Get Prepared for Your 312-38 Exam With Actual EC-COUNCIL Study Guide!
Pass Your Next 312-38 Certification Exam Easily & Hassle Free
NEW QUESTION # 62
Kyle is an IT consultant working on a contract for a large energy company in Houston. Kyle was hired on to do contract work three weeks ago so the company could prepare for an external IT security audit. With suggestions from upper management, Kyle has installed a network-based IDS system. This system checks for abnormal behavior and patterns found in network traffic that appear to be dissimilar from the traffic normally recorded by the IDS. What type of detection is this network-based IDS system using?
- A. This network-based IDS is utilizing definition-based detection.
- B. This network-based IDS system is using dissimilarity algorithms.
- C. This network-based IDS system is using anomaly detection.
- D. This system is using misuse detection.
Answer: C
NEW QUESTION # 63
Which of the following statements are true about security risks? Each correct answer represents a complete
solution. (Choose three.)
- A. They can be removed completely by taking proper actions.
- B. They can be mitigated by reviewing and taking responsible actions based on possible risks.
- C. They can be analyzed and measured by the risk analysis process.
- D. They are considered an indicator of threats coupled with vulnerability.
Answer: B,C,D
Explanation:
In information security, security risks are considered an indicator of threats coupled with vulnerability. In other
words, security risk is a probabilistic function of a given threat agent exercising a particular vulnerability and the
impact of that risk on the organization. Security risks can be mitigated by reviewing and taking responsible
actions based on possible risks. These risks can be analyzed and measured by the risk analysis process.
Answer option B is incorrect. Security risks can never be removed completely but can be mitigated by taking
proper actions.
NEW QUESTION # 64
Who is responsible for conveying company details after an incident?
- A. IR officer
- B. IR manager
- C. IR custodians
- D. PR specialist
Answer: D
NEW QUESTION # 65
Which of the following steps of the OPSEC process examines each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then compare those indicators with the adversary's intelligence collection capabilities identified in the previous action?
- A. Analysis of Threats
- B. Application of Appropriate OPSEC Measures
- C. Analysis of Vulnerabilities
- D. Assessment of Risk
- E. Identification of Critical Information
Answer: C
Explanation:
OPSEC is a 5-step process that helps in developing protection mechanisms in order to safeguard sensitive information and preserve essential secrecy.
The OPSEC process has five steps, which are as follows:
1.Identification of Critical Information: This step includes identifying information vitally needed by an adversary, which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to protect all classified or sensitive unclassified information.
2.Analysis of Threats: This step includes the research and analysis of intelligence, counter-intelligence, and open source information to identify likely adversaries to a planned operation.
3.Analysis of Vulnerabilities: It includes examining each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then comparing those indicators with the adversary's intelligence collection capabilities identified in the previous action.
4.Assessment of Risk: Firstly, planners analyze the vulnerabilities identified in the previous action and identify possible OPSEC measures for each vulnerability. Secondly, specific OPSEC measures are selected for execution based upon a risk assessment done by the commander and staff.
5.Application of Appropriate OPSEC Measures: The command implements the OPSEC measures selected in the assessment of risk action or, in the case of planned future operations and activities, includes the measures in specific OPSEC plans.
NEW QUESTION # 66
Which of the following is a software tool used in passive attacks for capturing network traffic?
- A. Intrusion detection system
- B. Sniffer
- C. Intrusion prevention system
- D. Warchalking
Answer: B
Explanation:
A sniffer is a software tool that is used to capture any network traffic. Since a sniffer changes the NIC of the LAN card into promiscuous mode, the NIC begins to record incoming and outgoing data traffic across the network. A sniffer attack is a passive attack because the attacker does not directly connect with the target host.
This attack is most often used to grab logins and passwords from network traffic. Tools such as Ethereal, Snort, Windump, EtherPeek, Dsniff are some good examples of sniffers. These tools provide many facilities to users such as graphical user interface, traffic statistics graph, multiple sessions tracking, etc.
Answer option C is incorrect. An intrusion prevention system (IPS) is a network security device that monitors network and/or system activities for malicious or unwanted behavior and can react, in real-time, to block or prevent those activities. When an attack is detected, it can drop the offending packets while still allowing all other traffic to pass.
Answer option B is incorrect. An IDS (Intrusion Detection System) is a device or software application that monitors network and/or system activities for malicious activities or policy violations and produces reports to a Management Station. Intrusion prevention is the process of performing intrusion detection and attempting to stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators.
Answer option D is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing and war driving.
NEW QUESTION # 67
Which of the following phases is the first step towards creating a business continuity plan?
- A. Business Impact Assessment
- B. Business Continuity Plan Development
- C. Scope and Plan Initiation
- D. Plan Approval and Implementation
Answer: C
NEW QUESTION # 68
Paul is a network security technician working on a contract for a laptop manufacturing company in Chicago.
He has focused primarily on securing network devices, firewalls, and traffic traversing in and out of the network. He just finished setting up a server a gateway between the internal private network and the outside public network. This server will act as a proxy, limited amount of services, and will filter packets. What is this type of server called?
