[Aug 27, 2021] 312-50v11 Ultimate Study Guide - ExamPrepAway [Q20-Q44]

Share

[Aug 27, 2021] 312-50v11 Ultimate Study Guide -  ExamPrepAway

Ultimate Guide to Prepare 312-50v11 Certification Exam for CEH v11 in 2021

NEW QUESTION 20
Allen, a professional pen tester, was hired by xpertTech solutWns to perform an attack simulation on the organization's network resources. To perform the attack, he took advantage of the NetBIOS API and targeted the NetBIOS service. B/enumerating NetBIOS, he found that port 139 was open and could see the resources that could be accessed or viewed on a remote system. He came across many NetBIOS codes during enumeration.
identify the NetBIOS code used for obtaining the messenger service running for the logged-in user?

  • A. <1B>
  • B. <00>
  • C. <20>
  • D. <03>

Answer: D

Explanation:
<03>
Windows Messenger administration
Courier administration is an organization based framework notice Windows administration by Microsoft that was remembered for some prior forms of Microsoft Windows.
This resigned innovation, despite the fact that it has a comparable name, isn't connected in any capacity to the later, Internet-based Microsoft Messenger administration for texting or to Windows Messenger and Windows Live Messenger (earlier named MSN Messenger) customer programming.
The Messenger Service was initially intended for use by framework managers to tell Windows clients about their networks.[1] It has been utilized malevolently to introduce spring up commercials to clients over the Internet (by utilizing mass-informing frameworks which sent an ideal message to a predetermined scope of IP addresses). Despite the fact that Windows XP incorporates a firewall, it isn't empowered naturally. Along these lines, numerous clients got such messages. Because of this maltreatment, the Messenger Service has been debilitated as a matter of course in Windows XP Service Pack 2.

 

NEW QUESTION 21
Wilson, a professional hacker, targets an organization for financial benefit and plans to compromise its systems by sending malicious emails. For this purpose, he uses a tool to track the emails of the target and extracts information such as sender identities, mall servers, sender IP addresses, and sender locations from different public sources. He also checks if an email address was leaked using the haveibeenpwned.com API.
Which of the following tools is used by Wilson in the above scenario?

  • A. Factiva
  • B. Zoominfo
  • C. Netcraft
  • D. infoga

Answer: D

Explanation:
Explanation
Infoga may be a tool gathering email accounts informations (ip,hostname,country,...) from completely different public supply (search engines, pgp key servers and shodan) and check if email was leaked using haveibeenpwned.com API. is a really simple tool, however very effective for the first stages of a penetration test or just to know the visibility of your company within the net.

 

NEW QUESTION 22
Techno Security Inc. recently hired John as a penetration tester. He was tasked with identifying open ports in the target network and determining whether the ports are online and any firewall rule sets are encountered.
John decided to perform a TCP SYN ping scan on the target network.
Which of the following Nmap commands must John use to perform the TCP SYN ping scan?

  • A. nmap -sn -PS < target IP address >
  • B. nmap -sn -PO < target IP address >
  • C. nmap -sn -PA < target IP address >
  • D. nmap -sn -PP < target IP address >

Answer: A

 

NEW QUESTION 23
Joel, a professional hacker, targeted a company and identified the types of websites frequently visited by its employees. Using this information, he searched for possible loopholes in these websites and injected a malicious script that can redirect users from the web page and download malware onto a victim's machine.
Joel waits for the victim to access the infected web application so as to compromise the victim's machine.
Which of the following techniques is used by Joel in the above scenario?

  • A. MarioNet attack
  • B. DNS rebinding attack
  • C. Clickjacking attack
  • D. Watering hole attack

Answer: C

 

NEW QUESTION 24
When you are getting information about a web server, it is very important to know the HTTP Methods (GET, POST, HEAD, PUT, DELETE, TRACE) that are available because there are two critical methods (PUT and DELETE). PUT can upload a file to the server and DELETE can delete a file from the server. You can detect all these methods (GET, POST, HEAD, DELETE, PUT, TRACE) using NMAP script engine. What Nmap script will help you with this task?

  • A. http enum
  • B. http-headers
  • C. http-git
  • D. http-methods

Answer: D

 

NEW QUESTION 25
Your company performs penetration tests and security assessments for small and medium-sized business in the local are a. During a routine security assessment, you discover information that suggests your client is involved with human trafficking.
What should you do?

  • A. Immediately stop work and contact the proper legal authorities.
  • B. Confront the client in a respectful manner and ask her about the data.
  • C. Ignore the data and continue the assessment until completed as agreed.
  • D. Copy the data to removable media and keep it in case you need it.

