Prepare Top EC-COUNCIL 312-38 Exam Study Guide Practice Questions Edition [Q22-Q42]

Share

Prepare Top EC-COUNCIL 312-38 Exam Study Guide Practice Questions Edition

Go to 312-38 Questions - Try 312-38 dumps pdf 


Preparation Process

Understanding the exam topics is very critical to success in the test. Therefore, the potential candidates must download the exam blueprint to review the comprehensive details of these domains. After exploring the scope of the test, they can proceed to choose ample resources to prepare for EC-Council 312-38 with great deliberation.


EC-Council CND Exam Certification Details:

Passing Score70%
Number of Questions100
Sample QuestionsEC-Council CND Sample Questions
Duration240 mins
Exam NameEC-Council Certified Network Defender (CND)
Books / TrainingCourseware
Exam Code312-38
Exam Price$450 (USD)
Schedule ExamPearson VUE OR ECC Exam Center


Understanding functional and technical aspects of Certified Network Defender Business Principles and Practices

The following will be discussed in ECCOUNCIL EC 312-38 dumps:

  • Understand Cloud Computing Fundamentals
  • Learn vulnerability assessment and scanning
  • Learn to manage vulnerabilities through vulnerability management program
  • Discuss log monitoring and analysis on Mac
  • Discuss BC/DR Activities
  • Understand the attack surface analysis
  • Determine baseline traffic signatures for normal and suspicious network traffic
  • Understand different types of threat Intelligence
  • Understand risk management concepts
  • Discuss Do’s and Don’t in first response
  • Learn to identify Indicators of Exposures (IoE)
  • Discuss Security in Google Cloud Platform (GCP)
  • Introduction to Business Continuity (BC) and Disaster Recovery (DR)
  • Understand incident response concept
  • Discuss log monitoring and analysis on Linux
  • Understand the role of cyber threat intelligence in network defense
  • Discuss centralized log monitoring and analysis
  • Learn to manage risk though risk management program
  • Understand wireless network encryption mechanisms
  • Discuss log monitoring and analysis on Routers
  • Setting up the environment for network monitoring
  • Discuss various BC/DR Standards
  • Understand the Insights of Cloud Security
  • Discuss network performance and bandwidth monitoring concepts
  • Discuss general security best practices and tools for cloud security
  • Discuss log monitoring and analysis on Windows systems
  • Learn to conduct attack simulation
  • Discuss security in Amazon Cloud (AWS)
  • Understand and visualize your attack surface
  • Learn to reduce the attack surface
  • Perform network monitoring and analysis for suspicious traffic using Wireshark
  • Understand wireless network authentication methods
  • Understand the layers of Threat Intelligence
  • Understand the role of first responder in incident response
  • Discuss and implement wireless network security measures
  • Discuss log monitoring and analysis on Firewall
  • Evaluate CSP for Security before Consuming Cloud Service
  • Explain Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)
  • Describe forensics investigation process
  • Discuss log monitoring and analysis on Web Servers
  • Understand wireless network fundamentals
  • Describe incident handling and response process
  • Understand the Indicators of Threat Intelligence: Indicators of Compromise (IoCs) and Indicators of Attack (IoA)
  • Understand logging concepts
  • Learn to leverage/consume threat intelligence for proactive defense
  • Discuss security in Microsoft Azure Cloud
  • Learn different Risk Management Frameworks (RMF)
  • Understand the need and advantages of network traffic monitoring

 

NEW QUESTION 22
John works as an Ethical Hacker for www.company.com Inc. He wants to find out the ports that are open in www.company.com's server using a port scanner. However, he does not want to establish a full TCP connection. Which of the following scanning techniques will he use to accomplish this task?

