312-50v13 Exam Question 126

During a controlled red team engagement at a financial institution in New Jersey, ethical hacker Ryan tests the bank ' s resilience against stealth-based malware. He plants a custom malicious program on an employee workstation. After execution, he observes that the infected files continue to function normally, but his malware conceals its modifications by intercepting operating system calls. Antivirus scans repeatedly return
"no threats detected," even though the malicious code remains active and hidden on the system.
Which type of virus did Ryan most likely deploy in this assessment?
  • 312-50v13 Exam Question 127

    A penetration tester is assessing an IoT thermostat used in a smart home system. The device communicates with a cloud server for updates and commands. The tester discovers that communication between the device and the cloud server is not encrypted. What is the most effective way to exploit this vulnerability?
  • 312-50v13 Exam Question 128

    What is the most plausible attack vector an APT group would use to compromise an IoT-based environmental control system?
  • 312-50v13 Exam Question 129

    A penetration tester targets a WPA2-PSK wireless network. The tester captures the handshake and wants to speed up cracking the pre-shared key. Which approach is most effective?
  • 312-50v13 Exam Question 130

    During a security assessment, a consultant investigates how the application handles requests from authenticated users. They discover that once a user logs in, the application does not verify the origin of subsequent requests. To exploit this, the consultant creates a web page containing a malicious form that submits a funds transfer request to the application. A logged-in user, believing the page is part of a promotional campaign, fills out the form and submits it. The application processes the request successfully without any reauthentication or user confirmation, completing the transaction under the victim's session.
    Which session hijacking technique is being used in this scenario?