Free EC-Council 312-50v12 Exam Braindumps (page: 21)

What is the role of test automation in security testing?

  1. It is an option but it tends to be very expensive.
  2. It should be used exclusively. Manual testing is outdated because of low speed and possible test setup inconsistencies.
  3. Test automation is not usable in security due to the complexity of the tests.
  4. It can accelerate benchmark tests and repeat them with a consistent test setup. But it cannot replace manual testing completely.

Answer(s): D



Your company performs penetration tests and security assessments for small and medium-sized business in the local area. During a routine security assessment, you discover information that suggests your client is involved with human trafficking.

What should you do?

  1. Confront the client in a respectful manner and ask her about the data.
  2. Copy the data to removable media and keep it in case you need it.
  3. Ignore the data and continue the assessment until completed as agreed.
  4. Immediately stop work and contact the proper legal authorities.

Answer(s): D



While using your bank’s online servicing you notice the following string in the URL bar: “http://www.MyPersonalBank.com/account?id=368940911028389&Damount=10980&Camount=21”

You observe that if you modify the Damount&Camount values and submit the request, that data on the web page reflect the changes.

Which type of vulnerability is present on this site?

  1. Cookie Tampering
  2. SQL Injection
  3. Web Parameter Tampering
  4. XSS Reflection

Answer(s): C



The establishment of a TCP connection involves a negotiation called three-way handshake. What type of message does the client send to the server in order to begin this negotiation?

  1. ACK
  2. SYN
  3. RST
  4. SYN-ACK

Answer(s): B






Post your Comments and Discuss EC-Council 312-50v12 exam prep with other Community members:

312-50v12 Exam Discussions & Posts