312-50v11 Attack Practice Questions
The free 312-50v11: Certified Ethical Hacker v11 questions that deal with attack, with answers and explanations. The full bank and the timed practice test cover every topic the exam asks about.
Question #3
A network administrator discovers several unknown files in the root directory of his Linux FTP server. One of the files is a tarball, two are shell script files, and the third is a binary file is named "nc." The FTP server's access logs show that the anonymous user account logged in to the server, uploaded the files, and extracted the contents of the tarball and ran the script using a function provided by the FTP server's software. The “ps” command shows that the “nc” file is running as process, and the netstat command shows the “nc” process is listening on a network port. What kind of vulnerability must be present to make this remote attack possible?
Correct answer: A
Explanation
The anonymous FTP account could write files and run a script through the server software, which only happens when directory and file permissions allow unauthenticated writes. Privilege escalation, traversal and brute force are not needed to explain the upload and execution.
Question #4
When a normal TCP connection starts, a destination host receives a SYN (synchronize/start) packet from a source host and sends back a SYN/ACK (synchronize acknowledge). The destination host must then hear an ACK (acknowledge) of the SYN/ACK before the connection is established. This is referred to as the "TCP three-way handshake." While waiting for the ACK to the SYN ACK, a connection queue of finite size on the destination host keeps track of connections waiting to be completed. This queue typically empties quickly since the ACK is expected to arrive a few milliseconds after the SYN ACK. How would an attacker exploit this design by launching TCP SYN attack?
Correct answer: B
Explanation
A SYN flood fills the destination's half-open connection queue with requests bearing spoofed source addresses, so the final ACK never arrives and legitimate connections are refused. Random destinations or ACK and RST packets do not consume that queue.
Continue with 312-50v11: Certified Ethical Hacker v11 Exam
Unlock the full question bank
You have read the first 10 questions. A subscription opens every question in 312-50v11: Certified Ethical Hacker v11 Exam, the full timed practice test, and your progress and weak-topic reporting.
Single exam
$19.99for 30 days
Full question bank and practice test for one exam, for 30 days.
Single exam
$49.99for 1 year
One exam for a full year. Nothing renews and nothing to cancel.
Full access
$39.99/mo
Every exam in the catalogue, month to month.
Full access
$199.99/yr
Every exam in the catalogue for a year.
Already subscribed? Sign in to pick up where you left off.
All 312-50v11: Certified Ethical Hacker v11 practice questions →
