NO.1 Information gathered from social networking websites such as Facebook, Twitter and
LinkedIn can be used to launch which of the following types of attacks? (Choose two.)
A. SQL injection attack
B. Phishing attack
C. Distributed denial of service attack
D. Smurf attack
E. Fraggle attack
F. Social engineering attack
Answer: B,F

NO.2 Under what conditions does a secondary name server request a zone transfer from a primary
name server?
A. When the TTL falls to zero
B. When a primary name server has had its service restarted
C. When a secondary SOA is higher that a primary SOA
D. When a secondary name server has had its service restarted
E. When a primary SOA is higher that a secondary SOA
Answer: E

NO.3 Bill has successfully executed a buffer overflow against a Windows IIS web server. He has
been able to spawn an interactive shell and plans to deface the main web page. He first attempts to
use the "echo" command to simply overwrite index.html and remains unsuccessful. He then
attempts to delete the page and achieves no progress. Finally, he tries to overwrite it with another
page in which also he remains unsuccessful. What is the probable cause of Bill's problem?
A. You cannot use a buffer overflow to deface a web page
B. There is a problem with the shell and he needs to run the attack again
C. The HTML file has permissions of read only
D. The system is a honeypot
Answer: C

NO.4 An attacker is attempting to telnet into a corporation's system in the DMZ.
The attacker doesn't want to get caught and is spoofing his IP address.
After numerous tries he remains unsuccessful in connecting to the system.
The attacker rechecks that the target system is actually listening on Port 23 and he verifies it with
both nmap and hping2. He is still unable to connect to the target system. What could be the reason?
A. He is attacking an operating system that does not reply to telnet even when open
B. The firewall is blocking port 23 to that system
C. He cannot spoof his IP and successfully use TCP
D. He needs to use an automated tool to telnet in
Answer: C

