[Q27-Q45] 312-38 Dumps are Available for Instant Access [2023]

Share

312-38 Dumps are Available for Instant Access [2023]

Practice with these 312-38 dumps Certification Sample Questions


EC-COUNCIL 312-38 exam is a popular certification among IT professionals and is recognized globally. EC-Council Certified Network Defender CND certification is highly regarded by employers, as it demonstrates a high level of proficiency in network defense. In addition, the certification is regularly updated to reflect the latest advancements in network security, ensuring that individuals who hold the certification are up-to-date with the latest technologies and best practices.

 

NEW QUESTION # 27
How can a WAF validate traffic before it reaches a web application?

  • A. It uses a rule-based filtering technique
  • B. It uses a role-based filtering technique
  • C. It uses an access-based filtering technique
  • D. It uses a sandboxing filtering technique

Answer: A


NEW QUESTION # 28
You are taking over the security of an existing network. You discover a machine that is not being used as such, but has software on it that emulates the activity of a sensitive database server. What is this?

  • A. A Honey Pot
  • B. A Polymorphic Virus
  • C. A Virus
  • D. A reactive IDS.

Answer: A

Explanation:
A honey pot is a device specifically designed to emulate a high value target such as a database server or entire sub section of your network. It is designed to attract the hacker's attention.


NEW QUESTION # 29
John wants to implement a firewall service that works at the session layer of the OSI model. The firewall must also have the ability to hide the private network information. Which type of firewall service is John thinking of implementing?

  • A. Packet Filtering
  • B. Application level gateway
  • C. Stateful Multilayer Inspection
  • D. Circuit level gateway

Answer: D


NEW QUESTION # 30
Which of the following is a class of attacks to break through, which depends on a greater probability of collisions between random attack was detected, and try to fixed rate permutations?

  • A. phishing attack
  • B. Dictionary attack
  • C. replay attack
  • D. None
  • E. birthday attack

Answer: E


NEW QUESTION # 31
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He is using a tool to crack the wireless encryption keys. The description of the tool is as follows:

Which of the following tools is John using to crack the wireless encryption keys?

  • A. PsPasswd
  • B. Kismet
  • C. AirSnort
  • D. Cain

Answer: C


NEW QUESTION # 32
Simon had all his systems administrators implement hardware and software firewalls to ensure network security. They implemented IDS/IPS systems throughout the network to check for and stop any unauthorized traffic that may attempt to enter. Although Simon and his administrators believed they were secure, a hacker group was able to get into the network and modify files hosted on the company's website. After searching through the firewall and server logs, no one could find how the attackers were able to get in. He decides that the entire network needs to be monitored for critical and essential file changes. This monitoring tool alerts administrators when a critical file is altered. What tool could Simon and his administrators implement to accomplish this?

  • A. They need to use Nessus
  • B. They can implement Wireshark
  • C. Snort is the best tool for their situation
  • D. They could use Tripwire

Answer: D


NEW QUESTION # 33
With which of the following flag sets does the Xmas tree scan send a TCP frame to a remote device? Each correct answer represents a part of the solution. Choose all that apply.

  • A. PUSH
  • B. FIN
  • C. URG
  • D. RST

Answer: A,B,C


NEW QUESTION # 34
Henry needs to design a backup strategy for the organization with no service level downtime. Which backup method will he select?

  • A. Cold backup
  • B. Normal backup
  • C. Warm backup
  • D. Hot backup

Answer: D


NEW QUESTION # 35
George works as a Network Administrator for Blue Soft Inc. The company uses Windows Vista operating system. The network of the company is continuously connected to the Internet. What will George use to protect the network of the company from intrusion?

Answer:

Explanation:


NEW QUESTION # 36
Which of the following is a presentation layer protocol?

  • A. LWAPP
  • B. BGP
  • C. TCP
  • D. RPC

Answer: A


NEW QUESTION # 37
You work as the network administrator for uCertify Inc. The company has planned to add the support for IPv6 addressing. The initial phase deployment of IPv6 requires support from some IPv6-only devices. These devices need to access servers that support only IPv4. Which of the following tools would be suitable to use?

  • A. Point-to-point tunnels
  • B. NAT-PT
  • C. Multipoint tunnels
  • D. Native IPv6

Answer: B


NEW QUESTION # 38
Which of the following is a communication protocol multicasts messages and information of all the member IP multicast group?

  • A. IGMP
  • B. ICMP
  • C. EGP
  • D. None
  • E. BGP

Answer: A


NEW QUESTION # 39
This is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b,
and 802.11g standards. The main features of these tools are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
This tool is known as __________.

  • A. Absinthe
  • B. Kismet
  • C. THC-Scan
  • D. NetStumbler

Answer: D

Explanation:
NetStumbler is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a,
802.11b, and 802.11g standards. The main features of NetStumbler are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
Answer option A is incorrect. Kismet is an IEEE 802.11 layer2 wireless network detector, sniffer, and intrusion
detection system.
Answer option C is incorrect. THC-Scan is a war-dialing tool.
Answer option B is incorrect. Absinthe is an automated SQL injection tool.


NEW QUESTION # 40
Which of the following is a distributed multi-access network that helps in supporting integrated communications using a dual bus and distributed queuing?

