CS6250 Computer Networks Exam 2
| 100% Correctly Answered and
Graded A+ | 2025/2026 Guide
When designing a system to identify DNS reflection and amplification
attacks, which network operation plane(s) is essential to monitor for
effective detection? (Control Plane, Data Plane, Management Plane,
Control Plane and Data Plane?)
- Correct Answer - Data Plane
To effectively identify BGP hijacking incidents, specifically targeting BGP
path and prefix manipulations, which network operation plane(s) should
you primarily monitor? (Control Plane, Data Plane, Management Plane,
Control Plane and Data Plane?)
- Correct Answer - Control Plane
Which of the following techniques can help an attacker to attract more
traffic when attempting to hijack a prefix? Select all that apply.
1. Advertise a more specific prefix than the original owner AS
2. Advertise a shorter path to the prefix.
3. Advertise the same path as the original owner AS but change the
origin AS.
- Correct Answer - 1. Advertise a more specific prefix than the original
owner AS
2. Advertise a shorter path to the prefix.
,A censorship technique can use any combination of criteria based on
content, source IP and destination IP to block access to objectionable
content. (T/F)
- Correct Answer - True
DNS injection uses DNS replies to censor network traffic based on the
source and destination IP address. (T/F)
- Correct Answer - False
With a censorship technique based on packet dropping, all network
traffic going to a set of specific IP addresses is discarded. (T/F)
- Correct Answer - True
When using DNS Poisoning, all traffic passes through a proxy where it
is examined for content, and the proxy rejects requests that serve
objectionable content. (T/F)
- Correct Answer - False
When using the Blocking with Resets technique, if a client sends a
request containing flaggable keywords, only the connection containing
requests with objectionable content is blocked. (T/F) - Correct Answer -
True
With the Immediate Reset of Connections technique, whenever a
request is sent containing flaggable keywords, any subsequent request
will receive resets from the firewall for a certain amount of time. (T/F) -
Correct Answer - True
, One of the obstacles to fully understand DNS censorship is the
heterogeneity of DNS manipulation across the globe. (T/F) - Correct
Answer - True
It is easy to infer if there is DNS manipulation based on few indications
such as inconsistent or anomalous DNS responses. (T/F) - Correct
Answer - False
There is a need for methods and tools independent of human
intervention and participation in order to achieve the scalability
necessary to measure Internet censorship. (T/F) - Correct Answer - True
It is considered safe for volunteers to participate in censorship
measurement studies and accessing DNS resolvers or DNS forwarders.
(T/F) - Correct Answer - False
Which of the following censorship detection systems target to identify
IP-based disruptions as opposed to DNS-based manipulations?
(CensMon, PlanetLab, OpenNet, Augur) - Correct Answer - Augur
[Iris] The Iris system uses home routers to identify DNS manipulation.
(T/F) - Correct Answer - False
[Iris] In order to infer DNS manipulation, Iris relies solely on metrics that
can be externally verified using external data sources. (T/F) - Correct
Answer - False
| 100% Correctly Answered and
Graded A+ | 2025/2026 Guide
When designing a system to identify DNS reflection and amplification
attacks, which network operation plane(s) is essential to monitor for
effective detection? (Control Plane, Data Plane, Management Plane,
Control Plane and Data Plane?)
- Correct Answer - Data Plane
To effectively identify BGP hijacking incidents, specifically targeting BGP
path and prefix manipulations, which network operation plane(s) should
you primarily monitor? (Control Plane, Data Plane, Management Plane,
Control Plane and Data Plane?)
- Correct Answer - Control Plane
Which of the following techniques can help an attacker to attract more
traffic when attempting to hijack a prefix? Select all that apply.
1. Advertise a more specific prefix than the original owner AS
2. Advertise a shorter path to the prefix.
3. Advertise the same path as the original owner AS but change the
origin AS.
- Correct Answer - 1. Advertise a more specific prefix than the original
owner AS
2. Advertise a shorter path to the prefix.
,A censorship technique can use any combination of criteria based on
content, source IP and destination IP to block access to objectionable
content. (T/F)
- Correct Answer - True
DNS injection uses DNS replies to censor network traffic based on the
source and destination IP address. (T/F)
- Correct Answer - False
With a censorship technique based on packet dropping, all network
traffic going to a set of specific IP addresses is discarded. (T/F)
- Correct Answer - True
When using DNS Poisoning, all traffic passes through a proxy where it
is examined for content, and the proxy rejects requests that serve
objectionable content. (T/F)
- Correct Answer - False
When using the Blocking with Resets technique, if a client sends a
request containing flaggable keywords, only the connection containing
requests with objectionable content is blocked. (T/F) - Correct Answer -
True
With the Immediate Reset of Connections technique, whenever a
request is sent containing flaggable keywords, any subsequent request
will receive resets from the firewall for a certain amount of time. (T/F) -
Correct Answer - True
, One of the obstacles to fully understand DNS censorship is the
heterogeneity of DNS manipulation across the globe. (T/F) - Correct
Answer - True
It is easy to infer if there is DNS manipulation based on few indications
such as inconsistent or anomalous DNS responses. (T/F) - Correct
Answer - False
There is a need for methods and tools independent of human
intervention and participation in order to achieve the scalability
necessary to measure Internet censorship. (T/F) - Correct Answer - True
It is considered safe for volunteers to participate in censorship
measurement studies and accessing DNS resolvers or DNS forwarders.
(T/F) - Correct Answer - False
Which of the following censorship detection systems target to identify
IP-based disruptions as opposed to DNS-based manipulations?
(CensMon, PlanetLab, OpenNet, Augur) - Correct Answer - Augur
[Iris] The Iris system uses home routers to identify DNS manipulation.
(T/F) - Correct Answer - False
[Iris] In order to infer DNS manipulation, Iris relies solely on metrics that
can be externally verified using external data sources. (T/F) - Correct
Answer - False