Question 696
A mid-sized manufacturing firm in Des Moines, lowa reported that several employee workstations were periodically communicating with an unfamiliar external server over an IRC channel. The affected systems showed no visible interface for remote control, yet investigators confirmed that the machines were receiving instructions and executing distributed traffic bursts at scheduled intervals.
Further review revealed that the initial infection occurred after employees opened a phishing email attachment. Once executed, the infected systems silently connected outward and began awaiting commands from a centralized remote controller.
Determine the Trojan classification that best matches this behavior.
Further review revealed that the initial infection occurred after employees opened a phishing email attachment. Once executed, the infected systems silently connected outward and began awaiting commands from a centralized remote controller.
Determine the Trojan classification that best matches this behavior.
Question 697
During a scheduled red team engagement at a regional investment firm in Phoenix, Arizona, security consultants were permitted limited after-hours access to employee workstations. As part of the evaluation, a small intermediary device was placed inline between a keyboard and its connected desktop system.
Over time, the device began forwarding captured keystroke activity through the company's established wireless environment, allowing the assessment team to collect periodic log data without interacting further with the workstation.
What type of keylogger does this scenario describe?
Over time, the device began forwarding captured keystroke activity through the company's established wireless environment, allowing the assessment team to collect periodic log data without interacting further with the workstation.
What type of keylogger does this scenario describe?
Question 698
jane invites her friends Alice and John over for a LAN party. Alice and John access Jane's wireless network without a password. However. Jane has a long, complex password on her router. What attack has likely occurred?
Question 699
A penetration tester discovers that a Linux server accepts SSH connections but limits password authentication after several failed attempts. The tester already possesses the target organization's written authorization. Which action BEST balances efficiency and responsible assessment practices while attempting authenticated access?
Question 700
In the bustling financial hub of Charlotte, North Carolina, ethical hacker Raj Patel is contracted by TrustBank, a regional US bank, to evaluate their online loan application portal. On April 22, 2025, Raj tests a feature allowing customers to upload structured financial documents for loan processing. By submitting a specially crafted document, he triggers a response that exposes internal server file paths and sensitive configuration data, including database connection strings. The issue arises from the portal's handling of external references in document parsing, not from response manipulation, authentication weaknesses, or undetected attack attempts. Raj compiles a detailed report to assist TrustBank's security team in mitigating the vulnerability.
Which type of vulnerability is Raj most likely exploiting in TrustBank's online loan application portal?
Which type of vulnerability is Raj most likely exploiting in TrustBank's online loan application portal?
