Question 41

During a recent vulnerability assessment of a major corporation's IT systems, the security team identified several potential risks. They want to use a vulnerability scoring system to quantify and prioritize these vulnerabilities. They decide to use the Common Vulnerability Scoring System (CVSS). Given the characteristics of the identified vulnerabilities, which of the following statements is the most accurate regarding the metric types used by CVSS to measure these vulnerabilities?
  • Question 42

    Mr. Omkar performed tool-based vulnerability assessment and found two vulnerabilities. During analysis, he found that these issues are not true vulnerabilities.
    What will you call these issues?
  • Question 43

    Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system.
    Which TCP and UDP ports must you filter to check null sessions on your network?
  • Question 44

    Which DNS resource record can indicate how long any "DNS poisoning" could last?
  • Question 45

    How is the public key distributed in an orderly, controlled fashion so that the users can be sure of the sender's identity?