Exam Dumps 312-38 Practice Free Latest EC-COUNCIL Practice Tests [Q29-Q46]

Share

Exam Dumps 312-38 Practice Free Latest EC-COUNCIL Practice Tests

312-38 Exam Questions | Real 312-38 Practice Dumps


Career Opportunities

The EC-Council 312-38 exam equips the professionals with the fundamental knowledge and skills in networking concepts. Without a doubt, earning the Certified Network Defender certification has a lucrative career outlook. Some of the positions that the certified individuals can consider include IT Administrators, Network Technicians, Data Analysts, Network Administrators, and Network Engineers, among others. The average remuneration for these titles is $94,000 per annum.


Topics of Certified Network Defender

Competitors should know the test themes before they start arrangement. Since it will help them in hitting the center. ECCOUNCIL EC 312-38 dumps pdf will incorporate the accompanying themes:

  • Application and Data Protection
  • Network Perimeter Protection
  • Incident Response
  • Enterprise Virtual, Cloud, and Wireless Network Protection
  • Endpoint Protection
  • Incident Detection
  • Network Defense Management
  • Incident Prediction

 

NEW QUESTION 29
Which of the following protocols is used to share information between routers to transport IP Multicast packets
among networks?

  • A. RPC
  • B. LWAPP
  • C. RSVP
  • D. DVMRP

Answer: D

Explanation:
The Distance Vector Multicast Routing Protocol (DVMRP) is used to share information between routers to
transport IP Multicast packets among networks. It uses a reverse path-flooding technique and is used as the
basis for the Internet's multicast backbone (MBONE). In particular, DVMRP is notorious for poor network
scaling, resulting from reflooding, particularly with versions that do not implement pruning. DVMRP's flat
unicast routing mechanism also affects its capability to scale.
Answer option A is incorrect. The Resource Reservation Protocol (RSVP) is a Transport layer protocol
designed to reserve resources across a network for an integrated services Internet. RSVP does not transport
application data but is rather an Internet control protocol, like ICMP, IGMP, or routing protocols. RSVP provides
receiver-initiated setup of resource reservations for multicast or unicast data flows with scaling and robustness.
RSVP can be used by either hosts or routers to request or deliver specific levels of quality of service (QoS) for
application data streams. RSVP defines how applications place reservations and how they can leave the
reserved resources once the need for them has ended. RSVP operation will generally result in resources being
reserved in each node along a path.
Answer option C is incorrect. A remote procedure call (RPC) hides the details of the network by using the
common procedure call mechanism familiar to every programmer. Like any ordinary procedure, RPC is also
synchronous and parameters are passed to it. A process of the client calls a function on a remote server and
remains suspended until it gets back the results.
Answer option D is incorrect. LWAPP (Lightweight Access Point Protocol) is a protocol used to control multiple
Wi-Fi wireless access points at once. This can reduce the amount of time spent on configuring, monitoring, or
troubleshooting a large network. This also allows network administrators to closely analyze the network.

 

NEW QUESTION 30
A network is setup using an IP address range of 0.0.0.0 to 127.255.255.255. The network has a default subnet mask of 255.0.0.0. What IP address class is the network range a part of?

  • A. Class A
  • B. Class C
  • C. Class B
  • D. Class D

Answer: A

 

NEW QUESTION 31
Which of the following are the six different phases of the Incident handling process? Each correct answer
represents a complete solution. Choose all that apply.

  • A. Containment
  • B. Preparation
  • C. Post mortem review
  • D. Recovery
  • E. Identification
  • F. Eradication
  • G. Lessons learned

