
Reliable Certified Ethical Hacker 312-38 Dumps PDF Jan 27, 2022 Recently Updated Questions
Pass Your EC-COUNCIL 312-38 Exam with Correct 171 Questions and Answers
NEW QUESTION 84
Management asked their network administrator to suggest an appropriate backup medium for their backup plan that best suits their organization's need. Which of the following factors will the administrator consider when deciding on the appropriate backup medium? (Choose all that apply.)
- A. Reliability
- B. Accountability
- C. Extensibility
- D. Capability
Answer: A,C,D
NEW QUESTION 85
Which of the following techniques uses a modem in order to automatically scan a list of telephone numbers?
- A. Warkitting
- B. War driving
- C. War dialing
- D. Warchalking
Answer: C
Explanation:
War dialing is a technique of using a modem to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for computers, BBS systems, and fax machines. Hackers use the resulting lists for various purposes, hobbyists for exploration, and crackers (hackers that specialize in computer security) for password guessing.
Answer option C is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing and war driving.
Answer option A is incorrect. War driving, also called access point mapping, is the act of locating and possibly exploiting connections to wireless local area networks while driving around a city or elsewhere. To do war driving, one needs a vehicle, a computer (which can be a laptop), a wireless Ethernet card set to work in promiscuous mode, and some kind of an antenna which can be mounted on top of or positioned inside the car.
Because a wireless LAN may have a range that extends beyond an office building, an outside user may be able to intrude into the network, obtain a free Internet connection, and possibly gain access to company records and other resources.
Answer option D is incorrect. Warkitting is a combination of wardriving and rootkitting. In a warkitting attack, a hacker replaces the firmware of an attacked router. This allows them to control all traffic for the victim, and could even permit them to disable SSL by replacing HTML content as it is being downloaded. Warkitting was identified by Tsow, Jakobsson, Yang, and Wetzel in 2006. Their discovery indicated that 10% of the wireless routers were susceptible to WAPjacking (malicious configuring of the firmware settings, but making no modification on the firmware itself) and 4.4% of wireless routers were vulnerable to WAPkitting (subverting the router firmware). Their analysis showed that the volume of credential theft possible through Warkitting exceeded the estimates of credential theft due to phishing.
NEW QUESTION 86
Which of the following network devices operate at the network layer of the OSI model? Each correct answer
represents a complete solution. Choose all that apply.
- A. Gateway
- B. Router
- C. Repeater
- D. Bridge
Answer: A,B
Explanation:
A router is a device that routes data packets between computers in different networks. It is used to connect
multiple networks, and it determines the path to be taken by each data packet to its destination computer. A
router maintains a routing table of the available routes and their conditions. By using this information, along
with distance and cost algorithms, the router determines the best path to be taken by the data packets to the
destination computer. A router can connect dissimilar networks, such as Ethernet, FDDI, and Token Ring, and
route data packets among them. Routers operate at the network layer (layer 3) of the Open Systems
Interconnection (OSI) model.
A gateway is a network point that acts as an entrance to another network. On the Internet, a node or stopping
point can be either a gateway node or a host (end-point) node. Both the computers of Internet users and the
computers that serve pages to users are host nodes. The computers that control traffic within a company's
network or at a local Internet service provider (ISP) are gateway nodes. In the network for an enterprise, a
computer server acting as a gateway node is often also acting as a proxy server and a firewall server. A
gateway is often associated with both a router, which knows where to direct a given packet of data that arrives
at the gateway, and a switch, which furnishes the actual path in and out of the gateway for a given packet. Most
of the gateways operate at the application layer, but can operate at the network or session layer of the OSI
model.
Answer option C is incorrect. A repeater operates only at the physical layer of the OSI model.
Answer option B is incorrect. A bridge operates at the data link layer of the OSI model.
NEW QUESTION 87
The IP addresses reserved for multicasting belong to which of the following classes?
- A. Class E
- B. Class C
- C. Class B
- D. Class D
Answer: D
NEW QUESTION 88
Which of the following features is used to generate spam on the Internet by spammers and worms?
