ETHICAL HACKING EXM WITH 100%
CORRECT NWER 2024 COMPLETE
DETAILED CASE STUDY
f What two scripts in the WEPCrack toolset are used to imitate IVs and encrypted output seen from an
access point, and then to crack the WEP key used by the access point? - Correct answer.WeakIVGen.pl
WEPCrack.pl
A client was recently compromised even though their IDS detected an attack. The compromise occurred
because there was no one actively monitoring the IDS. What can be done to ensure that the IDS grabs
the attention of a system administrator when attacks occur? - Correct answer.A sound file can be played
when an attack is detected, to generate an audible alarm that the administrator must respond to
The IDS can send an SNMP trap to the e-mail address of the administrator, or to a management system
What part of a cell phone jammer transmits the radio signals used to block cell traffic? - Correct
answer.voltage-controlled oscillator
What does the "++" line in a user's .rhosts file do? - Correct answer.It allows anyone to log into the
system using that user's ID without a password
A client has approached you with what they believe is a compromised Mac OS X machine. Upon
investigating the machine's filesystem, you uncover several odd files in the /tmp directory. Specifically,
you find /tmp/latestpics.tar.gz and /tmp/pic. What infection does the OS X computer have? - Correct
answer.OSX/Leap-A worm
Public-key cryptography is an example of what type of encryption? - Correct answer.asymmetric
encryption
You are attempting to penetrate a client's network by gaining physical access to their server room. Upon
finding the room, you discover a door that doesn't appear to have a corresponding strike plate on the
door knob side, and it doesn't appear to be using a tumbler lock, despite having a keyed entry. Through
the thick security glass next to the door, a visible rack system with a glass panel shows a reflection of the
,other side of the door. The top of the door appears to have an electric junction box just above the frame
portion of the door. What type of lock is most likely being used? - Correct answer.An electromagnetic
lock that requires a key to interrupt current to the magnet at the top of the door
What statement accurately describes the Blowfish secret-key cryptographic method? - Correct answer.It
uses a variable key length of 32 to 448 bits and utilizes a block cipher that organizes data into chunks of
64-bits before encrypting them
A client has asked that you evaluate the security mechanisms utilized on their wireless network. A
network administrator has informed you that the wireless networks utilize shared key authentication.
What can you determine from this statement? - Correct answer.The network is utilizing WEP encryption
What type of attack against RSA depends upon the weakness in implementations of the RSA protocol? -
Correct answer.esoteric RSA attack
You are utilizing a Mac OS X computer and you need to utilize industry-standard encryption to protect
confidential client data. What utility can you use for this purpose? - Correct answer.FileGuard
What statement accurately describes the iNdependence jailbreaking tool? - Correct answer.It provides
an interface for jailbreaking, SIM unlocking, SSH installation, and app insallation on an iPhone
You are attempting to access a secured file on a client's Linux system as part of an audit. Currently, the
permissions on the file are set to "-rwx-rw-r--", and you are not the file owner, nor are you in the group
that has been assigned to the file. What permissions do you have? - Correct answer.read
Where can the keys to access BlackBerry devices remotely be found? - Correct answer.The keys can be
found in the user's secure mailbox
A client was recently contacted by their ISP after the ISP detected their cable modem was operating at
uncapped speeds. The client has given you full access to their network to determine how the
compromise of their modem occurred. What software tool may have been used due to the fact that all
the uncapping steps are integrated into a single program? - Correct answer.OneStep: ZUP
, What tool can be used by a Linux administrator to monitor for port scan attempts? - Correct
answer.Klaxon
You are auditing a client's network and have gained physical access to a workstation. To prevent any
security software from detecting your intrustion, you would like to use a LiveCD that can crack Windows
passwords. What should you use? - Correct answer.OrphCrack LiveCD
Your client has asked you to secure the NNTP protocol services on a Linux server. What could you use to
encrypt these connections even though NNTP is not SSL aware? - Correct answer.Stunnel
After recovering a WEP key from a wireless network, your workstation still fails to connect to the
network. Other stations are seen in Kismet, so the network is clearly working. What could be the issue? -
Correct answer.The wireless network has implemented MAC filtering
You work for a consulting company based in Asia. Recently, an employee's phone has been behaving
strangely. The phone appears to send out SMS messages to all the employee's contacts at odd hours,
even when the employee has no access to the phone. The phone has not had any new applications
installed. What could be the cause of the strange behavior? - Correct answer.DeathRing
What three types of RFID tags are available for use? - Correct answer.Passive tags, which operate using
power from a reader
Semi-passive tags, which have their own internal power but communicate using power from a reader
Active tags, which have a transmitter and their own source of power
What are valid steps to securing a laptop with confidential data on it? - Correct answer.The laptop
should use a BIOS password that is required when it is turned on
The laptop should utilize encryption for sensitive data
What HTTP request string could be used to execute the "show config" command on a vulnerable Cisco
router? - Correct answer./level/<$NUMBER>/exec/show/config/cr
What are some countermeasures that can be taken to help prevent USB attacks and theft of USB data? -
Correct answer.USB devices should automatically be scanned for viruses as soon as they are connected
