Which of the following examples best represents a logical or technical control?
A. Security tokens
B. Heating and air conditioning
C. Smoke and fire alarms
D. Corporate security policy
Correct Answer: A


Company A and Company B have just merged and each has its own Public Key Infrastructure (PKI). What must the
Certificate Authorities (CAs) establish so that the private PKIs for Company A and Company B trust one another and
each private PKI can validate digital certificates from the other company?
A. Poly key exchange
B. Cross certification
C. Poly key reference
D. Cross-site exchange
Correct Answer: B


During a blackbox pen test you attempt to pass IRC traffic over port 80/TCP from a compromised web enabled host.
The traffic gets blocked; however, outbound HTTP traffic is unimpeded. What type of firewall is inspecting outbound
A. Application
B. Circuit
C. Stateful
D. Packet Filtering
Correct Answer: A
An application firewall is an enhanced firewall that limits access by applications to the operating system (OS) of a
computer. Conventional firewalls merely control the flow of data to and from the central processing unit (CPU),
examining each packet and determining whether or not to forward it toward a particular destination. An application
firewall offers additional protection by controlling the execution of files or the handling of data by specific applications.
References: http://searchsoftwarequality.techtarget.com/definition/application-firewall


While performing data validation of web content, a security technician is required to restrict malicious input. Which of the
following processes is an efficient way of restricting malicious input?
A. Validate web content input for query strings.
B. Validate web content input with scanning tools.
C. Validate web content input for type, length, and range.
D. Validate web content input for extraneous queries.
Correct Answer: C


While doing a technical assessment to determine network vulnerabilities, you used the TCP XMAS scan. What would be
the response of all open ports?
A. The port will send an ACK
B. The port will send a SYN
C. The port will ignore the packets
D. The port will send an RST
Correct Answer: C


What kind of risk will remain even if all theoretically possible safety measures would be applied?
A. Residual risk
B. Inherent risk
C. Impact risk
D. Deferred risk
Correct Answer: A


In order to prevent particular ports and applications from getting packets into an organization, what does a firewall
A. Network layer headers and the session layer port numbers
B. Presentation layer headers and the session layer port numbers
C. Application layer port numbers and the transport layer headers
D. Transport layer port numbers and application layer headers
Correct Answer: D


Which of the following cryptography attack is an understatement for the extraction of cryptographic secrets (e.g. the
password to an encrypted file) from a person by a coercion or torture?
A. Chosen-Cipher text Attack
B. Ciphertext-only Attack
C. Timing Attack
D. Rubber Hose Attack
Correct Answer: D


A network security administrator is worried about potential man-in-the-middle attacks when users access a corporate
web site from their workstations. Which of the following is the best remediation against this type of attack?
A. Implementing server-side PKI certificates for all connections
B. Mandating only client-side PKI certificates for all connections
C. Requiring client and server PKI certificates for all connections
D. Requiring strong authentication for all DNS queries
Correct Answer: C


A network admin contacts you. He is concerned that ARP spoofing or poisoning might occur on his network. What are
some things he can do to prevent it? Select the best answers.
A. Use port security on his switches.
B. Use a tool like ARPwatch to monitor for strange ARP activity.
C. Use a firewall between all LAN segments.
D. If you have a small network, use static ARP entries.
E. Use only static IP addresses on all PC\\’s.
Correct Answer: ABD


Which Intrusion Detection System is best applicable for large environments where critical assets on the network need
extra security and is ideal for observing sensitive network segments?
A. Network-based intrusion detection system (NIDS)
B. Host-based intrusion detection system (HIDS)
C. Firewalls
D. Honeypots
Correct Answer: A


If there is an Intrusion Detection System (IDS) in intranet, which port scanning technique cannot be used?
A. Spoof Scan
B. TCP Connect scan
D. Idle Scan
Correct Answer: C


QUESTION 13lead4pass 312-50V10 exam question q13

What does the option * indicate?
A. s
B. t
C. n
D. a
Correct Answer: C