- A. AutoComplete
- B. Server Message Block (SMB) signing
- C. AutoFill
- D. SMTP relay
Answer: D
Explanation:
SMTP relay feature of e-mail servers allows them to forward e-mail to other e-mail servers. Unfortunately, this
feature is exploited by spammers and worms to generate spam on the Internet.
NEW QUESTION 89
Which of the following is a software tool used in passive attacks for capturing network traffic?
- A. Intrusion detection system
- B. Sniffer
- C. Intrusion prevention system
- D. Warchalking
Answer: B
Explanation:
A sniffer is a software tool that is used to capture any network traffic. Since a sniffer changes the NIC of the LAN card into promiscuous mode, the NIC begins to record incoming and outgoing data traffic across the network. A sniffer attack is a passive attack because the attacker does not directly connect with the target host. This attack is most often used to grab logins and passwords from network traffic. Tools such as Ethereal, Snort, Windump, EtherPeek, Dsniff are some good examples of sniffers. These tools provide many facilities to users such as graphical user interface, traffic statistics graph, multiple sessions tracking, etc. Answer option C is incorrect. An intrusion prevention system (IPS) is a network security device that monitors network and/or system activities for malicious or unwanted behavior and can react, in real-time, to block or prevent those activities. When an attack is detected, it can drop the offending packets while still allowing all other traffic to pass. Answer option B is incorrect. An IDS (Intrusion Detection System) is a device or software application that monitors network and/or system activities for malicious activities or policy violations and produces reports to a Management Station. Intrusion prevention is the process of performing intrusion detection and attempting to stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators. Answer option D is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing and war driving.
NEW QUESTION 90
Which of the following UTP cables uses four pairs of twisted cable and provides transmission speeds of up to 16 Mbps?
- A. Category 5e
- B. Category 6
- C. Category 3
- D. Category 5
Answer: C
Explanation:
Category 3 type of UTP cable uses four pairs of twisted cable and provides transmission speeds of up to 16 Mbps. They are commonly used in Ethernet networks that operate at the speed of 10 Mbps. A higher speed is also possible by these cables implementing the Fast Ethernet (100BaseT4) specifications. This cable is used mainly for telephone systems. Answer option B is incorrect. This category of UTP cable is the most commonly used cable in present day networks. It consists of four twisted pairs and is used in those Ethernet networks that run at the speed of 100 Mbps. Category 5 cable can also provide a higher speed of up to 1000 Mbps. Answer option A is incorrect. It is also known as Category 5 Enhanced cable. Its specification is the same as category 5, but it has some enhanced features and is used in Ethernets that run at the speed of 1000 Mbps. Answer option D is incorrect. This category of UTP cable is designed to support high-speed networks that run at the speed of 1000 Mbps. It consists of four pairs of wire and uses all of them for data transmission. Category 6 provides more than twice the speed of Category 5e, but is also more expensive.
NEW QUESTION 91
Which of the following fields in the IPv6 header is decremented by 1 for each router that forwards the packet?
- A. Next header
- B. Hop limit
- C. Traffic class
- D. Flow label
Answer: B
Explanation:
The hop limit field in the IPv6 header is decremented by 1 for each router that forwards a packet.
The packet is discarded when the hop limit field reaches zero.
Answer option B is incorrect. Next header is an 8-bit field that specifies the next encapsulated
protocol.
Answer option A is incorrect. Flow label is a 20-bit field that is used for specifying special router
handling from source to destination for a sequence of packets.
Answer option C is incorrect. Traffic class is an 8-bit field that specifies the Internet traffic priority
delivery value.
NEW QUESTION 92
Which of the following types of RAID offers no protection for the parity disk?
- A. RAID 5
- B. RAID 3
- C. RAID 2
- D. RAID 1
Answer: B
NEW QUESTION 93
What is the range for well known ports?
- A. 49152 through 65535
- B. Above 65535
- C. 1024 through 49151
- D. 0 through 1023
Answer: D
NEW QUESTION 94
This is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b,
and 802.11g standards. The main features of these tools are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
This tool is known as __________.
- A. THC-Scan
- B. Absinthe
- C. NetStumbler
- D. Kismet
Answer: C
Explanation:
NetStumbler is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a,
802.11b, and 802.11g standards. The main features of NetStumbler are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
Answer option A is incorrect. Kismet is an IEEE 802.11 layer2 wireless network detector, sniffer, and intrusion
detection system.
