312-50v13 Exam Question 181

During a penetration test at Horizon Tech in Austin, ethical hacker Michael sets up a man-in-the-middle attack to intercept traffic between employees and the company ' s internal web applications. He uses a lightweight tool capable of performing ARP spoofing, DNS manipulation, and packet injection while providing an interactive interface for real-time monitoring. This allows him to capture and manipulate session tokens in transit, which he later presents to the security team as proof of risk.
Which tool is Michael most likely using in this exercise?
  • 312-50v13 Exam Question 182

    A kernel-level rootkit is discovered. What is the safest remediation strategy?
  • 312-50v13 Exam Question 183

    A tester evaluates a login form that constructs SQL queries using unsanitized user input. By submitting ' C 'll- T; -, the tester gains unauthorized access to the application. What type of SQL injection has occurred?
  • 312-50v13 Exam Question 184

    At a fast-growing startup in Austin, Texas, an ethical hacker is asked to simulate how attackers might gather information to gain initial access. During the assessment, she poses as a recruiter on a professional networking site and convinces several employees to share details about the company's internal software and VPN setup.
    Which type of threat best represents this adversary's method of information gathering?
  • 312-50v13 Exam Question 185

    As a cybersecurity professional at XYZ Corporation, you are tasked with investigating anomalies in system logs that suggest potential unauthorized activity. System administrators have detected repeated failed login attempts on a critical server, followed by a sudden surge in outbound data traffic. These indicators suggest a possible compromise. Given the sensitive nature of the system and the sophistication of the threat, what should be your initial course of action?