Certified Ethical Hacker 312-38 Dumps Full Questions with Free PDF Questions to Pass [Q93-Q114]

Share

Certified Ethical Hacker 312-38 Dumps Full Questions with Free PDF Questions to Pass

100% Updated EC-COUNCIL 312-38 Enterprise PDF Dumps

NEW QUESTION # 93
In which of the following types of port scans does the scanner attempt to connect to all 65,535 ports?

  • A. UDP
  • B. Strobe
  • C. Vanilla
  • D. FTP bounce

Answer: C


NEW QUESTION # 94
The IR team and the network administrator have successfully handled a malware incident on the network. The team is now preparing countermeasure guideline to avoid a future occurrence of the malware incident.
Which of the following countermeasure(s) should be added to deal with future malware incidents? (Select all that apply)

  • A. Implementing a strong password policy
  • B. Implementing strong authentication schemes
  • C. Install antivirus software
  • D. Complying with the company's security policies

Answer: C


NEW QUESTION # 95
Identify the Password Attack Technique in which the adversary attacks cryptographic hash functions based on the probability, that if a hashing process is used for creating a key, then the same is used for other keys?

  • A. Brute Forcing Attack
  • B. Dictionary Attack
  • C. Hybrid Attack
  • D. Birthday Attack

Answer: D


NEW QUESTION # 96
Which of the following tools is an open source protocol analyzer that can capture traffic in real time?

  • A. Wireshark
  • B. NetWitness
  • C. None
  • D. Bridle
  • E. NetResident

Answer: A

Explanation:
Wireshark is an open source protocol analyzer that can capture traffic in real time. Wireshark is a free packet
sniffer computer application. It is used for network troubleshooting, analysis, software and communications
protocol development, and education. Wireshark is very similar to tcpdump, but it has a graphical front-end,
and many more information sorting and filtering options. It allows the user to see all traffic being passed over
the network (usually an Ethernet network but support is being added for others) by putting the network interface
into promiscuous mode.
Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by
pcap. It has the following features:
Data can be captured "from the wire" from a live network connection or read from a file that records the
already-captured packets.
Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback.
Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility,
tshark.
Captured files can be programmatically edited or converted via command-line switches to the "editcap"
program.
Data display can be refined using a display filter. Plugins can be created for dissecting new protocols.
Answer option C is incorrect. Snort is an open source network intrusion prevention and detection system that
operates as a network sniffer. It logs activities of the network that is matched with the predefined signatures.
Signatures can be designed for a wide range of traffic, including Internet Protocol (IP), Transmission Control
Protocol (TCP), User Datagram Protocol (UDP), and Internet Control Message Protocol (ICMP).
Answer option D is incorrect. NetWitness is used to analyze and monitor the network traffic and activity.
Answer option A is incorrect. Netresident is used to capture, store, analyze, and reconstruct network events
and activities.


NEW QUESTION # 97
Which of the following steps are required in an idle scan of a closed port?
Each correct answer represents a part of the solution. Choose all that apply.

  • A. The attacker sends a SYN/ACK to the zombie.
  • B. The zombie's IP ID increases by 2.
  • C. The zombie's IP ID increases by only 1.
  • D. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.
  • E. In response to the SYN, the target sends a RST.

Answer: A,C,D,E

Explanation:
Following are the steps required in an idle scan of a closed port:
1.Probe the zombie's IP ID: The attacker sends a SYN/ACK to the zombie. The zombie, unaware
of the SYN/ACK, sends back a RST, thus disclosing its IP ID.

2.Forge a SYN packet from the zombie: In response to the SYN, the target sends a RST. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.

3.Probe the zombie's IP ID again: The zombie's IP ID has increased by only 1 since step 1. So the port is closed.


NEW QUESTION # 98
FILL BLANK
Fill in the blank with the appropriate term. ______________ encryption is a type of encryption that uses two
keys, i.e., a public key and a private key pair for data encryption. It is also known as public key encryption.

Answer:

Explanation:
Asymmetric
Explanation:
Asymmetric encryption is a type of encryption that uses two keys, i.e., a public key and a private key pair for
data encryption. The public key is available to everyone, while the private or secret key is available only to the
recipient of the message. For example, when a user sends a message or data to another user, the sender
uses the public key to encrypt the data. The receiver uses his private key to decrypt the data.


NEW QUESTION # 99
Which of the following is true regarding any attack surface?

