Question 781

A large company intends to use Blackberry for corporate mobile phones and a security analyst is assigned to evaluate the possible threats. The analyst will use the Blackjacking attack method to demonstrate how an attacker could circumvent perimeter defenses and gain access to the Prometric Online Testing - Reports
https://ibt1.prometric.com/users/custom/report_queue/rq_str... corporate network. What tool should the analyst use to perform a Blackjacking attack?
  • Question 782

    A technology consulting firm in Denver, Colorado, recently experienced a wave of suspicious account compromise incidents. Several employees reported receiving an email that appeared identical to a legitimate cloud storage notification they had received earlier that week.
    The message reused the original branding, formatting, sender display name, and subject line.
    However, it informed recipients that the previously shared document had been "updated due to synchronization errors" and instructed them to reauthenticate using the embedded link.
    The link directed users to a convincing replica of the organization's authentication portal.
    Investigation revealed that the attacker had reused content from a genuine prior communication and modified only the embedded hyperlink.
    Which type of social engineering attack does this scenario most accurately represent?
  • Question 783

    During a simulated attack against a university's IT network in California, ethical hacker Sophia deploys custom malicious code onto one lab workstation. Without requiring further user interaction, she observes the malware automatically copying itself into shared folders and spreading through weak admin credentials. Within a short time, dozens of computers across multiple departments are infected with the same payload, even though only one machine was initially targeted. Which type of malware is Sophia most likely demonstrating?
  • Question 784

    Alice, a professional hacker, targeted an organization's cloud services. She infiltrated the target's MSP provider by sending spear-phishing emails and distributed custom-made malware to compromise user accounts and gain remote access to the cloud service. Further, she accessed the target customer profiles with her MSP account, compressed the customer data, and stored them in the MSP. Then, she used this information to launch further attacks on the target organization. Which of the following cloud attacks did Alice perform in the above scenario?
  • Question 785

    The collection of potentially actionable, overt, and publicly available information is known as