Question 156

A post-breach forensic investigation revealed that a known vulnerability in Apache Struts was to blame for the Equifax data breach that affected 143 million customers. A fix was available from the software vendor for several months prior 10 the Intrusion. This Is likely a failure in which of the following security processes?
  • Question 157

    Which among the following is the best example of the third step (delivery) in the cyber kill chain?
  • Question 158

    John is investigating web-application firewall logs and observers that someone is attempting to inject the following:
    char buff[10];
    buff[>o] - 'a':
    What type of attack is this?
  • Question 159

    Ricardo has discovered the username for an application in his targets environment. As he has a limited amount of time, he decides to attempt to use a list of common passwords he found on the Internet. He compiles them into a list and then feeds that list as an argument into his password-cracking application, what type of attack is Ricardo performing?
  • Question 160

    Robin, an attacker, is attempting to bypass the firewalls of an organization through the DNS tunneling method in order to exfiltrate dat a. He is using the NSTX tool for bypassing the firewalls. On which of the following ports should Robin run the NSTX tool?