Question 271
A company ' s security policy states that all Web browsers must automatically delete their HTTP browser cookies upon terminating. What sort of security breach is this policy attempting to mitigate?
Question 272
During a compliance audit at a logistics company in Columbus, Ohio, the mobile security team discovers that several field-issued Android devices are responding to remote commands from an unknown external system.
The affected devices are not connected via USB, and no enterprise mobility policies were recently modified.
Network monitoring reveals that the devices have remote debugging enabled and are accepting connections over the wireless network on a specific high-numbered port commonly associated with remote device communication. Investigators determine that the external system was able to capture screenshots, list installed applications, forward ports, and install additional packages without requiring physical access to the devices.
Which attack technique most accurately explains this compromise?
The affected devices are not connected via USB, and no enterprise mobility policies were recently modified.
Network monitoring reveals that the devices have remote debugging enabled and are accepting connections over the wireless network on a specific high-numbered port commonly associated with remote device communication. Investigators determine that the external system was able to capture screenshots, list installed applications, forward ports, and install additional packages without requiring physical access to the devices.
Which attack technique most accurately explains this compromise?
Question 273
Late into the night shift inside the primary control room of a major oil refinery in Houston, Texas, security evaluator Lena Moreau sat at the central Human-Machine Interface console while the rest of the operations team monitored routine dashboards. Logged in with a routine operator account, she began navigating process- control screens and discovered she could freely adjust reactor temperatures, pressure-valve setpoints, and emergency-shutdown sequences-actions typically limited to higher-privilege roles.
These modifications took effect immediately across the live industrial equipment, yet the interface continued to display only standard operator-level indicators and normal status readings to the monitoring team.
Identify the SCADA vulnerability being exploited in this HMI-based attack.
These modifications took effect immediately across the live industrial equipment, yet the interface continued to display only standard operator-level indicators and normal status readings to the monitoring team.
Identify the SCADA vulnerability being exploited in this HMI-based attack.
Question 274
In the hushed offices of Pinecrest Solutions in Denver, network security analyst Lisa Nguyen began a covert review of a recent spike in network access issues reported by the sales team. The trouble surfaced during a low-traffic period when agents couldn't reach their CRM system, prompting Lisa to examine the subnet logs. She spotted irregular IP assignment attempts linked to an unfamiliar device. Acting quickly, Lisa entered a series of commands on the Cisco switches and later confirmed that connectivity issues had ceased without any new devices appearing in the logs. Which command did Lisa most likely use to address the issue?
Question 275
What is the algorithm used by LM for Windows 2000 SAM?