Answer: A,B,D,E,F,G

Explanation:
Following are the six different phases of the Incident handling process:
1.Preparation: Preparation is the first step in the incident handling process. It includes processes like backing
up copies of all key data on a regular basis, monitoring and updating software on a regular basis, and creating
and implementing a documented security policy. To apply this step a documented security policy is formulated
that outlines the responses to various incidents, as a reliable set of instructions during the time of an incident.
The following list contains items that the incident handler should maintain in the preparation phase i.e. before
an incident occurs:
Establish applicable policies
Build relationships with key players
Build response kit
Create incident checklists
Establish communication plan
Perform threat modeling
Build an incident response team
Practice the demo incidents
2.Identification: The Identification phase of the Incident handling process is the stage at which the Incident
handler evaluates the critical level of an incident for an enterprise or system. It is an important stage where the
distinction between an event and an incident is determined, measured and tested.
3.Containment: The Containment phase of the Incident handling process supports and builds up the incident
combating process. It helps in ensuring the stability of the system and also confirms that the incident does not
get any worse.
4.Eradication: The Eradication phase of the Incident handling process involves the cleaning-up of the identified
harmful incidents from the system. It includes the analyzing of the information that has been gathered for
determining how the attack was committed. To prevent the incident from happening again, it is vital to
recognize how it was conceded out so that a prevention technique is applied.
5.Recovery: Recovery is the fifth step of the incident handling process. In this phase, the Incident Handler
places the system back into the working environment. In the recovery phase the Incident Handler also works
with the questions to validate that the system recovery is successful. This involves testing the system to make
sure that all the processes and functions are working normal. The Incident Handler also monitors the system to
make sure that the systems are not compromised again. It looks for additional signs of attack.
6.Lessons learned: Lessons learned is the sixth and the final step of incident handling process. The Incident
Handler utilizes the knowledge and experience he learned during the handling of the incident to enhance and
improve the incident-handling process. This is the most ignorant step of all incident handling processes. Many
times the Incident Handlers are relieved to have systems back to normal and get busy trying to catch up other
unfinished work. The Incident Handler should make documents related to the incident or look for ways to
improve the process.
Answer option C is incorrect. The post mortem review is one of the phases of the Incident response process.

 

NEW QUESTION 32
You are monitoring your network traffic with the Wireshark utility and noticed that your network is experiencing a large amount of traffic from a certain region. You suspect a DoS incident on the network. What will be your first reaction as a first responder?

  • A. Communicate the incident
  • B. Disable Virus Protection
  • C. Make an initial assessment
  • D. Avoid Fear, Uncertainty and Doubt

Answer: D

 

NEW QUESTION 33
Which of the following types of coaxial cable is used for cable TV and cable modems?

  • A. RG-59
  • B. RG-58
  • C. RG-62
  • D. RG-8

Answer: A

Explanation:
RG-59 type of coaxial cable is used for cable TV and cable modems.
Answer option A is incorrect. RG-8 coaxial cable is primarily used as a backbone in an Ethernet LAN environment and often connects one wiring closet to another. It is also known as 10Base5 or ThickNet.
Answer option B is incorrect. RG-62 coaxial cable is used for ARCNET and automotive radio antennas.
Answer option D is incorrect. RG-58 coaxial cable is used for Ethernet networks. It uses baseband signaling and 50-Ohm terminator. It is also known as 10Base2 or ThinNet.

 

NEW QUESTION 34
Which of the following tools is used to ping a given range of IP addresses and resolve the host name of the remote system?

  • A. Nmap
  • B. Hping
  • C. SuperScan
  • D. Netscan

Answer: C

 

NEW QUESTION 35
A network administrator is monitoring the network traffic with Wireshark. Which of the following filters will she use to view the packets moving without setting a flag to detect TCP Null Scan attempts?

  • A. Tcp.dstport==7
  • B. TCRflags==0x000
  • C. Tcp.flags==0X029
  • D. Tcp.flags==0x003

Answer: B

 

NEW QUESTION 36
Which of the following is a standard-based protocol that provides the highest level of VPN security?

