[Q227-Q245] ベスト良質なEC-COUNCIL 312-50v10試験問題PassTestリアル練習試験 [2025]

Share

ベスト良質なEC-COUNCIL 312-50v10試験問題PassTestリアル練習試験 [2025]

重要な試験問題でCertified Ethical Hacker Exam (CEH v10)一発合格

質問 # 227
An IT employee got a call from one our best customers. The caller wanted to know about the company's
network infrastructure, systems, and team. New opportunities of integration are in sight for both company
and customer. What should this employee do?

  • A. The employee can not provide any information: but, anyway, he/she will provide the name of the
    person in charge
  • B. Since the company's policy is all about Customer Service. he/she will provide information
  • C. The employee should not provide any information without previous management authorization
  • D. Disregarding the call, the employee should hang up

正解:C


質問 # 228
You are logged in as a local admin on a Windows 7 system and you need to launch the Computer Management Console from command line.
Which command would you use?

  • A. c:\gpedit
  • B. c:\ncpa.cp
  • C. c:\services.msc
  • D. c:\compmgmt.msc

正解:D

解説:
To start the Computer Management Console from command line just type compmgmt.msc
/computer:computername in your run box or at the command line and it should automatically open the Computer Management console.
References: http://www.waynezim.com/tag/compmgmtmsc/


質問 # 229
Look at the following output. What did the hacker accomplish?

  • A. The hacker successfully transferred the zone and enumerated the hosts.
  • B. The hacker listed DNS records on his own domain.
  • C. The hacker used whois to gather publicly available records for the domain.
  • D. The hacker used the "fierce" tool to brute force the list of available domains.

正解:A


質問 # 230
Which of the following tools is used to detect wireless LANs using the 802.11a/b/g/n WLAN standards on a linux platform?

  • A. Netstumbler
  • B. Kismet
  • C. Abel
  • D. Nessus

正解:B

解説:
Kismet is a network detector, packet sniffer, and intrusion detection system for 802.11 wireless LANs. Kismet will work with any wireless card which supports raw monitoring mode, and can sniff 802.11a, 802.11b, 802.11g, and 802.11n traffic. The program runs under Linux, FreeBSD, NetBSD, OpenBSD, and Mac OS X.
References: https://en.wikipedia.org/wiki/Kismet_(software)


質問 # 231
An attacker runs netcat tool to transfer a secret file between two hosts.

He is worried about information being sniffed on the network.
How would the attacker use netcat to encrypt the information before transmitting onto the wire?

  • A. Machine A: netcat -l -p 1234 < testfile -pw passwordMachine B: netcat <machine A IP> 1234 -pw password
  • B. Machine A: netcat -l -p -s password 1234 < testfileMachine B: netcat <machine A IP> 1234
  • C. Machine A: netcat -l -e magickey -p 1234 < testfileMachine B: netcat <machine A IP> 1234
  • D. Use cryptcat instead of netcat

正解:D


質問 # 232
Joseph was the Web site administrator for the Mason Insurance in New York, who's main Web site was located at www.masonins.com. Joseph uses his laptop computer regularly to administer the Web site. One night, Joseph received an urgent phone call from his friend, Smith. According to Smith, the main Mason Insurance web site had been vandalized! All of its normal content was removed and replaced with an attacker's message ''Hacker Message: You are dead! Freaks!" From his office, which was directly connected to Mason Insurance's internal network, Joseph surfed to the Web site using his laptop. In his browser, the Web site looked completely intact.
No changes were apparent. Joseph called a friend of his at his home to help troubleshoot the problem. The Web site appeared defaced when his friend visited using his DSL connection. So, while Smith and his friend could see the defaced page, Joseph saw the intact Mason Insurance web site. To help make sense of this problem, Joseph decided to access the Web site using hisdial-up ISP. He disconnected his laptop from the corporate internal network and used his modem to dial up the same ISP used by Smith. After his modem connected, he quickly typed www.masonins.com in his browser to reveal the following web page:

After seeing the defaced Web site, he disconnected his dial-up line, reconnected to the internal network, and used Secure Shell (SSH) to log in directly to the Web server. He ran Tripwire against the entire Web site, and determined that every system file and all the Web content on the server were intact. How did the attacker accomplish this hack?

  • A. ARP spoofing
  • B. SQL injection
  • C. DNS poisoning
  • D. Routing table injection

正解:C


質問 # 233
Which United States legislation mandates that the Chief Executive Officer (CEO) and the Chief Financial Officer (CFO) must sign statements verifying the completeness and accuracy of financial reports?

