312-50v13 Exam Question 246
A large mobile telephony and data network operator has a data center that houses network elements. These are essentially large computers running on Linux. The perimeter of the data center is secured with firewalls and IPS systems. What is the best security policy concerning this setup?
312-50v13 Exam Question 247
An ethical hacker audits a hospital's wireless network secured with WPA using TKIP and successfully performs packet injection and decryption attacks. Which WPA vulnerability most likely enabled this?
312-50v13 Exam Question 248
During a UDP service enumeration scan, the tester sees that some ports respond with ICMP Type 3 Code 3 (Port Unreachable), while most remain silent. No firewall or IDS is interfering. What can the tester conclude about the non-responsive ports?
312-50v13 Exam Question 249
An enterprise collaboration platform used by a pharmaceutical distributor in Boston, Massachusetts relies on a centralized identity store to validate employee credentials. While reviewing the authentication workflow, a security tester notices that user-provided values are directly embedded into backend lookup expressions responsible for locating account records.
When specific logical operators and wildcard characters are introduced into the username field, the application's record-matching behavior changes. Instead of evaluating a single identity entry, the backend process begins matching a broader set of records than intended, altering the outcome of the authentication check.
The issue arises from improper handling of input within directory-based search logic.
From the following options, identify the injection technique illustrated in this scenario.
When specific logical operators and wildcard characters are introduced into the username field, the application's record-matching behavior changes. Instead of evaluating a single identity entry, the backend process begins matching a broader set of records than intended, altering the outcome of the authentication check.
The issue arises from improper handling of input within directory-based search logic.
From the following options, identify the injection technique illustrated in this scenario.
312-50v13 Exam Question 250
Which scenario best represents a social engineering attack?