Answer: A

 

NEW QUESTION 26
Richard, an attacker, targets an MNC. In this process, he uses a footprinting technique to gather as much information as possible. Using this technique, he gathers domain information such as the target domain name, contact details of its owner, expiry date, and creation date. With this information, he creates a map of the organization's network and misleads domain owners with social engineering to obtain internal details of its network.
What type of footprinting technique is employed by Richard?

  • A. Whois footprinting
  • B. VPN footprinting
  • C. VoIP footprinting
  • D. Email footprinting

Answer: A

 

NEW QUESTION 27
In the Common Vulnerability Scoring System (CVSS) v3.1 severity ratings, what range does medium vulnerability fall in?

  • A. 4.0-6.0
  • B. 3.0-6.9
  • C. 3.9-6.9
  • D. 4.0-6.9

Answer: D

 

NEW QUESTION 28
Firewalk has just completed the second phase (the scanning phase) and a technician receives the output shown below. What conclusions can be drawn based on these scan results?
TCP port 21 no response
TCP port 22 no response
TCP port 23 Time-to-live exceeded

  • A. The scan on port 23 was able to make a connection to the destination host prompting the firewall to respond with a TTL error
  • B. The lack of response from ports 21 and 22 indicate that those services are not running on the destination server
  • C. The firewall itself is blocking ports 21 through 23 and a service is listening on port 23 of the target host
  • D. The scan on port 23 passed through the filtering device. This indicates that port 23 was not blocked at the firewall

Answer: D

 

NEW QUESTION 29
Which regulation defines security and privacy controls for Federal information systems and organizations?

  • A. HIPAA
  • B. EU Safe Harbor
  • C. PCI-DSS
  • D. NIST-800-53

Answer: D

 

NEW QUESTION 30
David is a security professional working in an organization, and he is implementing a vulnerability management program in the organization to evaluate and control the risks and vulnerabilities in its IT infrastructure. He is currently executing the process of applying fixes on vulnerable systems to reduce the impact and severity of vulnerabilities.
Which phase of the vulnerability-management life cycle is David currently in?

  • A. Verification
  • B. Remediation
  • C. Vulnerability scan
  • D. Risk assessment

Answer: B

 

NEW QUESTION 31
Bob, your senior colleague, has sent you a mail regarding a deal with one of the clients. You are requested to accept the offer and you oblige. After 2 days. Bob denies that he had ever sent a mail. What do you want to
""know"" to prove yourself that it was Bob who had send a mail?

  • A. Integrity
  • B. Authentication
  • C. Non-Repudiation
  • D. Confidentiality

Answer: C

 

NEW QUESTION 32
What is the common name for a vulnerability disclosure program opened by companies In platforms such as HackerOne?

  • A. Vulnerability hunting program
  • B. Bug bounty program
  • C. White-hat hacking program
  • D. Ethical hacking program

