312-50v13 Exam Question 66

A biotech research firm in Boston, Massachusetts, migrates its laboratory management platform to the cloud.
The vendor provides an environment where developers can deploy and test custom applications without managing the underlying servers, operating systems, or storage. The firm controls the application logic but not the runtime infrastructure.
Which cloud service model is the company using?
  • 312-50v13 Exam Question 67

    Javier Ruiz from CyberFortress Solutions is tasked with auditing the mobile security practices of Apex Financial Services, a financial firm in Houston, Texas. During a covert penetration test, Javier targets employees' personal smartphones used to access corporate financial systems. He exploits a vulnerability by installing a malicious app that bypasses access controls, granting him unauthorized entry to sensitive financial data because the devices lack a specific security measure to restrict app access. Based on this vulnerability, which BYOD security guideline is most likely missing in Apex Financial Services' policy?
  • 312-50v13 Exam Question 68

    An attacker exploits legacy protocols to perform advanced sniffing. Which technique is the most difficult to detect and neutralize?
  • 312-50v13 Exam Question 69

    In Denver, Colorado, ethical hacker Sophia Nguyen is hired by Rocky Mountain Insurance to assess the effectiveness of their network security controls. During her penetration test, she attempts to evade the company's firewall by fragmenting malicious packets to avoid detection. The IT team, aware of such techniques, has implemented a security measure to analyze packet contents beyond standard headers. Sophia's efforts are thwarted as the system identifies and blocks her fragmented packets.
    Which security measure is the IT team most likely using to counter Sophia's firewall evasion attempt?
  • 312-50v13 Exam Question 70

    During a red team exercise at Apex Logistics in Denver, ethical hacker Rachel launches controlled packet injection attacks to simulate session hijacking attempts. The client ' s IT team wants a way to automatically detect such abnormal behaviors across the network in real time, instead of relying on manual analysis. They decide to deploy a monitoring system capable of flagging suspicious session activity based on predefined rules and traffic signatures.
    Which detection method best fits the IT team ' s requirement?