This type of Port Scanning technique splits TCP header into several packets so that the packet filters are not
This type of Port Scanning technique splits TCP header into several packets so that the packet
filters are not able to detect what the packets intends to do.
How would you call this type of activity?
Joel and her team have been going through tons of garbage, recycled paper, and other rubbish in
order to find some information about the target they are attempting to penetrate. How would you
call this type of activity?
which situations would you want to use anonymizer?
Anonymizer sites access the Internet on your behalf, protecting your personal information from
disclosure. An anonymizer protects all of your computer’s identifying information while it surfs for
you, enabling you to remain at least one step removed from the sites you visit.
You can visit Web sites without allowing anyone to gather information on sites visited by you.
Services that provide anonymity disable pop-up windows and cookies, and conceal visitor’s IP
address.
These services typically use a proxy server to process each HTTP request. When the user
requests a Web page by clicking a hyperlink or typing a URL into their browser, the service
retrieves and displays the information using its own server. The remote server (where the
requested Web page resides) receives information on the anonymous Web surfing service in
place of your information.
In which situations would you want to use anonymizer? (Select 3 answers)
What type of attack is shown in the following diagram?
What kind of attack is being illustrated here?
Jack Hacker wants to break into Brown Co.’s computers and obtain their secret double fudge
cookie recipe. Jack calls Jane, an accountant at Brown Co., pretending to be an administrator
from Brown Co. Jack tells Jane that there has been a problem with some accounts and asks her to
verify her password with him ”just to double check our records.” Jane does not suspect anything
amiss, and parts with her password. Jack can now access Brown Co.’s computers with a valid
user name and password, to steal the cookie recipe. What kind of attack is being illustrated here?
How do you defend against ARP Spoofing?
How do you defend against ARP Spoofing? Select three.
System B sends a SYN/ACK packet to victim
TCP SYN Flood attack uses the three-way handshake mechanism.
1. An attacker at system A sends a SYN packet to victim at system B.
2. System B sends a SYN/ACK packet to victim A.
3. As a normal three-way handshake mechanism system A should send an ACK packet to system
B, however, system A does not send an ACK packet to system B. In this case client B is waiting
for an ACK packet from client A.
This status of client B is called _________________
What technique was used by the Kiley Innovators employee to send information to the rival marketing company?
Lori is a Certified Ethical Hacker as well as a Certified Hacking Forensics Investigator working as
an IT security consultant. Lori has been hired on by Kiley Innovators, a large marketing firm that
recently underwent a string of thefts and corporate espionage incidents. Lori is told that a rival
marketing company came out with an exact duplicate product right before Kiley Innovators was
about to release it. The executive team believes that an employee is leaking information to the
rival company. Lori questions all employees, reviews server logs, and firewall logs; after which she
finds nothing. Lori is then given permission to search through the corporate email system. She
searches by email being sent to and sent from the rival marketing company.
She finds one employee that appears to be sending very large email to this other marketing
company, even though they should have no reason to be communicating with them. Lori tracks
down the actual emails sent and upon opening them, only finds picture files attached to them.
These files seem perfectly harmless, usually containing some kind of joke. Lori decides to use
some special software to further examine the pictures and finds that each one had hidden text that
was stored in each picture.
What technique was used by the Kiley Innovators employee to send information to the rival
marketing company?
Which of the following nmap command did you run?
How do you defend against Privilege Escalation?
How do you defend against Privilege Escalation?
 
                