Answer: B

Explanation:
Explanation
Bug bounty programs allow independent security researchers to report bugs to an companies and receive rewards or compensation. These bugs area unit sometimes security exploits and vulnerabilities, although they will additionally embody method problems, hardware flaws, and so on.
The reports area unit usually created through a program travel by associate degree freelance third party (like Bugcrowd or HackerOne). The companies can got wind of (and run) a program curated to the organization's wants.
Programs is also non-public (invite-only) wherever reports area unit unbroken confidential to the organization or public (where anyone will sign in and join). they will happen over a collection timeframe or with without stopping date (though the second possibility is a lot of common).
Who uses bug bounty programs?Many major organizations use bug bounties as an area of their security program, together with AOL, Android, Apple, Digital Ocean, and goldman Sachs. you'll read an inventory of all the programs offered by major bug bounty suppliers, Bugcrowd and HackerOne, at these links.
Why do corporations use bug bounty programs?Bug bounty programs provide corporations the flexibility to harness an outsized cluster of hackers so as to seek out bugs in their code.
This gives them access to a bigger variety of hackers or testers than they'd be able to access on a one-on-one basis. It {can also|also will|can even|may also|may} increase the probabilities that bugs area unit found and reported to them before malicious hackers can exploit them.
It may also be an honest publicity alternative for a firm. As bug bounties became a lot of common, having a bug bounty program will signal to the general public and even regulators that a corporation incorporates a mature security program.
This trend is likely to continue, as some have began to see bug bounty programs as an business normal that all companies ought to invest in.
Why do researchers and hackers participate in bug bounty programs?Finding and news bugs via a bug bounty program may end up in each money bonuses and recognition. In some cases, it will be a good thanks to show real-world expertise once you are looking for employment, or will even facilitate introduce you to parents on the protection team within an companies.
This can be full time income for a few of us, income to supplement employment, or the way to point out off your skills and find a full time job.
It may also be fun! it is a nice (legal) probability to check out your skills against huge companies and government agencies.
What area unit the disadvantages of a bug bounty program for independent researchers and hackers?A lot of hackers participate in these varieties of programs, and it will be tough to form a major quantity of cash on the platform.
In order to say the reward, the hacker has to be the primary person to submit the bug to the program. meaning that in apply, you may pay weeks searching for a bug to use, solely to be the person to report it and build no cash.
Roughly ninety seven of participants on major bug bounty platforms haven't sold-out a bug.
In fact, a 2019 report from HackerOne confirmed that out of quite three hundred,000 registered users, solely around two.5% received a bounty in their time on the platform.
Essentially, most hackers are not creating a lot of cash on these platforms, and really few square measure creating enough to switch a full time wage (plus they do not have advantages like vacation days, insurance, and retirement planning).
What square measure the disadvantages of bug bounty programs for organizations?These programs square measure solely helpful if the program ends up in the companies realizeing issues that they weren't able to find themselves (and if they'll fix those problems)!
If the companies is not mature enough to be able to quickly rectify known problems, a bug bounty program is not the right alternative for his or her companies.
Also, any bug bounty program is probably going to draw in an outsized range of submissions, several of which can not be high-quality submissions. a corporation must be ready to cope with the exaggerated volume of alerts, and also the risk of a coffee signal to noise magnitude relation (essentially that it's probably that they're going to receive quite few unhelpful reports for each useful report).
Additionally, if the program does not attract enough participants (or participants with the incorrect talent set, and so participants are not able to establish any bugs), the program is not useful for the companies.
The overwhelming majority of bug bounty participants consider web site vulnerabilities (72%, per HackerOn), whereas solely a number of (3.5%) value more highly to seek for package vulnerabilities.
This is probably because of the actual fact that hacking in operation systems (like network hardware and memory) needs a big quantity of extremely specialised experience. this implies that firms may even see vital come on investment for bug bounties on websites, and not for alternative applications, notably those that need specialised experience.
This conjointly implies that organizations which require to look at AN application or web site among a selected time-frame may not need to rely on a bug bounty as there is no guarantee of once or if they receive reports.
Finally, it are often probably risky to permit freelance researchers to try to penetrate your network. this could end in public speech act of bugs, inflicting name harm within the limelight (which could end in individuals not eager to purchase the organizations' product or service), or speech act of bugs to additional malicious third parties, United Nations agency may use this data to focus on the organization.

 

NEW QUESTION 33
Eve is spending her day scanning the library computers. She notices that Alice is using a computer whose port
445 is active and listening. Eve uses the ENUM tool to enumerate Alice machine. From the command prompt, she types the following command.

What is Eve trying to do?

  • A. Eve is trying to carry out a password crack for user Administrator
  • B. Eve is trying to connect as a user with Administrator privileges
  • C. Eve is trying to escalate privilege of the null user to that of Administrator
  • D. Eve is trying to enumerate all users with Administrative privileges

Answer: A

 

NEW QUESTION 34
You are a penetration tester and are about to perform a scan on a specific server. The agreement that you signed with the client contains the following specific condition for the scan: "The attacker must scan every port on the server several times using a set of spoofed sources IP addresses. " Suppose that you are using Nmap to perform this scan. What flag will you use to satisfy this requirement?

  • A. The -f flag
  • B. The -D flag
  • C. The -A flag
  • D. The -g flag

Answer: B

Explanation:
Explanation
flags -source-port and -g are equivalent and instruct nmap to send packets through a selected port. this option is used to try to cheat firewalls whitelisting traffic from specific ports. the following example can scan the target from the port twenty to ports eighty, 22, 21,23 and 25 sending fragmented packets to LinuxHint.

 

NEW QUESTION 35
A friend of yours tells you that he downloaded and executed a file that was sent to him by a coworker. Since the file did nothing when executed, he asks you for help because he suspects that he may have installed a trojan on his computer.
what tests would you perform to determine whether his computer Is Infected?

  • A. Upload the file to VirusTotal.
  • B. You do not check; rather, you immediately restore a previous snapshot of the operating system.
  • C. Use ExifTool and check for malicious content.
  • D. Use netstat and check for outgoing connections to strange IP addresses or domains.

