00:00

QUESTION 111

- (Topic 5)
What information should an IT system analysis provide to the risk assessor?

Correct Answer: C

QUESTION 112

- (Topic 8)
In order to attack a wireless network, you put up an access point and override the signal of the real access point. As users send authentication data, you are able to capture it. What kind of attack is this?

Correct Answer: C
The definition of a Rogue access point is:
1. A wireless access point (AP) installed by an employee without the consent of the IT department. Without the proper security configuration, users have exposed their company's network to the outside world.
2. An access point (AP) set up by an attacker outside a facility with a wireless network. Also called an "evil twin, " the rogue AP picks up beacons (signals that advertise its presence) from the company's legitimate AP and transmits identical beacons, which some client machines inside the building associate with.

QUESTION 113

- (Topic 5)
During a penetration test, a tester finds a target that is running MS SQL 2000 with default credentials. The tester assumes that the service is running with Local System account. How can this weakness be exploited to access the system?

Correct Answer: D

QUESTION 114

- (Topic 4)
Which of the following scanning tools is specifically designed to find potential exploits in Microsoft Windows products?

Correct Answer: D

QUESTION 115

- (Topic 6)
To what does “message repudiation” refer to what concept in the realm of email security?

Correct Answer: E
A quality that prevents a third party from being able to prove that a communication between two other parties ever took place. This is a desirable quality if you do not want your communications to be traceable.
Non-repudiation is the opposite quality—a third party can prove that a communication between two other parties took place. Non-repudiation is desirable if you want to be able to trace your communications and prove that they occurred. Repudiation – Denial of message submission or delivery.