Question 561

During a red team engagement at a logistics company in Dallas, Texas, ethical hacker Priya Nair was assessing exposed services within the internal network. She discovered that a service was accessible from external segments and allowed unauthenticated systems to establish sessions and interact with shared resources.
Further analysis revealed that the service relied on legacy communication channels commonly associated with remote file and printer access, making it susceptible to unauthorized enumeration and data exposure. Priya recommended implementing a control that would prevent external systems from directly interacting with this service at the network level.
Which enumeration countermeasure would be most effective in mitigating this exposure?
  • Question 562

    You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?
  • Question 563

    At Apex Financial Services in Houston, Texas, ethical hacker Javier Ruiz evaluates mobile security practices under the company ' s BYOD policy. He demonstrates that employees often install applications that request access to contact lists, cameras, and messaging services, even though these functions are unrelated to the apps
    ' intended purpose. This behavior allows a malicious program to harvest sensitive corporate information.
    Which security guideline would most directly prevent this issue?
  • Question 564

    Which iOS jailbreaking technique patches the kernel during the device boot so that it becomes jailbroken after each successive reboot?
  • Question 565

    While evaluating a smart card implementation, a security analyst observes that an attacker is measuring fluctuations in power consumption and timing variations during encryption operations on the chip. The attacker uses this information to infer secret keys used within the device. What type of exploitation is being carried out?