NO.1 You work as a Network Administrator for Net Perfect Inc. The company has a Windows-based
network. The company
wants to fix potential vulnerabilities existing on the tested systems. You use Nessus as a vulnerability
program to fix the vulnerabilities. Which of the following vulnerabilities can be fixed using Nessus?
Each correct answer represents a complete solution. Choose all that apply.
A. Vulnerabilities that allow a remote cracker to control sensitive data on a system
B. Vulnerabilities that help in Code injection attacks
C. Vulnerabilities that allow a remote cracker to access sensitive data on a system
D. Misconfiguration (e.g. open mail relay, missing patches, etc.)
Answer: A,C,D

NO.2 Which of the following statements are true about netcat?
Each correct answer represents a complete solution. Choose all that apply.
A. It provides outbound and inbound connections for TCP and UDP ports.
B. The nc -z command can be used to redirect stdin/stdout from a program.
C. It can be used as a file transfer solution.
D. It provides special tunneling, such as UDP to TCP, with the possibility of specifying all network
Answer: A,C,D

NO.3 Which of the following threats is a combination of worm, virus, and Trojan horse
A. Rootkits
B. Spyware
C. Blended
D. Heuristic
Answer: C

NO.4 Which of the following is a type of computer security vulnerability typically found in Web
applications that allow code
injection by malicious Web users into the Web pages viewed by other users?
A. SID filtering
B. Privilege Escalation
C. Cross-site scripting
D. Cookie poisoning
Answer: C

