312-50v13 Exam Question 196

Abnormal DNS resolution behavior is detected on an internal network. Users are redirected to altered login pages. DNS replies come from an unauthorized internal IP and are faster than legitimate responses. ARP spoofing alerts are also detected. What sniffing-based attack is most likely occurring?
  • 312-50v13 Exam Question 197

    A penetration tester is tasked with assessing the security of an Android mobile application that stores sensitive user data. The tester finds that the application does not use proper encryption to secure data at rest. What is the most effective way to exploit this vulnerability?
  • 312-50v13 Exam Question 198

    In the crisp mountain air of Denver, Colorado, ethical hacker Lila Chen investigates the security framework of MediVault, a U.S.-based healthcare platform used by regional clinics to manage patient data. During her review, Lila discovers that sensitive records are weakly protected, allowing attackers to intercept and manipulate the information in transit. She warns that such weaknesses could be exploited to commit credit- card fraud, identity theft, or similar crimes. Further analysis reveals that MediVault is vulnerable to well- documented flaws such as cookie snooping and downgrade attacks.
    Which issue is MOST clearly indicated?
  • 312-50v13 Exam Question 199

    During a red team engagement at Apex Biotech in Dallas, ethical hacker Rachel calls the company's HR desk pretending to be Mark Stevens, a senior finance manager. She pressures the HR staffer by citing his
    "upcoming presentation for the CFO" and insists he urgently needs a copy of the updated employee benefits spreadsheet. The staffer feels compelled to help due to Rachel's convincing manner and authoritative tone.
    Which social engineering technique is Rachel demonstrating in this exercise?
  • 312-50v13 Exam Question 200

    A penetration tester evaluates a company's susceptibility to advanced social engineering attacks targeting its executive team. Using detailed knowledge of recent financial audits and ongoing projects, the tester crafts a highly credible pretext to deceive executives into revealing their network credentials. What is the most effective social engineering technique the tester should employ to obtain the necessary credentials without raising suspicion?