Module 8 online quiz Exam 20 Questions with Verified Answers,100% CORRECT
Module 8 online quiz Exam 20 Questions with Verified Answers Which of the following attacks involves the capture of traffic flowing through a network to obtain sensitive information such as usernames and passwords? Packet Sniffing DoS Attack Data Modification Buffer Overflow - CORRECT ANSWER Packet sniffing Kasen, a professional hacker, performed an attack against a company's web server by flooding it with large amounts of invalid traffic; thereafter, the webserver stopped responding to legitimate incoming requests. Identify the type of attack performed by Kasen in the above scenario. Packet sniffing Denial-of-service attack IP address spoofing Man-in-the-middle attack - CORRECT ANSWER Denial-of-service attack Stetson, a professional hacker, targeted an organization to secretly listen to a client's conversation with a development team. In this process, he secretly installed a sniffing device in the organization's network, which allowed him to listen to voice messages actively. Identify the type of attack performed by Stetson in the above scenario. Dumpster diving Eavesdropping Piggybacking Shoulder surfing - CORRECT ANSWER Eavesdropping Which of the following refers to an analysis of logs performed to detect and study an incident that may have already occurred in a network or device, to determine what exactly occurred, and to identify the source of the event? Postmortem IP address spoofing Eavesdropping Real-time analysis - CORRECT ANSWER Postmortem In which of the following attacks does the attacker establish independent connections with users and relays the messages being transferred among them, thereby tricking them into assuming that their conversation is direct? Rogue access point attack Denial-of-service attack Enumeration Man-in-the-middle attack - CORRECT ANSWER Man-in-the-middle attack Renit, a professional hacker, is attempting to obtain sensitive information from a target network. In this process, he employs a technique to collect information such as network topology, live hosts, and potential vulnerabilities in host systems. Identify the technique employed by Renit in the above scenario. Malware attack Session hijacking Enumeration Buffer overflow - CORRECT ANSWER Enumeration Bruce, an attacker, targeted a Wi-Fi zone to temporarily block users from accessing the Wi-Fi network. To achieve this, Bruce used a specially designed radio transmitter that emits radio signals to overwhelm the access point. Which of the following types of attack has Bruce performed in the above scenario? Honeypot access point attack Access point MAC spoofing Jamming attack Ad-hoc connection attack - CORRECT ANSWER Jamming attack Which of the following layers of TCP/IP is responsible for selecting the best path through the network for data flow between the source and destination? Transport layer Application layer Network access layer Internet layer - CORRECT ANSWER Internet layer Which of the following is a digital forensic artifact that helps investigators detect a security incident that as occurred on a host system and includes logs related to systems, applications, networks, and firewalls? Event correlation Event aggregation Root cause analysis Indicators of compromise - CORRECT ANSWER Indicators of compromise Which of the following types of data is triggered by tools such as Snort IDS and Suricata that inspect network traffic flow and report potential security events as alerts? Session data Statistical data Alert data Full content data - CORRECT ANSWER Alert Data Identify the technique that refers to missing events related to systems downstream from a failed system and avoids events that can cause the system to crash. Event filtering Event aggregation Event masking Root cause analysis - CORRECT ANSWER Event masking Raphael, a forensics expert at an organization, was asked to analyze an issue that blocked devices from accessing the organization's network. In this process, Raphael employed a network behavior monitoring tool to identify and categorize different events and determine the events that caused the issue. In which of the following event correlation steps did Raphael identify the reason behind the issue? Event filtering Root cause analysis Event masking Event aggregation - CORRECT ANSWER Root cause analysis Identify the approach that assists forensic officers in correlating specific packets with other packets and comparing them with attack signatures to list new potential attacks on the network. Field-based approach Open-port-based correlation Graph-based approach Payload correlation - CORRECT ANSWER Payload correlation Identify the approach that helps users identify whether a system serves as a relay to a hacker and aids in gathering a series of data sets from forensic event data. Fingerprint-based approach Route correlation Role-based approach Open-port-based correlation - CORRECT ANSWER Fingerprint-based approach Albert, a network security specialist, was instructed to implement the best event correlation approach for the security event monitoring system. He employed an approach that correlates events according to a specified set of conditions. Identify the event correlation approach employed by Albert in the above scenario. Rule-based approach Field-based approach Bayesian correlation Open-port-based correlation - CORRECT ANSWER Rule-based approach Identify the color code in a Check Point firewall that signifies traffic detected as suspicious but accepted by the firewall. Green Blue Orange Red - CORRECT ANSWER orange Identify the numeric code that indicates the error condition message in Cisco IOS router logs. 2 0 3 1 - CORRECT ANSWER 3 Jude, a forensics expert, was inspecting a Cisco router as part of an investigation process. During analysis, Jude frequently received syslog messages describing the system unusable message on the Cisco router with number code 0. Identify the severity level of the syslog message in the above scenario. Debugging Emergency Alert Critical - CORRECT ANSWER Emergency In which of the following attacks does the attacker connect to a port on a switch and flood its interface by sending a large volume of Ethernet frames from various fake hardware addresses? MAC flooding SYN flooding HTTP flooding ICMP flooding - CORRECT ANSWER MAC flooding Identify the packet sniffing tool that assists forensic specialists in browsing data packets from a live network traffic interactively. Snagit Kaseya Ezvid Wireshark - CORRECT ANSWER Wireshark
Document information
- Uploaded on
- March 26, 2024
- Number of pages
- 6
- Written in
- 2023/2024
- Type
- Exam (elaborations)
- Contains
- Questions & answers