Question 451
Nedved is an IT Security Manager of a bank in his country. One day. he found out that there is a security breach to his company's email server based on analysis of a suspicious connection from the email server to an unknown IP Address.
What is the first thing that Nedved needs to do before contacting the incident response team?
What is the first thing that Nedved needs to do before contacting the incident response team?
Question 452
Take a look at the following attack on a Web Server using obstructed URL:

How would you protect from these attacks?

How would you protect from these attacks?
Question 453
Which of the following web vulnerabilities would an attacker be attempting to exploit if they delivered the following input?
<!DOCTYPE blah [ < IENTITY trustme SYSTEM "file:///etc/passwd" > ] >
<!DOCTYPE blah [ < IENTITY trustme SYSTEM "file:///etc/passwd" > ] >
Question 454
During a network analysis at a mid-sized enterprise, a security engineer detects irregular DHCP behavior. Multiple endpoints are being assigned incorrect gateway and DNS settings, causing loss of connectivity and redirection to unauthorized servers. Packet captures show that clients are receiving IP address offers from more than one DHCP source. Upon further investigation, the logs confirm that the access switch is forwarding DHCP responses from all connected ports without filtering. This indicates that an unauthorized (rogue) DHCP server has been introduced into the network, impersonating the legitimate server and responding to client DHCPDISCOVER messages. To prevent this type of attack from occurring in the future, what security feature should the administrator enable?
Question 455
During testing against a network protected by a signature-based IDS, the tester notices that standard scans are blocked. To evade detection, the tester sends TCP headers split into multiple small IP fragments so the IDS cannot reassemble or interpret them, but the destination host can. What technique is being used?
