Question 886

An organization deploys a web application firewall (WAF) that blocks common SQL injection signatures. During testing, the application remains vulnerable when equivalent SQL operators and alternate encodings are used. What does this MOST clearly demonstrate?
  • Question 887

    You perform a FIN scan and observe that many ports do not respond to FIN packets. How should these results be interpreted?
  • Question 888

    A security analyst is performing an audit on the network to determine if there are any deviations from the security policies in place. The analyst discovers that a user from the IT department had a dial-out modem installed.
    Which security policy must the security analyst check to see if dial-out modems are allowed?
  • Question 889

    What tool can crack Windows SMB passwords simply by listening to network traffic?
  • Question 890

    Jude, a pen tester, examined a network from a hacker's perspective to identify exploits and vulnerabilities accessible to the outside world by using devices such as firewalls, routers, and servers. In this process, he also estimated the threat of network security attacks and determined the level of security of the corporate network.
    What is the type of vulnerability assessment that Jude performed on the organization?