Question 286
During an internal penetration test within a large corporate environment, the red team gains access to an unrestricted network port in a public-facing meeting room. Upon connecting a laptop, the tester deploys an automated tool configured to continuously send DHCPDISCOVER requests using thousands of randomly generated spoofed MAC addresses. Within minutes, several employees report that their devices are unable to access the internal network or obtain valid IP configurations. The IT team observes that the DHCP server's IP lease pool is completely depleted, even though few devices are actually connected at the time. What type of attack did the penetration tester perform?
Question 287
Which Nmap switch helps evade IDS or firewalls?
Question 288
During a penetration test, a security analyst encounters a web page that returns identical generic error messages regardless of input. To test for SQL injection, they submit a query that includes AND 1=1 and later AND 1=2, observing a change in the page content. What type of injection is being tested?
Question 289
In the fast-paced financial district of Singapore, security analyst Priya Nair was investigating a sudden surge of suspicious messages received by multiple employees across the organization's internal collaboration platform. The messages appeared to originate from internal-looking accounts and contained urgent prompts related to account verification, along with embedded links directing users to external resources.
Several employees reported receiving these messages repeatedly throughout the day despite no prior interaction, and the activity was confined entirely to the organization's real-time communication system rather than traditional communication channels.
What type of phishing was most likely being used in this incident?
Several employees reported receiving these messages repeatedly throughout the day despite no prior interaction, and the activity was confined entirely to the organization's real-time communication system rather than traditional communication channels.
What type of phishing was most likely being used in this incident?
Question 290
A well-resourced attacker intends to launch a highly disruptive DDoS attack against a major online retailer.
The attacker aims to exhaust all the network resources while keeping their identity concealed. Their method should be resistant to simple defensive measures such as IP-based blocking. Based on these objectives, which of the following attack strategies would be most effective?
The attacker aims to exhaust all the network resources while keeping their identity concealed. Their method should be resistant to simple defensive measures such as IP-based blocking. Based on these objectives, which of the following attack strategies would be most effective?
