Pass EC-COUNCIL 312-38 exam questions - convert Test Engine to PDF
Pass Your 312-38 Exam Easily - Real 312-38 Practice Dump Updated Dec 29, 2023
The EC-Council CND certification exam is recognized by many organizations as a standard for network security professionals. EC-Council Certified Network Defender CND certification is highly regarded by employers and is often a requirement for employment in the field of network security. EC-Council Certified Network Defender CND certification provides candidates with a solid foundation in network security fundamentals, and is an excellent way to demonstrate their knowledge and skills to potential employers.
EC-COUNCIL 312-38 certification exam covers a broad range of topics related to network security, including network security controls, protocols, and devices. Candidates for this certification must have a deep understanding of network vulnerabilities and how to mitigate them. They must also have a strong understanding of network defense technologies, including firewalls, intrusion detection systems, and other security devices.
NEW QUESTION # 115
The _________ mechanism works on the basis of a client-server model.
- A. Network-based
- B. Host-based
- C. Push-based
- D. Pull-based
Answer: D
NEW QUESTION # 116
Which of the following policies helps in defining what users can and should do to use network and organization's computer equipment?
- A. Remote access policy
- B. General policy
- C. IT policy
- D. User policy
Answer: D
NEW QUESTION # 117
A newly joined network administrator wants to assess the organization against possible risk. He notices the organization doesn't have a________identified which helps measure how risky an activity is.
- A. Risk Matrix
- B. Key Risk Indicator
- C. Risk Severity
- D. Risk levels
Answer: B
NEW QUESTION # 118
Which of the following layers is closest to the end user?
- A. Presentation layer
- B. Session layer
- C. Physical layer
- D. Application layer
Answer: D
NEW QUESTION # 119
What is the response of an Xmas scan if a port is either open or filtered?
- A. FIN
- B. RST
- C. PUSH
- D. No response
Answer: D
NEW QUESTION # 120
You are a professional Computer Hacking forensic investigator. You have been called to collect evidences of buffer overflow and cookie snooping attacks. Which of the following logs will you review to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
- A. Web server logs
- B. Program logs
- C. Event logs
- D. System logs
Answer: B,C,D
Explanation:
Explanation
Explanation:
Evidences of buffer overflow and cookie snooping attacks can be traced from system logs, event logs, and program logs, depending on the type of overflow or cookie snooping attack executed and the error recovery method used by the hacker.
Answer option B is incorrect. Web server logs are used to investigate cross-site scripting attacks.
NEW QUESTION # 121
What is used for drawing symbols in public places following techniques of advertising an open Wi-Fi network?
- A. war call
- B. warchalking
- C. spam
- D. None
- E. wardriving
Answer: B
NEW QUESTION # 122
Which of the following representatives of the incident response team takes forensic backups of systems that are the focus of an incident?
- A. Lead investigator
- B. Legal representative
- C. Technical representative
- D. Information security representative
Answer: C
Explanation:
A technical representative creates forensic backups of systems that are the focus of an incident
and provides valuable information about the configuration of the network and target system.
Answer option B is incorrect. A lead investigator acts as the manager of the computer security
incident response team.
Answer option D is incorrect. The legal representative looks after legal issues and ensures that the
investigation process does not break any law.
Answer option C is incorrect. The information security representative informs about the security
safeguards that may affect their ability to respond to the incident.
NEW QUESTION # 123
Implementing access control mechanisms, such as a firewall, to protect the network is an example of which of the following network defense approach?
- A. Preventive approach
- B. Proactive approach
- C. Reactive approach
- D. Retrospective approach
Answer: A
NEW QUESTION # 124
Which of the following is used in conjunction with smoke detectors and fire alarm systems to improve and
increase public safety?
- A. Gaseous fire suppression
- B. Fire suppression system
- C. Gaseous emission system
- D. Fire sprinkler
Answer: B
NEW QUESTION # 125
What is the range for well known ports?
- A. Above 65535
- B. 49152 through 65535
- C. 0 through 1023
- D. 1024 through 49151
Answer: C
NEW QUESTION # 126
Fill in the blank with the appropriate term. ______________________ is typically carried out by a remote attacker attempting to gain information or access to a network on which it is not authorized or allowed.
