401 SEC+ Exam Guaranteed Pass: Curated
Questions from Global Experts with In-Depth
Answer Analysis and Explanations
Which of the following BEST allows Pete, a security administrator, to determine the type,
source, and flags of the packet traversing a network for troubleshooting purposes?
A. Switches
B. Protocol analyzers
C. Routers
D. Web security gateways - -correct ans- -Answer: B
Explanation:
A Protocol Analyzer is a hardware device or more commonly a software program used to
capture network data communications sent between devices on a network. By capturing
and analyzingthe packets, Pete will be able to determine the type, source, and flags of the
packets traversing a network for troubleshooting purposes.
Well known software protocol analyzers include Message Analyzer (formerly Network
Monitor) from Microsoft and Wireshark (formerly Ethereal).
Which of the following security architecture elements also has sniffer functionality? (Select
TWO).
A. HSM
B. IPS
C. SSL accelerator
D. WAP
E. IDS - -correct ans- -Answer: B,E
Explanation:
```
,Sniffer functionality means the ability to capture and analyze the content of data packets
as they are transmitted across the network.
IDS and IPS systems perform their functions by capturing and analyzing the content of data
packets.
An intrusion detection system (IDS) is a device or software application that monitors
network or system activities for malicious activities or policy violations and produces
reports to a management station. IDS come in a variety of "flavors" and approach the goal
of detecting suspicious traffic in different ways. There are network based (NIDS) and host
based (HIDS) intrusion detection systems. Some systems may attempt to stop an intrusion
attempt but this is neither required nor expected of a monitoring system. Intrusion
detection and prevention systems (IDPS) are primarily focused on identifying possible
incidents, logging information about them, and reporting attempts. In addition,
organizations use IDPSes for other purposes, such as identifying problems with security
policies, documenting existing threats and deterring individuals from violating security
policies. IDPSes have become a necessary addition to the security infrastructure of nearly
every organization.
IDPSes typically record information related to observed events, notify security
administrators of important observed events and produce reports. Many IDPSes can also
respond to a detected threat by attempting to prevent it from succeeding. They use several
response techniques, which involve the IDPS stopping the attack itself, changing the
security environment (e.g. reconfiguring a firewall) or changing the attack's content.
Which of the following would a security administrator implement in order to discover
comprehensive security threats on a network?
A. Design reviews
B. Baseline reporting
C. Vulnerability scan
D. Code review - -correct ans- -Answer: C
Explanation:
```
, A vulnerability scan is the process of scanning the network and/or I.T. infrastructure for
threats and vulnerabilities. Vulnerabilities include computer systems that do not have the
latest security patches installed.
The threats and vulnerabilities are then evaluated in a risk assessment and the necessary
actions taken to resolve and vulnerabilities.
A vulnerability scan is the automated process of proactively identifying security
vulnerabilities of computing systems in a network in order to determine if and where a
system can be exploited and/or threatened. While public servers are important for
communication and data transfer over the Internet, they open the door to potential security
breaches by threat agents, such as malicious hackers.
Vulnerability scanning employs software that seeks out security flaws based on a database
of known flaws, testing systems for the occurrence of these flaws and generating a report
of the findings that an individual or an enterprise can use to tighten the network's security.
Vulnerability scanning typically refers to the scanning of systems that are connected to the
Internet but can also refer to system audits on internal networks that are not connected to
the Internet in order to assess the threat of rogue software or malicious employees in an
enterprise.
Joe, the security administrator, has determined that one of his web servers is under attack.
Which of the following can help determine where the attack originated from?
A. Capture system image
B. Record time offset
C. Screenshots
D. Network sniffing - -correct ans- -Answer: D
Explanation:
Network sniffing is the process of capturing and analyzing the packets sent between
systems on the network. A network sniffer is also known as a Protocol Analyzer.
A Protocol Analyzer is a hardware device or more commonly a software program used to
capture network data communications sent between devices on a network. Capturing and
analyzing the packets sent to the web server will help determine the source IP address of
the system sending the packets.
