Unique Top-selling 312-50v10 Exams - New 2021 EC-COUNCIL Pratice Exam [Q349-Q369]

Share

Unique Top-selling 312-50v10 Exams - New 2021 EC-COUNCIL  Pratice Exam

Certified Ethical Hacker Dumps 312-50v10 Exam for Full Questions - Exam Study Guide

NEW QUESTION 349
Emil uses nmap to scan two hosts using this command.
nmap -sS -T4 -O 192.168.99.1 192.168.99.7
He receives this output:


What is his conclusion?

  • A. Host 192.168.99.7 is down.
  • B. He performed a SYN scan and OS scan on hosts 192.168.99.1 and 192.168.99.7.
  • C. Host 192.168.99.7 is an iPad.
  • D. Host 192.168.99.1 is the host that he launched the scan from.

Answer: B

 

NEW QUESTION 350
You have successfully gained access to your client's internal network and successfully comprised a Linux server which is part of the internal IP network. You want to know which Microsoft Windows workstations have file sharing enabled. Which port would you see listening on these Windows machines in the network?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: B

 

NEW QUESTION 351
Which of the following is considered an exploit framework and has the ability to perform automated attacks on services, ports, applications an unpatched security flaws in a computer system?

  • A. Metasploit
  • B. Nessus
  • C. Wireshark
  • D. Maltego

Answer: A

 

NEW QUESTION 352
Which cipher encrypts the plain text digit (bit or byte) one by one?

  • A. Classical cipher
  • B. Stream cipher
  • C. Modern cipher
  • D. Block cipher

Answer: B

 

NEW QUESTION 353
From the following table, identify the wrong answer in terms of Range (ft).

  • A. 802.11g
  • B. 802.11b
  • C. 802.16(WiMax)
  • D. 802.11a

Answer: D

 

NEW QUESTION 354
You need to deploy a new web-based software package for your organization. The package requires three separate servers and needs to be available on the Internet. What is the recommended architecture in terms of server placement?

  • A. All three servers need to face the Internet so that they can communicate between themselves
  • B. A web server and the database server facing the Internet, an application server on the internal network
  • C. A web server facing the Internet, an application server on the internal network, a database server on the internal network
  • D. All three servers need to be placed internally

Answer: C

 

NEW QUESTION 355
A security engineer has been asked to deploy a secure remote access solution that will allow employees to connect to the company's internal network. Which of the following can be implemented to minimize the opportunity for the man-in-the-middle attack to occur?

  • A. SSL
  • B. Static IP addresses
  • C. IPSec
  • D. Mutual authentication

Answer: C

 

NEW QUESTION 356
Which Open Web Application Security Project (OWASP) implements a web application full of known vulnerabilities?

  • A. WebScarab
  • B. WebGoat
  • C. WebBugs
  • D. VULN_HTML

Answer: B

 

NEW QUESTION 357
When you return to your desk after a lunch break, you notice a strange email in your inbox.
The sender is someone you did business with recently, but the subject line has strange characters in it.
What should you do?

  • A. Reply to the sender and ask them for more information about the message contents.
  • B. Forward the message to your company's security response team and permanently delete the message from your computer.
  • C. Delete the email and pretend nothing happened
  • D. Forward the message to your supervisor and ask for her opinion on how to handle the situation

Answer: B

Explanation:
By setting up an email address for your users to forward any suspicious email to, the emails can be automatically scanned and replied to, with security incidents created to follow up on any emails with attached malware or links to known bad websites.
References: https://docs.servicenow.com/bundle/helsinki-security-
management/page/product/threat-
intelligence/task/t_ConfigureScanEmailInboundAction.html

 

NEW QUESTION 358
Which tool allows analysts and pen testers to examine links between data using graphs and link analysis?

  • A. Metasploit
  • B. Maltego
  • C. Wireshark
  • D. Cain & Abel

Answer: B

Explanation:
Maltego is proprietary software used for open-source intelligence and forensics, developed by Paterva. Maltego focuses on providing a library of transforms for discovery of data from open sources, and visualizing that information in a graph format, suitable for link analysis and data mining.
References: https://en.wikipedia.org/wiki/Maltego

 

NEW QUESTION 359
What mechanism in Windows prevents a user from accidentally executing a potentially malicious batch (.bat) or PowerShell (.ps1) script?

