Question 536
A logistics technology provider in Kansas City, Missouri conducts an internal review after an ethical hacker demonstrates several recurring input-handling weaknesses across different customer-facing web applications. The findings show that validation logic varies between modules, with many controls implemented inconsistently across components developed by separate teams.
Although immediate patches are applied to address the identified flaws, similar issues have surfaced in previous platform iterations despite corrective updates. Leadership determines that isolated fixes are insufficient and initiates an effort to standardize how security requirements are defined and incorporated across future development initiatives.
Based on the web application attack countermeasures, which category best aligns with this remediation approach?
Although immediate patches are applied to address the identified flaws, similar issues have surfaced in previous platform iterations despite corrective updates. Leadership determines that isolated fixes are insufficient and initiates an effort to standardize how security requirements are defined and incorporated across future development initiatives.
Based on the web application attack countermeasures, which category best aligns with this remediation approach?
Question 537
After responding to an alert involving unauthorized access to payroll data, forensic analyst Jason Miller traces the breach to a Windows workstation previously used by a temporary staff member in Chicago. While analyzing the event timeline, Jason identifies a non-elevated process that launched a signed Microsoft binary
- one of several auto-elevate executables such as fodhelper.exe, eventvwr.exe, or sdclt.exe - which resulted in execution of unauthorized code without prompting the user. Registry analysis reveals manipulation of shell- related keys under the current user hive, redirecting the trusted binary to invoke a malicious payload.
Which technique most likely enabled the privilege escalation?
- one of several auto-elevate executables such as fodhelper.exe, eventvwr.exe, or sdclt.exe - which resulted in execution of unauthorized code without prompting the user. Registry analysis reveals manipulation of shell- related keys under the current user hive, redirecting the trusted binary to invoke a malicious payload.
Which technique most likely enabled the privilege escalation?
Question 538
In the vibrant startup hub of San Francisco, California, ethical hacker Mia Torres was conducting a detailed vulnerability assessment for a rapidly growing development company. While examining one of the organization's core services, she identified a critical weakness that allowed an attacker to execute arbitrary instructions by manipulating how external components were loaded and by forcing multiple simultaneous operations to interfere with each other.
The issue originated directly from the internal behavior of the service itself rather than from server settings, outdated updates, or high-level architectural decisions.
What category of vulnerability was most likely identified?
The issue originated directly from the internal behavior of the service itself rather than from server settings, outdated updates, or high-level architectural decisions.
What category of vulnerability was most likely identified?
Question 539
A penetration tester discovers that a system is infected with malware that encrypts all files and demands payment for decryption. What type of malware is this?
Question 540
A penetration tester needs to identify open ports and services on a target network without triggering the organization's intrusion detection systems, which are configured to detect high- volume traffic and common scanning techniques. To achieve stealth, the tester decides to use a method that spreads out the scan over an extended period. Which scanning technique should the tester employ to minimize the risk of detection?
