Which method of password cracking takes the most time and effort?
A. Dictionary attack
B. Shoulder surfing
C. Rainbow tables
D. Brute force
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
You are Emma Rodriguez, an ethical hacker at SecurePath Solutions, hired to test the mobile application security of Sterling & Associates, a law firm in New York City. During a covert assessment, your objective is to simulate an attacker attempting to exploit vulnerabilities in the firm's client case management app. You discover that the app stores user credentials in plain text on the device, enabling you to extract sensitive client login information using a rooted device. Based on this finding, which OWASP Top 10 Mobile Risk are you identifying in the app?
A. Insecure Data Storage
B. Improper Credential Usage
C. Inadequate Privacy Controls
D. Insecure Communication
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
In the hushed glow of multiple monitors lining the walls of a secure operations center in Hyderabad, security consultant Priyanka was deep into an authorized penetration test for a major banking consortium. While examining encrypted transaction logs transmitted between core banking servers and backup storage nodes, she noticed that incoming plaintext records were consistently divided into uniform segments of fixed length before any encryption steps were applied; each segment underwent independent processing with additional filler characters appended where the final segment fell short, ensuring every unit reached the exact required size prior to transformation.
Subsequent packet captures confirmed that the encryption routine treated these equal-length units separately, applying the same key material across them in a chained manner that prevented direct bit-by-bit streaming of the original data. The approach allowed the system to maintain consistent output sizes regardless of varying input lengths, which she later leveraged in her controlled test to predict padding patterns and explore potential weaknesses in segment handling.
What type of cipher is being used in this encryption process?
A. Stream Cipher
B. Substitution cipher
C. Transposition cipher
D. Block Cipher
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
A multinational manufacturing company in San Jose, California has deployed a perimeter firewall to protect its internal production networks. During a red team exercise, testers observe that the device monitors active TCP communications and allows traffic to continue only when packets correspond to recognized, previously established connections.
The firewall evaluates multiple header attributes across ongoing communications while operating inline at the network boundary.
From a firewall architecture perspective, what type of firewall is most likely in use at this perimeter?
A. Application-Level Firewall
B. Packet Filtering Firewall
C. Stateful Multilayer Inspection Firewall
D. Circuit-Level Gateway Firewall
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
In the fast-paced financial district of Singapore, security analyst Priya Nair was investigating a sudden surge of suspicious messages received by multiple employees across the organization's internal collaboration platform. The messages appeared to originate from internal-looking accounts and contained urgent prompts related to account verification, along with embedded links directing users to external resources.
Several employees reported receiving these messages repeatedly throughout the day despite no prior interaction, and the activity was confined entirely to the organization's real-time communication system rather than traditional communication channels.
What type of phishing was most likely being used in this incident?
A. Spear Phishing
B. Spimming
C. Whaling
D. Vishing
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
During an internal red team engagement at a software company in Boston, ethical hacker Meera gains access to a developer ' s workstation. To ensure long-term persistence, she plants a lightweight binary in a hidden directory and configures it to automatically launch every time the system is restarted. Days later, even after the host was rebooted during patching, the binary executed again without requiring user interaction, giving Meera continued access.
Which technique most likely enabled this persistence?
A. Startup Folder
B. Registry run keys
C. Scheduled Tasks
D. Creating a new service
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
You are Maya, a security engineer at HarborPoint Cloud Services in Chicago, Illinois, performing a post- incident hardening review after an internal audit flagged multiple services that rely on legacy public-key algorithms. The engineering team must prioritize actions company-wide to reduce long-term risk from future quantum-capable adversaries while development continues on a large refactor of several services. Which proactive control should Maya recommend as the highest-priority change to embed into the organization ' s development lifecycle to improve future resistance to quantum-based attacks?
A. Break data into fragments and distribute it across multiple locations
B. Include quantum-resistance checks in SDLC and code review processes
C. Encrypt stored data with quantum-resistant algorithms
D. Use quantum-specific firewalls to protect quantum communication channels
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
During a penetration test for a U.S.-based retail company, John gains access to a secondary server that responds unusually to structured queries. By sending a specially crafted request, he receives a full list of subdomains, MX records, and aliases belonging to the target organization. The response exposes sensitive internal mappings that could be leveraged for further attacks.
Which tool was MOST likely used to perform this enumeration?
A. nbtstat -A
B. smtp-user-enum.pl -u user -t host
C. ldapsearch -h -x
D. dig @server axfr
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
660 お客様のコメント
クリック」





Harada -
312-50v13試験対策のテキストです。内容もしっかりしているし、かなりコスパが高いです。