hacker?. Ethical hackers use the same methods but strive to do no harm. Malicious hackers are more advanced than ethical hackers because they can use any technique to attack a system or network. Ethical hackers obtain permission before bringing down servers or stealing credit card databases. Malicious hackers use different tools and techniques than ethical hackers use.

A U.S.-based online securities trading firm in New York is reviewing its transaction authentication process. The security team confirms that each transaction is processed by first generating a hash of the transaction data. The hash value is then signed using the sender's private key. During verification, the recipient uses the corresponding public key to validate the signature before approving the transaction. The system documentation specifies that the same algorithm supports encryption, digital signatures, and key exchange mechanisms within the organization's secure communications infrastructure. Which encryption algorithm is being used in this implementation?. RSA. DSA. ElGamal. Diffie-Hellman.

Your company performs PCI-DSS audits and penetration testing for third-party clients. During an approved pen test you have discovered a folder on an employee’s computer that appears to have hundreds of credit card numbers and other forms of personally identifiable information (PII). Which of the following is the best course of action?. Stop the pen test immediately and contact management. Continue the pen test and include this information in your report. Make a copy of the data and store it on your local machine. Contact the employee and ask why they have the data.

Which attack abuses business logic?. Logic flaw. XSS. CSRF. SQLi.

What is RID cycling?. SMB enumeration. DNS attack. DoS. SQLi.

Which of the following is a common framework applied by business management and other personnel to identify potential events that may affect the enterprise, manage the associated risks and opportunities, and provide reasonable assurance that objectives will be achieved?. Risk management framework. Qualitative risk assessment. NIST SP 800-37. PC-DSS.

A state benefits processing platform in Sacramento, California, implemented a multi-step identity verification process before granting access to sensitive citizen records, During a controlled assessment, security analyst Daniel Kim observed that by altering specific request parameters within the transaction sequence, it was possible to bypass an intermediate verification stage and retrieve restricted account data. Further analysis revealed that the authentication workflow advanced through sequential client-driven interactions, but the server did not enforce strict validation of completion for each required stage before granting access. Based on the scenario, which vulnerability classification best describes the issue identified?. Design Flaws. Misconfigurations / Weak Configurations. Poor Patch Management. Application Flaws.

This type of security test might seek to target the CEO’s laptop or the organization’s backup tapes to extract critical information, usernames, and passwords. Stolen equipment. Insider attack. Physical entry. Outsider attack.

A Python API allows unlimited file upload size. What attack is possible?. DoS. XSS. SQLi. CSRF.

During a security review, you have discovered that there are no documented security policies for the area you are assessing. Which of the following would be the most appropriate course of action?. Identify and evaluate current practices. Increase the level of testing. Stop the audit. Create policies while testing.

During a red team exercise at a financial institution in New York, penetration tester Bob investigates irregularities in time synchronization across critical servers. While probing one server, he decides to use a diagnostic command that allows him to directly interact with the NTP daemon and query its internal state. This command enables him to perform monitoring and retrieve statistics, but it is primarily focused on controlling and checking the operation of the NTP service rather than listing peers with delay, offset, and jitter values. Which command should Bob use to accomplish this?. ntpdc [-ilnps] [-c command] [host] [...]. ntpq -p [host]. ntpq [-inp] [-c command] [host] [...]. ntptrace [-n] [-m maxhosts] [servername/IP_address].

A retail brand based in San Diego, California, authorized a controlled mobile security exercise to evaluate risks associated with third-party application distribution channels. Testers acquired a version of the company's customer rewards application from an unofficial marketplace frequently used by overseas customers. The application's visual layout and functionality were indistinguishable from the officially released version available in mainstream app stores. Behavioral monitoring conducted in a sandbox environment revealed that, in addition to its normal operations, the application initiated outbound connections unrelated to its documented features. A binary comparison against the vendor-supplied build confirmed structural differences between the two versions. What mobile-based social engineering technique does this scenario most accurately represent?. Repackaging Legitimate Apps after modifying their internal structure. Conducting SMiShing campaigns through fraudulent text messages. Publishing Malicious Apps designed to mimic trusted brands. Deploying Fake Security Applications disguised as protection tools.

Which of the following is a proprietary information security standard that requires organizations to follow security best practices and use 12 high-level requirements, aligned across six goals?. PCI-DSS. sox. FISMA. Risk Management Framework.

A financial technology firm in Atlanta, Georgia, launches an internal investigation after multiple employees report that a popular messaging application on their Android devices has begun displaying excessive advertisements and behaving unpredictably. Security analysts discover that users had installed a utility application from a third-party marketplace weeks earlier. Further examination shows that this application silently replaced certain legitimate apps already present on the device. The compromised applications were then used to generate large volumes of advertisements and collect user data for external transmission. Based on the observed behavior, what malware is most consistent with this incident?. Agent Smith. GoldPickaxe. Pegasus. Mamont.

What does AXFR allow?. Zone transfer. Encryption. DNS tunneling. Resolution.

