Question 66

During a black-box pen test you attempt to pass IRC traffic over port 80/TCP from a compromised web enabled host. The traffic gets blocked; however, outbound HTTP traffic is unimpeded. What type of firewall is inspecting outbound traffic?
  • Question 67

    The collection of potentially actionable, overt, and publicly available information is known as
  • Question 68

    Which of the following tools performs comprehensive tests against web servers, including dangerous files and CGIs?
  • Question 69

    John is an incident handler at a financial institution. His steps in a recent incident are not up to the standards of the company. John frequently forgets some steps and procedures while handling responses as they are very stressful to perform. Which of the following actions should John take to overcome this problem with the least administrative effort?
  • Question 70

    Insecure direct object reference is a type of vulnerability where the application does not verify if the user is authorized to access the internal object via its name or key. Suppose a malicious user Rob tries to get access to the account of a benign user Ned.
    Which of the following requests best illustrates an attempt to exploit an insecure direct object reference vulnerability?