312-50v13 Exam Question 156
You must map open ports and services while remaining stealthy and avoiding IDS detection. Which scanning technique is best?
312-50v13 Exam Question 157
A tester evaluates a login form that builds SQL queries using unsanitized input. By submitting a single quote ('), the tester bypasses authentication and logs in. What type of SQL injection occurred?
312-50v13 Exam Question 158
Which WPA vulnerability allowed packet injection and decryption attacks?
312-50v13 Exam Question 159
A penetration tester evaluates a secure web application using HTTPS, secure cookies, and multi-factor authentication. To hijack a legitimate user's session without triggering alerts, which technique should be used?
312-50v13 Exam Question 160
A penetration tester intercepts HTTP requests between a user and a vulnerable web server. The tester observes that the session ID is embedded in the URL, and the web application does not regenerate the session upon login. Which session hijacking technique is most likely to succeed in this scenario?
