312-50v12 Exam Question 46

What is the following command used for?
sqlmap.py-u
,,http://10.10.1.20/?p=1
&forumaction=search" -dbs
  • 312-50v12 Exam Question 47

    An ethical hacker is testing the security of a website's database system against SQL Injection attacks. They discover that the IDS has a strong signature detection mechanism to detect typical SQL injection patterns.
    Which evasion technique can be most effectively used to bypass the IDS signature detection while performing a SQL Injection attack?
  • 312-50v12 Exam Question 48

    An organization has been experiencing intrusion attempts despite deploying an Intrusion Detection System (IDS) and Firewalls. As a Certified Ethical Hacker, you are asked to reinforce the intrusion detection process and recommend a better rule-based approach. The IDS uses Snort rules and the new recommended tool should be able to complement it. You suggest using YARA rules with an additional tool for rule generation. Which of the following tools would be the best choice for this purpose and why?
  • 312-50v12 Exam Question 49

    Thomas, a cloud security professional, is performing security assessment on cloud services to identify any loopholes. He detects a vulnerability in a bare-metal cloud server that can enable hackers to implant malicious backdoors in its firmware. He also identified that an installed backdoor can persist even if the server is reallocated to new clients or businesses that use it as an laaS.
    What is the type of cloud attack that can be performed by exploiting the vulnerability discussed in the above scenario?
  • 312-50v12 Exam Question 50

    Which of the following tools can be used for passive OS fingerprinting?