100% tevredenheidsgarantie Direct beschikbaar na je betaling Lees online óf als PDF Geen vaste maandelijkse kosten
logo-home
CEH v10 Exam Questions with Correct Answers €12,83
In winkelwagen

Tentamen (uitwerkingen)

CEH v10 Exam Questions with Correct Answers

 0 keer verkocht
  • Vak
  • CEH v10
  • Instelling
  • CEH V10

CEH v10 Exam Questions with Correct Answers What is the minimum number of network connections in a multi homed firewall? A. 3 B. 5 C. 4 D. 2 - Answer-A. 3 Sam is working as s pen-tester in an organization in Houston. He performs penetration testing on IDS in order to find the different wa...

[Meer zien]

Voorbeeld 2 van de 9  pagina's

  • 12 augustus 2024
  • 9
  • 2024/2025
  • Tentamen (uitwerkingen)
  • Vragen en antwoorden
  • CEH v10
  • CEH v10
avatar-seller
CEH v10 Exam Questions with Correct
Answers

What is the minimum number of network connections in a multi homed firewall?
A. 3
B. 5
C. 4
D. 2 - Answer-A. 3

Sam is working as s pen-tester in an organization in Houston. He performs penetration
testing on IDS in order to find the different ways an attacker uses to evade
the IDS. Sam sends a large amount of packets to the target IDS that generates alerts,
which enable Sam to hide the real traffic. What type of method is Sam using
to evade IDS?

A. Denial-of-Service
B. False Positive Generation
C. Insertion Attack
D. Obfuscating - Answer-B. False Positive Generation

Nedved is an IT Security Manager of a bank in his country. One day. he found out that
there is a security breach to his company's email server based on analysis
of a suspicious connection from the email server to an unknown IP Address.
What is the first thing that Nedved needs to do before contacting the incident response
team?

A. Leave it as it Is and contact the incident response te3m right away
B. Block the connection to the suspicious IP Address from the firewall
C. Disconnect the email server from the network
D. Migrate the connection to the backup email server - Answer-C. Disconnect the email
server from the network

What type of analysis is performed when an attacker has partial knowledge of inner-
workings of the application?

A. Black-box
B. Announced
C. White-box
D. Grey-box - Answer-D. Grey-box

What is the least important information when you analyze a public IP address in a
security alert?

, A. ARP
B. Whois
C. DNS
D. Geolocation - Answer-A. ARP

A hacker is an intelligent individual with excellent computer skills and the ability to
explore a computer's software and hardware without the owner's permission.
Their intention can either be to simply gain knowledge or to illegally make changes.
Which of the following class of hacker refers to an individual who works both
offensively and defensively at various times?

A. Suicide Hacker
B. Black Hat
C. White Hat
D. Gray Hat - Answer-D. Gray Hat

Insecure direct object reference is a type of vulnerability where the application does not
verify if the user is authorized to access the internal object via its name or
key.
Suppose a malicious user Rob tries to get access to the account of a benign user Ned.
Which of the following requests best illustrates an attempt to exploit an insecure direct
object reference vulnerability?

A. "GET/restricted/goldtransfer?to=Rob&from=1 or 1=1' HTTP/1.1Host: westbank.com"
B. "GET/restricted/accounts/?name=Ned HTTP/1.1 Host: westbank.com"
C. "GET/restricted/bank.getaccount('Ned') HTTP/1.1 Host: westbank.com"
D. "GET/restricted/\r\n\%00account%00Ned%00access HTTP/1.1 Host: westbank.com"
- Answer-B. "GET/restricted/accounts/?name=Ned HTTP/1.1 Host: westbank.com"

What network security concept requires multiple layers of security controls to be placed
throughout an IT infrastructure, which improves the security posture of an
organization to defend against malicious attacks or potential vulnerabilities?
What kind of Web application vulnerability likely exists in their software?

A. Host-Based Intrusion Detection System
B. Security through obscurity
C. Defense in depth
D. Network-Based Intrusion Detection System - Answer-C. Defense in depth

Firewalls are the software or hardware systems that are able to control and monitor the
traffic coming in and out the target network based on pre-defined set of rules.
Which of the following types of firewalls can protect against SQL injection attacks?

A. Data-driven firewall
B. Stateful firewall

Dit zijn jouw voordelen als je samenvattingen koopt bij Stuvia:

Bewezen kwaliteit door reviews

Bewezen kwaliteit door reviews

Studenten hebben al meer dan 850.000 samenvattingen beoordeeld. Zo weet jij zeker dat je de beste keuze maakt!

In een paar klikken geregeld

In een paar klikken geregeld

Geen gedoe — betaal gewoon eenmalig met iDeal, creditcard of je Stuvia-tegoed en je bent klaar. Geen abonnement nodig.

Direct to-the-point

Direct to-the-point

Studenten maken samenvattingen voor studenten. Dat betekent: actuele inhoud waar jij écht wat aan hebt. Geen overbodige details!

Veelgestelde vragen

Wat krijg ik als ik dit document koop?

Je krijgt een PDF, die direct beschikbaar is na je aankoop. Het gekochte document is altijd, overal en oneindig toegankelijk via je profiel.

Tevredenheidsgarantie: hoe werkt dat?

Onze tevredenheidsgarantie zorgt ervoor dat je altijd een studiedocument vindt dat goed bij je past. Je vult een formulier in en onze klantenservice regelt de rest.

Van wie koop ik deze samenvatting?

Stuvia is een marktplaats, je koop dit document dus niet van ons, maar van verkoper Scholarsstudyguide. Stuvia faciliteert de betaling aan de verkoper.

Zit ik meteen vast aan een abonnement?

Nee, je koopt alleen deze samenvatting voor €12,83. Je zit daarna nergens aan vast.

Is Stuvia te vertrouwen?

4,6 sterren op Google & Trustpilot (+1000 reviews)

Afgelopen 30 dagen zijn er 69484 samenvattingen verkocht

Opgericht in 2010, al 15 jaar dé plek om samenvattingen te kopen

Begin nu gratis

Laatst bekeken door jou


€12,83
  • (0)
In winkelwagen
Toegevoegd