| Exam Code/Number: | 312-50v9Join the discussion |
| Exam Name: | Certified Ethical Hacker v9 Exam |
| Certification: | EC-COUNCIL |
| Question Number: | 125 |
| Publish Date: | Jul 18, 2026 |
|
Rating
100%
|
|
To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following tools would most likely be used in such as audit?
Under the "Post-attach Phase and Activities," it is the responsibility of the tester to restore the system to a pre-test state. Which of the following activities should not be included in this phase? I.Removing all files uploaded on the system II.Cleaning all registry entries III.Mapping of network state IV.Removing all tools and maintaining backdoor for reporting
An incident investigator asks to receive a copy of the event from all firewalls, prosy servers, and Intrusion Detection Systems (IDS) on the network of an organization that has experienced a possible breach of security. When the investigator attempts to correlate the information in all of the logs the sequence of many of the logged events do not match up.
What is the most likely cause?
Jesse receives an email with an attachment labeled "Court_Notice_21206.zip". Inside the zip file is a file named "Court_Notice_21206.docx.exe" disguised as a word document.Upon execution, a windows appears stating, "This word document is corrupt." In the background, the file copies itself to Jesse APPDATA\local directory and begins to beacon to a C2 server to download additional malicious binaries. What type of malware has Jesse encountered?
Which of the following is a low-tech way of gaining unauthorized access to systems?