Fixed Single Master Operations Flexible Security Master Operations Flexible Single Master Operations Forest Single Master Operations Forest Security Master Operations Flexible Single Master Operations
The active direc
...
Fixed Single Master Operations Flexible Security Master Operations Flexible Single Master Operations Forest Single Master Operations Forest Security Master Operations Flexible Single Master Operations
The active directory database file is: - ANSWER NTDS.DAT NTDS.MDB MSAD.DIT NTDS.DIT MDAD.MDB NTDS.DIT
What command might you use to obtain a list of systems from a master browser, together with details about the version and available services. - ANSWER amap nbtstat lservers nbtquery hping3 lservers
What is used for authentication in a Microsoft Active Directory domain? - ANSWER RADIUS TACACS + TACACS + + Kerberos NIDS Kerberos
Which of the following Windows programs will list all the members of the Master Browser List? - ANSWER whoami dompromo lservers nbtstat None of the above nbtstat
"What does the following command achieve? - ANSWER
Telnet
- ANSWER
HEAD /HTTP/1.0 - ANSWER
- ANSWER
" - ANSWER This command returns the home page for the IP address specified This command opens a backdoor Telnet session to the IP address specified This command returns the banner of the website specified by the IP address This command allows a hacker to determine if the server has a SQL database None of these This command returns the banner of the website specified by the IP address
A system encrypts data prior to transmitting it over a network, and the system on the other end of the transmission media decrypts it. If the systems are using a symmetric encryption algorithm for encryption and decryption, which of the following statements is true? - ANSWER A symmetric encryption algorithm uses the same key to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm uses different keys to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm does not use keys to encrypt and decrypt data at both ends of the transmission media A symmetric encryption algorithm is an insecure method used to encrypt data transmitted over transmission media None of these A symmetric encryption algorithm uses the same key to encrypt and decrypt data at both ends of the transmission media
How many bits does SYSKEY use for encryption? - ANSWER 48 bits 56 bits 128 bits 256 bits None of these 128 bits
How many secret bits in a 128-bit WEP key? - ANSWER 128 64 104 40 96 104
In an IPSEC VPN there are four main attribute classes. Which of the following is NOT one of those classes? - ANSWER Encryption Algorithm Hash Algorithm Authentication Method Aggressive Mode Diffie-Hellman group Aggressive Mode
Of the following choices, what can you use to encrypt e-mail? - ANSWER HMAC RIPEMD PII S/ MIME None of these S/ MIME
Of the following choices, what is a benefit of IPsec? - ANSWER MAC filtering Flood guard Load balancing Payload encryption Secures your IP Payload encryption
Sally encrypted a project file with her public key. Later, an administrator accidentally deleted her account that had exclusive access to her private key. Can this project file be retrieved? - ANSWER No. If the private key is lost, the data cannot be retrieved Yes. The public key can decrypt the file Yes, if a copy of her public key is stored in escrow Yes, if the organization uses a recovery agent Yes, if she uses her password Yes, if the organization uses a recovery agent
What are the four mandatory transform attributes for an IKE Phase-1 SA? - ANSWER Encryption Algorithm, Hash Algorithm, Authentication Method, Diffie Hellman Group Encryption Algorithm, Key Length, Authentication Method, SA Lifetime SA Lifetime, Key length, PRF, Field Size SA Lifetime, Hash Algorithm, Authentication Method, PRF Protocol ID, Transform ID, IPsec Mode, Authentication Algorithm Encryption Algorithm, Hash Algorithm, Authentication Method, Diffie Hellman Group
What do programs, such as Tripwire, MD5sum, and Windows System File Protection, all rely on? - ANSWER Digital certificates Hashing Digital signatures Steganography Encryption Hashing
What does "export" signify for an SSL cipher - ANSWER It is a weak cipher that was acceptable for export under the old US cryptography export regulations It is the strongest cipher that is currently permitted to be exported from the US It is a cipher with integrated key escrow, which allows the NSA to recover the key It is a cipher that is suitable for encrypting information to be sent across national borders It is a stronger version of a cipher, similar to export versions of European lagers It is a weak cipher that was acceptable for export under the old US cryptography export regulations
