Question 256
During a red team engagement at a technology startup in Austin, ethical hacker Priya simulates an internal attacker by connecting a laptop to the corporate LAN. Within minutes, nearby workstations begin receiving incorrect network settings such as altered gateways and DNS servers. Employees trying to access the intranet are redirected to fake login portals hosted on Priya's machine. Security tools record temporary IP conflicts, but no alerts are triggered against the altered traffic paths.
Which attack technique did Priya most likely use?
Which attack technique did Priya most likely use?
Question 257
In the secure data center of a regional hospital in Denver, Colorado, ethical hacker Lila Chen was performing enumeration during the reconnaissance phase of a red-team assessment. She established a connection to a network-management service that responded to simple query strings without requiring authentication.
By issuing structured requests, she was able to retrieve detailed information about network resources, including hosts, routers, device statistics, routing relationships, and traffic patterns. This allowed her to build a clear understanding of the internal network layout and identify potential attack surfaces.
What enumeration technique was Lila most likely using?
By issuing structured requests, she was able to retrieve detailed information about network resources, including hosts, routers, device statistics, routing relationships, and traffic patterns. This allowed her to build a clear understanding of the internal network layout and identify potential attack surfaces.
What enumeration technique was Lila most likely using?
Question 258
A private equity firm in Minneapolis, Minnesota allows employees to access internal reporting tools from their personally owned smartphones under its BYOD program. During a routine security assessment, a consultant observes that when an employee leaves their unlocked phone unattended, a colleague can immediately open the firm's financial application and review client investment records without any additional verification step inside the application. The operating system itself requires a passcode to unlock the device, but once unlocked, corporate applications open directly to sensitive dashboards. Identify the BYOD security guideline that would directly mitigate this exposure.
Question 259
An attacker runs netcat tool to transfer a secret file between two hosts.

He is worried about information being sniffed on the network.
How would the attacker use netcat to encrypt the information before transmitting onto the wire?

He is worried about information being sniffed on the network.
How would the attacker use netcat to encrypt the information before transmitting onto the wire?
Question 260
Your company performs penetration tests and security assessments for small and medium-sized businesses in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking.
What should you do?
What should you do?