Answer option C is incorrect. THC-Scan is a war-dialing tool.
Answer option B is incorrect. Absinthe is an automated SQL injection tool.
NEW QUESTION 95
Which of the following tools is an open source protocol analyzer that can capture traffic in real time?
- A. Wireshark
- B. NetResident
- C. NetWitness
- D. None
- E. Bridle
Answer: A
Explanation:
Wireshark is an open source protocol analyzer that can capture traffic in real time. Wireshark is a free packet
sniffer computer application. It is used for network troubleshooting, analysis, software and communications
protocol development, and education. Wireshark is very similar to tcpdump, but it has a graphical front-end,
and many more information sorting and filtering options. It allows the user to see all traffic being passed over
the network (usually an Ethernet network but support is being added for others) by putting the network interface
into promiscuous mode.
Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by
pcap. It has the following features:
Data can be captured "from the wire" from a live network connection or read from a file that records the
already-captured packets.
Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback.
Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility,
tshark.
Captured files can be programmatically edited or converted via command-line switches to the "editcap"
program.
Data display can be refined using a display filter. Plugins can be created for dissecting new protocols.
Answer option C is incorrect. Snort is an open source network intrusion prevention and detection system that
operates as a network sniffer. It logs activities of the network that is matched with the predefined signatures.
Signatures can be designed for a wide range of traffic, including Internet Protocol (IP), Transmission Control
Protocol (TCP), User Datagram Protocol (UDP), and Internet Control Message Protocol (ICMP).
Answer option D is incorrect. NetWitness is used to analyze and monitor the network traffic and activity.
Answer option A is incorrect. Netresident is used to capture, store, analyze, and reconstruct network events
and activities.
NEW QUESTION 96
The network admin decides to assign a class B IP address to a host in the network. Identify which of the following addresses fall within a class B IP address range.
- A. 172.168.12.4
- B. 255.255.255.0
- C. 169.254.254.254
- D. 18.12.4.1
Answer: A
NEW QUESTION 97
Which of the following network scanning tools is a TCP/UDP port scanner that works as a ping sweeper and hostname resolver?
- A. Nmap
- B. Netstat
- C. Hping
- D. SuperScan
Answer: D
Explanation:
SuperScan is a TCP/UDP port scanner. It also works as a ping sweeper and hostname resolver. It
can ping a given range of IP addresses and resolve the host name of the remote system.
The features of SuperScan are as follows:
It scans any port range from a built-in list or any given range.
It performs ping scans and port scans using any IP range.
It modifies the port list and port descriptions using the built in editor.
It connects to any discovered open port using user-specified "helper" applications.
It has the transmission speed control utility.
Answer option D is incorrect. Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows, etc. Answer option C is incorrect. Netstat (network statistics) is a command-line tool that displays network connections (both incoming and outgoing), routing tables, and a number of network interface statistics. It is available on Unix, Unix-like, and Windows NT-based operating systems. It is used to find problems on the network and to determine the amount of traffic on the network as a performance measurement. Answer option A is incorrect. Hping is a free packet generator and analyzer for the TCP/IP protocol. Hping is one of the de facto tools for security auditing and testing of firewalls and networks. The new version of hping, hping3, is scriptable using the Tcl language and implements an engine for string based, human readable description of TCP/IP packets, so that the programmer can write scripts related to low level TCP/IP packet manipulation and analysis in very short time. Like most tools used in computer security, hping is useful to both system administrators and crackers (or script kiddies).
NEW QUESTION 98
Sophie has been working as a Windows network administrator at an MNC over the past 7 years. She wants to check whether SMB1 is enabled or disabled. Which of the following command allows Sophie to do so?
- A. Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol
- B. Get-WindowsOptionalFeatures -Online -FeatureNames SMB1Protocol
- C. Get-WindowsOptionalFeatures -Online -FeatureName SMB1Protocol
- D. Get-WindowsOptionalFeature -Online -FeatureNames SMB1Protocol
Answer: A
NEW QUESTION 99
Which of the following is a term to describe the use of inert gases and chemical agents to extinguish a fire?
