Authentic Best resources for 312-38 Test Engine Practice Exam [Q72-Q92]

Share

Authentic Best resources for 312-38 Test Engine Practice Exam

[2021] 312-38 PDF Questions - Perfect Prospect To Go With PracticeVCE Practice Exam


Understanding functional and technical aspects of Certified Network Defender Business Principles and Practices

The following will be discussed in ECCOUNCIL EC 312-38 dumps:

  • Understand the attack surface analysis
  • Understand the Insights of Cloud Security
  • Understand wireless network encryption mechanisms
  • Understand wireless network fundamentals
  • Understand the layers of Threat Intelligence
  • Introduction to Business Continuity (BC) and Disaster Recovery (DR)
  • Discuss Do’s and Don’t in first response
  • Discuss Security in Google Cloud Platform (GCP)
  • Understand different types of threat Intelligence
  • Learn to leverage/consume threat intelligence for proactive defense
  • Describe forensics investigation process
  • Understand risk management concepts
  • Understand the need and advantages of network traffic monitoring
  • Explain Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP)
  • Discuss log monitoring and analysis on Web Servers
  • Learn to manage risk though risk management program
  • Understand Cloud Computing Fundamentals
  • Discuss centralized log monitoring and analysis
  • Discuss log monitoring and analysis on Firewall
  • Setting up the environment for network monitoring
  • Discuss general security best practices and tools for cloud security
  • Learn different Risk Management Frameworks (RMF)
  • Learn to identify Indicators of Exposures (IoE)
  • Discuss log monitoring and analysis on Mac
  • Discuss and implement wireless network security measures
  • Discuss various BC/DR Standards
  • Discuss security in Microsoft Azure Cloud
  • Learn to reduce the attack surface
  • Understand and visualize your attack surface
  • Describe incident handling and response process
  • Discuss log monitoring and analysis on Linux
  • Discuss log monitoring and analysis on Routers
  • Understand wireless network authentication methods
  • Learn to manage vulnerabilities through vulnerability management program
  • Understand the role of cyber threat intelligence in network defense
  • Understand the role of first responder in incident response
  • Determine baseline traffic signatures for normal and suspicious network traffic
  • Discuss network performance and bandwidth monitoring concepts
  • Evaluate CSP for Security before Consuming Cloud Service
  • Learn to conduct attack simulation
  • Discuss security in Amazon Cloud (AWS)
  • Understand logging concepts
  • Understand the Indicators of Threat Intelligence: Indicators of Compromise (IoCs) and Indicators of Attack (IoA)
  • Understand incident response concept
  • Discuss BC/DR Activities
  • Learn vulnerability assessment and scanning
  • Discuss log monitoring and analysis on Windows systems
  • Perform network monitoring and analysis for suspicious traffic using Wireshark

 

NEW QUESTION 72
Kyle, a front office executive, suspects that a Trojan has infected his computer. What should be his first course of action to deal with the incident?

  • A. Disconnect the five infected devices from the network
  • B. Inform the IRT about the incident and wait for their response
  • C. Inform everybody in the organization about the attack
  • D. Contain the damage

Answer: B

 

NEW QUESTION 73
John has successfully remediated the vulnerability of an internal application that could have caused a threat to the network. He is scanning the application for the existence of a remediated vulnerability, this process is called a __________ and it has to adhere to the __________.

  • A. Risk analysis, Risk matrix
  • B. Verification, Security Policies
  • C. Vulnerability scanning, Risk Analysis
  • D. Mitigation, Security policies

Answer: A

 

NEW QUESTION 74
Which of the following is a network layer protocol used to obtain an IP address for a given hardware (MAC) address?

  • A. PIM
  • B. RARP
  • C. ARP
  • D. IP

Answer: B

Explanation:
Reverse Address Resolution Protocol (RARP) is a Network layer protocol used to obtain an IP address for a given hardware (MAC) address. RARP is sort of the reverse of an ARP. Common protocols that use RARP are BOOTP and DHCP. Answer option D is incorrect. Address Resolution Protocol (ARP) is a network maintenance protocol of the TCP/IP protocol suite. It is responsible for the resolution of IP addresses to media access control (MAC) addresses of a network interface card (NIC). The ARP cache is used to maintain a correlation between a MAC address and its corresponding IP address. ARP provides the protocol rules for making this correlation and providing address conversion in both directions. ARP is limited to physical network systems that support broadcast packets. Answer option B is incorrect. Protocol-Independent Multicast (PIM) is a family of multicast routing protocols for Internet Protocol (IP) networks that provide one-to-many and many-to-many distribution of data over a LAN, WAN, or the Internet. It is termed protocol-independent because PIM does not include its own topology discovery mechanism, but instead uses routing information supplied by other traditional routing protocols, such as Border Gateway Protocol (BGP). Answer option A is incorrect. The Internet Protocol (IP) is a protocol used for communicating data across a packet-switched inter-network using the Internet Protocol Suite, also referred to as TCP/IP. IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering distinguished protocol datagrams (packets) from the source host to the destination host solely based on their addresses. For this purpose, the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (IPv4), is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (IPv6), is being deployed actively worldwide.

