312-50v11 Exam Question 86

An organization has automated the operation of critical infrastructure from a remote location. For this purpose, all the industrial control systems are connected to the Internet. To empower the manufacturing process, ensure the reliability of industrial networks, and reduce downtime and service disruption, the organization deckled to install an OT security tool that further protects against security incidents such as cyber espionage, zero-day attacks, and malware. Which of the following tools must the organization employ to protect its critical infrastructure?
  • 312-50v11 Exam Question 87

    A company's Web development team has become aware of a certain type of security vulnerability in their Web software. To mitigate the possibility of this vulnerability being exploited, the team wants to modify the software requirements to disallow users from entering HTML as input into their Web application.
    What kind of Web application vulnerability likely exists in their software?
  • 312-50v11 Exam Question 88

    Bobby, an attacker, targeted a user and decided to hijack and intercept all their wireless communications. He installed a fake communication tower between two authentic endpoints to mislead the victim. Bobby used this virtual tower to interrupt the data transmission between the user and real tower, attempting to hijack an active session, upon receiving the users request. Bobby manipulated the traffic with the virtual tower and redirected the victim to a malicious website. What is the attack performed by Bobby in the above scenario?
  • 312-50v11 Exam Question 89

    An attacker can employ many methods to perform social engineering against unsuspecting employees, including scareware.
    What is the best example of a scareware attack?
  • 312-50v11 Exam Question 90

    A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer decides to start by using netcat to port 80.
    The engineer receives this output:
    HTTP/1.1 200 OK
    Server: Microsoft-IIS/6
    Expires: Tue, 17 Jan 2011 01:41:33 GMT
    Date: Mon, 16 Jan 2011 01:41:33 GMT
    Content-Type: text/html
    Accept-Ranges: bytes
    Last Modified: Wed, 28 Dec 2010 15:32:21 GMT
    ETag:"b0aac0542e25c31:89d"
    Content-Length: 7369
    Which of the following is an example of what the engineer performed?