Question 331

At a power distribution facility in Phoenix, Arizona, ethical hacker Sameer Das is performing an OT security assessment. He demonstrates that a programmable controller accepts modifications delivered over the network without checking the origin or cryptographic validity of the package. By uploading altered instructions, he changes how the controller processes commands during operations. Which IoT/OT threat best represents this technique?
  • Question 332

    As a cybersecurity analyst for SecureNet, you are performing a security assessment of a new mobile payment application. One of your primary concerns is the secure storage of customer data on the device. The application stores sensitive information such as credit card details and personal identification numbers (PINs) on the device. Which of the following measures would best ensure the security of this data?
  • Question 333

    An incident investigator asks to receive a copy of the event logs from all firewalls, proxy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs, the sequence of many of the logged events do not match up.
    What is the most likely cause?
  • Question 334

    At a multinational manufacturing company in Stuttgart, Germany, security architect Elena Schmidt was reviewing the configuration of the perimeter defense system during a network segmentation project. The system was responsible for controlling all inbound and outbound traffic between the corporate network and external partners.
    She observed that the firewall first ensured a valid connection had been successfully established between endpoints before permitting further communication. Once this validation was complete, traffic flowed freely in both directions without continued inspection at the packet level. However, any attempt to transmit data without completing this initial connection process was immediately rejected.
    Determine the type of firewall being described.
  • Question 335

    An authorized penetration tester is assessing an organization's external attack surface. The objective is to discover publicly accessible subdomains without directly interacting with the target's infrastructure whenever possible. Which reconnaissance technique BEST satisfies this requirement?