312-50v13 Exam Question 221

During a penetration test for a global e-commerce platform in Dallas, ethical hacker Maria simulates a large- scale DoS campaign. Instead of sending attack traffic directly, she forges requests to multiple open services across the internet. These services unknowingly reply to the victim system, multiplying the amount of traffic hitting the target. Within minutes, the victim ' s server is overwhelmed by a flood of responses, even though Maria ' s own machine generated only a small amount of traffic.
Which attack technique is Maria most likely demonstrating?
  • 312-50v13 Exam Question 222

    A corporation migrates to a public cloud service, and the security team identifies a critical vulnerability in the cloud provider's API. What is the most likely threat arising from this flaw?
  • 312-50v13 Exam Question 223

    During an internal red team engagement at a financial services firm, an ethical hacker named Anika tests persistence mechanisms after successfully gaining access to a junior employee's workstation. As part of her assessment, she deploys a lightweight binary into a low-visibility system folder. To maintain long-term access, she configures it to launch automatically on every system reboot without requiring user interaction.
    Which of the following techniques has most likely been used to ensure the persistence of the attacker's payload?
  • 312-50v13 Exam Question 224

    An e-commerce platform hosted on a public cloud infrastructure begins to experience significant latency and timeouts. Logs show thousands of HTTP connections sending headers extremely slowly and never completing the full request. What DoS technique is most likely responsible?
  • 312-50v13 Exam Question 225

    Which patch management strategy is most effective?