What does an ACK scan mainly identify?. Firewall rules. Services. Closed ports. Open ports.

Which attack abuses scheduled tasks?. Persistence. Reconnaissance. Sniffing. DoS.

A regional law firm authorizes a wireless resilience evaluation after employees report intermittent connectivity disruptions in conference rooms. An ethical hacker assigned to the assessment analyses client behaviour while transmitting carefully crafted 802.11 management frames toward the organization's primary access point. Each transmission immediately causes several connected laptops to lose association with the network, requiring users to reconnect manually. Connectivity interruptions occur only when the crafted frames are sent. Identify the wireless attack illustrated by this activity. Deauthentication Attack. Eavesdropping Attack. Evil Twin Attack. Jamming Attack.

What is the purpose of banner grabbing?. Identification. Exploitation. Cracking. Sniffing.

A regional e-commerce company in Dallas, Texas, operates an Apache-based web server to manage product catalogs and promotional campaigns. During an authorized assessment, a security consultant analyzes how the platform processes a referral parameter embedded in product-sharing links. While reviewing responses through an intercepting proxy, he observes that values supplied in the referral parameter are incorporated into metadata returned to the browser. By introducing carefully crafted; into the parameter, he notices that the structure of the server's outbound response changes in an unexpected manner. Further testing shows that the manipulated input causes the server to generate multiple logically distinct response segments within what should have been a single transaction. When the crafted link is accessed through a standard browser, the client interprets the injected portion as a separate directive, resulting in redirection behavior influenced by the attacker-controlled input. Identity the web server attack technique being demonstrated in this scenario. HTTP Response-Splitting Attack. Directory Traversal Attack. Frontjacking Attack. Web Cache Poisoning Attack.

A defense contractor in Arlington, Virginia, initiated an internal awareness exercise to test employee susceptibility to human-based manipulation. During the assessment, an individual posing as an external recruitment consultant began casually engaging several engineers at a nearby industry networking event. Over multiple conversations, the individual gradually steered discussions toward current research initiatives, development timelines, and internal project code names. No direct requests for credentials or system access were made. Instead, the information was obtained incrementally through carefully crafted questions embedded within informal dialogue. Which social engineering technique is most accurately demonstrated in this scenario?. Elicitation. Baiting. Quid Pro Quo. Honey Trap.

Clark is a talented coder and as such has found a vulnerability in a well-known application. Unconcerned about the ethics of the situation, he has developed an exploit that can leverage this unknown vulnerability. Based on this information, which of the following is most correct?. Clark has developed a zero-day. Clark is a suicide hacker. Clark has violated U.S. Code Section 1027. Clark is a white hat hacker.

Your ethical hacking firm has been hired to conduct a penetration test. Which of the following documents limits what you can discuss publicly?. Nondisclosure agreement. Memorandum of understanding. PCI-DSS. Terms of engagement.

A Windows endpoint generates alerts for credential dumping tools. What asset is targeted?. Credentials. Availability. Logs. Network.

Which of the following is the most important step for the ethical hacker to perform during the pre-assessment?. Obtain written permission to hack. Obtain verbal permission to hack. Gather information about the target. Hack the web server.

Which of the following hacking frameworks describes adversary tactics, techniques, and procedures (TTPs) used in cyberattacks?. MITRE ATT&CK. ISSF. NIST CSF 2.0. ISO 28901.

Massive outbound HTTPS traffic hides inside normal web traffic. Likely objective?. Data exfiltration. DoS. Scanning. Recon.

In an ethical hacking methodology and framework, which of the following step is known for “active and passive information gathering”. Reconnaissance. Exploitation. Obfuscation. Denial of service.

During a penetration test for a global e-commerce platform in Dallas, ethical hacker Maria simulates a large-scale DoS campaign. Instead of sending attack traffic directly, she forges requests to multiple open services across the internet. These services unknowingly reply to the victim system, multiplying the amount of traffic hitting the target. Within minutes, the victim’s server is overwhelmed by a flood of responses, even though Maria’s own machine generated only a small amount of traffic. Which attack technique is Maria most likely demonstrating?. Distributed Reflection Denial-of-Service (DRDoS). Botnet. NTP Amplification Attack. Smurf Attack.

A competing technology firm begins releasing products that closely mirror the design, pricing strategy, and feature roadmap of ApexDynamics Inc. An internal review reveals that detailed information about ApexDynamics's upcoming initiatives had been gradually collected through publicly available sources and external disclosures before product launch. Which footprinting-related threat does this scenario best represent?. Business Loss. Social Engineering. Information Leakage. Corporate Espionage.

This type of security test usually takes on an adversarial role and looks to see what an outsider can access and control. Penetration test. Policy assessment. High-level evaluation. Network evaluation.

