Sep-2021 Latest PassReview 312-38 Exam Dumps with PDF and Exam Engine Free Updated Today!
Following are some new 312-38 Real Exam Questions!
NEW QUESTION 19
With which of the following flag sets does the Xmas tree scan send a TCP frame to a remote device? Each correct answer represents a part of the solution. Choose all that apply.
- A. PUSH
- B. FIN
- C. RST
- D. URG
Answer: A,B,D
Explanation:
With the URG, PUSH, and FIN flag sets, the Xmas tree scan sends a TCP frame to a remote device. The Xmas tree scan is called an Xmas tree scan because the alternating bits are turned on and off in the flags byte (00101001), much like the lights of a Christmas tree. Answer option B is incorrect. The RST flag is not set when the Xmas tree scan sends a TCP frame to a remote device.
NEW QUESTION 20
Which of the following help in estimating and totaling up the equivalent money value of the benefits and costs to the community of projects for establishing whether they are worthwhile?
Each correct answer represents a complete solution. Choose all that apply.
- A. Cost-benefit analysis
- B. Business Continuity Planning
- C. Benefit-Cost Analysis
- D. Disaster recovery
Answer: A,C
Explanation:
Cost-benefit analysis is a process by which business decisions are analyzed. It is used to estimate and total up the equivalent money value of the benefits and costs to the community of projects for establishing whether they are worthwhile. It is a term that refers both to:
helping to appraise, or assess, the case for a project, program, or policy proposal; an approach to making economic decisions of any kind. Under both definitions, the process involves, whether explicitly or implicitly, weighing the total expected costs against the total expected benefits of one or more actions in order to choose the best or most profitable option. The formal process is often referred to as either CBA (Cost-Benefit Analysis) or BCA (Benefit-Cost Analysis).
Answer option A is incorrect. Business Continuity Planning (BCP) is the creation and validation of a practiced logistical plan that defines how an organization will recover and restore partially or completely interrupted critical (urgent) functions within a predetermined time after a disaster or extended disruption. The logistical plan is called a Business Continuity Plan.
Answer option C is incorrect. Disaster recovery is the process, policies, and procedures related to preparing for recovery or continuation of technology infrastructure critical to an organization after a natural or human-induced disaster. Disaster recovery planning is a subset of a larger process known as business continuity planning and should include planning for resumption of applications, data, hardware, communications (such as networking) and other IT infrastructure. A business continuity plan (BCP) includes planning for non-IT related aspects such as key personnel, facilities, crisis communication and reputation protection, and should refer to the disaster recovery plan (DRP) for IT related infrastructure recovery / continuity.
NEW QUESTION 21
Which of the following is a passive attack?
- A. Session hijacking
- B. Unauthorized access
- C. Traffic analysis
- D. Replay attack
Answer: C
NEW QUESTION 22
Which of the following is a method of authentication that uses physical characteristics?
- A. ACL
- B. Honeypot
- C. COMSEC
- D. Biometrics
Answer: D
NEW QUESTION 23
Which of the following encryption techniques do digital signatures use?
- A. IDEA
- B. RSA
- C. MD5
- D. Blowfish
Answer: C
NEW QUESTION 24
Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?
- A. NetRanger
- B. Nmap
- C. Hping
- D. PSAD
Answer: D
Explanation:
PSAD is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic. It includes many signatures from the IDS to detect probes for various backdoor programs such as EvilFTP, GirlFriend, SubSeven, DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS). If it is combined with fwsnort and the Netfilter string match extension, it detects most of the attacks described in the Snort rule set that involve application layer data. Answer option C is incorrect. NetRanger is the complete network configuration and information toolkit that includes the following tools: a Ping tool, Trace Route tool, Host Lookup tool, Internet time synchronizer, Whois tool, Finger Unix hosts tool, Host and port scanning tool, check multiple POP3 mail accounts tool, manage dialup connections tool, Quote of the day tool, and monitor Network Settings tool. These tools are integrated in order to use an application interface with full online help. NetRanger is designed for both new and experienced users. This tool is used to help diagnose network problems and to get information about users, hosts, and networks on the Internet or on a user computer network. NetRanger uses multi-threaded and multi-connection technologies in order to be very fast and efficient. Answer option B is incorrect. Hping is a free packet generator and analyzer for the TCP/IP protocol. Hping is one of the de facto tools for security auditing and testing of firewalls and networks. The new version of hping, hping3, is scriptable using the Tcl language and implements an engine for string based, human readable description of TCP/IP packets, so that the programmer can write scripts related to low level TCP/IP packet manipulation and analysis in very short time. Like most tools used in computer security, hping is useful to both system administrators and crackers (or script kiddies). Answer option A is incorrect. Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows, etc.
NEW QUESTION 25
Which of the following is a service discovery protocol that allows computers and other devices to find services in a local area network without prior configuration?
