試験科目:Certified Ethical Hacker (CEH)
問題と解答:全878問 CEH-001 資格取得

試験科目:Certified Business Analyst (CBA) - Foundation
問題と解答:全160問 CBAF-001 テストトレーニング

NO.1 Which of the following network attacks takes advantage of weaknesses in the fragment
reassembly functionality of the TCP/IP protocol stack?
A. SYN flood
B. Smurf attack
C. Teardrop
D. Ping of death
Answer: C

NO.2 Assuring two systems that are using IPSec to protect traffic over the internet, what type of
general attack could compromise the data?
A. Trojan Horse Attack
B. Smurf Attack
C. Back Orifice Attack
D. Spoof Attack
E. Man inthe Middle Attack
Answer: A,C

To compromise the data, the attack would need to be executed before the encryption takes place at
either end of the tunnel. Trojan Horse and Back Orifice attacks both allow for potential data
manipulation on host computers. In both cases, the data would be compromised either before
encryption or after decryption, so IPsec is not preventing the attack.

NO.3 A digital signature is simply a message that is encrypted with the public key instead of the
private key.
A. false
B. true
Answer: A

NO.4 Bill has successfully executed a buffer overflow against a Windows IIS web server. He has
been able to spawn an interactive shell and plans to deface the main web page. He first attempts to
use the "echo" command to simply overwrite index.html and remains unsuccessful. He then
attempts to delete the page and achieves no progress. Finally, he tries to overwrite it with another
page in which also he remains unsuccessful. What is the probable cause of Bill's problem?
A. The HTML file has permissions of read only
B. The system is a honeypot
C. There is a problem with the shell and he needs to run the attack again
D. You cannot use a buffer overflow to deface a web page
Answer: A