  • A. TCP SYN
  • B. TCP FIN
  • C. Xmas tree
  • D. TCP SYN/ACK

Answer: A

Explanation:
According to the scenario, John does not want to establish a full TCP connection. Therefore, he will use the TCP SYN scanning technique. TCP SYN scanning is also known as half-open scanning because in this type of scanning, a full TCP connection is never opened. The steps of TCP SYN scanning are as follows: 1.The attacker sends a SYN packet to the target port. 2.If the port is open, the attacker receives the SYN/ACK message. 3.Now the attacker breaks the connection by sending an RST packet. 4.If the RST packet is received, it indicates that the port is closed. This type of scanning is hard to trace because the attacker never establishes a full 3-way handshake connection and most sites do not create a log of incomplete TCP connections. Answer option C is incorrect. In TCP SYN/ACK scanning, an attacker sends a SYN/ACK packet to the target port. If the port is closed, the victim assumes that this packet was mistakenly sent by the attacker, and sends the RST packet to the attacker. If the port is open, the SYN/ACK packet will be ignored and the port will drop the packet. TCP SYN/ACK scanning is stealth scanning, but some intrusion detection systems can detect TCP SYN/ACK scanning. Answer option D is incorrect. TCP FIN scanning is a type of stealth scanning through which the attacker sends a FIN packet to the target port. If the port is closed, the victim assumes that this packet was sent mistakenly by the attacker and sends the RST packet to the attacker. If the port is open, the FIN packet will be ignored and the port will drop that packet. TCP FIN scanning is useful only for identifying ports of non-Windows operating systems because Windows operating systems send only RST packets irrespective of whether the port is open or closed. Answer option B is incorrect. Xmas Tree scanning is just the opposite of null scanning. In Xmas Tree scanning, all packets are turned on. If the target port is open, the service running on the target port discards the packets without any reply. According to RFC 793, if the port is closed, the remote system replies with the RST packet. Active monitoring of all incoming packets can help system network administrators detect an Xmas Tree scan.

 

NEW QUESTION 23
Which of the following is the practice of sending unwanted e-mail messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients? Each correct answer represents a complete solution. Choose all that apply.

  • A. Email spoofing
  • B. E-mail spam
  • C. Junk mail
  • D. Email jamming

Answer: B,C

Explanation:
E-mail spam, also known as unsolicited bulk email (UBE), junk mail, or unsolicited commercial email (UCE), is the practice of sending unwanted e-mail messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients. Answer option A is incorrect. Email spoofing is a fraudulent email activity in which the sender address and other parts of the email header are altered to appear as though the email originated from a different source. Email spoofing is a technique commonly used in spam and phishing emails to hide the origin of the email message. By changing certain properties of the email, such as the From, Return-Path and Reply-To fields (which can be found in the message header), ill-intentioned users can make the email appear to be from someone other than the actual sender. The result is that, although the email appears to come from the address indicated in the From field (found in the email headers), it actually comes from another source. Answer option D is incorrect. Email jamming is the use of sensitive words in e-mails to jam the authorities that listen in on them by providing a form of a red herring and an intentional annoyance. In this attack, an attacker deliberately includes "sensitive" words and phrases in otherwise innocuous emails to ensure that these are picked up by the monitoring systems. As a result the senders of these emails will eventually be added to a "harmless" list and their emails will be no longer intercepted, hence it will allow them to regain some privacy.

 

NEW QUESTION 24
Which of the following is a Cisco product that performs VPN and firewall functions?

  • A. Application Level Firewall
  • B. PIX Firewall
  • C. IP Packet Filtering Firewall
  • D. Circuit-Level Gateway

Answer: B

 

NEW QUESTION 25
You are a professional Computer Hacking forensic investigator. You have been called to collect evidences of buffer overflow and cookie snooping attacks. Which of the following logs will you review to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.

  • A. Event logs
  • B. Program logs
  • C. Web server logs
  • D. System logs

Answer: A,B,D

Explanation:
Evidences of buffer overflow and cookie snooping attacks can be traced from system logs, event logs, and program logs, depending on the type of overflow or cookie snooping attack executed and the error recovery method used by the hacker.
Answer option B is incorrect. Web server logs are used to investigate cross-site scripting attacks.

 

NEW QUESTION 26
Which of the following IEEE standards is also called Fast Basic Service Set Transition?

