Free CEH-001 Exam Braindumps (page: 96)

Page 95 of 220

A Security Engineer at a medium-sized accounting firm has been tasked with discovering how much information can be obtained from the firm's public facing web servers. The engineer decides to start by using netcat to port 80.
The engineer receives this output:

HTTP/1.1 200 OK
Server: Microsoft-IIS/6
Expires: Tue, 17 Jan 2011 01:41:33 GMT
Date. Mon, 16 Jan 2011 01:41:33 GMT
Content-Type. text/html
Accept-Ranges: bytes
Last-Modified. Wed, 28 Dec 2010 15:32:21 GMT
ETaG. "b0aac0542e25c31:89d"
Content-Length: 7369

Which of the following is an example of what the engineer performed?

  1. Cross-site scripting
  2. Banner grabbing
  3. SQL injection
  4. Whois database query

Answer(s): B



To reduce the attack surface of a system, administrators should perform which of the following processes to remove unnecessary software, services, and insecure configuration settings?

  1. Harvesting
  2. Windowing
  3. Hardening
  4. Stealthing

Answer(s): C



While conducting a penetration test, the tester determines that there is a firewall between the tester's machine and the target machine. The firewall is only monitoring TCP handshaking of packets at the session layer of the OSI model. Which type of firewall is the tester trying to traverse?

  1. Packet filtering firewall
  2. Application-level firewall
  3. Circuit-level gateway firewall
  4. Stateful multilayer inspection firewall

Answer(s): C



Which type of scan is used on the eye to measure the layer of blood vessels?

  1. Facial recognition scan
  2. Retinal scan
  3. Iris scan
  4. Signature kinetics scan

Answer(s): B






Post your Comments and Discuss GAQM CEH-001 exam with other Community members:

CEH-001 Exam Discussions & Posts