What is IKE? - ANSWER Internet Key Exchange Initial Key Exchange IBM Key Exchange Internal Key Exchange Integrated Key Exchange Internet Key Exchange
What is SSL used for? - ANSWER Encrypt data as it travels over a network Encrypt files located on a Web server Encrypt passwords for storage in a database Encrypt specific elements of data for application-specific purposes Encrypt digital certificates used to authenticate a Web site Encrypt data as it travels over a network
What is the length of the IV for a WEP key? - ANSWER 128 bits 64 bits 40 bits 24 bits 56 bits 24 bits
Which of the following algorithms could be used to negotiate a shared encryption key? - ANSWER Triple-DES SHA1 DES AES Diffie-Hellman Diffie-Hellman
Which of the following is the correct definition of WEP? - ANSWER Wireless Encrypted Password Wired Equivalent Privacy Wireless Enabled Password Wireless Extended Privacy Wired Equivalent Password Wired Equivalent Privacy
Which of the following key sizes is considered the minimum recommended for a new SSL certificate? - ANSWER 768 bits 1024 bits 2048 bits 3072 bits 256 bits 2048 bits
Which of the following protocols was developed to be used for key exchange? - ANSWER Diffie-Hellman MD5 Rijndael Base64 None of these Diffie-Hellman
Which of the following services does not encrypt its traffic? - ANSWER DNS All of these SSH FTPS TLS DNS
Which of the following statements accurately describes the relationship between keys in a PKI? - ANSWER Data encrypted with a public key can only be decrypted with the matching private key Data encrypted with a public key can only be decrypted with the matching public key Data encrypted with a private key can only be decrypted with the matching private key The public key always encrypts and the private key always decrypts None of these Data encrypted with a public key can only be decrypted with the matching private key
Which of the following uses the same key to encode and decode data? - ANSWER RSA El Gamel ECC RC5 None of these RC5
Which ports do you have to open on a firewall to allow IKE VPN to function correctly? - ANSWER All VPN associated Ports All ports UDP 500, Protocol 50 & 51 135 and 445 TCP ICMP UDP 500, Protocol 50 & 51
Which protocols are associated with IPsec? - ANSWER IP protocol 89 UDP port 500, IP protocol 50 and IP protocol 51. TCP port 1723 and IP protocol 47 IP protocol 94 TCP port 443 UDP port 500, IP protocol 50 and IP protocol 51.
Why can remote access VPNs not use Main Mode for IKE Phase-1 if the authentication method is pre-shared key? - ANSWER Because remote access servers always use aggressive mode for IKE Phase-1 Because XAUTH is not compatible with IKE Main Mode Because IKE Main Mode does not support the pre-shared key authentication method Because pre-shared key authentication with Main Mode requires that the peer's IP is known before the connection is established Because remote access clients always use aggressive mode for IKE Phase-1 Because pre-shared key authentication with Main Mode requires that the peer's IP is known before the connection is established
Which of the following is an example of multifactor authentication? - ANSWER Smart card and PIN Thumbprint and voice recognition Thumbprint and voice recognition Password and PIN Password and Breathalyser Smart card and PIN
Which of the following is the best example of a strong two factor authentication? - ANSWER A passcard and a token A token and a pin number A username and a password A hand scan and fingerprint scan None of these A token and a pin number
Which of the following vulnerabilities can be associated with Password Autocomplete being enabled on a web page visible from the Internet? - ANSWER Anyone on the Internet can login without authentication credentials Anyone on the Internet that knows a valid username for the web page would not need to know the password A SQL injection vulnerability would allow passwords to be extracted from the back-end database A file disclosure vulnerability would allow an attacker to read the list of Autocompleted passwords on the website A vulnerability on a client workstation could be leveraged to discover and take advantage of cached passwords A vulnerability on a client workstation could be leveraged to discover and take advantage of cached passwords