  • A. Token Ring network
  • B. Distributed-queue dual-bus
  • C. CSMA/CA
  • D. Logical Link Control

Answer: B

Explanation:
In telecommunication, a distributed-queue dual-bus network (DQDB) is a distributed multi-access network that helps in supporting integrated communications using a dual bus and distributed queuing, providing access to local or metropolitan area networks, and supporting connectionless data transfer, connection-oriented data transfer, and isochronous communications, such as voice communications. IEEE 802.6 is an example of a network providing DQDB access methods. Answer option B is incorrect. A Token Ring network is a local area network (LAN) in which all computers are connected in a ring or star topology and a bit- or token-passing scheme is used in order to prevent the collision of data between two computers that want to send messages at the same time. The Token Ring protocol is the second most widely-used protocol on local area networks after Ethernet. The IBM Token Ring protocol led to a standard version, specified as IEEE 802.5. Both protocols are used and are very similar. The IEEE 802.5 Token Ring technology provides for data transfer rates of either 4 or
16 megabits per second.
Answer option A is incorrect. The IEEE 802.2 standard defines Logical Link Control (LLC). LLC is the upper portion of the data link layer for local area networks.
Answer option D is incorrect. Carrier Sense Multiple Access/Collision Avoidance (CSMA/CA) is an access method used by wireless networks (IEEE 802.11). In this method, a device or computer that transmits data needs to first listen to the channel for an amount of time to check for any activity on the channel. If the channel is sensed as idle, the device is allowed to transmit data. If the channel is busy, the device postpones its transmission. Once the channel is clear, the device sends a signal telling all other devices not to transmit data, and then sends its packets. In Ethernet (IEEE 802.3) networks that use CSMA/CD, the device or computer continues to wait for a time and checks if the channel is still free. If the channel is free, the device transmits packets and waits for an acknowledgment signal indicating that the packets were received.


NEW QUESTION # 41
Which of the following is a standard-based protocol that provides the highest level of VPN security?

  • A. IPSec
  • B. IP
  • C. PPP
  • D. L2TP

Answer: A

Explanation:
Internet Protocol Security (IPSec) is a standard-based protocol that provides the highest level of VPN security. IPSec can encrypt virtually everything above the networking layer. It is used for VPN connections that use the L2TP protocol. It secures both data and password. IPSec cannot be used with Point-to-Point Tunneling Protocol (PPTP). Answer option B is incorrect. The Internet Protocol (IP) is a protocol used for communicating data across a packet-switched inter-network using the Internet Protocol Suite, also referred to as TCP/IP.IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering distinguished protocol datagrams (packets) from the source host to the destination host solely based on their addresses. For this purpose, the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (IPv4), is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (IPv6), is being deployed actively worldwide. Answer option C is incorrect. Point-to-Point Protocol (PPP) is a remote access protocol commonly used to connect to the Internet. It supports compression and encryption and can be used to connect to a variety of networks. It can connect to a network running on the IPX, TCP/IP, or NetBEUI protocol. It supports multi-protocol and dynamic IP assignments. It is the default protocol for the Microsoft Dial-Up adapter. Answer option A is incorrect. Layer 2 Tunneling Protocol (L2TP) is a more secure version of Point-to-Point Tunneling Protocol (PPTP). It provides tunneling, address assignment, and authentication. It allows the transfer of Point-to-Point Protocol (PPP) traffic between different networks.L2TP combines with IPSec to provide tunneling and security for Internet Protocol (IP), Internetwork Packet Exchange (IPX), and other protocol packets across IP networks.


NEW QUESTION # 42
Which of the following analyzes network traffic to trace specific transactions and can intercept and log traffic passing over a digital network? Each correct answer represents a complete solution. Choose all that apply.

  • A. Protocol analyzer
  • B. Spectrum analyzer
  • C. Performance Monitor
  • D. Wireless sniffer

Answer: A,D

Explanation:
Protocol analyzer (also known as a network analyzer, packet analyzer or sniffer, or for particular types of networks, an Ethernet sniffer or wireless sniffer) is computer software or computer hardware that can intercept and log traffic passing over a digital network. As data streams flow across the network, the sniffer captures each packet and, if needed, decodes and analyzes its content according to the appropriate RFC or other specifications.
Answer option D is incorrect. Performance Monitor is used to get statistical information about the hardware and software components of a server.
Answer option B is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of an electrical, acoustic, or optical waveform. It may also measure the power spectrum.


NEW QUESTION # 43
Adam, a malicious hacker, is sniffing an unprotected Wi-FI network located in a local store with Wireshark to capture hotmail e-mail traffic. He knows that lots of people are using their laptops for browsing the Web in the store. Adam wants to sniff their e-mail messages traversing the unprotected Wi-Fi network. Which of the following Wireshark filters will Adam configure to display only the packets with hotmail email messages?

  • A. (http contains "hotmail") && (http contains "Reply-To")
  • B. (http = "login.passport.com") && (http contains "POP3")
  • C. (http = "login.pass.com") && (http contains "SMTP")
  • D. (http contains "email") && (http contains "hotmail")

Answer: A


NEW QUESTION # 44
Which of the following representatives in the incident response process are included in the incident response team? Each correct answer represents a complete solution. Choose all that apply.

  • A. Legal representative
  • B. Sales representative
  • C. Human resources
  • D. Technical representative
  • E. Information security representative
  • F. Lead investigator

Answer: A,C,D,E,F


NEW QUESTION # 45
......

Get Instant Access REAL 312-38 DUMP Pass Your Exam Easily: https://www.vceprep.com/312-38-latest-vce-prep.html

312-38 Free Exam Questions with Quality Guaranteed: https://drive.google.com/open?id=1iIjzl94Rat6DX444srXm1umRmS1yt23p