- Học kỳ
- SU2026
- Thời Gian
- 26/7/26
- Loại tài liệu
- FE
HOD402 SU26 FE
1. (Choose 1 answer)
Which cloud technology attack method could generate crafted packets to cause a cloud application to crash?
A. resource exhaustion attack
B. account takeover
C. metadata service attack
D. side-channel attack
2. (Choose 1 answer)
Which tool organizes query entities within the Entity Palette and calls the search options "transforms"?
A. Shodan
B. FOCA
C. Maltego
D. theHarvester
3. (Choose 1 answer)
Which Wi-Fi protocol is most vulnerable to a brute-force attack during a Wi-Fi network deployment?
A. WPA2-EAP
B. WPS
C. WPA3
D. WPA2-TKIP
4. (Choose 2 answers)
Which are two best practices used to secure APIs? (Choose two.)
A. use reputable and standard libraries to create the APIs
B. make internal API documentation mandatory
C. discussing company API development (or any other application development) on public forums
D. secure API services to provide HTTP endpoints only keep API implementation and API security into one tier allowing the API developer to work on both facets simultaneously
5. (Choose 1 answer)
A contractor is hired to review and perform cybersecurity vulnerability assessments for a local health clinic facility. Which U.S. government regulation must the contractor understand before the contractor can start?
A. GDPR
B. GLBA
C. HIPAA
D. FedRAMP
6. (Choose 1 answer)
What procedure should be deployed to protect the network against lateral movement?
A. Database backups
B. VPNs
C. VLANs
D. Strong passwords for user accounts
7. (Choose 1 answer)
What is the purpose of bug bounty programs used by companies?
A. reward security professionals for finding vulnerabilities in the systems of the company
B. reward security professionals for discovering malicious activities by attackers in the systems of the company
C. reward security professionals for fixing vulnerabilities in the systems of the company
D. reward security professionals for breaking into a corporate facility to expose weaknesses in the physical perimeter
8. (Choose 1 answer)
Which Sysinternals tool is used by penetration testers to modify Windows registry values and connect a compromised system to another system?
A. PsInfo
B. PsLoggedOn
C. PsGetSid
D. PsExec
9. (Choose 1 answer)
If Alice wants to send a private message to Bob using asymmetric cryptography, what key does she use to encrypt the message?
A. Alice's private key
B. Alice's public key
C. Bob's private key
D. Bob's public key
E. None of the above
10. (Choose 1 answer)
Which of the following statements is not true regarding steganography?
A. Steganography can use least significant bit insertion, masking, and filtering as techniques to hide messaging.
B. Steganography only works on color images.
C. Image files embedded with steganography may be larger in size and display strange color palettes.
D. Character positioning, text patterns, unusual blank spaces, and language anomalies can all be symptoms of a text file embedded with steganography.
11. (Choose 3 answers)
In a defense-in-depth approach, which three options must be identified to effectively defend a network against attacks? (Choose three.)
A. total number of devices that attach to the wired and wireless network
B. assets that need protection
C. vulnerabilities in the system
D. location of attacker or attackers
E. past security breaches
F. threats to assets
12. (Choose 1 answer)
Which attack is a post-exploitation activity that an attacker uses to extract service account credential hashes from Active Directory for offline cracking?
A. MITM
B. On-Path attack
C. MAC spoofing
D. Kerberoasting
13. (Choose 1 answer)
What is a characteristic of a Kerberos silver ticket attack?
A. It uses forged service tickets for a given service on a particular server.
B. It mimics the authentication hash on a particular server.
C. It acts as the LDAP directory for authentication on a target server.
D. It converts the hashed value to the unencrypted value for an authentication attack on a particular server.
14. (Choose 1 answer)
Which component in the statement below is most likely user input on a web form? SELECT * FROM group WHERE attack = 'network' AND a-type LIKE 'ping%';
A. ping
B. group
C. attack
D. a-type
E. network
15. (Choose 1 answer)
Which of the following statements about extended IP access lists is correct?
A. Extended IP access lists can only filter traffic based on source IP addresses.
B. Extended IP access lists are identified by numbers ranging from 100 to 199 and 2000 to 2699.
C. Extended IP access lists must be applied only to inbound traffic.
D. Extended IP access lists cannot filter traffic based on protocol types.
16. (Choose 3 answers)
What are three considerations when planning a vulnerability scan on a target production network during a penetration test? (Choose three.)
