📘 Free 312-50V13 Sample Questions
In this form of encryption algorithm, every individual block contains 64-bit data, and three keys are used, where each
key consists of 56 bits. Which is this encryption algorithm?
A
A. IDEA
B
B. Triple Data Encryption Standard
C
C. AES
D
D. MD5 encryption algorithm
Correct Answer:
B. B. Triple Data Encryption Standard
Explanation:
Characteristics of Triple DES (3DES).
β- It operates on 64-bit blocks of data.
-- It uses three 56-bit keys (K1, K2, and K3), effectively providing a key length of up to 168 bits.
-- The encryption process involves three operations: encrypting with K1, decrypting with K2, and encrypting again
with K3 (Encrypt-Decrypt-Encrypt or EDE mode).
John is investigating web-application firewall logs and observers that someone is attempting to inject the following:
A
A. SQL injection
B
B. Buffer overflow
Correct Answer:
B. B. Buffer overflow
Explanation:
The buffer buff is defined to hold 10 elements (indices 0 through 9). Writing to buff[10] attempts to access memory
beyond the allocated buffer size. This can lead to overwriting adjacent memory, potentially corrupting data, crashing
the application, or enabling the execution of malicious code.
John, a professional hacker, performs a network attack on a renowned organization and gains unauthorized access
to the target network. He remains in the network without being detected for a long time and obtains sensitive
information without sabotaging the organization.
Which of the following attack techniques is used by John?
A
A. Insider threat
B
B. Diversion theft
C
C. Spear-phishing sites
D
D. Advanced persistent threat
Correct Answer:
D. D. Advanced persistent threat
Explanation:
Advanced Persistent Threat (APT) refers to an attack where a threat actor gains unauthorised access to a network
and remains undetected for an extended period.
You are attempting to run an Nmap port scan on a web server. Which of the following commands would result in a
scan of common ports with the least amount of noise in order to evade IDS?
A
A. nmap -A - Pn
B
B. nmap -sP -p-65535 -T5
C
C. nmap -sT -O -T0
D
D. nmap -A --host-timeout 99 -T1
Correct Answer:
C. C. nmap -sT -O -T0
This wireless security protocol allows 192-bit minimum-strength security protocols and cryptographic tools to
protect sensitive data, such as GCMP-256, HMAC-SHA384, and ECDSA using a 384-bit elliptic curve.
Which is this wireless security protocol?
A
A. WPA3-Personal
B
B. WPA3-Enterprise
C
C. WPA2-Enterprise
Correct Answer:
B. B. WPA3-Enterprise
What are common files on a web server that can be misconfigured and provide useful information for a hacker such
as verbose error messages?
A
A. httpd.conf
B
B. administration.config
C
C. php.ini
Correct Answer:
C. C. php.ini
Gerard, a disgruntled ex-employee of Sunglass IT Solutions, targets this organization to perform sophisticated attacks
and bring down its reputation in the market. To launch the attacks process, he performed DNS footprinting to gather
information about DNS servers and to identify the hosts connected in the target network. He used an automated
tool that can retrieve information about DNS zone data including DNS domain names, computer names, IP
addresses, DNS records, and network Whois records. He further exploited this information to launch other
sophisticated attacks.
What is the tool employed by Gerard in the above scenario?
A
A. Towelroot
B
B. Knative
C
C. zANTI
D
D. Bluto
Correct Answer:
D. D. Bluto
Tony is a penetration tester tasked with performing a penetration test. After gaining initial access to a target system,
he finds a list of hashed passwords.
Which of the following tools would not be useful for cracking the hashed passwords?
A
A. Hashcat
B
B. John the Ripper
C
C. THC-Hydra
D
D. netcat
Correct Answer:
D. D. netcat
Which of the following Google advanced search operators helps an attacker in gathering information about websites
that are similar to a specified target URL?
A
A. [inurl:]
B
B. [info:]
C
C. [site:]
D
D. [related:]
Correct Answer:
D. D. [related:]
You are a penetration tester working to test the user awareness of the employees of the client XYZ. You harvested
two employeesβ emails from some public sources and are creating a client-side backdoor to send it to the employees
via email.
Which stage of the cyber kill chain are you at?
A
A. Reconnaissance
B
B. Weaponization
C
C. Command and control
D
D. Exploitation
Correct Answer:
B. B. Weaponization
Questions: 1-10 out of 302
Continue Full Practice..
GET ALL 302 QUESTIONS