  • A. Sarbanes-Oxley Act (SOX)
  • B. Federal Information Security Management Act (FISMA)
  • C. Fair and Accurate Credit Transactions Act (FACTA)
  • D. Gramm-Leach-Bliley Act (GLBA)

正解:A


質問 # 234
A botnet can be managed through which of the following?

  • A. Linkedin and Facebook
  • B. A vulnerable FTP server
  • C. IRC
  • D. E-Mail

正解:C


質問 # 235
Which type of sniffing technique is generally referred as MiTM attack?

  • A. ARP Poisoning
  • B. Password Sniffing
  • C. Mac Flooding
  • D. DHCP Sniffing

正解:A


質問 # 236
The security administrator of ABC needs to permit Internet traffic in the host 10.0.0.2 and UDP traffic in the host 10.0.0.3. Also he needs to permit all FTP traffic to the rest of the network and deny all other traffic. After he applied his ACL configuration in the router nobody can access to the ftp and the permitted hosts cannot access to the Internet. According to the next configuration what is happening in the network?

  • A. The ACL for FTP must be before the ACL 110
  • B. The ACL 104 needs to be first because is UDP
  • C. The ACL 110 needs to be changed to port 80
  • D. The first ACL is denying all TCP traffic and the other ACLs are being ignored by the router

正解:D


質問 # 237
Vlady works in a fishing company where the majority of the employees have very little understanding of IT let alone IT Security. Several information security issues that Vlady often found includes, employees sharing password, writing his/her password on a post it note and stick it to his/her desk, leaving the computer unlocked, didn't log out from emails or other social media accounts, and etc.
After discussing with his boss, Vlady decided to make some changes to improve the security environment in his company. The first thing that Vlady wanted to do is to make the employees understand the importance of keeping confidential information, such as password, a secret and they should not share it with other persons.
Which of the following steps should be the first thing that Vlady should do to make the employees in his company understand to importance of keeping confidential information a secret?

  • A. Information security awareness training
  • B. Conducting a one to one discussion with the other employees about the importance of information security
  • C. Warning to those who write password on a post it note and put it on his/her desk
  • D. Developing a strict information security policy

正解:C


質問 # 238
A tester has been hired to do a web application security test. The tester notices that the site is dynamic and must make use of a back end database.
In order for the tester to see if SQL injection is possible, what is the first character that the tester should use to attempt breaking a valid SQL request?

  • A. Semicolon
  • B. Single quote
  • C. Double quote
  • D. Exclamation mark

正解:B


質問 # 239
What is the known plaintext attack used against DES which gives the result that encrypting plaintext with one DES key followed by encrypting it with a second DES key is no more secure than using a single key?

  • A. Traffic analysis attack
  • B. Meet-in-the-middle attack
  • C. Man-in-the-middle attack
  • D. Replay attack

正解:B

解説:
Explanation/Reference:


質問 # 240
Which of the following is an NMAP script that could help detect HTTP Methods such as GET, POST, HEAD, PUT, DELETE, TRACE?

  • A. http-git
  • B. http enum
  • C. http-headers
  • D. http-methods

正解:D


質問 # 241
Which type of access control is used on a router or firewall to limit network activity?

  • A. Mandatory
  • B. Discretionary
  • C. Rule-based
  • D. Role-based

正解:C


質問 # 242
A hacker was able to easily gain access to a website. He was able to log in via the frontend user login form of the website using default or commonly used credentials. This exploitation is an example of what Software design flaw?

  • A. Insufficient exception handling
  • B. Insufficient database hardening
  • C. Insufficient input validation
  • D. Insufficient security management

正解:B


質問 # 243
Which of the following security policies defines the use of VPN for gaining access to an internal corporate
network?

  • A. Access control policy
  • B. Network security policy
  • C. Remote access policy
  • D. Information protection policy

正解:C


質問 # 244
Which of the following is a design pattern based on distinct pieces of software providing application functionality as services to other applications?

  • A. Agile Process
  • B. Object Oriented Architecture
  • C. Service Oriented Architecture
  • D. Lean Coding

正解:C

解説:
A service-oriented architecture (SOA) is an architectural pattern in computer software design in which application components provide services to other components via a communications protocol, typically over a network.
References: https://en.wikipedia.org/wiki/Service-oriented_architecture


質問 # 245
......

312-50v10試験問題集合格保証:https://www.passtest.jp/EC-COUNCIL/312-50v10-shiken.html