Which of the following LM hashes represent a password of less than 8 characters? (Choose two.)
A. 0182BD0BD4444BF836077A718CCDF409
B. CEC52EB9C8E3455DC2265B23734E0DAC
C. B757BF5C0D87772FAAD3B435B51404EE
D. E52CAC67419A9A224A3B108F3FA6CB6D
E. BA810DBA98995F1817306D272A9441BB
F. 44EFCE164AB921CQAAD3B435B51404EE
正解:C,F
質問 2:
Which among the following is the best example of the third step (delivery) in the cyber kill chain?
A. An intruder's malware is triggered when a target opens a malicious email attachment.
B. An intruder sends a malicious attachment via email to a target.
C. An intruder creates malware to be used as a malicious attachment to an email.
D. An intruder's malware is installed on a target's machine.
正解:B
質問 3:
While testing a web application in development, you notice that the web server does not properly ignore the "dot dot slash" (../) character string and instead returns the file listing of a folder structure of the server.
What kind of attack is possible in this scenario?
A. Cross-site scripting
B. SQL injection
C. Denial of service
D. Directory traversal
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Tremp is an IT Security Manager, and he is planning to deploy an IDS in his small company. He is looking for an IDS with the following characteristics: - Verifies success or failure of an attack - Monitors system activities Detects attacks that a network-based IDS fails to detect - Near real-time detection and response - Does not require additional hardware - Lower entry cost Which type of IDS is best suited for Tremp's requirements?
A. Gateway-based IDS
B. Host-based IDS
C. Network-based IDS
D. Open source-based
正解:B
質問 5:
A penetration tester is performing the footprinting process and is reviewing publicly available information about an organization by using the Google search engine.
Which of the following advanced operators would allow the pen tester to restrict the search to the organization's web domain?
A. [location:]
B. [site:]
C. [link:]
D. [allinurl:]
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
CyberTech Inc. recently experienced SQL injection attacks on its official website. The company appointed Bob, a security professional, to build and incorporate defensive strategies against such attacks. Bob adopted a practice whereby only a list of entities such as the data type, range, size, and value, which have been approved for secured access, is accepted. What is the defensive technique employed by Bob in the above scenario?
A. Blacklist validation
B. Enforce least privileges
C. Whitelist validation
D. Output encoding
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
1375 お客様のコメント





Makino -
過去問でどのくらいの結果が出るか楽しみです。
312-50問題を解きながら解説も理解できるので学び易いと思います。