ExamGecko
Home / ECCouncil / 112-51 / List of questions
Ask Question

ECCouncil 112-51 Practice Test - Questions Answers, Page 2

Add to Whishlist

List of questions

Question 11

Report Export Collapse

Cibel.org, an organization, wanted to develop a web application for marketing its products to the public. In this process, they consulted a cloud service provider and requested provision of development tools, configuration management, and deployment platforms for developing customized applications.

Identify the type of cloud service requested by Cibel.org in the above scenario.

Security-as-a-service (SECaaS)
Security-as-a-service (SECaaS)
Platform-as-a-service
Platform-as-a-service
Infrastructure-as-a-service {laaS)
Infrastructure-as-a-service {laaS)
ldentity-as-a-service {IDaaS)
ldentity-as-a-service {IDaaS)
Suggested answer: B
Explanation:

The type of cloud

The type of cloud service requested by Cibel.org in the above scenario is Platform-as-a-service (PaaS). PaaS is a cloud-based service that delivers a range of developer tools and deployment capabilities. PaaS provides a complete, ready-to-use, cloud-hosted platform for developing, running, maintaining and managing applications. PaaS customers do not need to install, configure, or manage the underlying infrastructure, such as servers, storage, network, or operating system. Instead, they can focus on the application development and deployment process, using the tools and services provided by the cloud service provider. PaaS solutions support cloud-native development technologies, such as microservices, containers, Kubernetes, serverless computing, that enable developers to build once, then deploy and manage consistently across private cloud, public cloud and on-premises environments. PaaS also offers features such as scalability, availability, security, backup, and monitoring for the applications.PaaS is suitable for organizations that want to develop customized applications without investing in or maintaining the infrastructure123.Reference:

Network Defense Essentials Courseware, EC-Council, 2020, pp. 3-40 to 3-41

What is PaaS? A Beginner's Guide to Platform as a Service - G2, G2, February 19, 2020

Cloud Service Models Explained: SaaS, IaaS, PaaS, FaaS - Jelvix, Jelvix, July 14, 2020

asked 18/09/2024
Ricardson Albuquerque
38 questions

Question 12

Report Export Collapse

Ben, a computer user, applied for a digital certificate. A component of PKI verifies Ben's identity using the credentials provided and passes that request on behalf of Ben to grant the digital certificate.

Which of the following PKI components verified Ben as being legitimate to receive the certificate?

Certificate authority (CA)
Certificate authority (CA)
Registration authority {RA)
Registration authority {RA)
Certificate directory
Certificate directory
Validation authority (VA)
Validation authority (VA)
Suggested answer: B
Explanation:

The PKI component that verified Ben as being legitimate to receive the certificate is the registration authority (RA). An RA is an entity that is responsible for identifying and authenticating certificate applicants, approving or rejecting certificate applications, and initiating certificate revocations or suspensions under certain circumstances. An RA acts as an intermediary between the certificate authority (CA) and the certificate applicant, and performs the necessary checks and validations before forwarding the request to the CA. The CA is the entity that signs and issues the certificates, and maintains the certificate directory and the certificate revocation list. A certificate directory is a repository of issued certificates that can be accessed by users or applications to verify the validity and status of a certificate. A validation authority (VA) is an entity that provides online certificate validation services, such as OCSP or SCVP, to verify the revocation status of a certificate in real time123.

Reference:

Public key infrastructure - Wikipedia, Wikipedia, March 16, 2021

Components of a PKI - The National Cyber Security Centre, NCSC, 2020

Network Defense Essentials Courseware, EC-Council, 2020, pp. 3-26 to 3-27

asked 18/09/2024
Gift Thanyane
37 questions

Question 13

Report Export Collapse

George, a certified security professional, was hired by an organization to ensure that the server accurately responds to customer requests. In this process, George employed a security solution to monitor the network traffic toward the server. While monitoring the traffic, he identified attack signatures such as SYN flood and ping of death attempts on the server.

Which of the following categories of suspicious traffic signature has George identified in the above scenario?

Informational
Informational
Reconnaissance
Reconnaissance
Unauthorized access
Unauthorized access
Denial-of-service (DoS)
Denial-of-service (DoS)
Suggested answer: D
Explanation:

Denial-of-service (DoS) is the category of suspicious traffic signature that George identified in the above scenario. DoS signatures are designed to detect attempts to disrupt or degrade the availability or performance of a system or network by overwhelming it with excessive or malformed traffic. SYN flood and ping of death are examples of DoS attacks that exploit the TCP/IP protocol to consume the resources or crash the target server. A SYN flood attack sends a large number of TCP SYN packets to the target server, without completing the three-way handshake, thus creating a backlog of half-open connections that exhaust the server's memory or bandwidth. A ping of death attack sends a malformed ICMP echo request packet that exceeds the maximum size allowed by the IP protocol, thus causing the target server to crash or reboot. DoS attacks can cause serious damage to the organization's reputation, productivity, and revenue, and should be detected and mitigated as soon as possible123.