A. the timing of the scan
B. the available network bandwidth
C. the network topology
D. authenticated scans are less complex and are quicker than unauthenticated scans
E. the available scanning tools
F. the trained personnel available to analyze the scan results
17. (Choose 1 answer)
What technology can you use temporarily to connect networks from two different companies?
A. VPN
B. HTTP
C. DHCP
D. Passive router
18. (Choose 1 answer)
What initial information can be obtained when performing user enumeration in a penetration test?
A. a valid list of users
B. the IP addresses of the target hosts
C. the credentials of a specified user
19. (Choose 1 answer)
Which tool is an open-source framework used to test the security of iOS applications?
A. Needle
B. Drozer
C. APK Studio
D. ApkX
20. (Choose 1 answer)
Which framework is used to exploit XSS vulnerabilities and manipulate victim browsers?
A. SET
B. BeEF
C. Metasploit
D. Asterisk
21. (Choose 1 answer)
Match the elements in the URL ftp://xyz-company.com:2457/support/file;id=65?name=intro&r=true to the description. Elements: 1. xyz-company.com 2. 2457 3. support/file 4. name=intro&r=true Description: a. host b. query-string c. port d. path
A. 1 - a, 2 - b, 3 - c, 4 - d
B. 1 - a, 2 - c, 3 - d, 4 - b
C. 1 - b, 2 - c, 3 - a, 4 - d
D. 1 - c, 2 - b, 3 - a, 4 - d
22. (Choose 3 answers)
You are studying the penetration testing agreement for a new engagement with one of Protego's customers. You are especially interested in the information that the client will provide to Protego to support the test. What technical assets may be identified as provided in the scope of the test? (Choose three.)
A. system architecture and network topology documents
B. non-disclosure agreements
C. the service-level agreement
D. API documentation
E. wireless SSIDs
F. credentials and skills of the penetration testing team
23. (Choose 1 answer)
A company hires a cybersecurity consultant to perform penetration testing to assess government regulation compliance. The consultant is preparing the final report after the penetration testing is completed. In which section of the report should the consultant cover the limitation of the work performed, such as the only dates when the testing is performed and that the findings mentioned in the report do not guarantee that all vulnerabilities are covered?
A. disclaimers
B. scope of work
C. findings and analysis
D. non-disclosure statement
24. (Choose 1 answer)
Which term describes a programming language component such as JavaScript Object Notation (JSON)?
A. Data structures
B. Logic constructs
C. Procedures
D. Classes
25. (Choose 1 answer)
Which tool permits post-exploitation activities, such as Windows reverse VNC DLL and reverse TCP shell?
A. Nikto
B. Nessus
C. SET
D. BeEF
26. (Choose 1 answer)
Which tool could be used to find vulnerabilities that could lead to metadata service attacks?
A. Nimbostratus
B. Clair
C. Falco
D. Dagda
27. (Choose 1 answer)
Which resource is a lightweight and portable tool that allows the creation of bind and reverse shells from a compromised host?
A. WMImplant
B. WSC2
C. BloodHound
D. Netcat
28. (Choose 1 answer)
A company uses the Microsoft Active Directory service to manage the authentication and authorization of employee workstations. The company hires a cybersecurity professional to perform compliance penetration testing. Which type of penetration testing can be used to verify the proper configuration of the Active Directory service?
A. SQL Union injection
B. LDAP injection
C. HTTP command injection
D. Stacked query SQL injection
29. (Choose 1 answer)
Which Linux distribution is specifically mentioned for penetration testing practice?
A. Ubuntu
B. Fedora
C. Kali Linux
D. Red Hat
30. (Choose 1 answer)
A recent pen-test results in a cybersecurity analyst report, including information on process-level remediation, patch management, and secrets management solutions. Which control category is represented by this example?
A. technical
B. administrative
C. operational
D. physical
31. (Choose 1 answer)
What is one of the main purposes of the Rules of Engagement document in penetration testing?
A. To list vulnerabilities found
B. To specify payment terms
C. To document testing conditions
D. To finalize software licensing
32. (Choose 1 answer)
What is the purpose of host enumeration when beginning a penetration test?