  • A. 802.11r
  • B. 802.11b
  • C. 802.11e
  • D. 802.11a

Answer: A

 

NEW QUESTION 27
Which of the following IEEE standards adds QoS features and multimedia support?

  • A. 802.11b
  • B. 802.11e
  • C. 802.11a
  • D. 802.5

Answer: B

 

NEW QUESTION 28
Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect
port scans and other suspicious traffic?

  • A. Nmap
  • B. NetRanger
  • C. PSAD
  • D. Hping

Answer: C

Explanation:
PSAD is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and
other suspicious traffic. It includes many signatures from the IDS to detect probes for various backdoor
programs such as EvilFTP, GirlFriend, SubSeven, DDoS tools (mstream, shaft), and advanced port scans
(FIN, NULL, XMAS). If it is combined with fwsnort and the Netfilter string match extension, it detects most of
the attacks described in the Snort rule set that involve application layer data.
Answer option C is incorrect. NetRanger is the complete network configuration and information toolkit that
includes the following tools: Ping tool, Trace Route tool, Host Lookup tool, Internet time synchronizer, Whois
tool, Finger Unix hosts tool, Host and port scanning tool, check multiple POP3 mail accounts tool, manage
dialup connections tool, Quote of the day tool, and monitor Network Settings tool. These tools are integrated in
order to use an application interface with full online help. NetRanger is designed for both new and experienced
users. This tool is used to help diagnose network problems and to get information about users, hosts, and
networks on the Internet or on a user computer network. NetRanger uses multi-threaded and multi-connection
technologies in order to be very fast and efficient.
Answer option D is incorrect. Nmap is a free open-source utility for network exploration and security auditing. It
is used to discover computers and services on a computer network, thus creating a "map" of the network. Just
like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be
able to determine various details about the remote computers. These include operating system, device type,
uptime, software product used to run a service, exact version number of that product, presence of some
firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux,
Microsoft Windows, etc.

 

NEW QUESTION 29
John is working as a network defender at a well-reputed multinational company. He wanted to implement security that can help him identify any future attacks that can be targeted toward his organization and take appropriate security measures and actions beforehand to defend against them. Which one of the following security defense techniques should be implement?

  • A. Retrospective security approach
  • B. Reactive security approach
  • C. Proactive security approach
  • D. Preventive security approach

Answer: C

 

NEW QUESTION 30
Which of the following is a Unix and Windows tool capable of intercepting traffic on a network segment and
capturing username and password?

  • A. AirSnort
  • B. Aircrack
  • C. Ettercap
  • D. BackTrack

Answer: C

Explanation:
Ettercap is a Unix and Windows tool for computer network protocol analysis and security auditing. It is capable
of intercepting traffic on a network segment, capturing passwords, and conducting active eavesdropping
against a number of common protocols. It is a free open source software. Ettercap supports active and passive
dissection of many protocols (including ciphered ones) and provides many features for network and host
analysis.
Answer option C is incorrect. BackTrack is a Linux distribution distributed as a Live CD, which is used for
penetration testing. It allows users to include customizable scripts, additional tools and configurable kernels in
personalized distributions. It contains various tools, such as Metasploit integration, RFMON injection capable
wireless drivers, kismet, autoscan-network (network discovering and managing application), nmap, ettercap,
wireshark (formerly known as Ethereal).
Answer option A is incorrect. AirSnort is a Linux-based WLAN WEP cracking tool that recovers encryption
keys. AirSnort operates by passively monitoring transmissions. It uses Ciphertext Only Attack and captures
approximately 5 to 10 million packets to decrypt the WEP keys. Answer option D is incorrect. Aircrack is the
fastest WEP/WPA cracking tool used for 802.11a/b/g WEP and WPA cracking.

 

NEW QUESTION 31
Which of the following provide an "always on" Internet access service when connecting to an ISP? Each correct answer represents a complete solution. (Choose two.)

  • A. Analog modem
  • B. Digital modem
  • C. Cable modem
  • D. DSL

Answer: C,D

Explanation:
DSL and Cable modems are used in remote-access WAN technology for connecting to the Internet. Both provide an "always on" Internet access service.
Answer options C and A are incorrect. Analog and Digital modems are not always in 'ON' mode when connecting to an ISP. Analog modems transmit analog voice signals, while Digital modems transmit digital signals over a link.

 

NEW QUESTION 32
Which of the following routing metrics refers to the time required to transfer the package to the source via the Internet?

  • A. routing delay
  • B. charge
  • C. length of the trail
  • D. None
  • E. bandwidth

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 33
How many layers are present in the TCP/IP model?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: D

 

NEW QUESTION 34
Which of the following representatives in the incident response process are included in the incident response team? Each correct answer represents a complete solution. Choose all that apply.

  • A. Human resources
  • B. Legal representative
  • C. Information security representative
  • D. Lead investigator
  • E. Technical representative
  • F. Sales representative

Answer: A,B,C,D,E

Explanation:
Incident response is a process that detects a problem, determines the cause of an issue, minimizes the damages, resolves the problem, and documents each step of process for future reference. To perform all these roles, an incident response team is needed. The incident response team includes the following representatives who are involved in the incident response process:
Lead investigator: The lead investigator is the manager of an incident response team. He is always involved in the creation of an incident response plan. The duties of a lead investigator are as follows: Keep the management updated. Ensure that the incident response moves smoothly and efficiently. Interview and interrogate the suspects and witnesses.
Information security representative: The information security representative is a member of the incident response team who alerts the team about possible security safeguards that can impact their ability to respond to an incident.
Legal representative: The legal representative is a member of the incident response team who ensures that the process follows all the laws during the response to an incident.
Technical representative: Technical representative is a representative of the incident response team. More than one technician can be deployed to an incident. The duties of a technical representative are as follows:
Perform forensic backups of the systems that are involved in an incident. Provide more information about the configuration of the network or system.
Human resources: Human resources personnel ensure that the policies of the organization are enforced during the incident response process. They suspend access to a suspect if it is needed. Human resources personnel are closely related with the legal representatives and cover up the organization's legal responsibility.

 

NEW QUESTION 35
Which of the following organizations is responsible for managing the assignment of domain names and IP addresses?

  • A. W3C
  • B. ISO
  • C. ICANN
  • D. ANSI

Answer: C

Explanation:
ICANN stands for Internet Corporation for Assigned Names and Numbers. ICANN is responsible for managing the assignment of domain names and IP addresses. ICANN's tasks include responsibility for IP address space allocation, protocol identifier assignment, top-level domain name system management, and root server system management functions. Answer option A is incorrect. The International Organization for Standardization, widely known as ISO, is an international-standard-setting body composed of representatives from various national standards organizations. Founded on 23 February 1947, the organization promulgates worldwide proprietary industrial and commercial standards. It has its headquarters in Geneva, Switzerland. While ISO defines itself as a non-governmental organization, its ability to set standards that often become law, either through treaties or national standards, makes it more powerful than most nongovernmental organizations. In practice, ISO acts as a consortium with strong links to governments. Answer option C is incorrect. The World Wide Web Consortium (W3C) is an international industry consortium that develops common standards for the World Wide Web to promote its evolution and interoperability. It was founded in October 1994 by Tim Berners-Lee, the inventor of the Web, at the Massachusetts Institute of Technology, Laboratory for Computer Science [MIT/LCS] in collaboration with CERN, where the Web had originated , with support from DARPA and the European Commission. Answer option D is incorrect. ANSI (American National Standards Institute) is the primary organization for fostering the development of technology standards in the United States. ANSI works with industry groups and is the U.S. member of the International Organization for Standardization (ISO) and the International Electro-technical Commission (IEC). Long-established computer standards from ANSI include the American Standard Code for Information Interchange (ASCII) and the Small Computer System Interface (SCSI).

 

NEW QUESTION 36
Token Ring is standardized by which of the following IEEE standards?

  • A. 802.3
  • B. 802.1
  • C. 802.2
  • D. 802.4

Answer: D

 

NEW QUESTION 37
Adam, a malicious hacker, is sniffing an unprotected Wi-FI network located in a local store with Wireshark to capture hotmail e-mail traffic. He knows that lots of people are using their laptops for browsing the Web in the store. Adam wants to sniff their e-mail messages traversing the unprotected Wi-Fi network. Which of the following Wireshark filters will Adam configure to display only the packets with hotmail email messages?

  • A. (http = "login.pass.com") && (http contains "SMTP")
  • B. (http = "login.passport.com") && (http contains "POP3")
  • C. (http contains "email") && (http contains "hotmail")
  • D. (http contains "hotmail") && (http contains "Reply-To")

Answer: D

Explanation:
Adam will use (http contains "hotmail") && (http contains "Reply-To") filter to display only the packets with hotmail email messages. Each Hotmail message contains the tag Reply-To: and "xxxx-xxx- xxx.xxxx.hotmail.com" in the received tag. Wireshark is a free packet sniffer computer application. It is used for network troubleshooting, analysis, software and communications protocol development, and education.
Wireshark is very similar to tcpdump, but it has a graphical front-end, and many more information sorting and filtering options. It allows the user to see all traffic being passed over the network (usually an Ethernet network but support is being added for others) by putting the network interface into promiscuous mode. Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by pcap. It has the following features: Data can be captured "from the wire" from a live network connection or read from a file that records the already-captured packets. Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback. Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility, tshark. Captured files can be programmatically edited or converted via command-line switches to the "editcap" program. Data display can be refined using a display filter. Plugins can be created for dissecting new protocols.
Answer options B, A, and D are incorrect. These are invalid tags.

 

NEW QUESTION 38
Which of the following tools scans the network systems for well-known and often exploited vulnerabilities?

  • A. HPing
  • B. SATAN
  • C. Nessus
  • D. SAINT

Answer: B

 

NEW QUESTION 39
John works as an Incident manager for TechWorld Inc. His task is to set up a wireless network for his
organization. For this, he needs to decide the appropriate devices and policies required to set up the network.
Which of the following phases of the incident handling process will help him accomplish the task?

  • A. Containment
  • B. Eradication
  • C. Recovery
  • D. Preparation

Answer: D

Explanation:
Preparation is the first step in the incident handling process. It includes processes like backing up copies of all
key data on a regular basis, monitoring and updating software on a regular basis, and creating and
implementing a documented security policy. To apply this step a documented security policy is formulated that
outlines the responses to various incidents, as a reliable set of instructions during the time of an incident. The
following list contains items that the incident handler should maintain in the preparation phase i.e. before an
incident occurs:
Establish applicable policies
Build relationships with key players
Build response kit
Create incident checklists
Establish communication plan
Perform threat modeling
Build an incident response team
Practice the demo incidents
Answer option A is incorrect. The Containment phase of the Incident handling process is responsible for
supporting and building up the incident combating process. It ensures the stability of the system and also
confirms that the incident does not get any worse. The Containment phase includes the process of preventing
further contamination of the system or network, and preserving the evidence of the contamination.
Answer option D is incorrect. The Eradication phase of the Incident handling process involves the cleaning-up
of the identified harmful incidents from the system. It includes the analyzing of the information that has been
gathered for determining how the attack was committed. To prevent the incident from happening again, it is
vital to recognize how it was conceded out so that a prevention technique is applied.
Answer option B is incorrect. Recovery is the fifth step of the incident handling process. In this phase, the
Incident Handler places the system back into the working environment. In the recovery phase the Incident
Handler also works with the questions to validate that the system recovery is successful. This involves testing
the system to make sure that all the processes and functions are working normal. The Incident Handler also
monitors the system to make sure that the systems are not compromised again. It looks for additional signs of
attack.

 

NEW QUESTION 40
In which of the following attacks does an attacker use software that tries a large number of key combinations in order to get a password?

  • A. Buffer overflow
  • B. Zero-day attack
  • C. Brute force attack
  • D. Smurf attack

Answer: C

Explanation:
In a brute force attack, an attacker uses software that tries a large number of key combinations in order to get a password. To prevent such attacks, users should create passwords that are more difficult to guess, i.e., by using a minimum of six characters, alphanumeric combinations, and lower-upper case combinations.
Answer option D is incorrect. Smurf is an attack that generates significant computer network traffic on a victim network. This is a type of denial-of-service attack that floods a target system via spoofed broadcast ping messages. In such attacks, a perpetrator sends a large amount of ICMP echo request (ping) traffic to IP broadcast addresses, all of which have a spoofed source IP address of the intended victim. If the routing device delivering traffic to those broadcast addresses delivers the IP broadcast to all hosts, most hosts on that IP network will take the ICMP echo request and reply to it with an echo reply, which multiplies the traffic by the number of hosts responding.
Answer option A is incorrect. Buffer overflow is a condition in which an application receives more data than it is configured to accept. It helps an attacker not only to execute a malicious code on the target system but also to install backdoors on the target system for further attacks. All buffer overflow attacks are due to only sloppy programming or poor memory management by the application developers. The main types of buffer overflows are:
Stack overflow
Format string overflow
Heap overflow
Integer overflow
Answer option C is incorrect. A zero-day attack, also known as zero-hour attack, is a computer threat that tries to exploit computer application vulnerabilities which are unknown to others, undisclosed to the software vendor, or for which no security fix is available. Zero-day exploits (actual code that can use a security hole to carry out an attack) are used or shared by attackers before the software vendor knows about the mvulnerability. User awareness training is the most effective technique to mitigate such attacks.

 

NEW QUESTION 41
In which of the following attacks does an attacker use software that tries a large number of key combinations in
order to get a password?

  • A. Buffer overflow
  • B. Zero-day attack
  • C. Brute force attack
  • D. Smurf attack

Answer: C

Explanation:
In a brute force attack, an attacker uses software that tries a large number of key combinations in order to get
a password. To prevent such attacks, users should create passwords that are more difficult to guess, i.e., by
using a minimum of six characters, alphanumeric combinations, and lower-upper case combinations.
Answer option D is incorrect. Smurf is an attack that generates significant computer network traffic on a victim
network. This is a type of denial-of-service attack that floods a target system via spoofed broadcast ping
messages. In such attacks, a perpetrator sends a large amount of ICMP echo request (ping) traffic to IP
broadcast addresses, all of which have a spoofed source IP address of the intended victim. If the routing
device delivering traffic to those broadcast addresses delivers the IP broadcast to all hosts, most hosts on that
IP network will take the ICMP echo request and reply to it with an echo reply, which multiplies the traffic by the
number of hosts responding.
Answer option A is incorrect. Buffer overflow is a condition in which an application receives more data than it is
configured to accept. It helps an attacker not only to execute a malicious code on the target system but also to
install backdoors on the target system for further attacks. All buffer overflow attacks are due to only sloppy
programming or poor memory management by the application developers. The main types of buffer overflows
are:
Stack overflow
Format string overflow
Heap overflow
Integer overflow
Answer option C is incorrect. A zero-day attack, also known as zero-hour attack, is a computer threat that tries
to exploit computer application vulnerabilities which are unknown to others, undisclosed to the software vendor,
or for which no security fix is available. Zero-day exploits (actual code that can use a security hole to carry out
an attack) are used or shared by attackers before the software vendor knows about the mvulnerability. User
awareness training is the most effective technique to mitigate such attacks.

 

NEW QUESTION 42
......

Free Certified Ethical Hacker 312-38 Exam Question: https://www.prep4sures.top/312-38-exam-dumps-torrent.html

Dumps Practice Exam Questions Study Guide for the 312-38 Exam: https://drive.google.com/open?id=1wZf-dGLI3TvWnfgA2_Fnjd83-COBicY9