  • A. Increase in vulnerabilities decreases the attack surface
  • B. Decrease in vulnerabilities decreases the attack surface
  • C. Decrease in vulnerabilities increases the attack surface
  • D. Decrease in risk exposures increases the attack surface

Answer: B


NEW QUESTION # 100
You are taking over the security of an existing network. You discover a machine that is not being used as such, but has software on it that emulates the activity of a sensitive database server.
What is this?

  • A. A Polymorphic Virus
  • B. A Virus
  • C. A Honey Pot
  • D. A reactive IDS.

Answer: C

Explanation:
A honey pot is a device specifically designed to emulate a high value target such as a database server or entire sub section of your network. It is designed to attract the hacker's attention.


NEW QUESTION # 101
Which of the following is a network layer protocol used to obtain an IP address for a given hardware (MAC) address?

  • A. RARP
  • B. ARP
  • C. IP
  • D. PIM

Answer: A


NEW QUESTION # 102
Which of the following statements are NOT true about the FAT16 file system? Each correct answer represents
a complete solution. Choose all that apply.

  • A. It supports the Linux operating system.
  • B. It supports file-level compression.
  • C. It works well with large disks because the cluster size increases as the disk partition size increases.
  • D. It does not support file-level security.

Answer: B,C

Explanation:
The FAT16 file system was developed for disks larger than 16MB. It uses 16-bit allocation table entries. The
FAT16 file system supports all Microsoft operating systems. It also supports OS/2 and Linux.
Answer options C and A are incorrect. All these statements are true about the FAT16 file system.


NEW QUESTION # 103
What is used for drawing symbols in public places following techniques of advertising an open Wi-Fi network?

  • A. war call
  • B. wardriving
  • C. None
  • D. spam
  • E. warchalking

Answer: E

Explanation:
Explanation


NEW QUESTION # 104
Which of the following is a non-profit organization that oversees the allocation of IP addresses, management of
the DNS infrastructure, protocol parameter assignment, and root server system management?

  • A. ITU
  • B. ANSI
  • C. ICANN
  • D. IEEE

Answer: C

Explanation:
ICANN stands for Internet Corporation for Assigned Names and Numbers. ICANN is responsible for managing
the assignment of domain names and IP addresses. ICANN's tasks include responsibility for IP address space
allocation, protocol identifier assignment, top-level domain name system management, and root server system
management functions. Internet Corporation for Assigned Names and Numbers (ICANN) is a non-profit
organization that oversees the allocation of IP addresses, management of the DNS infrastructure, protocol
parameter assignment, and root server system management.
Answer option B is incorrect. Institute of Electrical and Electronics Engineers (IEEE) is an organization of
engineers and electronics professionals who develop standards for hardware and software.
Answer option C is incorrect. The International Telecommunication Union is an agency of the United Nations
which regulates information and communication technology issues. ITU coordinates the shared global use of
the radio spectrum, promotes international cooperation in assigning satellite orbits, works to improve
telecommunication infrastructure in the developing world and establishes worldwide standards. ITU is active in
areas including broadband Internet, latest-generation wireless technologies, aeronautical and maritime
navigation, radio astronomy, satellite-based meteorology, convergence in fixed-mobile phone, Internet access,
data, voice, TV broadcasting, and next-generation networks.
Answer option A is incorrect. ANSI (American National Standards Institute) is the primary organization for
fostering the development of technology standards in the United States. ANSI works with industry groups and
is the U.S. member of the International Organization for Standardization (ISO) and the International
Electrotechnical Commission (IEC). Long-established computer standards from ANSI include the American
Standard Code for Information Interchange (ASCII) and the Small Computer System Interface (SCSI).


NEW QUESTION # 105
Which of the following is a worldwide organization that aims to establish, refine, and promote Internet security standards?

  • A. ITU
  • B. ANSI
  • C. WASC
  • D. IEEE

Answer: C


NEW QUESTION # 106
Which of the following is the practice of sending unwanted e-mail messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients? Each correct answer represents a complete solution. Choose all that apply.

