Question 841

A Certified Ethical Hacker (CEH) is auditing a company's web server that employs virtual hosting.
The server hosts multiple domains and uses a web proxy to maintain anonymity and prevent IP blocking. The CEH discovers that the server's document root directory, which stores critical HTML files, is named "certroot" and is stored in the directory /admin/web. The server root, which stores the server's configuration, error, executable, and log files, is also identified. The CEH also notes that the server uses a virtual document tree for additional storage. Given this scenario which of the following actions would most likely increase the security of the web server?
  • Question 842

    During a compliance audit at a logistics company in Columbus, Ohio, the mobile security team discovers that several field-issued Android devices are responding to remote commands from an unknown external system. The affected devices are not connected via USB, and no enterprise mobility policies were recently modified. Network monitoring reveals that the devices have remote debugging enabled and are accepting connections over the wireless network on a specific high- numbered port commonly associated with remote device communication. Investigators determine that the external system was able to capture screenshots, list installed applications, forward ports, and install additional packages without requiring physical access to the devices. Which attack technique most accurately explains this compromise?
  • Question 843

    You start performing a penetration test against a specific website and have decided to start by grabbing all the links from the main page.
    What is the best Linux pipe to achieve your milestone?
  • Question 844

    You are Evelyn, an ethical hacker at LoneStar Health in Austin, Texas, engaged to investigate a recent compromise of archived patient records. During the investigation you recover a large set of encrypted records from a compromised backup and, separately, obtain several original template records (standard headers and form fields) that correspond to some entries in the encrypted set. You plan to use these paired examples (the original templates and their encrypted counterparts) to attempt to recover keys or deduce other plaintext values. Which cryptanalytic approach is most appropriate for this situation?
  • Question 845

    Josh has finished scanning a network and has discovered multiple vulnerable services. He knows that several of these usually have protections against external sources but are frequently susceptible to internal users. He decides to draft an email, spoof the sender as the internal IT team, and attach a malicious file disguised as a financial spreadsheet. Before Josh sends the email, he decides to investigate other methods of getting the file onto the system. For this particular attempt, what was the last stage of the cyber kill chain that Josh performed?