  • A. User Access Control (UAC)
  • B. Windows firewall
  • C. Address Space Layout Randomization (ASLR)
  • D. Data Execution Prevention (DEP)

Answer: D

 

NEW QUESTION 360
A hacker was able to sniff packets on a company's wireless network. The following information was discovered:

Using the Exlcusive OR, what was the original message?

  • A. 11010111 00010001
  • B. 00001101 10100100
  • C. 11110010 01011011
  • D. 00101000 11101110

Answer: A

 

NEW QUESTION 361
You are tasked to perform a penetration test. While you are performing information gathering, you find an employee list in Google. You find the receptionist's email, and you send her an email changing the source email to her boss's email( boss@company ). In this email, you ask for a pdf with information. She reads your email and sends back a pdf with links. You exchange the pdf links with your malicious links (these links contain malware) and send back the modified pdf, saying that the links don't work. She reads your email, opens the links, and her machine gets infected. You now have access to the company network.
What testing method did you use?

  • A. Eavesdropping
  • B. Social engineering
  • C. Tailgating
  • D. Piggybacking

Answer: B

Explanation:
Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme.

 

NEW QUESTION 362
What kind of detection techniques is being used in antivirus softwares that identifies malware by collecting data from multiple protected systems and instead of analyzing files locally it's made on the premiers environment-

  • A. Honypot based
  • B. Behaviour based
  • C. VCloud based
  • D. Heuristics based

Answer: C

 

NEW QUESTION 363
A computer science student needs to fill some information into a secured Adobe PDF job application that was received from a prospective employer. Instead of requesting a new document that allowed the forms to be completed, the student decides to write a script that pulls passwords from a list of commonly used passwords to try against the secured PDF until the correct password is found or the list is exhausted. Which cryptography attack is the student attempting?

  • A. Dictionary-attack
  • B. Brute-force attack
  • C. Session hijacking
  • D. Man-in-the-middle attack

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 364
Which of the following can the administrator do to verify that a tape backup can be recovered in its entirety?

  • A. Read the last 512 bytes of the tape.
  • B. Read the first 512 bytes of the tape.
  • C. Restore a random file.
  • D. Perform a full restore.

Answer: D

Explanation:
A full restore is required.

 

NEW QUESTION 365
Which of the following resources does NMAP need to be used as a basic vulnerability scanner covering several vectors like SMB, HTTP and FTP?

  • A. NMAP scripting engine
  • B. Metasploit scripting engine
  • C. Nessus scripting engine
  • D. SAINT scripting engine

Answer: A

 

NEW QUESTION 366
You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8.
While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP.
Therefore, the Internal IP's are sending data to the Public IP.
After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised.
What kind of attack does the above scenario depict?

  • A. Advanced Persistent Threats
  • B. Botnet Attack
  • C. Rootkit Attack
  • D. Spear Phishing Attack

Answer: B

 

NEW QUESTION 367
_________ is a tool that can hide processes from the process list, can hide files, registry entries, and intercept keystrokes.

  • A. Scanner
  • B. Trojan
  • C. Backdoor
  • D. RootKit
  • E. DoS tool

Answer: D

 

NEW QUESTION 368
When a normal TCP connection starts, a destination host receives a SYN (synchronize/start) packet from a source host and sends back a SYN/ACK (synchronize acknowledge). The destination host must then hear an ACK (acknowledge) of the SYN/ACK before the connection is established. This is referred to as the "TCP three-way handshake." While waiting for the ACK to the SYN ACK, a connection queue of finite size on the destination host keeps track of connections waiting to be completed. This queue typically empties quickly since the ACK is expected to arrive a few milliseconds after the SYN ACK.
How would an attacker exploit this design by launching TCP SYN attack?

  • A. Attacker generates TCP RST packets with random source addresses towards a victim host
  • B. Attacker generates TCP SYN packets with random destination addresses towards a victim host
  • C. Attacker generates TCP ACK packets with random source addresses towards a victim host
  • D. Attacker floods TCP SYN packets with random source addresses towards a victim host

Answer: D

 

NEW QUESTION 369
......

Best way to practice test for EC-COUNCIL 312-50v10: https://www.pass4sures.top/CertifiedEthicalHacker/312-50v10-testking-braindumps.html