Which of the following web vulnerabilities would an attacker be attempting to exploit if they delivered the following input?
<!DOCTYPE blah [ < IENTITY trustme SYSTEM "file:///etc/passwd" > ] >
A. XXE
B. IDOR
C. SQLi
D. XXS
正解:A
質問 2:
A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT department had a dial-out modem installed.
Which security policy must the security analyst check to see if dial-out modems are allowed?
A. Acceptable-use policy
B. Firewall-management policy
C. Remote-access policy
D. Permissive policy
正解:C
質問 3:
Which of the following algorithms can be used to guarantee the integrity of messages being sent, in transit, or stored?
A. hashing algorithms
B. integrity algorithms
C. asymmetric algorithms
D. symmetric algorithms
正解:A
質問 4:
Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications and unpatched security flaws in a computer system?
A. Wireshark
B. Maltego
C. Nessus
D. Metasploit
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network.
What is this type of DNS configuration commonly called?
A. DNSSEC
B. DynDNS
C. Split DNS
D. DNS Scheme
正解:C
質問 6:
Under what conditions does a secondary name server request a zone transfer from a primary name server?
A. When a secondary SOA is higher that a primary SOA
B. When a primary name server has had its service restarted
C. When a secondary name server has had its service restarted
D. When a primary SOA is higher that a secondary SOA
E. When the TTL falls to zero
正解:D
質問 7:
A penetration tester is tasked with gathering information about the subdomains of a target organization's website. The tester needs a versatile and efficient solution for the task. Which of the following options would be the most effective method to accomplish this goal?
A. Employing a tool like Sublist3r, which is designed to enumerate the subdomains of websites using OSINT
B. Using a people search service, such as Spokeo or Intelius, to gather information about the employees of the target organization
C. Utilizing the Harvester tool to extract email addresses related to the target domain using a search engine like Google or Bing
D. Analyzing Linkedin profiles to find employees of the target company and their job titles
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
Joel, a professional hacker, targeted a company and identified the types of websites frequently visited by its employees. Using this information, he searched for possible loopholes in these websites and injected a malicious script that can redirect users from the web page and download malware onto a victim's machine.
Joel waits for the victim to access the infected web application so as to compromise the victim's machine.
Which of the following techniques is used by Joel in the above scenario?
A. DNS rebinding attack
B. Clickjacking attack
C. MarioNet attack
D. Watering hole attack
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
854 お客様のコメント
クリック」





Sonobe -
どうもありがとうございます!この312-50v12問題集に収めていて、本当に助けになりました。