Answer: C

 

NEW QUESTION 36
Alice, a professional hacker, targeted an organization's cloud services. She infiltrated the targets MSP provider by sending spear-phishing emails and distributed custom-made malware to compromise user accounts and gain remote access to the cloud service. Further, she accessed the target customer profiles with her MSP account, compressed the customer data, and stored them in the MSP. Then, she used this information to launch further attacks on the target organization. Which of the following cloud attacks did Alice perform in the above scenario?

  • A. Cloud hopper attack
  • B. Man-in-the-cloud (MITC) attack
  • C. Cloud cryptojacking
  • D. Cloudborne attack

Answer: A

Explanation:
Operation Cloud Hopper was an in depth attack and theft of data in 2017 directed at MSP within the uk (U.K.), us (U.S.), Japan, Canada, Brazil, France, Switzerland, Norway, Finland, Sweden, South Africa , India, Thailand, South Korea and Australia. The group used MSP as intermediaries to accumulate assets and trade secrets from MSP client engineering, MSP industrial manufacturing, retail, energy, pharmaceuticals, telecommunications, and government agencies. Operation Cloud Hopper used over 70 variants of backdoors, malware and trojans. These were delivered through spear-phishing emails. The attacks scheduled tasks or leveraged services/utilities to continue Microsoft Windows systems albeit the pc system was rebooted. It installed malware and hacking tools to access systems and steal data.

 

NEW QUESTION 37
Which of the following DoS tools is used to attack target web applications by starvation of available sessions on the web server?
The tool keeps sessions at halt using never-ending POST transmissions and sending an arbitrarily large content-length header value.

  • A. Astacheldraht
  • B. R-U-Dead-Yet?(RUDY)
  • C. My Doom
  • D. LOIC

Answer: B

 

NEW QUESTION 38
You start performing a penetration test against a specific website and have decided to start from grabbing all the links from the main page.
What is the best Linux pipe to achieve your milestone?

  • A. curl -s https://site.com | grep "<a href=\"http" | grep "site.com" | cut -d "\"" -f 2
  • B. dirb https://site.com | grep "site"
  • C. wget https://site.com | grep "<a href=\"http" | grep "site.com"
  • D. wget https://site.com | cut -d "http"

Answer: C

 

NEW QUESTION 39
You are using a public Wi-Fi network inside a coffee shop. Before surfing the web, you use your VPN to prevent intruders from sniffing your traffic. If you did not have a VPN, how would you identify whether someone is performing an ARP spoofing attack on your laptop?

  • A. You should use netstat to check for any suspicious connections with another IP address within the LAN.
  • B. You should scan the network using Nmap to check the MAC addresses of all the hosts and look for duplicates.
  • C. You should check your ARP table and see if there is one IP address with two different MAC addresses.
  • D. You cannot identify such an attack and must use a VPN to protect your traffic, r

Answer: C

 

NEW QUESTION 40
Which protocol is used for setting up secure channels between two devices, typically in VPNs?

  • A. SET
  • B. PEM
  • C. ppp
  • D. IPSEC

Answer: D

 

NEW QUESTION 41
What two conditions must a digital signature meet?

  • A. Has to be unforgeable, and has to be authentic.
  • B. Must be unique and have special characters.
  • C. Has to be legible and neat.
  • D. Has to be the same number of characters as a physical signature and must be unique.

Answer: A

 

NEW QUESTION 42
Ricardo has discovered the username for an application in his target's environment. As he has a limited amount of time, he decides to attempt to use a list of common passwords he found on the Internet. He compiles them into a list and then feeds that list as an argument into his password-cracking application.
What type of attack is Ricardo performing?

  • A. Known plaintext
  • B. Brute force
  • C. Password spraying
  • D. Dictionary

Answer: D

 

NEW QUESTION 43
A company's policy requires employees to perform file transfers using protocols which encrypt traffic. You suspect some employees are still performing file transfers using unencrypted protocols because the employees do not like changes. You have positioned a network sniffer to capture traffic from the laptops used by employees in the data ingest department. Using Wireshark to examine the captured traffic, which command can be used as a display filter to find unencrypted file transfers?

  • A. tcp.port = 23
  • B. tcp.port = = 21 | | tcp.port = =22
  • C. tcp.port = = 21
  • D. tcp.port ! = 21

Answer: C

 

NEW QUESTION 44
......

CEH v11 Fundamentals-312-50v11 Exam-Practice-Dumps: https://www.examprepaway.com/EC-COUNCIL/braindumps.312-50v11.ete.file.html

Use Real 312-50v11 Dumps - EC-COUNCIL Correct Answers: https://drive.google.com/open?id=10IAmcUZq6DHMNyHEu1ECgFAK9lLY_nBT