Cisco 350-701 Practice Test - Questions Answers
List of questions
Related questions
In which form of attack is alternate encoding, such as hexadecimal representation, most often observed?
Smurf
distributed denial of service
cross-site scripting
rootkit exploit
Which flaw does an attacker leverage when exploiting SQL injection vulnerabilities?
user input validation in a web page or web application
Linux and Windows operating systems
database
web page images
Which two prevention techniques are used to mitigate SQL injection attacks? (Choose two)
Check integer, float, or Boolean string parameters to ensure accurate values.
Use prepared statements and parameterized queries.
Secure the connection between the web and the app tier.
Write SQL code instead of using object-relational mapping libraries.
Block SQL code execution in the web application database login.
Which two endpoint measures are used to minimize the chances of falling victim to phishing and social engineering attacks? (Choose two)
Patch for cross-site scripting.
Perform backups to the private cloud.
Protect against input validation and character escapes in the endpoint.
Install a spam and virus email filter.
Protect systems with an up-to-date antimalware program
Which two mechanisms are used to control phishing attacks? (Choose two)
Enable browser alerts for fraudulent websites.
Define security group memberships.
Revoke expired CRL of the websites.
Use antispyware software.
Implement email filtering techniques.
Which two behavioral patterns characterize a ping of death attack? (Choose two)
The attack is fragmented into groups of 16 octets before transmission.
The attack is fragmented into groups of 8 octets before transmission.
Short synchronized bursts of traffic are used to disrupt TCP connections.
Malformed packets are used to crash systems.
Publicly accessible DNS servers are typically used to execute the attack.
Which two preventive measures are used to control cross-site scripting? (Choose two)
Enable client-side scripts on a per-domain basis.
Incorporate contextual output encoding/escaping.
Disable cookie inspection in the HTML inspection engine.
Run untrusted HTML input through an HTML sanitization engine.
Same Site cookie attribute should not be used.
What is the difference between deceptive phishing and spear phishing?
Deceptive phishing is an attacked aimed at a specific user in the organization who holds a C-level role.
A spear phishing campaign is aimed at a specific person versus a group of people.
Spear phishing is when the attack is aimed at the C-level executives of an organization.
Deceptive phishing hijacks and manipulates the DNS server of the victim and redirects the user to a false webpage.
Which attack is commonly associated with C and C++ programming languages?
cross-site scripting
water holing
DDoS
buffer overflow
What is a language format designed to exchange threat intelligence that can be transported over the TAXII protocol?
STIX
XMPP
pxGrid
SMTP
Question