Question 986

You have compromised a server and successfully gained a root access. You want to pivot and pass traffic undetected over the network and evade any possible Intrusion Detection System. What is the best approach?
  • Question 987

    The Heartbleed bug was discovered in 2014 and is widely referred to under MITRE's Common Vulnerabilities and Exposures (CVE) as CVE-2014-0160. This bug affects the OpenSSL implementation of the Transport Layer Security (TLS) protocols defined in RFC6520.
    What type of key does this bug leave exposed to the Internet making exploitation of any compromised system very easy?
  • Question 988

    CompanyXYZ has asked you to assess the security of their perimeter email gateway. From your office in New York, you craft a specially formatted email message and send it across the Internet to an employee of CompanyXYZ. The employee of CompanyXYZ is aware of your test. Your email message looks like this:
    From: [email protected]
    To: [email protected] Subject: Test message
    Date: 4/3/2017 14:37
    The employee of CompanyXYZ receives your email message.
    This proves that CompanyXYZ's email gateway doesn't prevent what?
  • Question 989

    Maya Patel from SecureHorizon Consulting is investigating a breach at Dallas General Hospital in Texas after a nurse misplaced a smartphone containing patient management software. Although the device remained active on the network, administrators had no way to identify its physical whereabouts, delaying incident response and allowing sensitive medical records to be exposed for hours. Which mobile security guideline would have most directly reduced the impact of this incident?
  • Question 990

    Tremp is an IT Security Manager planning to deploy an IDS. He needs a solution that:
    Verifies success/failure of an attack
    Monitors system activities
    Detects local (host-based) attacks
    Provides near real-time detection
    Doesn't require additional hardware
    Has a lower entry cost
    Which type of IDS is best suited for Tremp's requirements?