312-50v13 Exam Question 241

A penetration tester evaluates a secure web application using HTTPS, secure cookies, and multi-factor authentication. To hijack a legitimate user's session without triggering alerts, which technique should be used?
  • 312-50v13 Exam Question 242

    Which WPA vulnerability allowed packet injection and decryption attacks?
  • 312-50v13 Exam Question 243

    An IDS generates alerts during normal user activity. What is the most likely cause?
  • 312-50v13 Exam Question 244

    During an internal red team engagement at a software company in Boston, ethical hacker Meera gains access to a developer ' s workstation. To ensure long-term persistence, she plants a lightweight binary in a hidden directory and configures it to automatically launch every time the system is restarted. Days later, even after the host was rebooted during patching, the binary executed again without requiring user interaction, giving Meera continued access.
    Which technique most likely enabled this persistence?
  • 312-50v13 Exam Question 245

    During a red team exercise at a technology consulting firm in San Francisco, analyst Evelyn deploys a malicious payload disguised within a software update installer. When the target runs the installer, the main application functions normally, but behind the scenes, additional malware components are silently placed on the system without the user ' s knowledge. These hidden components later activate to establish remote access for the red team.
    Which technique was most likely used to deliver the hidden malware?