```
Questions from Global Experts with In-Depth
Answer Analysis and Explanations
Which of the following BEST allows Pete, a security administrator, to determine the type,
source, and flags of the packet traversing a network for troubleshooting purposes?
A. Switches
B. Protocol analyzers
C. Routers
D. Web security gateways - -correct ans- -Answer: B
Explanation:
A Protocol Analyzer is a hardware device or more commonly a software program used to
capture network data communications sent between devices on a network. By capturing
and analyzingthe packets, Pete will be able to determine the type, source, and flags of the
packets traversing a network for troubleshooting purposes.
Well known software protocol analyzers include Message Analyzer (formerly Network
Monitor) from Microsoft and Wireshark (formerly Ethereal).
Which of the following security architecture elements also has sniffer functionality? (Select
TWO).
A. HSM
B. IPS
C. SSL accelerator
D. WAP
E. IDS - -correct ans- -Answer: B,E
Explanation:
```
,Sniffer functionality means the ability to capture and analyze the content of data packets
as they are transmitted across the network.
IDS and IPS systems perform their functions by capturing and analyzing the content of data
packets.
An intrusion detection system (IDS) is a device or software application that monitors
network or system activities for malicious activities or policy violations and produces
reports to a management station. IDS come in a variety of "flavors" and approach the goal
of detecting suspicious traffic in different ways. There are network based (NIDS) and host
based (HIDS) intrusion detection systems. Some systems may attempt to stop an intrusion
attempt but this is neither required nor expected of a monitoring system. Intrusion
detection and prevention systems (IDPS) are primarily focused on identifying possible
incidents, logging information about them, and reporting attempts. In addition,
organizations use IDPSes for other purposes, such as identifying problems with security
policies, documenting existing threats and deterring individuals from violating security
policies. IDPSes have become a necessary addition to the security infrastructure of nearly
every organization.
IDPSes typically record information related to observed events, notify security
administrators of important observed events and produce reports. Many IDPSes can also
respond to a detected threat by attempting to prevent it from succeeding. They use several
response techniques, which involve the IDPS stopping the attack itself, changing the
security environment (e.g. reconfiguring a firewall) or changing the attack's content.
Which of the following would a security administrator implement in order to discover
comprehensive security threats on a network?
A. Design reviews
B. Baseline reporting
C. Vulnerability scan
D. Code review - -correct ans- -Answer: C
Explanation:
```
, A vulnerability scan is the process of scanning the network and/or I.T. infrastructure for
threats and vulnerabilities. Vulnerabilities include computer systems that do not have the
latest security patches installed.
The threats and vulnerabilities are then evaluated in a risk assessment and the necessary
actions taken to resolve and vulnerabilities.
A vulnerability scan is the automated process of proactively identifying security
vulnerabilities of computing systems in a network in order to determine if and where a
system can be exploited and/or threatened. While public servers are important for
communication and data transfer over the Internet, they open the door to potential security
breaches by threat agents, such as malicious hackers.
Vulnerability scanning employs software that seeks out security flaws based on a database
of known flaws, testing systems for the occurrence of these flaws and generating a report
of the findings that an individual or an enterprise can use to tighten the network's security.
Vulnerability scanning typically refers to the scanning of systems that are connected to the
Internet but can also refer to system audits on internal networks that are not connected to
the Internet in order to assess the threat of rogue software or malicious employees in an
enterprise.
Joe, the security administrator, has determined that one of his web servers is under attack.
Which of the following can help determine where the attack originated from?
A. Capture system image
B. Record time offset
C. Screenshots
D. Network sniffing - -correct ans- -Answer: D
Explanation:
Network sniffing is the process of capturing and analyzing the packets sent between
systems on the network. A network sniffer is also known as a Protocol Analyzer.
A Protocol Analyzer is a hardware device or more commonly a software program used to
capture network data communications sent between devices on a network. Capturing and
analyzing the packets sent to the web server will help determine the source IP address of
the system sending the packets.
```