- A. SOCKS hsot
- B. Session layer firewall
- C. Edge transport server
- D. Bastion host
Answer: D
NEW QUESTION # 69
Which of the following IEEE standards is also called Fast Basic Service Set Transition?
- A. 802.11b
- B. 802.11e
- C. 802.11r
- D. 802.11a
Answer: C
NEW QUESTION # 70
Which of the following is a distributed multi-access network that helps in supporting integrated communications using a dual bus and distributed queuing?
- A. Logical Link Control
- B. Distributed-queue dual-bus
- C. Token Ring network
- D. CSMA/CA
Answer: B
NEW QUESTION # 71
Steven is a Linux system administrator at an IT company. He wants to disable unnecessary services in the system, which can be exploited by the attackers. Which among the following is the correct syntax for disabling a service?
- A. $ sudo systemctl disable [service]
- B. $ sudo system.ctl disable [service]
- C. $ sudo system ctl disable [service]
- D. $ sudo system-ctl disable [service]
Answer: A
NEW QUESTION # 72
The bank where you work has 600 windows computers and 400 Red Hat computers which primarily serve as bank teller consoles. You have created a plan and deployed all the patches to the Windows computers and you are now working on updating the Red Hat computers. What command should you run on the network to update the Red Hat computers, download the security package, force the package installation, and update all currently installed packages?
- A. You should type the sysupdate -d command
- B. You should run the up2data -u command
- C. You should run the up2date -d -f -u command
- D. You should run the WSUS -d -f -u command.
Answer: C
Explanation:
The up2date command was used in older versions of Red Hat Enterprise Linux to update installed packages to their latest available versions. The -d option downloads the packages without installing them, -f forces the installation of the package even if it is already installed, and -u updates all installed packages to the latest versions. However, it's important to note that up2date has been replaced by yum and more recently by dnf in the newer versions of Red Hat Enterprise Linux. For the scenario described, where security is a concern and the systems are likely to be running a more current version of Red Hat, the correct command would be yum update or dnf upgrade.
NEW QUESTION # 73
Which of the following is a distance vector routing protocols? Each correct answer represents a complete solution. Choose all that apply.
- A. OSPF
- B. IS-IS
- C. IGRP
- D. REST IN PEACE
Answer: C,D
NEW QUESTION # 74
Which of the following offer "always-on" Internet service for connecting to your ISP? Each correct answer represents a complete solution. Choose all that apply.
- A. DSL
- B. analog modem
- C. cable modem
- D. digital modem
Answer: A,C
Explanation:
Explanation
NEW QUESTION # 75
John has successfully remediated the vulnerability of an internal application that could have caused a threat to the network. He is scanning the application for the existence of a remediated vulnerability, this process is called a __________ and it has to adhere to the __________.
- A. Mitigation, Security policies
- B. Risk analysis, Risk matrix
- C. Verification, Security Policies
- D. Vulnerability scanning, Risk Analysis
Answer: B
NEW QUESTION # 76
Which of the following are the various methods that a device can use for logging information on a Cisco router? Each correct answer represents a complete solution. Choose all that apply.
- A. Buffered logging
- B. Terminal logging
- C. NTP logging
- D. SNMP logging
- E. Console logging
- F. Syslog logging
Answer: A,B,D,E,F
Explanation:
There are different methods that a device can use for logging information on a Cisco router:
Terminal logging: In this method, log messages are sent to the VTY session.
Console logging: In this method, log messages are sent directly to the console port.
Buffered logging: In this method, log messages are kept in the RAM on the router. As the buffer
fills, the older messages are overwritten by the newer messages.
Syslog logging: In this method, log messages are sent to an external syslog server where they are
stored and sorted.
SNMP logging: In this method, log messages are sent to an SNMP server in the network.
Answer option C is incorrect. This is an invalid option.
NEW QUESTION # 77
CORRECT TEXT
Fill in the blank with the appropriate term.
______________ is a prime example of a high-interaction honeypot.
Answer:
Explanation:
Honeynet
Explanation:
Honeynet is a prime example of a high-interaction honeypot. Two or more honeypots on a network form a honeynet. Typically, a honeynet is used for monitoring a larger and/or more diverse network in which one honeypot may not be sufficient. Honeynets and honeypots are usually implemented as parts of larger network intrusion-detection systems. A honeyfarm is a centralized collection of honeypots and analysis tools.
NEW QUESTION # 78
Michael decides to view the ________ to track employee actions on the organization's network.
- A. Firewall policy
- B. Firewall rule set
- C. Firewall log
- D. Firewall settings
Answer: C
NEW QUESTION # 79
An administrator wants to monitor and inspect large amounts of traffic and detect unauthorized attempts from inside the organization, with the help of an IDS. They are not able to recognize the exact location to deploy the IDS sensor. Can you help him spot the location where the IDS sensor should be placed?
- A. Location 1
- B. Location 2
- C. Location 4
- D. Location 3
Answer: B
NEW QUESTION # 80
......
Ace 312-38 Certification with 348 Actual Questions: https://examcollection.bootcamppdf.com/312-38-exam-actual-tests.html