312-50v13 Exam Question 36

During a red team assessment at a university in Chicago, Jake, a penetration tester, scans a group of older Windows workstations in the administration department. On several hosts, he notices traffic on UDP ports
137 and 138 as well as an open TCP port 139. Curious, he uses a utility to query the name table and session services. Within moments, he collects information including machine names, logged-in usernames, and available shared folders without authentication.
Which enumeration method is being demonstrated in this scenario?
  • 312-50v13 Exam Question 37

    A penetration tester is investigating a web server that allows unrestricted file uploads without validating file types. Which technique should be used to exploit this vulnerability and potentially gain control of the server?
  • 312-50v13 Exam Question 38

    A large online retail platform in Seattle, Washington, maintains continuous telemetry of inbound network flows to detect abnormal surges that may indicate a distributed denial-of-service condition.
    During a recent monitoring exercise, the security engineering team implemented a statistical mechanism that continuously evaluates streaming traffic metrics and mathematically determines the exact point at which normal behavior shifts into an anomalous state. Rather than comparing traffic against static baselines or clustering historical profiles, the system dynamically identifies the precise moment when distribution characteristics deviate beyond an established threshold.
    This approach is designed to flag sudden structural changes in traffic behavior in near real time, even if the overall traffic volume appears similar to prior peaks.
    Which detection technique is being applied in this scenario?
  • 312-50v13 Exam Question 39

    Scenario:
    * Victim opens the attacker ' s website.
    * Attacker sets up a website containing interesting and attractive content such as "Do you want to make
    $1000 in a day?".
    * Victim clicks the attractive content URL.
    * The attacker creates a transparent iframe in front of the URL that the victim attempts to click. The victim believes he/she is clicking the "Do you want to make $1000 in a day?" link, but is actually clicking content or a URL hidden inside the transparent iframe controlled by the attacker.
    What is the name of the attack mentioned in the scenario?
  • 312-50v13 Exam Question 40

    A red team operator wants to obtain credentials from a Windows machine without touching LSASS memory due to security controls and Credential Guard. They use SSPI to generate NetNTLM responses in the logged- in user context and collect those responses for offline cracking. Which attack technique is being used?