Reference:

Network Defense Essentials Courseware, EC-Council, 2020, pp. 3-33 to 3-34

What is a denial-of-service attack?, Cloudflare, 2020

Denial-of-service attack - Wikipedia, Wikipedia, March 16, 2021

asked 18/09/2024
Hristo Slaveev
33 questions

Question 14

Report Export Collapse

Identify the loT communication model that serves as an analyzer for a company to track monthly or yearly energy consumption. Using this analysis, companies can reduce the expenditure on energy.

Device-to-device model
Device-to-device model
Cloud-to-cloud model
Cloud-to-cloud model
Device-to-cloud model
Device-to-cloud model
Device-to-gateway model
Device-to-gateway model
Suggested answer: C
Explanation:

The loT communication model that serves as an analyzer for a company to track monthly or yearly energy consumption is the device-to-cloud model. The device-to-cloud model is a loT communication model where the loT devices, such as smart meters, sensors, or thermostats, send data directly to the cloud platform, such as AWS, Azure, or Google Cloud, over the internet. The cloud platform then processes, analyzes, and stores the data, and provides feedback, control, or visualization to the users or applications. The device-to-cloud model enables the company to monitor and optimize the energy consumption of the loT devices in real time, and to leverage the cloud services, such as machine learning, big data analytics, or artificial intelligence, to perform advanced energy management and demand response. The device-to-cloud model also reduces the complexity and cost of the loT infrastructure, as it does not require intermediate gateways or servers to connect the loT devices to the cloud123.

Reference:

Network Defense Essentials Courseware, EC-Council, 2020, pp. 3-38 to 3-39

loT Communication Models: Device-to-Device, Device-to-Cloud, Device-to-Gateway, and Back-End Data-Sharing, DZone, July 9, 2018

loT Communication Models: Device-to-Device, Device-to-Cloud, Device-to-Gateway, and Back-End Data-Sharing, Medium, March 26, 2019

asked 18/09/2024
Bruno De Brida
36 questions

Question 15

Report Export Collapse

Amber is working as a team lead in an organization. She was instructed to share a policy document with all the employees working from remote locations and collect them after filling. She shared the files from her mobile device to the concerned employees through the public Internet. An unauthorized user accessed the file in transit, modified the file, and forwarded it to the remote employees.

Based on the above scenario, identify the security risk associated with mobile usage policies.

Become a Premium Member for full access
  Unlock Premium Member

Question 16

Report Export Collapse

Barbara, a security professional, was monitoring the loT traffic through a security solution. She identified that one of the infected devices is trying to connect with other loT devices and spread malware onto the network. Identify the port number used by the malware to spread the infection to other loT devices.

Become a Premium Member for full access
  Unlock Premium Member

Question 17

Report Export Collapse

Below are the various steps involved in establishing a network connection using the shared key authentication process.

1.The AP sends a challenge text to the station.

2.The station connects to the network.

3.The station encrypts the challenge text using its configured 128-bit key and sends the encrypted text to the AP.

4.The station sends an authentication frame to the AP.

5.The AP uses its configured WEP key to decrypt the encrypted text and compares it with the original challenge text.

What is the correct sequence of steps involved in establishing a network connection using the shared key authentication process?

Become a Premium Member for full access
  Unlock Premium Member

Question 18

Report Export Collapse

Identify the backup mechanism that is performed within the organization using external devices such as hard disks and requires human interaction to perform the backup operations, thus, making it suspectable to theft or natural disasters.

Become a Premium Member for full access
  Unlock Premium Member

Question 19

Report Export Collapse

Which of the following types of network traffic flow does not provide encryption in the data transfer process, and the data transfer between the sender and receiver is in plain text?

Become a Premium Member for full access
  Unlock Premium Member

Question 20

Report Export Collapse

Alice was working on her major project; she saved all her confidential files and locked her laptop. Bob wanted to access Alice's laptop for his personal use but was unable to access the laptop due to biometric authentication.

Which of the following network defense approaches was employed by Alice on her laptop?

Become a Premium Member for full access
  Unlock Premium Member
Total 75 questions
Go to page: of 8
Search

Related questions