EC-COUNCIL 312-50V13 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/312-50v13.html
Hackers often raise the trust level of a phishing message by modeling the email to look similar to the internal email used by the target company. This includes using logos, formatting, and names of the target company. The phishing message will often use the name of the company CEO, President, or Managers.
The time a hacker spends performing research to locate this information about a company is known as?
A penetration tester performs a vulnerability scan on a company's network and identifies a critical vulnerability related to an outdated version of a database server.
What should the tester prioritize as the next step?
To hide the file on a Linux system, you have to start the filename with a specific character.
What is the character?
During an internal assessment, a penetration tester gains access to a hash dump containing NTLM password hashes from a compromised Windows system. To crack the passwords efficiently, the tester uses a high-performance CPU setup with Hashcat, attempting millions of password combinations per second.
Which technique is being optimized in this scenario?
_________ is a tool that can hide processes from the process list, can hide files, registry entries, and intercept keystrokes.
During a black-box security assessment of a large enterprise network, the penetration tester scans the internal environment and identifies that TCP port 389 is open on a domain controller. Upon further investigation, the tester runs the ldapsearch utility without providing any authentication credentials and successfully retrieves a list of usernames, email addresses, and departmental affiliations from the LDAP directory. The tester notes that this sensitive information was disclosed without triggering any access control mechanisms or requiring login credentials.
Based on this behavior, what type of LDAP access mechanism is most likely being exploited?
As a securing consultant, what are some of the things you would recommend to a company to ensure DNS security?
An attacker scans a host with the below command. Which three flags are set?
# nmap -sX host.domain.com
Fingerprinting an Operating System helps a cracker because:
What is the main difference between ethical hacking and malicious hacking?