- A. Fire suppression system
- B. Fire sprinkler
- C. Gaseous fire suppression
- D. Fire alarm system
Answer: C
NEW QUESTION 100
Which of the following is a distributed application architecture that partitions tasks or work loads between service providers and service requesters?Each correct answer represents a complete solution. Choose all that apply.
- A. Peer-to-peer (P2P) computing
- B. Peer-to-peer networking
- C. Client-server computing
- D. Client-server networking
Answer: C,D
Explanation:
Client-server networking is also known as client-server computing. It is a distributed application architecture that partitions tasks or work loads between service providers (servers) and service requesters, called clients. Often clients and servers operate over a computer network on separate hardware. A server machine is a high-performance host that is running one or more server programs which share its resources with clients. A client does not share any of its resources, but requests a server's content or service function. Clients therefore initiate communication sessions with servers which await (listen to) incoming requests. Answer options D and B are incorrect. Peer-to-peer (P2P) computing or networking is a distributed application architecture that partitions tasks or workloads between peers. Peers are equally privileged, equipotent participants in the application. They are said to form a peer-to-peer network of nodes. Peer-to-peer networking (also known simply as peer networking) differs from client-server networking, where certain devices have the responsibility to provide or "serve" data, and other devices consume or otherwise act as "clients" of those servers.
NEW QUESTION 101
Which among the following is used to limit the number of cmdlets or administrative privileges of administrator, user, or service accounts?
- A. User Account Control (UAC)
- B. Credential Guard
- C. Just Enough Administration (EA)
- D. Windows Security Identifier (SID)
Answer: C
NEW QUESTION 102
......
Understanding functional and technical aspects of Certified Network Defender Security Principles and Practices
The following will be discussed in ECCOUNCIL EC 312-38 dumps:
- Understand principal objective, advantages, and difficulties in network protection
- Discuss firewall execution and sending measure
- Describe Attacker’s Hacking Methodologies and Frameworks
- Describe the different instances of social designing assault strategies
- Obtain consistence with administrative structures
- Describe the different instances of cell phone explicit assault methods
- Describe the different instances of applicationlevel assault strategies
- Learn to plan and foster security approaches
- Select firewalls dependent on its profound traffic examination ability
- Discuss firewall organization exercises - Understand job, abilities, limits, and worries in IDS arrangement
- Understand firewall geographies and their use - Distinguish between equipment, programming, have, network, inner, and outer firewalls
- Discuss the determination of fitting IDS arrangements
- Distributed and Mobile Computing World
- Describe the different instances of cloud-explicit assault methods
- Explain fundamental wordings identified with network security assaults
- Discuss Identity and Access Management (IAM) ideas
- Discuss different Regulatory Frameworks, Laws, and Acts
- Discuss security advantages of organization division strategies
- Understand various sorts of firewall advances and their use
- Discuss access control standards, wordings, and models
- Learn to how to manage bogus positive and bogus negative IDS cautions
- Discuss different cryptographic calculations
- Describe the different instances of organization level assault strategies
- Describe the different instances of remote organization explicit assault methods
- Discuss switch and switch safety efforts, proposals, and best practices
- Discuss suggestions and best practices for secure firewall Implementation and arrangement
- Discuss IDS/IPS arrangement - Discuss different parts of IDS - Discuss viable organization of organization and host-based IDS
- Describe the different instances of email assault methods
- Redefine Access Control security in Today’s
- Leverage Zero Trust Model Security utilizing Programming Defined Perimeter (SDP)
- Discuss different fundamental organization security arrangements
- Discuss different fundamental organization security conventions
- Discuss other regulatory safety efforts
- Discuss cryptographic security procedures
- Understand firewall security concerns, abilities, and impediments
- Explain Continual/Adaptive security procedure
- Describe the different instances of host-level assault strategies
- Explain protection top to bottom security system
- Discuss different NIDS and HIDS Solutions with their interruption location capacities
- Conduct security mindfulness preparing
For more info read reference:
Latest 2022 Realistic Verified 312-38 Dumps: https://www.passreview.com/312-38_exam-braindumps.html
Pass 312-38 Exam Updated 171 Questions: https://drive.google.com/open?id=1VB1cpyJ82ylxOq7wEZT3zrag5f0hQv4J