  • A. L2TP
  • B. PPP
  • C. IPSec
  • D. IP

Answer: C

Explanation:
Internet Protocol Security (IPSec) is a standard-based protocol that provides the highest level of VPN security. IPSec can encrypt virtually everything above the networking layer. It is used for VPN connections that use the L2TP protocol. It secures both data and password. IPSec cannot be used with Point-to-Point Tunneling Protocol (PPTP). Answer option B is incorrect. The Internet Protocol (IP) is a protocol used for communicating data across a packet-switched inter-network using the Internet Protocol Suite, also referred to as TCP/IP.IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering distinguished protocol datagrams (packets) from the source host to the destination host solely based on their addresses. For this purpose, the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (IPv4), is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (IPv6), is being deployed actively worldwide. Answer option C is incorrect. Point-to-Point Protocol (PPP) is a remote access protocol commonly used to connect to the Internet. It supports compression and encryption and can be used to connect to a variety of networks. It can connect to a network running on the IPX, TCP/IP, or NetBEUI protocol. It supports multi-protocol and dynamic IP assignments. It is the default protocol for the Microsoft Dial-Up adapter. Answer option A is incorrect. Layer 2 Tunneling Protocol (L2TP) is a more secure version of Point-to-Point Tunneling Protocol (PPTP). It provides tunneling, address assignment, and authentication. It allows the transfer of Point-to-Point Protocol (PPP) traffic between different networks.L2TP combines with IPSec to provide tunneling and security for Internet Protocol (IP), Internetwork Packet Exchange (IPX), and other protocol packets across IP networks.

 

NEW QUESTION 37
An enterprise recently moved to a new office and the new neighborhood is a little risky. The CEO wants to monitor the physical perimeter and the entrance doors 24 hours. What is the best option to do this job?

  • A. Use fences in the entrance doors
  • B. Use lights in all the entrance doors and along the company's perimeter
  • C. Install a CCTV with cameras pointing to the entrance doors and the street
  • D. Use an IDS in the entrance doors and install some of them near the corners

Answer: C

 

NEW QUESTION 38
Which of the following is a telecommunication service designed for cost-efficient data transmission for intermittent traffic between local area networks (LANs) and between end-points in a wide area network (WAN)?

  • A. X.25
  • B. ISDN
  • C. PPP
  • D. Frame relay
  • E. None

Answer: D

Explanation:
Frame relay is a telecommunication service designed for cost-efficient data transmission for intermittent traffic between local area networks (LANs) and between end-points in a wide area network (WAN). Frame relay puts data in a variable-size unit called a frame. It checks for lesser errors as compared to other traditional forms of packet switching and hence speeds up data transmission. When an error is detected in a frame, it is simply dropped. The end points are responsible for detecting and retransmitting dropped frames.
Answer option C is incorrect. Integrated Services Digital Network (ISDN) is a digital telephone/ telecommunication network that carries voice, data, and video over an existing telephone network infrastructure. It requires an ISDN modem at both the ends of a transmission. ISDN is designed to provide a single interface for hooking up a telephone, fax machine, computer, etc. ISDN has two levels of service, i.e., Basic Rate Interface (BRI) and Primary Rate Interface (PRI).
Answer option A is incorrect. The Point-to-Point Protocol, or PPP, is a data link protocol commonly used to establish a direct connection between two networking nodes. It can provide connection authentication, transmission encryption privacy, and compression. PPP is commonly used as a data link layer protocol for connection over synchronous and asynchronous circuits, where it has largely superseded the older, non- standard Serial Line Internet Protocol (SLIP) and telephone company mandated standards (such as Link Access Protocol, Balanced (LAPB) in the X.25 protocol suite). PPP was designed to work with numerous network layer protocols, including Internet Protocol (IP), Novell's Internetwork Packet Exchange (IPX), NBF, and AppleTalk.
Answer option D is incorrect. The X.25 protocol, adopted as a standard by the Consultative Committee for International Telegraph and Telephone (CCITT), is a commonly-used network protocol. The X.25 protocol allows computers on different public networks (such as CompuServe, Tymnet, or a TCP/IP network) to communicate through an intermediary computer at the network layer level. X.25's protocols correspond closely to the data-link and physical-layer protocols defined in the Open Systems Interconnection (OSI) communication model.

 

NEW QUESTION 39
Malone is finishing up his incident handling plan for IT before giving it to his boss for review. He is outlining the incident response methodology and the steps that are involved. What is the last step he should list?

  • A. A follow-up.
  • B. Containment
  • C. Assign eradication.
  • D. Recovery

Answer: A

 

NEW QUESTION 40
Which of the following provide an "always on" Internet access service when connecting to an ISP? Each correct answer represents a complete solution. (Choose two.)

  • A. Cable modem
  • B. Analog modem
  • C. Digital modem
  • D. DSL

Answer: A,D

Explanation:
DSL and Cable modems are used in remote-access WAN technology for connecting to the Internet. Both provide an "always on" Internet access service.
Answer options C and A are incorrect. Analog and Digital modems are not always in 'ON' mode when connecting to an ISP. Analog modems transmit analog voice signals, while Digital modems transmit digital signals over a link.