A. to identify all active IP addresses within the scope of the test
B. to count the total number of IP addresses within the scope of the test
C. to identify all vulnerable hosts within the scope of the test
D. to count the total number of vulnerable hosts within the scope of the test
33. (Choose 1 answer)
Which option is a PowerShell-based post-exploitation tool that can maintain persistence on a compromised system and run PowerShell agents without the need for powershell.exe?
A. Empire
B. Veil
C. Patator
D. Security Onion
34. (Choose 1 answer)
What kind of attack involves leaving infected USB drives for victims to pick up?
A. Watering Hole
B. Badge Cloning
C. Dumpster Diving
D. USB Drop Key
35. (Choose 1 answer)
What method of influence is characterized when a celebrity endorses a product on social media?
A. fear
B. authority
C. scarcity
D. social proof
36. (Choose 1 answer)
Which kind of event is a successful identification of a security attack?
A. false negatives
B. false positives
C. true negatives
D. true positives
37. (Choose 1 answer)
What characterizes a partially known environment penetration test?
A. The tester must test the electrical grid supporting the infrastructure of the target.
B. The tester is provided with a list of domain names and IP addresses in the scope of a particular target.
C. The test is a hybrid approach between unknown and known environment tests.
D. The tester should not have prior knowledge of the organization and infrastructure of the target.
38. (Choose 1 answer)
A company has hired a cybersecurity firm to assess web server security posture. To test for cross-site scripting vulnerabilities, the tester will use the string. Where would the tester use the string?
A. in an HTTP header
B. in an error message
C. in a terminal window on the server
D. in a user input field in a web form
39. (Choose 1 answer)
What control category does system hardening belong to?
A. technical
B. administrative
C. operational
D. physical
40. (Choose 1 answer)
Which of the following is considered an administrative control in penetration testing remediation?
A. Implementing biometric access systems
B. Installing firewalls
C. Enforcing minimum password requirements
D. Using network segmentation
41. (Choose 2 answers)
Which two IoT systems should never be exposed to the Internet? (Choose two.)
A. turbines in a power plant
B. robots in a factory
C. refrigerators in a restaurant
D. thermostat in a home
E. carbon monoxide detectors in a home
42. (Choose 1 answer)
Which statement describes an example of an out-of-band SQL injection attack?
A. An attacker launches the attack on a web site and forces the web application to delay the query results.
B. An attacker launches the attack on a web site and views the query results immediately on the screen.
C. An attacker launches the attack on a web site and reconstructs the information by sending specific SQL statements.
D. An attacker launches the attack on a web site and forces the web application to send the query results via an email.
43. (Choose 1 answer)
What process decrypts an encrypted message by finding mathematical problems in the technique?
A. Enigma
B. Substitution Cipher
C. Cryptanalysis
D. Brute Force
44. (Choose 2 answers)
What are two shared characteristics of the IDS and the IPS? (Choose two.)
A. Both have minimal impact on network performance.
B. Both are deployed as sensors.
C. Both analyze copies of network traffic.
D. Both use signatures to detect malicious traffic.
E. Both rely on an additional network device to respond to malicious traffic.
45. (Choose 1 answer)
What differentiates an ethical hacker from a nonethical hacker?
A. Tools used
B. Technical skills
C. Intent
D. Operating systems used
46. (Choose 1 answer)
What task can be accomplished with the steghide tool?
A. to modify Windows registry values and to connect a compromised system to another system
B. to find complex attack paths in Microsoft Azure
C. to obfuscate, to evade and to cover the attacker tracks
D. to allow administrators to control a Windows-based computer from a remote terminal
47. (Choose 1 answer)
Which command-line option in Nmap sets the timing to "very aggressive"?
A. -T2
B. -T3
C. -T4
D. -T5
48. (Choose 1 answer)
What type of social engineering attack involves phone conversations to extract sensitive information?
A. Pharming
B. Vishing
C. Shoulder surfing
D. Dumpster diving
49. (Choose 1 answer)
What type of social engineering attack involves phone conversations to extract sensitive information?
A. Pharming
B. Vishing
C. Shoulder surfing
D. Dumpster diving
50. (Choose 1 answer)
A person approaches a network administrator and wants advice on how to send encrypted e-mail from home. The end user does not want to have to pay for any license fees or manage server services. Which of the following
offers a method for sending encrypted e-mail without having to pay for license fees or manage a server?
