NO.1 Perspective clients wantto see sample reports from previous penetration tests. What should
you do next?
A. Share reports, after NDA is signed.
B. Share full reports, not redacted.
C. Share full reports, with redacted.
D. Decline but, provide references.
Answer: C

NO.2 Session splicing is an IDS evasiontechnique in which an attacker delivers data in multiple,
smallsized packets to the target computer, making it very difficult for an IDS to detect the attack
Which tool can used to perform session splicing attacks?
A. Hydra
B. Tcpsplice
C. Burp
D. Whisker
Answer: D


NO.3 In 2007, this wireless security algorithm was rendered useless by capturing packets and
discovering the passkey in a matter of seconds. This security flaw led to a network invasion of TJ
Maxx and data theft through a technique known wardriving.
Which algorithm is this referring to?
A. Wired Equivalent Privacy (WEP)
B. Wi-Fi Protected Access (WPA)
C. Wi-Fi Protected Access 2(WPA2)
D. Temporal Key Integrity Protocol (TRIP)
Answer: A


NO.4 This tool is an 802.11 WEP and WPA-PSK keys cracking program that can recover keys once
enough data packets have been captured. It implements the standard FMS attach along with some
optimizations like Korek attacks, as well as the PTW attack, thus making the attack much faster
compared to other WEP cracking tools.
Which of the following tools is being described?
A. Aircrack-ng
B. Airguard
C. Wificracker
D. WLAN-crack
Answer: A


投稿日: 2016/4/23 21:59:47  |  カテゴリー: EC-COUNCIL  |  タグ: 312-50v9資格試験EC-COUNCIL