1.
An attacker uses a communication channel within an operating system that is neither designed nor intended to transfer information. What is the name of the communications channel?
2.
Which of the following is used to indicate a single-line comment in structured query language (SQL)?
3.
What is the primary drawback to using advanced encryption standard (AES) algorithm with a 256 bit key to share sensitive data?
4.
Pentest results indicate that voice over IP traffic is traversing a network. Which of the following tools will decode a packet capture and extract the voice conversations?
5.
Which of the following examples best represents a logical or technical control?
6.
Which of the following resources does NMAP need to be used as a basic vulnerability scanner covering several vectors like SMB, HTTP and FTP?
7.
A penetration tester is hired to do a risk assessment of a company's DMZ. The rules of engagement states that the penetration test be done from an external IP address with no prior knowledge of the internal IT systems. What kind of test is being performed?
8.
How can a policy help improve an employee's security awareness?
9.
Which statement is TRUE regarding network firewalls preventing Web Application attacks?
10.
An organization hires a tester to do a wireless penetration test. Previous reports indicate that the last test did not contain management or control packets in the submitted traces. Which of the following is the most likely reason for lack of management or control packets?