num10
|
|
Título del Test:
![]() num10 Descripción: numero 10 |



| Comentarios |
|---|
NO HAY REGISTROS |
|
MidWest BioAnalytics, a pharmaceutical research firm in Columbus, Ohio, authorizes a controlled adversarial simulation to assess the resilience of its internal web-based inventory management platform. During the exercise, administrators observe that several active client connections briefly lose synchronization, and unexpected command patterns appear within system transaction logs. The irregularities are subtle and become apparent only after reviewing stored network captures. Executive leadership requests a solution that can maintain ongoing visibility into network exchanges and highlight activity that diverges from typical communication behavior across the organization's infrastructure. Which approach best satisfies this requirement?. Perform manual packet inspection using a protocol analyzer. Monitor for abnormal surges of repeated ACK responses. Use an Intrusion Detection System (IDS). Evaluate authentication token generation patterns. During a red team engagement at a biotechnology firm in San Diego, California, the security team observed that a compromised internal workstation was generating an unusually high number of outbound name resolution requests to external servers. Upon deeper inspection, analysts discovered that the query strings contained encoded data segments rather than typical lookup patterns. Further analysis revealed that these outbound requests were being used to transfer sensitive information to an attacker controlled system outside the corporate network. Which technique was most likely used to covertly transfer the data in this scenario?. TCP Parameter Manipulation. Reverse ICMP Tunnel. DNS Tunneling. Reverse HTTP Shell. A logistics technology provider in Kansas City, Missouri conducts an internal review after an ethical hacker demonstrates several recurring input-handling weaknesses across different customer-facing web applications. The findings show that validation logic varies between modules, with many controls implemented inconsistently across components developed by separate teams. Although immediate patches are applied to address the identified flaws, similar issues have surfaced in previous platform iterations despite corrective updates. Leadership determines that isolated fixes are insufficient and initiates an effort to standardize how security requirements are defined and incorporated across future development initiatives. Based on the web application attack countermeasures, which category best aligns with this remediation approach?. Insecure Design. Broken Access Control. Security Misconfiguration. Cryptographic Failures / Sensitive Data Exposure. During a targeted intrusion against a cloud infrastructure company in Salt Lake City, Utah, an attacker distributes a modified installation package of a legitimate network diagnostic utility widely used by employees. Before distributing the package, the attacker binds a malicious remote-access payload with the original executable so that both components are installed together. When users launch the diagnostic tool, it performs its normal troubleshooting functions, while the hidden payload simultaneously executes in the background and establishes communication with a remote command server. From a malware deployment perspective, what technique best describes this approach?. Wrapper. Downloader. Packer. Dropper. |