A. IP Security (IPSec)
B. Multipurpose Internet Mail Extensions (MIME)
C. Pretty Good Privacy (PGP)
D. Hypertext Transfer Protocol with Secure Socket Layer (HTTPS
Đính kèm
-
hod402_su26_fe_01.webp23 KB · Lượt xem: 1 -
hod402_su26_fe_02.webp18.3 KB · Lượt xem: 1 -
hod402_su26_fe_03.webp17.9 KB · Lượt xem: 1 -
hod402_su26_fe_04.webp40.6 KB · Lượt xem: 1 -
hod402_su26_fe_05.webp25.6 KB · Lượt xem: 0 -
hod402_su26_fe_06.webp19.7 KB · Lượt xem: 0 -
hod402_su26_fe_07.webp43.3 KB · Lượt xem: 0 -
hod402_su26_fe_08.webp21.7 KB · Lượt xem: 0 -
hod402_su26_fe_09.webp24.5 KB · Lượt xem: 0 -
hod402_su26_fe_10.webp44.8 KB · Lượt xem: 0 -
hod402_su26_fe_11.webp33.9 KB · Lượt xem: 0 -
hod402_su26_fe_12.webp23.2 KB · Lượt xem: 2 -
hod402_su26_fe_13.webp34.2 KB · Lượt xem: 2 -
hod402_su26_fe_14.webp22.2 KB · Lượt xem: 2 -
hod402_su26_fe_15.webp36.4 KB · Lượt xem: 1 -
hod402_su26_fe_16.webp37.7 KB · Lượt xem: 1 -
hod402_su26_fe_17.webp17 KB · Lượt xem: 1 -
hod402_su26_fe_18.webp21.4 KB · Lượt xem: 1 -
hod402_su26_fe_19.webp16.7 KB · Lượt xem: 1 -
hod402_su26_fe_20.webp16.9 KB · Lượt xem: 1 -
hod402_su26_fe_21.webp29.9 KB · Lượt xem: 1 -
hod402_su26_fe_22.webp46.5 KB · Lượt xem: 1 -
hod402_su26_fe_23.webp47.3 KB · Lượt xem: 1 -
hod402_su26_fe_24.webp19.8 KB · Lượt xem: 1 -
hod402_su26_fe_25.webp17.5 KB · Lượt xem: 0 -
hod402_su26_fe_26.webp17.3 KB · Lượt xem: 0 -
hod402_su26_fe_27.webp20.4 KB · Lượt xem: 0 -
hod402_su26_fe_28.webp39.5 KB · Lượt xem: 0 -
hod402_su26_fe_29.webp16.6 KB · Lượt xem: 0 -
hod402_su26_fe_30.webp27.9 KB · Lượt xem: 0 -
hod402_su26_fe_31.webp23.5 KB · Lượt xem: 0 -
hod402_su26_fe_32.webp33.4 KB · Lượt xem: 0 -
hod402_su26_fe_33.webp24 KB · Lượt xem: 0 -
hod402_su26_fe_34.webp18.7 KB · Lượt xem: 0 -
hod402_su26_fe_35.webp17.6 KB · Lượt xem: 0 -
hod402_su26_fe_36.webp17.8 KB · Lượt xem: 0 -
hod402_su26_fe_37.webp40 KB · Lượt xem: 0 -
hod402_su26_fe_38.webp29.7 KB · Lượt xem: 0 -
hod402_su26_fe_39.webp15.9 KB · Lượt xem: 0 -
hod402_su26_fe_40.webp25.2 KB · Lượt xem: 0 -
hod402_su26_fe_41.webp23.9 KB · Lượt xem: 0 -
hod402_su26_fe_42.webp46.8 KB · Lượt xem: 0 -
hod402_su26_fe_43.webp19.6 KB · Lượt xem: 0 -
hod402_su26_fe_44.webp32.1 KB · Lượt xem: 0 -
hod402_su26_fe_45.webp17.1 KB · Lượt xem: 0 -
hod402_su26_fe_46.webp33.8 KB · Lượt xem: 0 -
hod402_su26_fe_47.webp14.1 KB · Lượt xem: 0 -
hod402_su26_fe_48.webp19.5 KB · Lượt xem: 0 -
hod402_su26_fe_49.webp19.5 KB · Lượt xem: 0 -
hod402_su26_fe_50.webp43.6 KB · Lượt xem: 1