  • A. Email jamming
  • B. Junk mail
  • C. Email spoofing
  • D. E-mail spam

Answer: B,D

Explanation:
E-mail spam, also known as unsolicited bulk email (UBE), junk mail, or unsolicited commercial email (UCE), is the practice of sending unwanted e-mail messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients. Answer option A is incorrect. Email spoofing is a fraudulent email activity in which the sender address and other parts of the email header are altered to appear as though the email originated from a different source. Email spoofing is a technique commonly used in spam and phishing emails to hide the origin of the email message. By changing certain properties of the email, such as the From, Return-Path and Reply-To fields (which can be found in the message header), ill-intentioned users can make the email appear to be from someone other than the actual sender. The result is that, although the email appears to come from the address indicated in the From field (found in the email headers), it actually comes from another source. Answer option D is incorrect. Email jamming is the use of sensitive words in e-mails to jam the authorities that listen in on them by providing a form of a red herring and an intentional annoyance. In this attack, an attacker deliberately includes "sensitive" words and phrases in otherwise innocuous emails to ensure that these are picked up by the monitoring systems. As a result the senders of these emails will eventually be added to a "harmless" list and their emails will be no longer intercepted, hence it will allow them to regain some privacy.


NEW QUESTION # 107
Which of the following honeypots provides an attacker access to the real operating system without any
restriction and collects a vast amount of information about the attacker?

  • A. Low-interaction honeypot
  • B. Honeyd
  • C. Medium-interaction honeypot
  • D. High-interaction honeypot

Answer: D

Explanation:
A high-interaction honeypot offers a vast amount of information about attackers. It provides an attacker access
to the real operating system without any restriction. A high-interaction honeypot is a powerful weapon that
provides opportunities to discover new tools, to identify new vulnerabilities in the operating system, and to learn
how blackhats communicate with one another.
Answer option D is incorrect. A low-interaction honeypot captures limited amounts of information that are
mainly transactional data and some limited interactive information. Because of simple design and basic
functionality, low-interaction honeypots are easy to install, deploy, maintain, and configure. A low-interaction
honeypot detects unauthorized scans or unauthorized connection attempts. A low-interaction honeypot is like a
one-way connection, as the honeypot provides services that are limited to listening ports. Its role is very
passive and does not alter any traffic. It generates logs or alerts when incoming packets match their patterns.
Answer option B is incorrect. A medium-interaction honeypot offers richer interaction capabilities than a low-
interaction honeypot, but does not provide any real underlying operating system target. Installing and
configuring a medium-interaction honeypot takes more time than a low-interaction honeypot. It is also more
complicated to deploy and maintain as compared to a low-interaction honeypot. A medium-interaction honeypot
captures a greater amount of information but comes with greater risk. Answer option C is incorrect. Honeyd is
an example of a low-interaction honeypot.


NEW QUESTION # 108
Which of the following protocols is used for routing of voice conversation over the Internet?

  • A. DHCP
  • B. DNS
  • C. IP
  • D. VoIP

Answer: D


NEW QUESTION # 109
Which of the following TCP/IP state transitions represents no connection state at all?

  • A. Closing
  • B. Closed
  • C. Close-wait
  • D. Fin-wait-1

Answer: B


NEW QUESTION # 110
Which of the following fields in the IPv6 header replaces the TTL field in the IPv4 header?

  • A. Version
  • B. Traffic class
  • C. Next header
  • D. Hop limit

Answer: D

Explanation:
Explanation/Reference:


NEW QUESTION # 111
FILL BLANK
Fill in the blank with the appropriate term. ______________is a free open-source utility for network exploration
and security auditing that is used to discover computers and services on a computer network, thus creating a
"map" of the network.

Answer:

Explanation:
Nmap
Explanation:
Nmap is a free open-source utility for network exploration and security auditing. It is used to discover
computers and services on a computer network, thus creating a "map" of the network. Just like many simple
port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine
various details about the remote computers. These include operating system, device type, uptime, software
product used to run a service, exact version number of that product, presence of some firewall techniques and,
on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows,
etc.


NEW QUESTION # 112
Which of the following is the full form of SAINT?

  • A. System Admin Integrated Network Tool
  • B. Security Admin Integrated Network Tool
  • C. System Automated Integrated Network Tool
  • D. System Administrators Integrated Network Tool

Answer: D

Explanation:
Explanation


NEW QUESTION # 113
Docker provides Platforms-a-Service (PaaS) through __________ and deliver*; containerized software packages

  • A. OS level visualization
  • B. Network level virtualization
  • C. Storage-level virtualization
  • D. Server-level visualization

Answer: A


NEW QUESTION # 114
......

Use Valid Exam 312-38 by TestPassed Books For Free Website: https://www.testpassed.com/312-38-still-valid-exam.html

Free Certified Ethical Hacker 312-38 Official Cert Guide PDF Download: https://drive.google.com/open?id=11GR8BiL_j0Dh5rz5XMt4kW4p7wEZDMlS