SEC504 Sample Questions

SEC504 Sample Questions & Answers

Expect even emphasis across incident response and digital investigations, MITRE ATT&CK-driven reconnaissance, attacks on passwords and cloud accounts, exploiting public-facing systems with Metasploit, evasion after a foothold is gained, and a capture-the-flag exercise.

Launch the full SEC504 simulator →

Showing 10 of 20 free samples.

  1. Question 1

    Fill in the blank with the appropriate word. StackGuard (as used by Immunix),ssp/ProPolice(as used by OpenBSD), and Microsoft's/GS option use_______defense against buffer overflow attacks.

    Show answer & explanation

    Correct answer: A

    A

  2. Question 2

    John works as a Network Security Professional. He is assigned a project to test the security of www.we-are-secure.com. He establishes a connection to a target host running a Web service with netcat and sends a bad html request in order to retrieve information about the service on the host.

    Which of the following attacks is John using?

    Show answer & explanation

    Correct answer: D

    D

  3. Question 3Select 3

    Many organizations create network maps of their network system to visualize the network and understand the relationship between the end devices and the transport layer that provide services.

    Which of the following are the techniques used for network mapping by large organizations? Each correct answer represents a complete solution. Choose three.

    Show answer & explanation

    Correct answers: B, C, D

    B, C, D

    B, C, D

    B, C, D

  4. Question 4

    Which of the following methods can be used to detect session hijacking attack?

    Show answer & explanation

    Correct answer: D

    D

  5. Question 5

    Which of the following attacks involves multiple compromised systems to attack a single target?

    Show answer & explanation

    Correct answer: D

    D

  6. Question 6Select 3

    Which of the following steps can be taken as countermeasures against sniffer attacks? Each correct answer represents a complete solution. Choose all that apply.

    Show answer & explanation

    Correct answers: A, B, D

    A, B, D

    A, B, D

    A, B, D

  7. Question 7Select 2

    Which of the following statements about buffer overflow are true?

    Each correct answer represents a complete solution. Choose two.

    Show answer & explanation

    Correct answers: B, D

    B, D

    B, D

  8. Question 8Select 2

    Which of the following statements are true about Dsniff?

    Each correct answer represents a complete solution. Choose two.

    Show answer & explanation

    Correct answers: A, D

    A, D

    A, D

  9. Question 9Select 5

    Andrew, a bachelor student of Faulkner University, creates a gmail account. He uses 'Faulkner' as the password for the gmail account. After a few days, he starts receiving a lot of e-mails stating that his gmail account has been hacked. He also finds that some of his important mails have been deleted by someone. Which of the following methods has the attacker used to crack Andrew's password? Each correct answer represents a complete solution. Choose all that apply.

    Show answer & explanation

    Correct answers: C, D, F, G, H

    C, D, F, G, H

    C, D, F, G, H

    C, D, F, G, H

    C, D, F, G, H

    C, D, F, G, H

  10. Question 10

    You work as a Network Penetration tester in the Secure Inc. Your company takes the projects to test the security of various companies. Recently, Secure Inc. has assigned you a project to test the security of a Web site. You go to the Web site login page and you run the following SQL query:

    What task will the above SQL query perform?

    SEC504 sample question 10
    Show answer & explanation

    Correct answer: D

    D

Ready for the real thing?

The full SEC504 simulator has every exam-style question, timed mode, and instant scoring.

Go to the SEC504 simulator →