- A. NTP
- B. SLP
- C. DCAP
- D. NNTP
Answer: B
Explanation:
The Service Location Protocol (SLP, srvloc) is a service discovery protocol that allows computers and other devices to find services in a local area network without prior configuration. SLP has been designed to scale from small, unmanaged networks to large enterprise networks. Answer option C is incorrect. The Network News Transfer Protocol (NNTP) is an Internet application protocol used for transporting Usenet news articles (netnews) between news servers and for reading and posting articles by end user client applications. NNTP is designed so that news articles are stored in a central database, allowing the subscriber to select only those items that he wants to read. Answer option A is incorrect. Network Time Protocol (NTP) is used to synchronize the timekeeping among the number of distributed time servers and clients. It is used for the time management in a large and diverse network that contains many interfaces. In this protocol, servers define the time, and clients have to be synchronized with the defined time. These clients can choose the most reliable source of time defined from the several NTP servers for their information transmission. Answer option D is incorrect. The Data Link Switching Client Access Protocol (DCAP) is an application layer protocol that is used between workstations and routers for transporting SNA/NetBIOS traffic over TCP sessions. It was introduced in order to address a few deficiencies by the Data Link Switching Protocol (DLSw). The DLSw raises the important issues of scalability and efficiency, and since DLSw is a switch-to-switch protocol, it is not efficient when implemented on workstations. DCAP was introduced in order to address these issues.
NEW QUESTION 26
Which of the following layers provides communication session management between host computers?
- A. Transport layer
- B. Internet layer
- C. Application layer
- D. Link layer
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 27
Which of the following is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies?
- A. Bridge
- B. Router
- C. Switch
- D. Gateway
Answer: D
Explanation:
A gateway is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies. It provides greater functionality than a router or bridge because a gateway functions both as a translator and a router. Gateways are slower than bridges and routers. A gateway is an application layer device. Answer option B is incorrect. A router is an electronic device that interconnects two or more computer networks. It selectively interchanges packets of data between them. It is a networking device whose software and hardware are customized to the tasks of routing and forwarding information. It helps in forwarding data packets between networks. Answer option C is incorrect. A bridge is an interconnectivity device that connects two local area networks (LANs) or two segments of the same LAN using the same communication protocols, and provides address filtering between them. Users can use this device to divide busy networks into segments and reduce network traffic. A bridge broadcasts data packets to all the possible destinations within a specific segment. Bridges operate at the data-link layer of the OSI model. Answer option D is incorrect. A switch is a network device that selects a path or circuit for sending a data unit to its next destination. It is not required in smaller networks, but is required in large inter-networks, where there can be many possible ways of transmitting a message from a sender to destination. The function of switch is to select the best possible path. On an Ethernet local area network (LAN), a switch determines from the physical device (Media Access Control or MAC) address in each incoming message frame which output port to forward it to and out of. In a wide area packet-switched network, such as the Internet, a switch determines from the IP address in each packet which output port to use for the next part of its trip to the intended destination.
NEW QUESTION 28
Which of the following features is used to generate spam on the Internet by spammers and worms?
- A. AutoComplete
- B. SMTP relay
- C. Server Message Block (SMB) signing
- D. AutoFill
Answer: B
Explanation:
SMTP relay feature of e-mail servers allows them to forward e-mail to other e-mail servers. Unfortunately, this
feature is exploited by spammers and worms to generate spam on the Internet.
NEW QUESTION 29
Identify the minimum number of drives required to setup RAID level 5.
- A. 0
- B. 1
- C. Multiple
- D. 2
Answer: B
NEW QUESTION 30
The IP addresses reserved for experimental purposes belong to which of the following classes?
- A. Class D
- B. Class A
- C. Class E
- D. Class C
Answer: C
NEW QUESTION 31
Which of the following steps are required in an idle scan of a closed port?
Each correct answer represents a part of the solution. Choose all that apply.
- A. The zombie's IP ID increases by only 1.
- B. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.
- C. The attacker sends a SYN/ACK to the zombie.
- D. In response to the SYN, the target sends a RST.
- E. The zombie's IP ID increases by 2.
Answer: A,B,C,D
Explanation:
Following are the steps required in an idle scan of a closed port:
1.Probe the zombie's IP ID: The attacker sends a SYN/ACK to the zombie. The zombie, unaware
of the SYN/ACK, sends back a RST, thus disclosing its IP ID.
2.Forge a SYN packet from the zombie: In response to the SYN, the target sends a RST. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.
3.Probe the zombie's IP ID again: The zombie's IP ID has increased by only 1 since step 1. So the port is closed.
NEW QUESTION 32
Which of the following IEEE standards adds QoS features and multimedia support?
- A. 802.11b
- B. 802.5
- C. 802.11e
- D. 802.11a
Answer: C
NEW QUESTION 33
Which of the following tools is used for wireless LANs detection?
- A. Airopeek
- B. NetStumbler
- C. Sniffer
- D. Fort Knox
Answer: B
NEW QUESTION 34
......
Resources From:
- 2021 Latest PassReview 312-38 Exam Dumps (PDF & Exam Engine) Free Share: https://www.passreview.com/312-38_exam-braindumps.html
- 2021 Latest PassReview 312-38 PDF and 312-38 Exam Dumps Free Share: https://drive.google.com/open?id=1mTe5vGMzC4tacJsuhcaev0Pu0cr6Urzd
Free Resources from PassReview, We Devoted to Helping You 100% Pass All Exams!