to a PC
CORRECT NWER 2024 COMPLETE
DETAILED CASE STUDY
f What two scripts in the WEPCrack toolset are used to imitate IVs and encrypted output seen from an
access point, and then to crack the WEP key used by the access point? - Correct answer.WeakIVGen.pl
WEPCrack.pl
A client was recently compromised even though their IDS detected an attack. The compromise occurred
because there was no one actively monitoring the IDS. What can be done to ensure that the IDS grabs
the attention of a system administrator when attacks occur? - Correct answer.A sound file can be played
when an attack is detected, to generate an audible alarm that the administrator must respond to
The IDS can send an SNMP trap to the e-mail address of the administrator, or to a management system
What part of a cell phone jammer transmits the radio signals used to block cell traffic? - Correct
answer.voltage-controlled oscillator
What does the "++" line in a user's .rhosts file do? - Correct answer.It allows anyone to log into the
system using that user's ID without a password
A client has approached you with what they believe is a compromised Mac OS X machine. Upon
investigating the machine's filesystem, you uncover several odd files in the /tmp directory. Specifically,
you find /tmp/latestpics.tar.gz and /tmp/pic. What infection does the OS X computer have? - Correct
answer.OSX/Leap-A worm
Public-key cryptography is an example of what type of encryption? - Correct answer.asymmetric
encryption
You are attempting to penetrate a client's network by gaining physical access to their server room. Upon
finding the room, you discover a door that doesn't appear to have a corresponding strike plate on the
door knob side, and it doesn't appear to be using a tumbler lock, despite having a keyed entry. Through
the thick security glass next to the door, a visible rack system with a glass panel shows a reflection of the
,other side of the door. The top of the door appears to have an electric junction box just above the frame
portion of the door. What type of lock is most likely being used? - Correct answer.An electromagnetic
lock that requires a key to interrupt current to the magnet at the top of the door
What statement accurately describes the Blowfish secret-key cryptographic method? - Correct answer.It
uses a variable key length of 32 to 448 bits and utilizes a block cipher that organizes data into chunks of
64-bits before encrypting them
A client has asked that you evaluate the security mechanisms utilized on their wireless network. A
network administrator has informed you that the wireless networks utilize shared key authentication.
What can you determine from this statement? - Correct answer.The network is utilizing WEP encryption
What type of attack against RSA depends upon the weakness in implementations of the RSA protocol? -
Correct answer.esoteric RSA attack
You are utilizing a Mac OS X computer and you need to utilize industry-standard encryption to protect
confidential client data. What utility can you use for this purpose? - Correct answer.FileGuard
What statement accurately describes the iNdependence jailbreaking tool? - Correct answer.It provides
an interface for jailbreaking, SIM unlocking, SSH installation, and app insallation on an iPhone
You are attempting to access a secured file on a client's Linux system as part of an audit. Currently, the
permissions on the file are set to "-rwx-rw-r--", and you are not the file owner, nor are you in the group
that has been assigned to the file. What permissions do you have? - Correct answer.read
Where can the keys to access BlackBerry devices remotely be found? - Correct answer.The keys can be
found in the user's secure mailbox
A client was recently contacted by their ISP after the ISP detected their cable modem was operating at
uncapped speeds. The client has given you full access to their network to determine how the
compromise of their modem occurred. What software tool may have been used due to the fact that all
the uncapping steps are integrated into a single program? - Correct answer.OneStep: ZUP
, What tool can be used by a Linux administrator to monitor for port scan attempts? - Correct
answer.Klaxon
You are auditing a client's network and have gained physical access to a workstation. To prevent any
security software from detecting your intrustion, you would like to use a LiveCD that can crack Windows
passwords. What should you use? - Correct answer.OrphCrack LiveCD
Your client has asked you to secure the NNTP protocol services on a Linux server. What could you use to
encrypt these connections even though NNTP is not SSL aware? - Correct answer.Stunnel
After recovering a WEP key from a wireless network, your workstation still fails to connect to the
network. Other stations are seen in Kismet, so the network is clearly working. What could be the issue? -
Correct answer.The wireless network has implemented MAC filtering
You work for a consulting company based in Asia. Recently, an employee's phone has been behaving
strangely. The phone appears to send out SMS messages to all the employee's contacts at odd hours,
even when the employee has no access to the phone. The phone has not had any new applications
installed. What could be the cause of the strange behavior? - Correct answer.DeathRing
What three types of RFID tags are available for use? - Correct answer.Passive tags, which operate using
power from a reader
Semi-passive tags, which have their own internal power but communicate using power from a reader
Active tags, which have a transmitter and their own source of power
What are valid steps to securing a laptop with confidential data on it? - Correct answer.The laptop
should use a BIOS password that is required when it is turned on
The laptop should utilize encryption for sensitive data
What HTTP request string could be used to execute the "show config" command on a vulnerable Cisco
router? - Correct answer./level/<$NUMBER>/exec/show/config/cr
What are some countermeasures that can be taken to help prevent USB attacks and theft of USB data? -
Correct answer.USB devices should automatically be scanned for viruses as soon as they are connected
to a PC