최신EC-COUNCIL Certified Ethical Hacker Exam (CEH v11) - 312-50v11무료샘플문제
문제1
what firewall evasion scanning technique make use of a zombie system that has low network activity as well as its fragment identification numbers?
what firewall evasion scanning technique make use of a zombie system that has low network activity as well as its fragment identification numbers?
정답: C
설명: (ExamPassdump 회원만 볼 수 있음)
문제2
You have gained physical access to a Windows 2008 R2 server which has an accessible disc drive. When you attempt to boot the server and log in, you are unable to guess the password. In your toolkit, you have an Ubuntu 9.10 Linux LiveCD. Which Linux-based tool can change any user's password or activate disabled Windows accounts?
You have gained physical access to a Windows 2008 R2 server which has an accessible disc drive. When you attempt to boot the server and log in, you are unable to guess the password. In your toolkit, you have an Ubuntu 9.10 Linux LiveCD. Which Linux-based tool can change any user's password or activate disabled Windows accounts?
정답: D
문제3
What useful information is gathered during a successful Simple Mail Transfer Protocol (SMTP) enumeration?
What useful information is gathered during a successful Simple Mail Transfer Protocol (SMTP) enumeration?
정답: B
문제4
Which tier in the N-tier application architecture is responsible for moving and processing data between the tiers?
Which tier in the N-tier application architecture is responsible for moving and processing data between the tiers?
정답: B
문제5
What is one of the advantages of using both symmetric and asymmetric cryptography in SSL/TLS?
What is one of the advantages of using both symmetric and asymmetric cryptography in SSL/TLS?
정답: C
문제6
When considering how an attacker may exploit a web server, what is web server footprinting?
When considering how an attacker may exploit a web server, what is web server footprinting?
정답: B
문제7
Ron, a security professional, was pen testing web applications and SaaS platforms used by his company. While testing, he found a vulnerability that allows hackers to gain unauthorized access to API objects and perform actions such as view, update, and delete sensitive data of the company. What is the API vulnerability revealed in the above scenario?
Ron, a security professional, was pen testing web applications and SaaS platforms used by his company. While testing, he found a vulnerability that allows hackers to gain unauthorized access to API objects and perform actions such as view, update, and delete sensitive data of the company. What is the API vulnerability revealed in the above scenario?
정답: B
문제8
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?
정답: B
문제9
What would be the purpose of running "wget 192.168.0.15 -q -S" against a web server?
What would be the purpose of running "wget 192.168.0.15 -q -S" against a web server?
정답: D
설명: (ExamPassdump 회원만 볼 수 있음)
문제10
During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network.
What is this type of DNS configuration commonly called?
During a recent security assessment, you discover the organization has one Domain Name Server (DNS) in a Demilitarized Zone (DMZ) and a second DNS server on the internal network.
What is this type of DNS configuration commonly called?
정답: D
문제11
A regional bank hires your company to perform a security assessment on their network after a recent data breach. The attacker was able to steal financial data from the bank by compromising only a single server. Based on this information, what should be one of your key recommendations to the bank?
A regional bank hires your company to perform a security assessment on their network after a recent data breach. The attacker was able to steal financial data from the bank by compromising only a single server. Based on this information, what should be one of your key recommendations to the bank?
정답: C
문제12
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?
정답: B
설명: (ExamPassdump 회원만 볼 수 있음)
문제13
What is the most common method to exploit the "Bash Bug" or "Shellshock" vulnerability?
What is the most common method to exploit the "Bash Bug" or "Shellshock" vulnerability?
정답: D
문제14
A zone file consists of which of the following Resource Records (RRs)?
A zone file consists of which of the following Resource Records (RRs)?
정답: A
문제15
An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network.
Which AAA protocol is the most likely able to handle this requirement?
An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network.
Which AAA protocol is the most likely able to handle this requirement?
정답: C