Question - ANSWER Option 1 Option 2 Option 3 Option 4 Option 5 Correct Answer 1
What does NAC refer to in respect to Cisco? - ANSWER Network Access Control Network Authentication Command Network Administration Control Network Adapter Card Network Admission Control Network Admission Control
What is the significance of the string "SEP" in the configuration filename of a Cisco IP phone? - ANSWER It stands for Skinny Enchanced Phone It stands for Cisco Ethernet Phone, but someone misspelled it and the name stuck It stands for SIP Enhanced Phone No one knows It stands for Selsius Ethernet Phone, which was the original name of the Cisco IP phone It stands for Selsius Ethernet Phone, which was the original name of the Cisco IP phone
"What would be the effect of writing the string x to the following OID on a Cisco router running IOS 11? - ANSWER
.1.3.6.1.4.1.9.2.1.53.172.25.1.1" - ANSWER The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine The router whose IP address is 172.25.1.1 would have its system name changed to x The configuration file of the router would be downloaded to file x in the FTP root of the FTP server at 172.25.1.1 It would force the running config to be reloaded on the router whose IP address is 172.25.1.1 The configuration file x in the TFTP root of the TFTP server at 172.25.1.1 would be uploaded to the router The configuration file x in the TFTP root of the TFTP server at 172.25.1.1 would be uploaded to the router
"What would be the effect of writing the string x to the following OID on a Cisco router running IOS 11? - ANSWER
.1.3.6.1.4.1.9.2.1.55.172.25.1.1" - ANSWER The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine The router whose IP address is 172.25.1.1 would have its system name changed to x The configuration file of the router would be downloaded to file x in the FTP root of the FTP server at 172.25.1.1 It would force the running config to be reloaded on the router whose IP address is 172.25.1.1 The running config of the router would be downloaded to TFTP server at 172.25.1.1 and stored with a filename of x The configuration file of the router whose IP address is 172.25.1.1 would be downloaded to the local machine
When downloading a Cisco router's config file, which of the following OIDs would be used to set the SourceFileType? - ANSWER 1.3.6.1.4.1.9.9.96.1.1.1.1.3.111 1.3.6.1.2.1.25.2.2.0 1.3.6.1.4.1.9.9.96.1.1.1.1.14.111 1.3.6.1.4.1.9.2.10.6.0 1.3.6.1.4.1.9.9.96.1.1.1.1.6.111 1.3.6.1.4.1.9.9.96.1.1.1.1.3.111
Which VLAN tag would a Cisco switch by default, use to tag your packets? - ANSWER VLAN0 VLAN1 VLAN99 VLAN100 nothing VLAN1
Which statement regarding a pentest report is true? - ANSWER Only the executive summary will be read by the IT/Information Security department. Senior management won't even bother with reading the report. Only the technical details will be read by the senior management. The IT/Information Security department won't even bother with reading the report. The technical details will be read by the IT/Information security people responsible. The technical details will be read by the IT/Information security people responsible.
What is Egress filtering (in terms of a network)? - ANSWER The practice of monitoring or potentially blocking incoming traffic from IP addresses that are not permitted to access the network. The practice of monitoring or potentially blocking outgoing traffic to IP addresses that are not permitted to be accessed. The practice of preventing employees from removing sensitive data via USB. The practice of preventing employees from installing viruses/malware via USB. Using air-gapped devices which have no interconnectivity. The practice of monitoring or potentially blocking outgoing traffic to IP addresses that are not permitted to be accessed.
Which Nmap command can allow you to perform an "Idle Zombie Scan" and what is the effect? - ANSWER Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses. Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of yours and the zombie addresses. Command: "nmap -f [target ip]. This gives you control of the target machine and adds it to your 1337 botnet. Command: "nmap -D [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of yours and the zombie addresses. Command: "nmap -D [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses. Command: "nmap -sl [zombie ip][target ip]". This results in the firewall logs recording the IP addresses of only the zombie addresses.
