[2024年07月29日] 最速合格には素晴らしい312-50v10無料テストPDF本日更新です
無料でゲット!最新の2024年最新の有効な練習Certified Ethical Hacker 312-50v10問題と解答でテストエンジン
CEH V10認定試験は、最新のハッキング技術、方法論、ツールの理解を検証しようとしているIT専門家を対象としています。この試験では、列挙、フットプリントと偵察、システムのハッキング、情報収集、スキャンネットワーク、マルウェアの脅威、サービス攻撃の拒否、ソーシャルエンジニアリング、セッションハイジャックなどを含むさまざまなトピックについて説明します。 CEH V10試験は、候補者の実用的なスキルをテストするように設計されており、倫理的ハッカーが直面する実際の状況をシミュレートするように設計されています。
質問 # 18
Alice encrypts her data using her public key PK and stores the encrypted data in the cloud. Which of the following attack scenarios will compromise the privacy of her data?
- A. None of these scenarios compromise the privacy of Alice's data
- B. Alice also stores her private key in the cloud, and Harry breaks into the cloud server as before
- C. Hacker Harry breaks into the cloud server and steals the encrypted data
- D. Agent Andrew subpoenas Alice, forcing her to reveal her private key. However, the cloud server successfully resists Andrew's attempt to access the stored data
正解:B
質問 # 19
You are performing a penetration test. You achieved access via a buffer overflow exploit and you proceed to find interesting data, such as files with usernames and passwords. You find a hidden folder that has the administrator's bank account password and login information for the administrator's bitcoin account.
What should you do?
- A. Do not transfer the money but steal the bitcoins.
- B. Report immediately to the administrator
- C. Transfer money from the administrator's account to another account.
- D. Do not report it and continue the penetration test.
正解:B
質問 # 20
Which of the following BEST describes how Address Resolution Protocol (ARP) works?
- A. It sends a reply packet for a specific IP, asking for the MAC address
- B. It sends a reply packet to all the network elements, asking for the MAC address from a specific IP
- C. It sends a request packet to all the network elements, asking for the domain name from a specific IP
- D. It sends a request packet to all the network elements, asking for the MAC address from a specific IP
正解:D
質問 # 21
An attacker tries to do banner grabbing on a remote web server and executes the following command.
Service
detection performed. Please report any incorrect results at http://nmap.org/submit/.
Nmap done: 1 IP address (1 host up) scanned in 6.42 seconds
What did the hacker accomplish?
- A. nmap can't retrieve the version number of any running remote service.
- B. The hacker successfully completed the banner grabbing.
- C. The hacker failed to do banner grabbing as he didn't get the version of the Apache web server.
- D. The hacker should've used nmap -O host.domain.com.
正解:B
質問 # 22
It is a vulnerability in GNU's bash shell, discovered in September of 2014, that gives attackers access to run remote commands on a vulnerable system. The malicious software can take control of an infected machine, launch denial-of-service attacks to disrupt websites, and scan for other vulnerable devices (including routers).
Which of the following vulnerabilities is being described?
- A. Rootshock
- B. Shellbash
- C. Rootshell
- D. Shellshock
正解:D
解説:
Shellshock, also known as Bashdoor, is a family of security bugs in the widely used Unix Bash shell, the first of which was disclosed on 24 September 2014.
References: https://en.wikipedia.org/wiki/Shellshock_(software_bug)
質問 # 23
You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine.
What wireshark filter will show the connections from the snort machine to kiwi syslog machine?
- A. tcp.srcport==514 && ip.src==192.168.150
- B. tcp.dstport==514 && ip.dst==192.168.0.150
- C. tcp.srcport==514 && ip.src==192.168.0.99
- D. tcp.dstport==514 && ip.dst==192.168.0.0/16
正解:B
解説:
Explanation
We need to configure destination port at destination ip. The destination ip is 192.168.0.150, where the kiwi syslog is installed.
References: https://wiki.wireshark.org/DisplayFilters
質問 # 24
An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces. Which of the following is the most likely reason for lack of management or control packets?
- A. The wireless card was not turned on.
- B. On Linux and Mac OS X, only 802.11 headers are received in promiscuous mode.
- C. Certain operating systems and adapters do not collect the management or control packets.
- D. The wrong network card drivers were in use by Wireshark.
正解:C
質問 # 25
Which of the following is an advantage of utilizing security testing methodologies to conduct a security audit?
- A. They provide a repeatable framework.
- B. They are available at low cost.
- C. They are subject to government regulation.
- D. Anyone can run the command line scripts.
正解:A
質問 # 26
Eve stole a file named secret.txt, transferred it to her computer and she just entered these commands:
What is she trying to achieve?
- A. She is using John the Ripper to view the contents of the file.
- B. She is using John the Ripper to crack the passwords in the secret.txt file
- C. She is using ftp to transfer the file to another hacker named John.
- D. She is encrypting the file.
正解:B
質問 # 27
You are working as a Security Analyst in a company XYZ that owns the whole subnet range of 23.0.0.0/8 and 192.168.0.0/8.
While monitoring the data, you find a high number of outbound connections. You see that IP's owned by XYZ (Internal) and private IP's are communicating to a Single Public IP. Therefore, the Internal IP's are sending data to the Public IP.
After further analysis, you find out that this Public IP is a blacklisted IP, and the internal communicating devices are compromised.
What kind of attack does the above scenario depict?
- A. Spear Phishing Attack
- B. Advanced Persistent Threats
- C. Botnet Attack
- D. Rootkit Attack
正解:C
質問 # 28
When does the Payment Card Industry Data Security Standard (PCI-DSS) require organizations to perform external and internal penetration testing?
