Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

401 SEC+ Exam Guaranteed Pass: Expert-Verified Questions & In-Depth Analysis to Boost Academic Performance

Document preview thumbnail
Preview 3 out of 22 pages

401 SEC+ Exam Guaranteed Pass: Expert-Verified Questions & In-Depth Analysis to Boost Academic Performance

Content preview

401 SEC+ Exam Guaranteed Pass: Expert-Verified
Questions & In-Depth Analysis to Boost Academic
Performance
Which of the following devices is used for the transparent security inspection of network
traffic by redirecting user packets prior to sending the packets to the intended destination?

A. Proxies

B. Load balancers

C. Protocol analyzer

D. VPN concentrator - -correct ans- -Answer: A




Explanation:

A proxy is a device that acts on behalf of other(s). A commonly used proxy in computer
networks is a web proxy. Web proxy functionality is often combined into a proxy firewall.

A proxy firewall can be thought of as an intermediary between your network and any other
network. Proxy firewalls are used to process requests from an outside network; the proxy
firewall examines the data and makes rule-based decisions about whether the request
should be forwarded or refused. The proxy intercepts all of the packets and reprocesses
them for use internally. This process includes hiding IP addresses.

The proxy firewall provides better security than packet filtering because of the increased
intelligence that a proxy firewall offers. Requests from internal network users are routed
through the proxy. The proxy, in turn, repackages the request and sends it along, thereby
isolating the user from the external network. The proxy can also offer caching, should the
same request be made again, and it can increase the efficiency of data delivery.



An administrator is investigating a system that may potentially be compromised, and sees
the following log entries on the router.

*Jul 15 14:47:29.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet
0/3) -> 10.10.1.5 (6667), 3 packets.

,*Jul 15 14:47:38.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet
0/3) -> 10.10.1.5 (6667), 6 packets.

*Jul 15 14:47:45.779:%Router1: list 101 permitted tcp 192.10.3.204(57222) (FastEthernet
0/3) -> 10.10.1.5 (6667), 8 packets.

Which of the following BEST describes the compromised system?

A. It is running a rogue web server

B. It is being used in a man-in-the-middle attack

C. It is participating in a botnet

D. It is an ARP poisoning attack - -correct ans- -Answer:



C Explanation:

In this question, we have a source computer (192.10.3.204) sending data to a single
destination IP address 10.10.1.5. No data is being received back by source computer which
suggests the data being sent is some kind of Denial-of-service attack. This is common
practice for computers participating in a botnet. The port used is TCP 6667 which is IRC
(Internet Relay Chat). This port is used by many Trojans and is commonly used for DoS
attacks.

Software running on infected computers called zombies is often known as a botnet. Bots,
by themselves, are but a form of software that runs automatically and autonomously. (For
example, Google uses the Googlebot to find web pages and bring back values for the
index.)

Botnet, however, has come to be the word used to describe malicious software running on
a zombie and under the control of a bot-herder.

Denial-of-service attacks—DoS and DDoS—can be launched by botnets, as can many
forms of adware, spyware, and spam (via spambots). Most bots are written to run in the
background with no visible evidence of their presence. Many malware kits can be used to
create botnets and modify existing ones.



The Chief Executive Officer (CEO) receives a suspicious voice mail warning of credit card
fraud. No one else received the voice mail. Which of the following BEST describes this
attack?

, A. Whaling

B. Vishing

C. Spear phishing

D. Impersonation - -correct ans- -Answer: A



Explanation:

Whaling is a specific kind of malicious hacking within the more general category of
phishing, which

involves hunting for data that can be used by the hacker. In general, phishing efforts are
focused on collecting personal data about users. In whaling, the targets are high-ranking
bankers, executives or others in powerful positions or job titles.

Hackers who engage in whaling often describe these efforts as "reeling in a big fish,"
applying a familiar metaphor to the process of scouring technologies for loopholes and
opportunities for data theft. Those who are engaged in whaling may, for example, hack into
specific networks where these powerful individuals work or store sensitive data. They may
also set up keylogging or other malware on a work station associated with one of these
executives. There are many ways that hackers can pursue whaling, leading C-level or top-
level executives in business and government to stay vigilant about the possibility of cyber
threats.



An administrator was asked to review user accounts. Which of the following has the
potential to cause the MOST amount of damage if the account was compromised?

A. A password that has not changed in 180 days

B. A single account shared by multiple users

C. A user account with administrative rights

D. An account that has not been logged into since creation - -correct ans- -Answer: C



Explanation:

A user account with administrative rights has the same rights as an administrator account
on a computer.

Document information

Uploaded on
December 24, 2024
Number of pages
22
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$25.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
johnwachi22
4.3
(281)
Sold
1232
Followers
957
Items
4040
Last sold
2 months ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions