option
Questions
ayuda
daypo
search.php

JJJ

COMMENTS STATISTICS RECORDS
TAKE THE TEST
Title of test:
JJJ

Description:
Testi J ok

Creation Date: 2026/08/26

Category: Others

Number of questions: 100

Rating:(0)
Share the Test:
Nuevo ComentarioNuevo Comentario
New Comment
NO RECORDS
Content:

A REST API uses user-provided object IDs without authorization checks. What flaw is this?. BOLA. SQLi. XSS. Mass assignment.

A new wireless client is configured to join a 802.11 network. This client uses the same hardware and software as many of the other clients on the network. The client can see the network, but cannot connect. A wireless packet sniffer shows that the Wireless Access Point (WAP) is not responding to the association requests being sent by the wireless client. What is a possible source of this problem?. The WAP does not recognize the client’s MAC address. The wireless client is not configured to use DHCP. Client is configured for the wrong channel. The client cannot see the SSID of the wireless network.

The company ABC recently contracts a new accountant. The accountant will be working with the financial statements. Those financial statements need to be approved by the CFO and then they will be sent to the accountant but the CFO is worried because he wants to be sure that the information sent to the accountant was not modified once he approved it. Which of the following options can be useful to ensure the integrity of the data?. The CFO can use a hash algorithm in the document once he approved the financial statements. The financial statements can be sent twice, one by email and the other delivered in USB and the accountant can compare both to be sure is the same document. The CFO can use an excel file with a password. The document can be sent to the accountant using an exclusive USB for that document.

A large mobile telephony and data network operator has a data center that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup?. Network elements must be hardened with user ids and strong passwords. Regular security tests and audits should be performed. As long as the physical access to the network elements is restricted, there is no need for additional measures. The operator knows that attacks and down time are inevitable and should have a backup site. There is no need for specific security measures on the network elements as long as firewalls and IPS systems exist.

A DevOps engineer at a Toronto-based SaaS provider deploys a multi-tenant application within a shared orchestration environment. During a security assessment, a penetration tester discovers that a compromised workload is able to access host-level system resources and interact with adjacent workloads beyond its intended isolation controls. Further investigation reveals that the workload was launched with elevated privileges and insufficient runtime restrictions, allowing the attacker to cross the intended isolation boundary and gain unauthorized access to the underlying infrastructure. Which cloud attack technique best describes this security weakness?. Container Escape. Man-in-the-Cloud Attack. Golden SAML Attack. Side-Channel Attack.

A technology consulting firm in Charlotte, North Carolina experienced a targeted intrusion after an employee interacted with a carefully crafted phishing email. Security analysts reconstructed the sequence of events and determined that once the email attachment was opened, built-in scripting utilities were invoked to inject malicious instructions into an active system process. No standalone malicious executables were discovered on disk. The injected instructions began running directly inside legitimate processes before any registry modifications or task scheduling changes were observed. At this point in the attack sequence, which operational phase of the fileless attack lifecycle is being demonstrated?. Code Execution. Achieving Objectives. Point of Entry. Persistence.

At Redwood Financial Group in Boston, Massachusetts, the security leadership team is formalizing a continual security strategy composed of four coordinated activities. During implementation planning, one team is assigned responsibility for reviewing operational data across the enterprise environment to recognize irregular patterns that may indicate malicious activity. Within this model, which activity is responsible for this responsibility?. Detect. Respond. Protect. Predict.

What is a “Collision attack” in cryptography?. Collision attacks try to find two inputs producing the same hash. Collision attacks try to get the public key. Collision attacks try to break the hash into three parts to get the plaintext value. Collision attacks try to break the hash into two parts, with the same bytes in each part to get the private key.

Which type of security feature stops vehicles from crashing through the doors of a building?. Bollards. Mantrap. Receptionist. Turnstile.

An attacker exploits a misconfigured S3 bucket containing application backups with database credentials. What cloud security failure category does this fall under?. Misconfiguration. Insider threat. Malware infection. Zero-day vulnerability.

Which technique is MOST effective to bypass signature-based IDS?. Obfuscation. Polymorphism. Encryption. Port scanning.

At a petrochemical processing facility in Corpus Christi, Texas, a certified ethical hacker performs an authorized reconnaissance assessment within the manufacturing zone. The objective is to identify programmable controllers responsible for automated production processes. The tester initiates a targeted scan against a TCP service commonly used by industrial controllers that support structured function-code exchanges for reading and writing memory areas. Multiple field devices respond to this service, confirming the presence of automation controllers communicating over that port. Based on this reconnaissance pattern, what type of OT device scan is being performed?. Scanning Modbus devices. Scanning Siemens SIMATIC S7 PLCs. Capturing Modbus/TCP traffic using Wireshark. Scanning Omron PLC devices.

A city utility billing portal in Raleigh, North Carolina includes a search field used to retrieve customer records. During an authorized penetration test, an assessor submits repeated instances of a character commonly interpreted within SQL statements as part of the input value. The application does not display detailed error messages, yet certain submissions result in irregular response behavior and partial rendering of results. The tester suspects the input may be affecting how the SQL command is internally constructed. Which black-box testing technique is being applied?. Sending isolated quotation characters to detect unsanitized input. Using right square bracket characters to detect identifier handling issues. Sending arbitrary data to detect truncation issues. Sending special characters to detect SQL modification behavior.

Which method of password cracking takes the most time and effort?. Brute force. Shoulder surfing. Rainbow tables. Dictionary attack.

A DNS server responds with different IP addresses rapidly for the same domain, pointing to constantly changing hosts. What technique is being used?. Fast flux. DNS poisoning. DNS tunneling. Zone transfer.

During an authorized cloud security assessment for an e-commerce company based in Seattle, Washington, a certified ethical hacker gains temporary programmatic access to the organization's cloud account. The tester focuses on identifying permission boundaries by querying the account to determine which identity entities are associated with attached policies and what level of access those identities possess across cloud resources. The objective is to understand privilege relationships before attempting any further controlled actions. Which cloud reconnaissance activity best aligns with this effort?. Enumerating IAM Roles. Enumerating Serverless Resources. Enumerating EC2 Instances. Enumerating S3 Buckets.

A compromised admin account is used to disable logging services. What is the attacker attempting?. Anti-forensics. Recon. Exfiltration. Privilege escalation.

A company’s security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate?. Attempts by attackers to access Web sites that trust the Web browser user by stealing the user’s authentication credentials. Attempts by attackers to access password stored on the user's computer without the user’s knowledge. Attempts by attackers to access the user and password information stored in the company’s SQL database. Attempts by attackers to determine the user’s Web browser usage patterns, including when sites were visited and for how long.

An internal review at a financial analytics firm in Minneapolis, Minnesota, uncovered unusual query patterns directed at the company's directory services infrastructure. Security engineer Olivia Grant examined the logs and discovered that a user account had been issuing structured directory queries to retrieve lists of user objects, group memberships, and organizational units. Further inspection revealed that the account was able to access information about privileged groups containing the word "Admin" in their titles. The activity did not involve password guessing or authentication bypass, but rather systematic directory lookups to map internal user and group relationships. What type of enumeration is illustrated in this scenario?. LDAP Enumeration. DNS Enumeration. SMTP Enumeration. VoIP Enumeration.

A healthcare technology company deploys internet-connected cardiac monitoring devices across several hospitals in Minneapolis, Minnesota. During a controlled security review, an analyst discovers that administrative configuration features can be accessed remotely through components that interact with external management platforms. Further analysis reveals that these externally reachable components process user-supplied data without sufficient validation checks. Additionally, authentication controls protecting remote configuration features rely solely on basic credential verification without additional safeguards against automated misuse. According to the OWASP Top 10 IoT Vulnerabilities, how should this weakness be classified?. Insecure Ecosystem Interfaces. Insecure Default Settings. Insecure Network Services. Lack of Device Management.

The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the Central Processing Unit (CPU), rather than passing only the frames that the controller is intended to receive. Which of the following is being described?. Promiscuous mode. Multi-cast mode. WEM. Port forwarding.

Bob received this text message on his mobile phone: "Hello, this is Scott Smelby from the Yahoo Bank. Kindly contact me for a vital transaction on: [email protected]". Which statement below is true?. This is a scam as everybody can get a @yahoo address, not the Yahoo customer service employees. Bob should write to [email protected] to verify the identity of Scott. This is probably a legitimate message as it comes from a respectable organization. This is a scam because Bob does not know Scott.

Which of the following is a component of a risk assessment?. Administrative safeguards. Logical interface. Physical security. DMZ.

Which encoding often bypasses filters?. Unicode. Base64. ROT13. Hex.

A Linux server has world-writable cron directories. What can attackers achieve?. Persistence. XSS. SQLi. DoS.

A financial technology company in Charlotte, North Carolina authorizes a controlled red team engagement to evaluate defensive monitoring within its Windows server environment. During testing, the team executes a series of scripted administrative commands through the native automation shell. The security controls initially prevent the activity from completing. The tester then modifies how the command content is expressed while preserving its original functionality. After this adjustment, the same administrative operations execute successfully without triggering the operating system's integrated content inspection mechanism. Which technique was most likely used to bypass the Windows Antimalware Scan Interface (AMSI)?. Obfuscation. Memory Hijacking. PowerShell Downgrade. Forcing an Error.

During a penetration test, an analyst repeatedly initiates TCP connections to a target host and records the sequence numbers returned in the SYN/ACK responses. By examining predictable or incremental patterns in these values, the analyst attempts to infer characteristics of the underlying operating system. What OS fingerprinting attribute is being analyzed in this scenario?. Initial Sequence Number (ISN). Time to Live (TTL). TCP Window Size. TCP Timestamp Analysis.

A payroll management portal used by a manufacturing firm in Toledo, Ohio allows administrators to configure customizable notification templates that are later incorporated into automated reporting functions. During an authorized assessment, an ethical hacker submits specially structured input into a template field while creating a test notification. The application accepts and stores the value without any noticeable disruption to the interface. Days later, when a scheduled reporting task executes, the resulting dataset includes records beyond the expected scope defined by the report criteria. Further review reveals that the reporting engine dynamically constructs database queries using previously stored template values during execution. Determine the SQL injection variant illustrated in this scenario. Second-Order SQL Injection. Stored Procedure Injection. Error-Based SQL Injection. Piggybacked Query Injection.

During an executive-level incident review at HarborTech Industries in Baltimore, Maryland, analysts categorize key elements of a recent intrusion. They identify the organization that orchestrated the attack, document the malicious infrastructure used to reach internal systems, outline the technical approach employed to exploit weaknesses, and specify which internal business unit was affected. Within the Diamond Model of Intrusion Analysis, which element represents the technical approach used to carry out the attack?. Capability. Infrastructure. Victim. Adversary.

Which address translation scheme would allow a single public IP address to always correspond to a single machine on an internal network, allowing “server publishing”?. Overloading Port Address Translation. Dynamic Port Address Translation. Dynamic Network. Address Translation. Static Network Address Translation.

A Java app uses Random() for session tokens. What is the risk?. Predictable tokens. Session fixation. XSS. CSRF.

During an authorized security assessment of a smart thermostat manufacturer in Denver, Colorado, a certified ethical hacker receives a firmware image extracted from a production device for further evaluation. The tester begins by examining the binary file to determine its format and architecture. Basic inspection commands are executed against the image to review embedded human-readable content and observe low-level binary structure before proceeding with deeper analysis. Within the firmware analysis workflow, which stage is the tester performing?. Analyze Firmware. Obtain Firmware. Emulate Firmware. Extract the Filesystem.

A security consultant is conducting an authorized assessment for a healthcare billing provider in Phoenix, Arizona. While monitoring internal traffic, he observes an authenticated employee interacting with a sensitive web-based management portal over TCP. During the session, the consultant carefully crafts and injects packets into the ongoing communication stream. Shortly afterward, the legitimate user experiences irregular responses from the application, and the server begins processing commands originating from the consultant's injected traffic as though they were part of the established session. The technique does not involve credential guessing or forcing the user to reauthenticate. Instead, it targets the communication channel already in progress. From a network-level perspective, what type of session hijacking technique is being demonstrated?. TCP/IP Hijacking. Blind Hijacking. RST Hijacking. UDP Hijacking.

Scenario: 1.Victim opens the attacker’s web site. 2.Attacker sets up a web site which contains interesting and attractive content like ‘Do you want to make S1000 in a day?’. 3.Victim clicks to the interesting and attractive content URL. 4.Attacker creates a transparent ‘iframe’ in front of the URL which victim attempts to click, so victim thinks that he/she clicks to the ‘Do you want to make $1000 in a day?’ URL but actually he/she clicks to the content or URL that exists in the transparent ‘iframe’ which is setup by the attacker. What is the name of the attack which is mentioned in the scenario?. Clickjacking Attack. HTTP Parameter Pollution. Session Fixation. HTML Injection.

A regional healthcare provider in Phoenix began experiencing intermittent outages affecting its patient portal. Network monitoring showed an abrupt surge of traffic consisting of short, stateless datagrams directed at random service ports across multiple edge-facing servers. Unlike connection-oriented attacks, there was no evidence of incomplete handshakes or abnormal session buildup. Instead, the attack traffic simply consumed available upstream capacity through sheer packet volume, preventing legitimate users from reaching the web platform. Based on the observed behavior, determine the most likely attack technique. UDP flood attack. ICMP flood attack. Ping of Death attack. NTP amplification attack.

A web application allows users to upload files and later include them in pages dynamically. Attackers exploit this to execute code. Which vulnerability exists?. RFI. LFI. CSRF. XSS.

Which of the following program infects the system boot sector and the executable files at the same time?. Multipartite Virus. Macro virus. Polymorphic virus. Stealth virus.

A media streaming company in Los Angeles, California engages a certified ethical hacker to evaluate the resilience of its cloud-hosted infrastructure. After initial access is obtained through an exposed credential in a development repository, the tester systematically modifies logging configurations, establishes alternate access keys for persistence, and documents privilege relationships between services within the tenant. The tester's actions are focused on maintaining continued access and mapping the internal structure of the environment after initial compromise has occurred. Within the cloud attack lifecycle, which phase best represents this stage of activity?. Post-Exploitation. Vulnerability Assessment. Information Gathering. Exploitation.

An enterprise organization in Chicago deploys a WPA2-Enterprise wireless network integrated with a centralized authentication server to validate user credentials through 802.1X. A security consultant is tasked with assessing the resilience of the authentication workflow. While monitoring wireless traffic near the facility, the consultant captures a successful authentication exchange between a legitimate employee device and the authentication infrastructure. Instead of attempting to derive credentials or modify packet contents, the consultant retransmits portions of the previously observed authentication messages to the network under controlled conditions. The access point processes the retransmitted authentication sequence in a manner that suggests acceptance of reused authentication data rather than rejecting it as stale or duplicated. Identify the wireless attack technique demonstrated in this assessment. RADIUS Replay Attack. Initialization Vector Replay Attack. Data Frame Injection. Bit-Flipping Attack.

Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?. 139 and 445. 137 and 443. 137 and 139. 139 and 443.

A financial services firm detects that outbound corporate emails containing sensitive underwriting data were intercepted while transmitted over unsecured channels. To immediately restore confidentiality and ensure authenticity of executive communications, the security operations team deploys a standardized email encryption framework compatible with the organization's Microsoft Outlook environment. The selected solution must support digital signatures for sender authentication, rely on a public-key infrastructure for secure key exchange, and enable recipients to validate signed messages using certificates issued by trusted authorities. Identify the email encryption standard that best fulfills these requirements. S/MIME. RMail. FlowCrypt. QpenPGP.

The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?. SYN. SYN-ACK. ACK. RST.

An attacker, using a rogue wireless AP, performed an MITM attack and injected an HTML code to embed a malicious applet in all HTTP connections. When users accessed any page, the applet ran and exploited many machines. Which one of the following tools the hacker probably used to inject HTML code?. Ettercap. Aircrack-ng. Tcpdump. Wireshark.

You have successfully comprised a server having an IP address of 10.10.0.5. You would like to enumerate all machines in the same network quickly. What is the best Nmap command you will use?. nmap -T4 -F 10.10.0.0/24. nmap -T4 -r 10.10.1.0/24. nmap -T4 -O 10.10.0.0/24. nmap -T4 -q 10.10.0.0/24.

A security consultant is performing an authorized assessment of a regional healthcare provider's patient portal in Portland, Oregon. During testing, he observes that authenticated users are assigned session identifiers embedded within URL parameters after login. To evaluate the robustness of the session management implementation, he initiates multiple authentication requests in rapid succession using controlled test accounts. He then compares the issued identifiers and notices that although parts of the value remain constant, certain segments change in a predictable progression over time. By analyzing the incremental pattern across a controlled batch of issued identifiers generated within the same time window, he is able to anticipate future valid identifiers without capturing traffic from other users. Which token prediction mechanism best explains the weakness identified in this scenario?. Seguential Tokens. Timestamp-based Tokens. Small Token Space. Weak Random Number Generator (PRNG).

During a forensic log review at a satellite communications provider in Denver, Colorado, cybersecurity analyst Kevin Morales identified subtle timestamp irregularities in archived telemetry records. Although the discrepancies were minor, regulatory reporting standards required confirmation that the system clock was synchronizing correctly with its configured time sources. Kevin needed to interact directly with the host's running time service to review its current associations and operational state. He was not attempting to reset the clock or trace the hierarchy of upstream time authorities, but rather to query the active service for detailed status information from the target machine. Identify the command Kevin should execute to obtain this information. ntpq [-inp] [-c command] [host] […]. ntptrace [-n] [-m maxhosts] [servername/IP_address]. npg -p [host]. ntpdc [-ilnps] [-c command] [host] […].

Why would you consider sending an email to an address that you know does not exist within the company you are performing a Penetration Test for?. To illicit a response back that will reveal information about email servers and how they treat undeliverable mail. To perform a DoS. To test for virus protection. To determine who is the holder of the root account. To create needless SPAM.

Natalie Brooks is leading an authorized red team exercise for Sentinel Networks in Seattle. While briefing her team on different attacker profiles, she describes an individual who is new to cybersecurity, actively learning techniques through online communities, and experimenting with basic tools on low-risk targets to build practical skills without causing significant damage. Which hacker class best matches this profile?. Green Hat hacker. Gray Hat hacker. Red Hat hacker. Blue Hat hacker.

What is MAC spoofing used for?. Bypass filters. IDS. Logging. Encryption.

A Java app uses ObjectInputStream.readObject() on untrusted data. What is the risk?. Insecure Deserialization. SQLi. XSS. DoS.

Which attack targets WPA WPS PIN?. Reaver. Wireshark. Aircrack. Kismet.

What is the minimum number of network connections in a multihomed firewall?. 3. 2. 5. 4.

What is GINA?. Graphical Identification and Authentication DLL. Global Internet National Authority (G-USA). Gateway Interface Network Application. GUI Installed Network Application CLASS.

By using a smart card and pin, you are using a two-factor authentication that satisfies. Something you have and something you know. Something you are and something you remember. Something you have and something you are. Something you know and something you are.

Is a set of extensions to DNS that provide the origin authentication of DNS data to DNS clients (resolvers) so as to reduce the threat of DNS poisoning, spoofing, and similar types of attacks. DNSSEC. Resource records. Resource transfer. Zone transfer.

Which of the following is the primary objective of a rootkit?. It replaces legitimate programs. It provides an undocumented opening in a program. It creates a buffer overflow. It opens a port to provide an unauthorized service.

A Java app uses outdated libraries with known CVEs. What risk does this create?. Supply chain risk. XSS. DoS. CSRF.

What does a NULL scan send?. No flags set. RST packet. ACK packet. SYN packet.

What kind of detection techniques is being used in antivirus software that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it’s made on the provider’s environment?. Cloud based. Behavioral based. Honeypot based. Heuristics based.

A Windows system shows LSASS memory access by unknown processes. What attack is likely?. Credential dumping. DoS. XSS. SQLi.

A Windows machine shows disabled Windows Defender without admin approval. What phase is this?. Defense evasion. Recon. Persistence. Delivery.

Attackers compromise a legitimate email account and send convincing internal messages requesting urgent actions. What attack is this?. Business Email Compromise. Spear phishing. Phishing. Spoofing.

Which metric best measures detection speed?. MTTD. SLA. MTTR. CVSS.

At HarborGrid Utilities in Oregon, a security assessment team is reviewing how the organization's network monitoring platform evaluates inbound traffic targeting its SCADA management interface. During testing, the red team introduces carefully crafted packets that adhere to known protocol standards but contain payload sequences previously identified in documented exploit repositories. The monitoring system immediately flags the activity because it matches patterns stored in its internal threat database. However, when the team slightly modifies the exploit sequence while preserving its overall malicious intent, the alerts are no longer triggered. Based on this behavior, which intrusion detection is most likely deployed in this environment?. Signature Recognition. Stateful Protocol Analysis. Anomaly Detection. Protocol Anomaly Detection.

A web app fails to restrict API request frequency. What risk exists?. Data scraping. CSRF. XSS. SQLi.

An organization lacks centralized logs. Which attack phase is hardest to detect?. Lateral movement. Recon. Delivery. Initial access.

A penetration tester extracts NTLM hashes but does not crack them, instead reuses them to authenticate. What attack is this?. Pass-the-hash. Kerberoasting. Brute force. Replay attack.

During an external assessment, a security analyst configures Nmap so that the hardware address recorded in firewall logs differs from the original interface address of the scanning system. Repeated executions of the scan show that the recorded hardware address changes automatically each time. What Nmap option enables this behavior?. --spoof-mac 0. --spoof-mac 00:01:02:25:56:AE. --spoof-mac Dell 10.10.1.11. --spoof-mac Dell.

Which wireless attack captures handshake?. Deauth. Jamming. Spoofing. Replay.

During a red team assessment of a mid-sized insurance provider in Denver, Colorado, testers established persistent access on an internal developer workstation after exploiting a misconfigured automation service. To sustain command-and-control without triggering perimeter defenses, they configured a low-bandwidth outbound channel designed to blend into infrastructure traffic that is routinely permitted through egress controls. Security operations later identified periodic outbound communication from the compromised host to a single unfamiliar external endpoint not associated with approved vendors or user activity. The traffic was distributed over time rather than bursty. Although the exchanges resembled legitimate service requests, packet inspection revealed irregular payload sizing and structured encoding patterns inconsistent with typical client behavior across the environment. What covert communication technique was most likely used to sustain the red team's access?. DNS Tunneling. HTTR/S Tunneling. TCP Sequence Tunneling. ICMP Tunneling.

A financial services provider in Frankfurt, Germany, experienced intermittent service disruption affecting its public-facing transaction portal. Network engineers observed a surge of connection attempts targeting the web servers. Packet inspection revealed that the majority of incoming traffic consisted of connection initiation requests that were never completed. The servers allocated memory and maintained half-open connection states while waiting for acknowledgments that never arrived. Over time, the connection table reached capacity, preventing legitimate users from establishing new sessions. No abnormal payloads were detected, and the packets themselves appeared structurally valid. Which attack technique best explains this behavior?. SYN flood attack. Fragmentation attack. ACK flood attack. Spoofed session flood attack.

What is the proper response for a NULL scan if the port is closed?. FIN. RST. No response. SYN. ACK. PSH.

User A is writing a sensitive email message to user B outside the local network. User A has chosen to use PKI to secure his message and ensure only user B can read the sensitive email. At what layer of the OSI layer does the encryption and decryption of the message take place?. Presentation. Application. Session. Transport.

Which of the following tools can be used for passive OS fingerprinting?. tcpdump. tracert. ping. nmap.

A Java app allows file download via user-controlled path. What attack is possible?. Path traversal. CSRF. XSS. SQLi.

A fintech startup in Austin, Texas authorizes a controlled red team engagement to evaluate the resilience of its web-based loan management platform. At the outset of the engagement, the assessment team concentrates on developing a structural understanding of the application. They examine publicly exposed endpoints, observe server responses under different navigation paths, identify accessible directories, and document the relationships between client-side scripts, form parameters, and backend behaviors. Error handling patterns and response variations are cataloged to understand how user interactions are processed across various components of the platform. The collected information is used to guide strategic planning for subsequent phases of the engagement. Within the web application hacking methodology, which phase is most accurately demonstrated in this scenario?. Scanning. Maintaining Access. Gaining Access. Reconnaissance.

Which attack manipulates hidden fields?. Parameter tampering. CSRF. XSS. SQLi.

What does DEP block?. Execution in data memory. Scanning. Logging. Encryption.

What is CVSS used for?. Severity scoring. Exploitation. Encryption. Auditing.

A senior attacker uses OAuth tokens stolen from browser storage to access APIs. What attack does this represent?. Token replay. XSS. CSRF. SQL Injection.

Suppose your company has just passed a security risk assessment exercise. The results display that the risk of the breach in the main company application is 50%. Security staff has taken some measures and implemented the necessary controls. After that, another security risk assessment was performed showing that risk has decreased to 10%. The risk threshold for the application is 20%. Which of the following risk decisions will be the best for the project in terms of its successful continuation with the most business profit?. Accept the risk. Mitigate the risk. Avoid the risk. Introduce more controls to bring risk to 0%.

During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network. What is this type of DNS configuration commonly called?. Split DNS. DynDNS. DNSSEC. DNS Scheme.

A financial analytics platform in Newark, New Jersey exposes a search parameter used to filter archived transaction records. During controlled testing, a security consultant submits carefully structured input designed to influence how the backend evaluates filtering conditions. The application continues to render the standard page layout, but response times fluctuate noticeably when specific logical expressions are introduced. By refining those conditions incrementally, the consultant observes consistent timing differences that align with changes in database evaluation behavior. The visible output remains unchanged, yet measurable performance variations provide feedback to the tester. Identify the SQL injection technique being demonstrated. Performing Heavy Query-Based Blind SQL Injection. Using HTTP Parameter Fragmentation to bypass firewall filtering. Executing Qut-of-Band SQL Injection via database-initiated HTTP requests. Applying Hex Encoding Evasion to obfuscate SQL keywords.

An attacker accesses a server using reused NTLM hashes without cracking passwords. What attack is this?. Pass-the-hash. Kerberoasting. Replay. Brute force.

Several months prior to a confirmed compromise, security telemetry at a semiconductor manufacturer in Phoenix, Arizona showed systematic intelligence gathering focused on executive leadership, research engineers, and publicly exposed infrastructure. Subsequent investigation determined that the adversary had assembled customized exploit frameworks, tested malware variants against commercial defensive products in isolated environments, and mapped externally accessible services associated with the organization. These activities were part of a coordinated strategy developed well before any credential abuse or lateral movement was observed. Determine the APT lifecycle stage represented by these actions. Preparation. Initial Intrusion. Expansion. Persistence.

An enterprise logistics company in Nashville, Tennessee recently rolled out an automation update across its internal administrative systems. Within days, performance monitoring tools began reporting sporadic spikes in outbound connections and short-lived execution chains tied to a built-in scripting utility. Security teams conducted full disk scans and integrity checks but found no unfamiliar executables or altered application binaries. Closer inspection of live system activity revealed that encoded command sequences were being executed within trusted system processes. The activity ceased after a restart but reappeared when similar administrative actions were triggered. Identify the malware category that best aligns with this operational pattern. Fileless Malware. Worm. Trojan. Rootkit.

An authorized security assessment is performed on a public-sector services portal in Madison, Wisconsin. After authenticating with a controlled test account, the assessor captures the authentication identifier issued by the application. Under controlled lab conditions, she attempts to reuse the captured identifier from a separate machine connected through a different encrypted channel. Although the identifier remains valid and within its lifetime, the application rejects the request when presented from the alternate environment. Analysis indicates that the server evaluates characteristics associated with the original secure exchange before allowing continued use of the issued identifier. Which defensive mechanism most likely explains this behavior?. Cryptographically binding authentication tokens to the TLS connection context. Enforcing HTTP Strict Transport Security. Applying IPsec protection at the network layer. Encrypting DNS resolution traffic using DNS over HTTPS.

Although FTP traffic is not encrypted by default, which layer 3 protocol would allow for end-to-end encryption of the connection?. IPsec. SSL. SFTP. FTPS.

What is lateral movement?. Pivoting. Privilege escalation. Network traversal. Data exfiltration.

While conducting a compliance-driven security assessment at a public healthcare data center in Maryland, Jason, a senior penetration tester, was asked to reconcile outdated asset documentation for several legacy network appliances still active within the environment. Internal records lacked accurate device identifiers, administrative contact entries, and interface-level statistics needed for regulatory reporting. Preliminary testing revealed that the devices were still exposing management information through long-standing read-only credentials configured years earlier. Rather than logging into each device manually or passively observing traffic, Jason decided to use a command-line approach that would systematically traverse the exposed management object tree of each system and redirect the complete output into a file for automated processing. Determine which tool aligns with this requirement. SnmpWalk. Nmap. Wireshark. SoftPerfect Network Scanner.

Anthony works as a security consultant for a financial services firm in Chicago, Illinois. During an internal engagement, he reviews traffic logs and observes repeated connection attempts to a service that appears to provide directory- related information beyond a single domain. The responses suggest that the underlying database contains entries representing objects across the entire organization rather than being limited to a single segment. As Anthony continues his assessment, he notices that administrators commonly connect to this service when troubleshooting directory-related issues. The service listens on a dedicated port and allows object searches across multiple domains without requiring prior knowledge of the specific domain name. Which service is Anthony most likely enumerating?. Global Catalog Service (TCP/UDP 3268). Microsoft RPC Endpoint Mapper (TCP/UDP 135). Lightweight Directory Access Protocol (TCP/UDP 389). Session Initiation Protocol (TCP/UDP 5060, 5061).

Bob is doing a password assessment for one of his clients. Bob suspects that security policies are not in place. He also suspects that weak passwords are probably the norm throughout the company he is evaluating. Bob is familiar with password weaknesses and key loggers. Which of the following options best represents the means that Bob can adopt to retrieve passwords from his clients hosts and servers?. Hardware, Software, and Sniffing. Passwords are always best obtained using Hardware key loggers. Hardware and Software Keyloggers. Software only, they are the most effective.

A mid-sized manufacturing firm in Des Moines, lowa reported that several employee workstations were periodically communicating with an unfamiliar external server over an IRC channel. The affected systems showed no visible interface for remote control, yet investigators confirmed that the machines were receiving instructions and executing distributed traffic bursts at scheduled intervals. Further review revealed that the initial infection occurred after employees opened a phishing email attachment. Once executed, the infected systems silently connected outward and began awaiting commands from a centralized remote controller. Determine the Trojan classification that best matches this behavior. Botnet Trojan. Rootkit Trojan. E-banking Trojan. Backdoor Trojan.

A web app does not limit API request rate in code. What attack is enabled?. Data scraping. CSRF. SQLi. XSS.

The tools which receive event logs from servers, network equipment, and applications, and perform analysis and correlation on those logs, and can generate alarms for security relevant issues, are known as what?. Security incident and event Monitoring. Vulnerability Scanner. network Sniffer. Intrusion prevention Server.

A subscription-based analytics platform in Portland, Oregon provides enterprise clients with API access to project dashboards. Each dashboard is associated with a unique identifier included in client-side API requests when retrieving project data. While evaluating access controls, a security analyst signs in using a standard user account and captures a legitimate API request used to retrieve a specific project dashboard. By altering only the identifier value within the request and replaying it through the same authenticated session, the analyst receives data belonging to a different client organization. The session remains valid, and no elevated privileges are granted. The behavior indicates that access validation does not adequately verify whether the requesting user is authorized to access the referenced resource. Identify the OWASP API security risk illustrated in this scenario. Broken Object Level Authorization (BOLA). Broken Authentication. Broken Function Level Authorization. Broken Object Property Level Authorization.

Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?. Nikto. Snort. Dsniff. John the Ripper.

What is SMB relay attack?. MITM. Spoofing. Replay. DoS.

A regional hospital network is conducting incident containment after discovering that an internal file server was accessed by unauthorized actors. While forensic analysis is ongoing, a security engineer must immediately protect sensitive medical records stored on a mounted partition without shutting down the system. The solution must support strong encryption (including 256-bit AES), allow creation of encrypted containers within existing storage volumes, and provide the capability to conceal protected data inside standard-looking volumes to reduce visibility during continued investigation. Select the disk encryption tool that best satisfies these operational and security requirements. VeraCrypt. Rohos Disk Encryption. FileVault. BitLocker Drive Encryption.

Which of the following algorithms can be used to guarantee the integrity of messages being sent, in transit, or stored?. hashing algorithms. integrity algorithms. symmetric algorithms. asymmetric algorithms.

Report abuse