2022年最新のの検証済み312-50v10問題と解答で合格保証 もしくは全額返金
[2022年03月]更新の312-50v10認証と実際の解答はここにあるPassTest
質問 283
Which of the following commands runs snort in packet logger mode?
- A. ./snort -dev -p ./log
- B. ./snort -dev -l ./log
- C. ./snort -dev -h ./log
- D. ./snort -dev -o ./log
正解: B
質問 284
From the two screenshots below, which of the following is occurring?
- A. 10.0.0.253 is performing an IP scan against 10.0.0.0/24, 10.0.0.252 is performing a port scan against
10.0.0.2. - B. 10.0.0.2 is performing an IP scan against 10.0.0.0/24, 10.0.0.252 is performing a port scan against
10.0.0.2. - C. 10.0.0.252 is performing an IP scan against 10.0.0.2, 10.0.0.252 is performing a port scan against
10.0.0.2. - D. 10.0.0.253 is performing an IP scan against 10.0.0.2, 10.0.0.252 is performing a port scan against
10.0.0.2.
正解: A
質問 285
The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the central processing unit (CPU), rather than passing only the frames that the controller is intended to receive.
Which of the following is being described?
- A. port forwarding
- B. WEM
- C. promiscuous mode
- D. multi-cast mode
正解: C
解説:
Promiscuous mode refers to the special mode of Ethernet hardware, in particular network interface cards (NICs), that allows a NIC to receive all traffic on the network, even if it is not addressed to this NIC. By default, a NIC ignores all traffic that is not addressed to it, which is done by comparing the destination address of the Ethernet packet with the hardware address (a.k.a. MAC) of the device. While this makes perfect sense for networking, non- promiscuous mode makes it difficult to use network monitoring and analysis software for diagnosing connectivity issues or traffic accounting.
References: https://www.tamos.com/htmlhelp/monitoring/
質問 286
Port scanning can be used as part of a technical assessment to determine network vulnerabilities. The TCP XMAS scan is used to identify listening ports on the targeted system.
If a scanned port is open, what happens?
- A. The port will ignore the packets.
- B. The port will send a SYN.
- C. The port will send an RST.
- D. The port will send an ACK.
正解: A
解説:
An attacker uses a TCP XMAS scan to determine if ports are closed on the target machine.
This scan type is accomplished by sending TCP segments with the all flags sent in the packet header, generating packets that are illegal based on RFC 793. The RFC 793 expected behavior is that any TCP segment with an out-of-state Flag sent to an open port is discarded, whereas segments with out-of-state flags sent to closed ports should be handled with a RST in response. This behavior should allow an attacker to scan for closed ports by sending certain types of rule-breaking packets (out of sync or disallowed by the TCB) and detect closed ports via RST packets.
References: https://capec.mitre.org/data/definitions/303.html
質問 287
In both pharming and phishing attacks an attacker can create websites that look similar to legitimate sites with the intent of collecting personal identifiable information from its victims. What is the difference between pharming and phishing attacks?
- A. Both pharming and phishing attacks are identical.
- B. Both pharming and phishing attacks are purely technical and are not considered forms of social engineering
- C. In a phishing attack a victim is redirected to a fake website by modifying their host configuration file or by exploiting vulnerabilities in DNS. In a phishing attack an attacker provides the victim with a URL that is either misspelled or looks similar to the actual websites domain name.
- D. In a pharming attack a victim is redirected to a fake website by modifying their host configuration file or by exploiting vulnerabilities in DNS. In a phishing attack an attacker provides the victim with a URL that is either misspelled or looks similar to the actual websites domain name.
正解: D
質問 288
Which of the following BEST describes the mechanism of a Boot Sector Virus?
- A. Moves the MBR to another location on the hard disk and copies itself to the original location of the MBR
- B. Modifies directory table entries so that directory entries point to the virus code instead of the actual program
- C. Moves the MBR to another location on the RAM and copies itself to the original location of the MBR
- D. Overwrites the original MBR and only executes the new virus code
正解: A
質問 289
Analyst is investigating proxy logs and found out that one of the internal user visited website storing suspicious Java scripts. After opening one of them, he noticed that it is very hard to understand the code and that all codes differ from the typical Java script. What is the name of this technique to hide the code and extend analysis time?
- A. Obfuscation
- B. Steganography
- C. Encryption
- D. Code encoding
正解: C
質問 290
Which of the following antennas is commonly used in communications for a frequency band of 10 MHz to
VHF and UHF?
- A. Dipole antenna
- B. Omnidirectional antenna
- C. Yagi antenna
- D. Parabolic grid antenna
正解: C
質問 291
Which of the following is an NMAP script that could help detect HTTP Methods such as GET, POST, HEAD, PUT, DELETE, TRACE?
