Exam Code : 312-49v10
Exam Name : Computer Hacking Forensic Investigator (CHFI-v10)
Vendor Name :
"EC-Council"
312-49v10 Dumps
312-49v10 Braindumps 312-49v10 Real Questions 312-49v10 Practice Test
312-49v10 Actual Questions
killexams.com
Computer Hacking Forensic Investigator (CHFI-v10)
https://killexams.com/pass4sure/exam-detail/312-49v10
Question: 90
Kyle is performing the final testing of an application he developed for the accounting department.
His last round of testing is to ensure that the program is as secure as possible. Kyle runs the following command. What is he testing at this point?
#include #include int main(int argc, char
*argv[]) { char buffer[10]; if (argc < 2) { fprintf (stderr, "USAGE: %s stringn", argv[0]); return 1; } strcpy(buffer, argv[1]); return 0; }
Buffer overflow
SQL injection
Format string bug
Kernal injection
Question: 91
After passing her CEH exam, Carol wants to ensure that her network is completely secure. She implements a DMZ, stateful firewall, NAT, IPSEC, and a packet filtering firewall. Since all security measures were taken, none of the hosts on her network can reach the Internet.
Why is that?
Stateful firewalls do not work with packet filtering firewalls
NAT does not work with stateful firewalls
IPSEC does not work with packet filtering firewalls
NAT does not work with IPSEC
Question: 92
You are the security analyst working for a private company out of France. Your current assignment is to obtain credit card information from a Swiss bank owned by that company. After initial reconnaissance, you discover that the bank security defenses are very strong and would take too long to penetrate. You decide to get the information by monitoring the traffic between the bank and one of its subsidiaries in London. After monitoring some of the traffic, you see a lot of FTP packets traveling back and forth. You want to sniff the traffic and extract usernames and
passwords.
What tool could you use to get this information?
Airsnort
Snort
Ettercap
RaidSniff
Question: 93
What TCP/UDP port does the toolkit program netstat use?
Port 7
Port 15
Port 23
Port 69
Question: 94
Jonathan is a network administrator who is currently testing the internal security of his network. He is attempting to hijack a session, using Ettercap, of a user connected to his Web server.
Why will Jonathan not succeed?
Only an HTTPS session can be hijacked
HTTP protocol does not maintain session
Only FTP traffic can be hijacked
Only DNS traffic can be hijacked
Question: 95
You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers.
What type of firewall must you implement to abide by this policy?
Packet filtering firewall
Circuit-level proxy firewall
Application-level proxy firewall
Stateful firewall
Question: 96
Printing under a Windows Computer normally requires which one of the following files types to be created?
EME
MEM
EMF
CME
Question: 97
Frank is working on a vulnerability assessment for a company on the West coast. The company hired Frank to assess its network security through scanning, pen tests, and vulnerability assessments. After discovering numerous known vulnerabilities detected by a temporary IDS he set up, he notices a number of items that show up as unknown but Questionable in the logs. He looks up the behavior on the Internet, but cannot find anything related.
What organization should Frank submit the log to find out if it is a new vulnerability or not?
APIPA
IANA
CVE
RIPE
Question: 98
Meyer Electronics Systems just recently had a number of laptops stolen out of their office. On these laptops contained sensitive corporate information regarding patents and company strategies. A month after the laptops were stolen, a competing company was found to have just developed products that almost exactly duplicated products that Meyer produces.
What could have prevented this information from being stolen from the laptops?
EFS Encryption
DFS Encryption
IPS Encryption
SDW Encryption
Question: 99
This organization maintains a database of hash signatures for known software.
International Standards Organization
Institute of Electrical and Electronics Engineers
National Software Reference Library
American National standards Institute
Question: 100
You have compromised a lower-level administrator account on an Active Directory network of a small company in Dallas, Texas. You discover Domain Controllers through enumeration. You connect to one of the Domain Controllers on port 389 using ldp.exe.
What are you trying to accomplish here?
Poison the DNS records with false records
Enumerate MX and A records from DNS
Establish a remote connection to the Domain Controller
Enumerate domain user accounts and built-in groups