312-50v13 Exam Question 56

During a red team exercise at a financial institution in New York, penetration tester Bob investigates irregularities in time synchronization across critical servers. While probing one server, he decides to use a diagnostic command that allows him to directly interact with the NTP daemon and query its internal state.
This command enables him to perform monitoring and retrieve statistics, but it is primarily focused on controlling and checking the operation of the NTP service rather than listing peers with delay, offset, and jitter values.
Which command should Bob use to accomplish this?
  • 312-50v13 Exam Question 57

    During a cybersecurity awareness drill at Quantum Analytics in San Francisco, California, the ethical hacking team tests the company's defenses against social media-based threats. Nadia creates a fake LinkedIn profile posing as a senior HR manager from Quantum Analytics, using a stolen company logo and publicly available employee details. Nadia sends connection requests to several employees, including data analyst Priya Sharma, inviting them to join a private group called Quantum Analytics Innovation Hub. The group's page prompts members to share their work email and department role for exclusive project updates.
    What social engineering threat to corporate networks is Nadia's exercise primarily simulating?
  • 312-50v13 Exam Question 58

    Repeated failed login attempts are followed by a sudden surge in outbound data traffic from a critical server.
    What should be your initial course of action?
  • 312-50v13 Exam Question 59

    You are leading an internal red team assessment for a multinational bank with a highly complex and distributed IT infrastructure. Your team is required to simulate attacks across cloud services, servers, and remote endpoints. Due to the sheer scale of the environment, you deploy an AI-based platform that automatically scans the entire network, flags anomalies based on prior breach data, and adjusts its threat detection models as new attack behaviors are encountered.
    What key benefit of AI-driven ethical hacking is most critical to your success in this scenario?
  • 312-50v13 Exam Question 60

    During a red team assessment of a mid-sized insurance provider in Denver, Colorado, testers established persistent access on an internal developer workstation after exploiting a misconfigured automation service. To sustain command-and-control without triggering perimeter defenses, they configured a low-bandwidth outbound channel designed to blend into infrastructure traffic that is routinely permitted through egress controls.
    Security operations later identified periodic outbound communication from the compromised host to a single unfamiliar external endpoint not associated with approved vendors or user activity. The traffic was distributed over time rather than bursty. Although the exchanges resembled legitimate service requests, packet inspection revealed irregular payload sizing and structured encoding patterns inconsistent with typical client behavior across the environment.
    What covert communication technique was most likely used to sustain the red team's access?