A penetration tester identifies that a web application's login form is not using secure password hashing mechanisms, allowing attackers to steal passwords if the database is compromised.
What is the best approach to exploit this vulnerability?
A. Capture the login request using a proxy tool and attempt to decrypt the passwords
B. Conduct a brute-force attack on the login form to guess weak passwords
C. Perform a dictionary attack using a list of commonly used passwords against the stolen hash values
D. Input a SQL query to check for SQL injection vulnerabilities in the login form
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
During a red team assessment at Alpine Manufacturing Corp., network security consultant Marcus Lee is instructed to evaluate the security of internal communications within their switched LAN environment. Without altering any switch configurations, Marcus manages to intercept credentials being transmitted between a payroll administrator's workstation and the backend authentication server. His setup reroutes the communication path through his testing machine, though no proxy or VPN was involved. Analysis shows the redirection was achieved by injecting crafted messages that silently altered how the two hosts identified each other on the local network. Which sniffing technique did Marcus most likely use?
A. DNS Spoofing
B. ARP Spoofing
C. Switch Port Stealing
D. MAC Flooding
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?
A. RST
B. SYN
C. SYN-ACK
D. ACK
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
The various hping commands are as follows. During an authorized penetration test, a security analyst executes a TCP-based probe using hping without attempting to complete the three-way handshake. Packet analysis shows that closed ports return a TCP RST response, while open ports do not generate any reply. The crafted packets contain a non-standard combination of TCP control bits rather than relying on a single control flag. Which scanning technique is being performed?
A. UDP scan on port 80
B. ICMP ping
C. FIN, PUSH and URG scan on port 80
D. ACK scan on port 80
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
During a forensic investigation of an attack on a media company in New York, analysts discovered that a non-privileged process loaded a malicious library instead of the intended library because the attacker placed the rogue file in a directory Windows searched before the legitimate location. When the trusted application started, the attacker's code executed with the application's privileges. No registry changes or kernel exploits were involved. Which technique most likely enabled the privilege escalation?
A. Privilege Escalation by Exploiting Vulnerabilities
B. Access Token Manipulation
C. Privilege Escalation Using DLL Hijacking
D. Privilege Escalation by Bypassing User Account Control
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
As part of an authorized security assessment at a maritime logistics firm in Charleston, South Carolina, an ethical hacker evaluated the organization's resilience to coordinated endpoint compromise.
Employees received a carefully crafted email attachment disguised as a routine operational update. After execution on several systems, monitoring tools later revealed that the infected machines periodically contacted an external host controlled by the tester.
Over time, the compromised systems began receiving commands from a centralized control server and simultaneously generated coordinated network traffic toward designated targets when instructed, without any direct user interaction.
From a malware classification standpoint, what component is being simulated in this scenario?
A. Potentially Unwanted Applications (PUAs)
B. Botnet Agents
C. Spyware
D. Scareware
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
A penetration tester suspects that a web application's login form is vulnerable to SQL injection due to improper sanitization of user input. What is the most appropriate approach to test for SQL injection in the login form?
A. Perform a directory traversal attack to access sensitive files
B. Use a brute-force attack on the login page to guess valid credentials
C. Enter ' OR '1'='1 in the username and password fields to bypass authentication
D. Inject JavaScript into the input fields to test for Cross-Site Scripting (XSS)
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
You are Riley, an incident responder at NovaEx Crypto in San Antonio, Texas, tasked with investigating a recent double-spend reported by a retail merchant that accepts the exchange's token. Your telemetry shows that a reseller node used by the merchant received blocks only from a small, fixed set of peers for several hours and accepted a conflicting history that later allowed the attacker to reverse a confirmed payment. The attacker appears to have controlled which peers that node communicated with and supplied it a private chain until they were ready to reveal it. Which blockchain attack does this behavior most closely describe?
A. Finney Attack
B. DeFi Sandwich Attack
C. Eclipse Attack
D. 51% Attack
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 9:
Which of the following is the primary goal of ethical hacking?
A. To steal sensitive information from a company's network
B. To disrupt services by launching denial-of-service attacks
C. To spread malware to compromise multiple systems
D. To identify and fix security vulnerabilities in a system
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
1175 お客様のコメント
クリック」





Nakano -
とりあえずこれ1冊しっかりやれば合格できる内容です。312-50v13平易な記述となっているので初学者でも自学自習進めやすい内容だと思います。