Answer:
Explanation:
Network reconnaissance
NEW QUESTION # 127
Which of the following is also known as stateful firewall?
- A. Stateless firewall
- B. Dynamic packet-filtering firewall
- C. DMZ
- D. PIX firewall
Answer: B
NEW QUESTION # 128
Which of the following representatives of the incident response team takes forensic backups of systems that are the focus of an incident?
- A. Lead investigator
- B. Legal representative
- C. Technical representative
- D. Information security representative
Answer: C
NEW QUESTION # 129
Physical access controls help organizations monitor, record, and control access to the information assets and facility. Identify the category of physical security controls which includes security labels and warning signs.
- A. Environmental control
- B. Technical control
- C. Administrative control
- D. Physical control
Answer: C
NEW QUESTION # 130
Fill in the blanks with the appropriate terms. In L2TP ______________ tunnel mode, the ISP must support L2TP, whereas in L2TP tunnel mode, the ISP does not need to support L2TP.
Answer:
Explanation:
compulsory
NEW QUESTION # 131
An administrator wants to monitor and inspect large amounts of traffic and detect unauthorized attempts from inside the organization, with the help of an IDS. They are not able to recognize the exact location to deploy the IDS sensor. Can you help him spot the location where the IDS sensor should be placed?
- A. Location 3
- B. Location 1
- C. Location 2
- D. Location 4
Answer: C
NEW QUESTION # 132
How many layers are present in the TCP/IP model?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION # 133
Which of the following is an open source implementation of the syslog protocol for Unix?
- A. syslog Unix
- B. syslog-os
- C. Unix-syslog
- D. syslog-ng
Answer: D
NEW QUESTION # 134
Which of the following layers of TCP/IP model is used to move packets between the Internet Layer interfaces of two different hosts on the same link?
- A. Internet layer
- B. Application layer
- C. Link layer
- D. Transport Layer
Answer: C
NEW QUESTION # 135
In which of the following attacks does an attacker use software that tries a large number of key combinations in
order to get a password?
- A. Buffer overflow
- B. Zero-day attack
- C. Smurf attack
- D. Brute force attack
Answer: D
Explanation:
In a brute force attack, an attacker uses software that tries a large number of key combinations in order to get
a password. To prevent such attacks, users should create passwords that are more difficult to guess, i.e., by
using a minimum of six characters, alphanumeric combinations, and lower-upper case combinations.
Answer option D is incorrect. Smurf is an attack that generates significant computer network traffic on a victim
network. This is a type of denial-of-service attack that floods a target system via spoofed broadcast ping
messages. In such attacks, a perpetrator sends a large amount of ICMP echo request (ping) traffic to IP
broadcast addresses, all of which have a spoofed source IP address of the intended victim. If the routing
device delivering traffic to those broadcast addresses delivers the IP broadcast to all hosts, most hosts on that
IP network will take the ICMP echo request and reply to it with an echo reply, which multiplies the traffic by the
number of hosts responding.
Answer option A is incorrect. Buffer overflow is a condition in which an application receives more data than it is
configured to accept. It helps an attacker not only to execute a malicious code on the target system but also to
install backdoors on the target system for further attacks. All buffer overflow attacks are due to only sloppy
programming or poor memory management by the application developers. The main types of buffer overflows
are:
Stack overflow
Format string overflow
Heap overflow
Integer overflow
Answer option C is incorrect. A zero-day attack, also known as zero-hour attack, is a computer threat that tries
to exploit computer application vulnerabilities which are unknown to others, undisclosed to the software vendor,
or for which no security fix is available. Zero-day exploits (actual code that can use a security hole to carry out
an attack) are used or shared by attackers before the software vendor knows about the mvulnerability. User
awareness training is the most effective technique to mitigate such attacks.
NEW QUESTION # 136
......
EC-COUNCIL 312-38 certification exam is designed to test the candidate's knowledge and skills in network security. 312-38 exam consists of 100 multiple-choice questions that must be answered within a three-hour time frame. 312-38 exam covers a broad range of topics related to network security, including network protocols, network security controls, and network defense technologies.
312-38 Real Exam Questions and Answers FREE: https://examcollection.bootcamppdf.com/312-38-exam-actual-tests.html