A financial clearinghouse in Newark, New Jersey, initiated a structured vulnerability review across its enterprise servers. The scanning platform was configured to collect detailed information about installed updates, local security configurations, and system policy settings on each target machine. The resulting report contained granular host-level findings, including configuration inconsistencies and patch gaps that required direct system-level inspection to obtain. Based on the activity described, what type of vulnerability scanning is being performed?. Credentialed Scanning. Application Scanning. Non-Credentialed Scanning. Automated Scanning.

Following reports of inconsistent IP-to-MAC mappings on an internal access switch at a manufacturing company in Detroit, Michigan, the network security team enabled additional validation controls. Soon afterward, the switch began automatically discarding certain ARP replies that did not match previously recorded IP address assignments. Log entries indicated that packets were being denied due to validation failures tied to existing address-to-port mappings learned earlier from legitimate host configuration traffic. Which switch-level security feature is most likely responsible for enforcing this ARP validation behavior?. Activating Dynamic ARP Inspection to validate ARP packets. Displaying the DHCP Snooping binding table for verification. Enabling DHCP Snooping to track address assignments. Configuring BPDU Guard to protect spanning-tree topology.

Attackers exploit SMBv1 to spread malware across hosts. What attack behavior is this?. Worm-like propagation. Phishing. DoS. Credential stuffing.

An energy infrastructure company in Tulsa, Oklahoma, initiated a controlled phishing simulation targeting multiple operational departments. The test email claimed to originate from the corporate compliance office and instructed employees to "complete a mandatory regulatory update within the next 30 minutes to avoid account suspension." The message used a broad salutation instead of employee names and lacked the standard corporate signature footer normally appended to official communications. Additionally, security analysts observed that the embedded Hyperlink displayed the organization's domain in the message body; however, when examined more closely, the actual destination resolved to a shortened external URL redirecting to an unrelated host. From a defensive analysis standpoint, which indicator provides the strongest technical validation that the message is malicious?. Identification of Hover Mismatch URLs in the embedded link. Absence of a formal corporate Missing Signature. Use of Generic Greetings rather than individualized addressing. Presence of aggressive Urgency Language.

When referring to the domain name service, what is a zone?. A collection of resource records. A collection of alias records. The zone namespace. A collection of domains.

A technology consulting firm in Portland, Oregon began experiencing repeated topology recalculations across its switching infrastructure. Shortly after a newly connected device came online in a conference room, spanning-tree convergence events were triggered across multiple distribution switches. Engineers determined that the access-layer interface connected to that device was influencing path-selection decisions, introducing a more favorable bridge priority value into the environment and affecting the established hierarchy. To preserve the intended switching structure and prevent unauthorized devices from altering root selection decisions, which control should be employed?. Applying Root Guard on designated interfaces. Enabling BPDU Guard on edge ports. Activating UDLD (Unidirectional Link Detection) on uplinks. Configuring Loop Guard on non-designated ports.

An attacker abuses weak password reuse across services using leaked credentials. What attack is this?. Credential stuffing. Replay. Brute force. Dictionary attack.

A Linux system allows passwordless sudo for multiple commands. What security principle is violated?. Least privilege. CIA. Defense in depth. Zero trust.

Prior to a federal audit, a cybersecurity consulting firm conducted an exposure review for a software company in Salt Lake City, Utah. The engagement focused on evaluating infrastructure reachable through the organization's publicly registered domain records. The consultants identified open service ports on several servers, examined their patch levels for outdated components, and reviewed available DNS zone information to understand how systems were presented to remote systems. Based on the activities described, what type of vulnerability scanning is being performed?. External Scanning. Manual Scanning. Internal Scanning. Network-based Scanning.

At Norwest Freight Services, Simon, a junior analyst, is tasked with running a vulnerability scan on several departmental servers. This time, he is provided with administrator-level credentials to input into the scanner. The scan takes significantly longer than usual but returns detailed results, including weak registry permissions, outdated patches, and insecure configuration files that would not have been visible to an outsider. SIEM logs confirm that successful logins occurred during the scanning process. Which type of vulnerability scan BEST explains the behavior observed in Simon’s assessment?. Credentialed Scanning. Internal Scanning. External Scanning. Non-Credentialed Scanning.

Which of the following protocols is used when an attacker attempts to launch a man-in-the-middle attack by manipulating sequence and acknowledgment numbers?. TCP. ICMP. IP. UDP.

Which attack exploits weak cipher suites?. Downgrade. DoS. Replay. Spoofing.

A cloud storage provider discovers that an unauthorized party obtained a complete backup of encrypted database files containing archived client communications. The attacker did not compromise the encryption keys, nor is there evidence that any original plaintext records were exposed. A forensic cryptography specialist reviewing the breach considers the possibility that the adversary is attempting to analyze the encrypted data in isolation, searching for statistical irregularities or structural repetition within the encrypted output to infer meaningful information. To properly assess the organization's exposure, the specialist must determine which cryptanalytic approach best matches an attack conducted using only the intercepted encrypted data. Known-plaintext attack. Chosen-plaintext attack. Chosen-ciphertext attack. Ciphertext-only attack.

Report abuse