- A. http enum
- B. http-methods
- C. http-headers
- D. http-git
正解: B
質問 292
XOR is a common cryptographic tool. 10110001 XOR 00111010 is?
- A. 0
- B. 1
- C. 2
- D. 3
正解: D
質問 293
Which of the following Secure Hashing Algorithm (SHA) produces a 160-bit digest from a message with a maximum length of (264-1) bits and resembles the MD5 algorithm?
- A. SHA-0
- B. SHA-2
- C. SHA-3
- D. SHA-1
正解: D
質問 294
What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?
- A. Residual risk
- B. Deferred risk
- C. Inherent risk
- D. Impact risk
正解: A
解説:
Explanation
The residual risk is the risk or danger of an action or an event, a method or a (technical) process that, although being abreast with science, still conceives these dangers, even if all theoretically possible safety measures would be applied (scientifically conceivable measures); in other words, the amount of risk left over after natural or inherent risks have been reduced by risk controls.
References: https://en.wikipedia.org/wiki/Residual_risk
質問 295
During a penetration test, the tester conducts an ACK scan using NMAP against the external interface of the DMZ firewall. NMAP reports that port 80 is unfiltered. Based on this response, which type of packet inspection is the firewall conducting?
- A. Host
- B. Application
- C. Stateless
- D. Stateful
正解: C
質問 296
Which of the following is one of the most effective ways to prevent Cross-site Scripting (XSS) flaws in software applications?
- A. Validate and escape all information sent to a server.
- B. Use digital certificates to authenticate a server prior to sending data.
- C. Verify access right before allowing access to protected information and UI controls.
- D. Use security policies and procedures to define and implement proper security settings.
正解: A
質問 297
You work for Acme Corporation as Sales Manager. The company has tight network security restrictions. You are trying to steal data from the company's Sales database (Sales.xls) and transfer them to your home computer. Your company filters and monitors traffic that leaves from the internal network to the Internet. How will you achieve this without raising suspicion?
- A. Encrypt the Sales.xls using PGP and e-mail it to your personal gmail account
- B. You can conceal the Sales.xls database in another file like photo.jpg or other files and send it out in an innocent looking email or file transfer using Steganography techniques
- C. Change the extension of Sales.xls to sales.txt and upload them as attachment to your hotmail account
- D. Package the Sales.xls using Trojan wrappers and telnet them back your home computer
正解: B
質問 298
Which of the following tools are used for enumeration? (Choose three.)
- A. SID2USER
- B. DumpSec
- C. SolarWinds
- D. USER2SID
- E. Cheops
正解: A,B,D
質問 299
Risks=Threats x Vulnerabilities is referred to as the:
- A. BIA equation
- B. Disaster recovery formula
- C. Threat assessment
- D. Risk equation
正解: D
質問 300
You receive an e-mail like the one shown below. When you click on the link contained in the mail, you are redirected to a website seeking you to download free Anti-Virus software.
Dear valued customers,
We are pleased to announce the newest version of Antivirus 2010 for Windows which will probe you with total security against the latest spyware, malware, viruses, Trojans and other online threats. Simply visit the link below and enter your antivirus code:
or you may contact us at the following address:
Media Internet Consultants, Edif. Neptuno, Planta
Baja, Ave. Ricardo J. Alfaro, Tumba Muerto, n/a Panama
How will you determine if this is Real Anti-Virus or Fake Anti-Virus website?
- A. Search using the URL and Anti-Virus product name into Google and lookout for suspicious warnings against this site
- B. Download and install Anti-Virus software from this suspicious looking site, your Windows 7 will prompt you and stop the installation if the downloaded file is a malware
- C. Look at the website design, if it looks professional then it is a Real Anti-Virus website
- D. Connect to the site using SSL, if you are successful then the website is genuine
- E. Download and install Anti-Virus software from this suspicious looking site, your Windows 7 will prompt you and stop the installation if the downloaded file is a malware
正解: A
質問 301
Which results will be returned with the following Google search query? site:target.com site:Marketing.target.com accounting
- A. Results matching "accounting" in domain target.com but not on the site Marketing.target.com
- B. Results matching all words in the query.
- C. Results for matches on target.com and Marketing,target.com that include the word "accounting"
- D. Results from matches on the site marketing.target.com that are in the domain target.com but do not include the word accounting.
正解: A
質問 302
......
312-50v10リアル有効で正確な問題集745問題と解答が待ってます:https://www.passtest.jp/EC-COUNCIL/312-50v10-shiken.html