 

NEW QUESTION 41
Which of the following is an IPSec protocol that can be used alone in combination with Authentication Header
(AH)?

  • A. L2TP
  • B. ESP
  • C. PPTP
  • D. PPP

Answer: B

 

NEW QUESTION 42
Which of the following is a network layer protocol used to obtain an IP address for a given hardware (MAC) address?

  • A. PIM
  • B. RARP
  • C. ARP
  • D. IP

Answer: B

Explanation:
Reverse Address Resolution Protocol (RARP) is a Network layer protocol used to obtain an IP address for a given hardware (MAC) address. RARP is sort of the reverse of an ARP. Common protocols that use RARP are BOOTP and DHCP. Answer option D is incorrect. Address Resolution Protocol (ARP) is a network maintenance protocol of the TCP/IP protocol suite. It is responsible for the resolution of IP addresses to media access control (MAC) addresses of a network interface card (NIC). The ARP cache is used to maintain a correlation between a MAC address and its corresponding IP address. ARP provides the protocol rules for making this correlation and providing address conversion in both directions. ARP is limited to physical network systems that support broadcast packets. Answer option B is incorrect. Protocol-Independent Multicast (PIM) is a family of multicast routing protocols for Internet Protocol (IP) networks that provide one-to-many and many-to-many distribution of data over a LAN, WAN, or the Internet. It is termed protocol-independent because PIM does not include its own topology discovery mechanism, but instead uses routing information supplied by other traditional routing protocols, such as Border Gateway Protocol (BGP). Answer option A is incorrect. The Internet Protocol (IP) is a protocol used for communicating data across a packet-switched inter-network using the Internet Protocol Suite, also referred to as TCP/IP. IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering distinguished protocol datagrams (packets) from the source host to the destination host solely based on their addresses. For this purpose, the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (IPv4), is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (IPv6), is being deployed actively worldwide.

 

NEW QUESTION 43
How many layers are present in the TCP/IP model?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 44
Which of the following recovery plans include specific strategies and actions to address the specific variances assumptions lead to a particular safety problem or emergency situation?

  • A. The emergency plan
  • B. disaster survival plan
  • C. None
  • D. Business Continuity Plan

Answer: A

 

NEW QUESTION 45
Which of the following is a service discovery protocol that allows computers and other devices to find services in a local area network without prior configuration?

  • A. SLP
  • B. NTP
  • C. NNTP
  • D. DCAP

Answer: A

Explanation:
The Service Location Protocol (SLP, srvloc) is a service discovery protocol that allows computers and other devices to find services in a local area network without prior configuration. SLP has been designed to scale from small, unmanaged networks to large enterprise networks. Answer option C is incorrect. The Network News Transfer Protocol (NNTP) is an Internet application protocol used for transporting Usenet news articles (netnews) between news servers and for reading and posting articles by end user client applications. NNTP is designed so that news articles are stored in a central database, allowing the subscriber to select only those items that he wants to read. Answer option A is incorrect. Network Time Protocol (NTP) is used to synchronize the timekeeping among the number of distributed time servers and clients. It is used for the time management in a large and diverse network that contains many interfaces. In this protocol, servers define the time, and clients have to be synchronized with the defined time. These clients can choose the most reliable source of time defined from the several NTP servers for their information transmission. Answer option D is incorrect. The Data Link Switching Client Access Protocol (DCAP) is an application layer protocol that is used between workstations and routers for transporting SNA/NetBIOS traffic over TCP sessions. It was introduced in order to address a few deficiencies by the Data Link Switching Protocol (DLSw). The DLSw raises the important issues of scalability and efficiency, and since DLSw is a switch-to-switch protocol, it is not efficient when implemented on workstations. DCAP was introduced in order to address these issues.

 

NEW QUESTION 46
......

Verified 312-38 Exam Dumps Q&As - Provide 312-38 with Correct Answers: https://www.vceprep.com/312-38-latest-vce-prep.html

Pass Your 312-38 Dumps Free Latest EC-COUNCIL Practice Tests: https://drive.google.com/open?id=1gJmbjXZ1psoyVEzToG4zBg9ahi3opZvm