Which statement is true regarding IPSec filters when compared to TCP/IP filters? - ANSWER IPSec filters can be applied to individual interfaces. IPSec filters can block subtypes of ICMP (eg. Echo, timestamp, echo reply etc.) They are both the same thing. IPSec filter cannot block ICMP at all. IPSec cannot be used to filter, only to tunnel sensitive traffic over encrypted channels. IPSec filters can be applied to individual interfaces.
Which statement regarding Authorisation and Authentication is true? - ANSWER Authorisation is the process where requests to access a particular resource is granted or denied. Authentication is providing and validating identity. Authentication is the process where requests to access a particular resource is granted or denied. Authorisation is providing and validating identity. Authentication includes the execution rules that determines what functionality and data the user can access. Authentication and Authorisation are both the same thing. Neither Authentication nor Authorisation are important. Authorisation is the process where requests to access a particular resource is granted or denied. Authentication is providing and validating identity.
What is a valid example of Code Injection? - ANSWER SQL injection. HTML script injection. Remote file injection. Shell injection. All of the above. All of the above.
An accepted limitation of Diffie-Hellman key agreement protocol is - ANSWER It is vital to keep the shared prime secret It can only generate encryption keys up to 128 bits It is vulnerable to a man-in-the-middle attack An attacker who can monitor the exchange can determine the shared se It is possible for one of the peers to control the generated secret It is vulnerable to a man-in-the-middle attack
DES has an effective key length of which of the following? - ANSWER 48 bit 56 bit 64 bit 128 bit 256 bits 56 bit
What are the valid key lengths for the AES encryption cipher? - ANSWER 128 and 256 56, 112 and 168 64, 128 and 256 128, 192 and 256 128, 160 and 256 128, 192 and 256
What encryption standard was chosen as the replacement for 3DES? - ANSWER RC5 ECC Knapsack Rijndael Blowfish Rijndael
What happens if you digitally sign and inject a footer on an e-mail message in the wrong order? - ANSWER Nothing The message won't be sent The footer will invalidate the signature The footer will be illegible The header will show that the email is still valid The footer will invalidate the signature
What hashing algorithm produces a 128-bit hash value? - ANSWER MD5 3DES SHA-1 AES SHA-256 MD5
What is a hash function? - ANSWER An encryption algorithm for sending encrypted data to a trusted recipient A decryption algorithm to decrypt data from a trusted source An algorithm to scramble the characters in a string A one way mathematical function that does not allow the original value to be calculated from the result A random number generator A one way mathematical function that does not allow the original value to be calculated from the result
What is the blocksize of the AES encryption cipher? - ANSWER 64 bits 40 bits 56 bits 256 bits 128 bits 128 bits
What is the blocksize of the DES encryption cipher? - ANSWER 128 bits 112 bits 56 bits 64 bits 40 bits 64 bits
What is the difficulty with Symmetric encryption? - ANSWER Assurance of secure receipt of the secret key used both for encrypting and decrypting Assurance of secure receipt of the secret key used only for decrypting (separate key used for encrypting) Assurance of secure sending of the encrypted message Assurance of secure receipt of the encrypted message None of these Assurance of secure receipt of the secret key used both for encrypting and decrypting
What is the digest length for the SHA1 hash function? - ANSWER 192 bits 128 bits 160 bits 56 bits 256 bits 160 bits
What is the key size for the Data Encryption Standard (DES) encryption mechanism? - ANSWER 40 56 64 112 128 64
What is the purpose of message integrity codes (HMAC) - ANSWER To simultaneously verify confidentiality of message (via message sequencing) and authenticity of message (by use of a secret key) To ensure message integrity via cryptographic hashing functions To simultaneously verify both data integrity (via cryptographic hashing function) and message authenticity (by use of a secret key) To verify message authenticity and confidentiality via the use of a SHA hashing function None of these To simultaneously verify both data integrity (via cryptographic hashing function) and message authenticity (by use of a secret key)
What is this: password 7 052D131D3
[Show More]