1.
An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces. Which of the following is the most likely reason for lack of management or control packets?
2.
Which of the following techniques will identify if computer files have been changed?
3.
Which of the following does proper basic configuration of snort as a network intrusion detection system require?
4.
When analyzing the IDS logs, the system administrator notices connections from outside of the LAN have been sending packets where the Source IP address and Destination IP address are the same. There have been no alerts sent via email or logged in the IDS. Which type of an alert is this?
5.
Which of the following descriptions is true about a static NAT?
6.
Which United States legislation mandates that the Chief Executive Officer (CEO) and the Chief Financial Officer (CFO) must sign statements verifying the completeness and accuracy of financial reports?
7.
Which of the following is a component of a risk assessment?
8.
What information should an IT system analysis provide to the risk assessor?
9.
Which security strategy requires using several, varying methods to protect IT systems against attacks?
10.
During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?