IT Exam Items Repository Which two misconfigured cloud authentication methods could leverage a cloud asset? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerAn attacker enters the string 192.168.78.6;cat /etc/httpd/httpd.conf on a web application hosted on a Linux server. Which type of attack occurred?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat are two examples of immutable queries that should be used as mitigation for SQL injection vulnerabilities? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerAn attacker enters the string ‘John’ or ‘1=1’ on a web form that is connected to a back-end SQL server causing the server to display all records in the database table. Which type of SQL injection attack was used in this scenario?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat kind of social engineering attack can be prevented by developing policies such as updating anti-malware applications regularly and using secure virtual browsers with little connectivity to the rest of the system and the rest of the network?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhat is a characteristic of a pharming attack?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich statement correctly describes a type of physical social engineering attack?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA threat actor spoofed the phone number of the director of HR and called the IT help desk with a login problem. The threat actor claims to be the director and wants the help desk to change the password. What method of influence is this cybercriminal using?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA cybersecurity student is learning about the Social-Engineer Toolkit (SET), and the student has discovered that this tool can be used to launch various social engineering attacks. Which two social engineering attacks can be launched using SET?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA penetration tester deploys a rogue AP in the target wireless infrastructure. What is the first step that has to be taken to force wireless clients to connect to the rogue AP?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerRefer to the exhibit. What is the penetration tester trying to achieve by running this exploit?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerA penetration tester runs the Nmap NSE script nmap --script smtp-open-relay.nse 10.0.0.1 command on a Kali Linux PC. What is the purpose of running this script?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerRefer to the exhibit. A penetration is being prepared to run the EternalBlue exploit using Metasploit against a target with an IP address of 10.0.0.1/8 from the source PC with an IP address of 10.0.0.111/8. What two commands must be entered before the exploit command can be run? (Choose two.)ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerAn organization wants to test its vulnerability to an employee with network privileges accessing the network maliciously. Which type of penetration test should be used to test this vulnerability?ITExamAnswers Editorial Team asked 3 years ago • Ethical HackerWhich three practices are commonly adopted when setting up a penetration testing lab environment? (Choose three.)ITExamAnswers Editorial Team asked 3 years ago • Ethical Hacker