312-50v13 Exam Question 81

In the context of Windows Security, what is a 'null' user?
  • 312-50v13 Exam Question 82

    When you are testing a web application, it is very useful to employ a proxy tool to save every request and response. You can manually test every request and analyze the response to find vulnerabilities. You can test parameters and headers manually to get more precise results than if using web vulnerability scanners.
    What proxy tool will help you find web vulnerabilities?
  • 312-50v13 Exam Question 83

    A penetration tester discovers that a system is infected with malware that encrypts all files and demands payment for decryption. What type of malware is this?
  • 312-50v13 Exam Question 84

    A penetration tester is conducting an assessment of a web application for a financial institution. The application uses form-based authentication and does not implement account lockout policies after multiple failed login attempts. Interestingly, the application displays detailed error messages that disclose whether the username or password entered is incorrect. The tester also notices that the application uses HTTP headers to prevent clickjacking attacks but does not implement Content Security Policy (CSP). With these observations, which of the following attack methods would likely be the most effective for the penetration tester to exploit these vulnerabilities and attempt unauthorized access?
  • 312-50v13 Exam Question 85

    A penetration tester evaluates an industrial control system (ICS) that manages critical infrastructure. The tester discovers that the system uses weak default passwords for remote access. What is the most effective method to exploit this vulnerability?