Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 1 out of 4 pages
Exam (elaborations)

Ch 11 Ethical Hacker Pro Review Questions and Answers

Document preview thumbnail
Preview 1 out of 4 pages

An IT technician receives an IDS alert on the company network she manages. A seemingly random user now has administration privileges in the system, some files are missing, and other files seem to have just been created. Which of the following alerts did this technician receive? True positive An IDS can perform many types of intrusion detections. Three common detection methods are signature-based, anomaly-based, and protocol-based. Which of the following best describes protocol-based detection? This detection method can include malformed messages and sequencing errors. Which of the following IDS detection types compare behavior to baseline profiles or network behavior baselines? Anomaly-based What are the two types of Intrusion Detection Systems (IDSs)? HIDS and NIDS You are on a Windows system. You receive an alert that a file named MyF had been found. Which of the following could this indicate? Host-based IDS Which of the following is a sign of a network-based intrusion? New or unusual protocols and services running. ARP, DNS, and IP are all examples of which of the following? Spoofing methods An attacker conducts a normal port scan on a host and detects protocols used by a Windows operating system and protocols used by a Linux operating system. Which of the following might this indicate? A honeypot Which of the following is another name for the signature-based detection method? Misuse detection Ping of death, teardrop, SYN flood, Smurf, and fraggle are all examples of which of the following? DoS attack types Robin, an IT technician, has implemented identification and detection techniques based on the ability to distinguish legitimate traffic from illegitimate traffic over the network. Which of the following is he trying to achieve? Defend the network against IDS evasions. When it comes to obfuscation mechanisms, nmap has the ability to generate decoys, meaning that detection of the actual scanning system becomes much more difficult.

Content preview

Ch 11 Ethical Hacker Pro Review
Questions and Answers
An IT technician receives an IDS alert on the company network she manages. A
seemingly random user now has administration privileges in the system, some files are
missing, and other files seem to have just been created. Which of the following alerts
did this technician receive? ✅True positive

An IDS can perform many types of intrusion detections. Three common detection
methods are signature-based, anomaly-based, and protocol-based. Which of the
following best describes protocol-based detection? ✅This detection method can
include malformed messages and sequencing errors.

Which of the following IDS detection types compare behavior to baseline profiles or
network behavior baselines? ✅Anomaly-based

What are the two types of Intrusion Detection Systems (IDSs)? ✅HIDS and NIDS

You are on a Windows system. You receive an alert that a file named MyFile.txt.exe
had been found. Which of the following could this indicate? ✅Host-based IDS

Which of the following is a sign of a network-based intrusion? ✅New or unusual
protocols and services running.

ARP, DNS, and IP are all examples of which of the following? ✅Spoofing methods

An attacker conducts a normal port scan on a host and detects protocols used by a
Windows operating system and protocols used by a Linux operating system. Which of
the following might this indicate? ✅A honeypot

Which of the following is another name for the signature-based detection method?
✅Misuse detection

Ping of death, teardrop, SYN flood, Smurf, and fraggle are all examples of which of the
following? ✅DoS attack types

Robin, an IT technician, has implemented identification and detection techniques based
on the ability to distinguish legitimate traffic from illegitimate traffic over the network.
Which of the following is he trying to achieve? ✅Defend the network against IDS
evasions.

When it comes to obfuscation mechanisms, nmap has the ability to generate decoys,
meaning that detection of the actual scanning system becomes much more difficult.

Document information

Uploaded on
September 24, 2024
Number of pages
4
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$9.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
twishfrancis
3.9
(42)
Sold
225
Followers
43
Items
10596
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions