Question 66
During a red team engagement at a healthcare provider in Miami, ethical hacker Rachel suspects that a compromised workstation is running a sniffer in promiscuous mode. To confirm her suspicion, she sends specially crafted ICMP packets with a mismatched MAC address but a correct IP destination. Minutes later, the suspected machine responds to the probe even though ordinary systems would ignore it.
Which detection technique is Rachel most likely using to validate the presence of a sniffer?
Which detection technique is Rachel most likely using to validate the presence of a sniffer?
Question 67
During a security penetration test at Sterling Manufacturing in Cleveland, Ohio, the ethical hacking team evaluates the company's physical security controls. On a chilly evening in July
2025, ethical hacker Priya Desai, posing as a facilities contractor, accesses the company's loading dock area after regular business hours. Behind the employee entrance, she comes across an unsecured maintenance container with discarded packaging, shipping labels, and shredded office material. Among the clutter, Priya retrieves a crumpled document listing temporary access codes for the employee break room, along with a partially shredded memo referencing an upcoming audit. The exercise tests whether sensitive information discarded improperly can be exploited. The next day, Priya uses the recovered access codes to enter the break room undetected during a shift change, logging her entry on a controlled test system to simulate a breach. What social engineering technique is Priya's exercise primarily simulating?
2025, ethical hacker Priya Desai, posing as a facilities contractor, accesses the company's loading dock area after regular business hours. Behind the employee entrance, she comes across an unsecured maintenance container with discarded packaging, shipping labels, and shredded office material. Among the clutter, Priya retrieves a crumpled document listing temporary access codes for the employee break room, along with a partially shredded memo referencing an upcoming audit. The exercise tests whether sensitive information discarded improperly can be exploited. The next day, Priya uses the recovered access codes to enter the break room undetected during a shift change, logging her entry on a controlled test system to simulate a breach. What social engineering technique is Priya's exercise primarily simulating?
Question 68
When configuring wireless on his home router, Javik disables SSID broadcast. He leaves authentication
"open" but sets the SSID to a 32-character string of random letters and numbers.
What is an accurate assessment of this scenario from a security perspective?
"open" but sets the SSID to a 32-character string of random letters and numbers.
What is an accurate assessment of this scenario from a security perspective?
Question 69
A certified ethical hacker is conducting a Whois footprinting activity on a specific domain. The individual is leveraging various tools such as Batch IP Converter and Whols Analyzer Pro to retrieve vital details but is unable to gather complete Whois information from the registrar for a particular set of data. As the hacker, what might be the probable data model being utilized by the domain's registrar for storing and looking up Who is information?
Question 70
Jake, a cybersecurity investigator at a Miami-based cryptocurrency exchange, uncovers a sinister plot during a late-night breach response. Attackers have infiltrated the company's cloud environment, leveraging a technique to siphon computing power from misconfigured AWS instances. The breach, traced through compromised secrets and unauthorized API calls, has triggered a surge in resource consumption, threatening the platform's integrity during a high- stakes trading surge. As Jake races against time to pinpoint the attack method, he must identify the primary cloud hacking technique at play. What cloud hacking technique should Jake identify as the primary method used by attackers to siphon computing power in the cloud environment?
