
CertNexusCyberSec First Responder (CFR)
Domain 1Objective 5
Objective 1.5 Exploiting Vulnerabilities in Systems. CYBERSEC-FIRST-RESPONDER Practice Questions (Page 6)
Part of the 1.0 Attack Computing Environments to Test Cybersecurity domain, which accounts for 52% of the CYBERSEC-FIRST-RESPONDER exam.
67questions here
14free pages
26concepts
52%of the exam
Questions 26–30
- 26
A penetration tester is on a network and wants to perform a man-in-the-middle attack to intercept credentials from a target host. The tester wants a tool that can automate ARP poisoning and also capture the intercepted traffic. Which tool is best suited for this task?
Select an answer first - 27
A penetration tester successfully performs ARP poisoning to intercept traffic between a user and a web application. The application uses HTTPS, and the tester cannot decrypt the TLS session. However, the tester notices that the application sets a session cookie without the Secure flag. Which technique could the tester use to hijack the user's session despite the HTTPS encryption?
Select an answer first - 28
What is the risk of poorly configured file permissions?
Select an answer first - 29
What is John the Ripper used for?
Select an answer first - 30
What is a distributed denial-of-service (DDoS) attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CertNexus. “CYBERSEC-FIRST-RESPONDER” is a trademark of its owner, used for identification only.