- A. At least once a year and after any significant upgrade or modification
- B. At least once every three years or after any significant upgrade or modification
- C. At least twice a year or after any significant upgrade or modification
- D. At least once every two years and after any significant upgrade or modification
正解:A
質問 # 29
You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection System.
What is the best approach?
- A. Install and use Telnet to encrypt all outgoing traffic from this server.
- B. Install Cryptcat and encrypt outgoing packets from this server.
- C. Use Alternate Data Streams to hide the outgoing packets from this server.
- D. Use HTTP so that all traffic can be routed via a browser, thus evading the internal Intrusion Detection Systems.
正解:B
解説:
Cryptcat enables us to communicate between two systems and encrypts the communication between them with twofish.
References: http://null-byte.wonderhowto.com/how-to/hack-like-pro-create-nearly- undetectable-backdoor-with-cryptcat-0149264/
質問 # 30
The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the central processing unit (CPU), rather than passing only the frames that the controller is intended to receive.
Which of the following is being described?
- A. WEM
- B. port forwarding
- C. multi-cast mode
- D. promiscuous mode
正解:D
解説:
Promiscuous mode refers to the special mode of Ethernet hardware, in particular network interface cards (NICs), that allows a NIC to receive all traffic on the network, even if it is not addressed to this NIC. By default, a NIC ignores all traffic that is not addressed to it, which is done by comparing the destination address of the Ethernet packet with the hardware address (a.k.a. MAC) of the device. While this makes perfect sense for networking, non- promiscuous mode makes it difficult to use network monitoring and analysis software for diagnosing connectivity issues or traffic accounting.
References: https://www.tamos.com/htmlhelp/monitoring/
質問 # 31
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database. In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?
- A. Double quote
- B. Exclamation mark
- C. Semicolon
- D. Single quote
正解:D
質問 # 32
You receive an e-mail like the one shown below. When you click on the link contained in the mail, you are redirected to a website seeking you to download free Anti-Virus software.
Dear valued customers,
We are pleased to announce the newest version of Antivirus 2010 for Windows which will probe you with total security against the latest spyware, malware, viruses, Trojans and other online threats. Simply visit the link below and enter your antivirus code:
or you may contact us at the following address:
Media Internet Consultants, Edif. Neptuno, Planta
Baja, Ave. Ricardo J. Alfaro, Tumba Muerto, n/a Panama
How will you determine if this is Real Anti-Virus or Fake Anti-Virus website?
- A. Download and install Anti-Virus software from this suspicious looking site, your Windows
7 will prompt you and stop the installation if the downloaded file is a malware - B. Download and install Anti-Virus software from this suspicious looking site, your Windows
7 will prompt you and stop the installation if the downloaded file is a malware - C. Search using the URL and Anti-Virus product name into Google and lookout for suspicious warnings against this site
- D. Connect to the site using SSL, if you are successful then the website is genuine
- E. Look at the website design, if it looks professional then it is a Real Anti-Virus website
正解:C
質問 # 33
Bob finished a C programming course and created a small C application to monitor the network traffic and
produce alerts when any origin sends "many" IP packets, based on the average number of packets sent by
all origins and using some thresholds.
In concept, the solution developed by Bob is actually:
- A. A behavior-based IDS
- B. A hybrid IDS
- C. Just a network monitoring tool
- D. A signature-based IDS
正解:C
質問 # 34
During a wireless penetration test, a tester detects an access point using WPA2 encryption.
Which of the following attacks should be used to obtain the key?
- A. The tester must capture the WPA2 authentication handshake and then crack it.
- B. The tester cannot crack WPA2 because it is in full compliance with the IEEE 802.11i standard.
- C. The tester must change the MAC address of the wireless network card and then use the AirTraf tool to obtain the key.
- D. The tester must use the tool inSSIDer to crack it using the ESSID of the network.
正解:A
質問 # 35
The configuration allows a wired or wireless network interface controller to pass all traffic it receives to the Central Processing Unit (CPU), rather than passing only the frames that the controller is intended to receive.
Which of the following is being described?
- A. Promiscuous mode
- B. WEM
- C. Multi-cast mode
- D. Port forwarding
正解:A
質問 # 36
You are using NMAP to resolve domain names into IP addresses for a ping sweep later.
Which of the following commands looks for IP addresses?
- A. >host -t a hackeddomain.com
- B. >host -t AXFR hackeddomain.com
- C. >host -t soa hackeddomain.com
- D. >host -t ns hackeddomain.com
正解:A
解説:
The A record is an Address record. It returns a 32-bit IPv4 address, most commonly used to map hostnames to an IP address of the host.
References: https://en.wikipedia.org/wiki/List_of_DNS_record_types
質問 # 37
......
EC-Council 312-50V10(認定倫理ハッカー試験(CEH V10))認定試験は、サイバーの脅威を特定して防止するために必要な知識とスキルを実証するグローバルに認められた認定です。 CEH V10認定は、倫理的ハッキングとサイバーセキュリティのキャリアを追求することに関心のある専門家向けに設計されています。認定試験では、コンピューターシステムとネットワークの脆弱性を認識し、攻撃を防ぐための適切なセキュリティ対策を実装する候補者の能力をテストします。
CEH V10認定試験は、偵察、スキャンネットワーク、列挙、システムハッキング、トロイの木馬やバックドアなど、倫理的ハッキングのさまざまな側面で専門家の知識とスキルをテストするように設計されています。この試験では、スニッフィングやセッションハイジャック、ソーシャルエンジニアリング、Webアプリケーションのハッキング、ワイヤレスネットワークハッキング、暗号化などのトピックについてもカバーしています。この試験は、倫理的ハッキングの理論的および実用的な側面の両方で、専門家の知識とスキルをテストするように設計されています。
312-50v10問題集PDFで100%合格保証付き:https://www.passtest.jp/EC-COUNCIL/312-50v10-shiken.html