SANS SEC504 - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/sec504.html
The Klez worm is a mass-mailing worm that exploits a vulnerability to open an executable attachment even in Microsoft Outlook's preview pane. The Klez worm gathers email addresses from the entries of the
default Windows Address Book (WAB).
Which of the following registry values can be used to identify this worm?
You see the career section of a company's Web site and analyze the job profile requirements. You conclude that the company wants professionals who have a sharp knowledge of Windows server 2003 and Windows active directory installation and placement.
Which of the following steps are you using to perform hacking?
Which of the following are types of access control attacks? Each correct answer represents a complete solution. Choose all that apply.
Which of the following tools combines two programs, and also encrypts the resulting package in an attempt to foil antivirus programs?
Which of the following is a computer worm that caused a denial of service on some Internet hosts and dramatically slowed down general Internet traffic?
John works as a Professional Penetration Tester. He has been assigned a project to test the Website security of www.we-are-secure Inc. On the We-are-secure Website login page, he enters ='or''=' as a username and successfully logs on to the user page of the Web site. Now, John asks the we-aresecure
Inc. to improve the login page PHP script.
Which of the following suggestions can John give to improve the security of the we-are-secure Website login page from the SQL injection attack?
Which of the following statements about Denial-of-Service (DoS) attack are true? Each correct answer represents a complete solution. Choose three.
Which of the following statements about buffer overflow is true?
Which of the following is a technique of using a modem to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for computers, Bulletin board systems, and fax machines?
Which of the following refers to the exploitation of a valid computer session to gain unauthorized access to information or services in a computer system?