Question 961

As a Certified Ethical Hacker assessing session management vulnerabilities in a secure web application using MFA, encrypted cookies, and a WAF, which technique would most effectively exploit a session management weakness while bypassing these defenses?
  • Question 962

    Olivia, a cybersecurity architect at a Boston-based fintech company, is tasked with upgrading the organization
    ' s cryptographic infrastructure in preparation for future quantum computing threats. A recent internal audit flagged that sensitive customer data stored in the company ' s cloud environment could be vulnerable if quantum decryption methods become practically viable. To strengthen their post-quantum defense, Olivia must recommend a proactive cryptographic control that ensures long-term confidentiality of stored data, even against advanced quantum attackers.
    Which cryptographic defense should Olivia prioritize to mitigate the risk of future quantum-based decryption?
  • Question 963

    Which regulation defines security and privacy controls for Federal information systems and organizations?
  • Question 964

    In an ethical hacking methodology and framework, which of the following step is known for "active and passive information gathering"?
  • Question 965

    The web application security team of a global firm detected a sophisticated injection attack that exploited a flaw in the application's input validation. The attack was carried out using a custom script that used obfuscation and evasion techniques to bypass security measures. To counter such attacks in the future, the security team is considering implementing additional security measures. Which of the following would be the most effective?