 

NEW QUESTION 75
Which of the following is an example of a network providing DQDB access methods?

  • A. IEEE 802.6
  • B. IEEE 802.4
  • C. IEEE 802.3
  • D. IEEE 802.2

Answer: A

 

NEW QUESTION 76
CORRECT TEXT
Fill in the blank with the appropriate term. ______________is a powerful and low-interaction open source honeypot.

Answer:

Explanation:
Honeyd
Explanation:
Honeyd is a powerful and low-interaction open source honeypot. It was released by Niels Provos in 2002. It was written in C and designed for Unix platforms. It introduced a variety of new concepts, including the ability to monitor millions of unused IPs, IP stack spoofing, etc. It can also simulate hundreds of operating systems and monitor all UDP and TCP-based ports.

 

NEW QUESTION 77
The network administrator wants to strengthen physical security in the organization. Specifically, to implement a solution stopping people from entering certain restricted zones without proper credentials. Which of following physical security measures should the administrator use?

  • A. Fence
  • B. Bollards
  • C. Mantrap
  • D. Video surveillance

Answer: A

 

NEW QUESTION 78
Which of the following is an open source implementation of the syslog protocol for Unix?

  • A. syslog Unix
  • B. syslog-os
  • C. syslog-ng
  • D. Unix-syslog

Answer: C

 

NEW QUESTION 79
Which of the following analyzes network traffic to trace specific transactions and can intercept and log traffic passing over a digital network? Each correct answer represents a complete solution. Choose all that apply.

  • A. Performance Monitor
  • B. Protocol analyzer
  • C. Wireless sniffer
  • D. Spectrum analyzer

Answer: B,C

Explanation:
Protocol analyzer (also known as a network analyzer, packet analyzer or sniffer, or for particular types of networks, an Ethernet sniffer or wireless sniffer) is computer software or computer hardware that can intercept and log traffic passing over a digital network. As data streams flow across the network, the sniffer captures each packet and, if needed, decodes and analyzes its content according to the appropriate RFC or other specifications.
Answer option D is incorrect. Performance Monitor is used to get statistical information about the hardware and software components of a server. Answer option B is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of an electrical, acoustic, or optical waveform. It may also measure the power spectrum.

 

NEW QUESTION 80
Which of the following UTP cables uses four pairs of twisted cable and provides transmission speeds of up to
16 Mbps?

  • A. Category 5e
  • B. Category 3
  • C. Category 6
  • D. Category 5

Answer: B

Explanation:
Category 3 type of UTP cable uses four pairs of twisted cable and provides transmission speeds of up to 16
Mbps. They are commonly used in Ethernet networks that operate at the speed of 10 Mbps. A higher speed is
also possible by these cables implementing the Fast Ethernet (100Base-T4) specifications. This cable is used
mainly for telephone systems.
Answer option C is incorrect. This category of UTP cable is the most commonly used cable in present day
networks. It consists of four twisted pairs and is used in those Ethernet networks that run at the speed of 100
Mbps. Category 5 cable can also provide a higher speed of up to 1000 Mbps.
Answer option A is incorrect. It is also known as Category 5 Enhanced cable. Its specification is the same as
category 5, but it has some enhanced features and is used in Ethernets that run at the speed of 1000 Mbps.
Answer option D is incorrect. This category of UTP cable is designed to support high-speed networks that run
at the speed of 1000 Mbps. It consists of four pairs of wire and uses all of them for data transmission. Category
6 provides more than twice the speed of Category 5e, but is also more expensive.

 

NEW QUESTION 81
Jason works as a System Administrator for www.company.com Inc. The company has a Windows-based network. Sam, an employee of the company, accidentally changes some of the applications and system settings. He complains to Jason that his system is not working properly. To troubleshoot the problem, Jason diagnoses the internals of his computer and observes that some changes have been made in Sam's computer registry. To rectify the issue, Jason has to restore the registry. Which of the following utilities can Jason use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.

  • A. EventCombMT
  • B. Regedit.exe
  • C. Resplendent registrar
  • D. Reg.exe

Answer: B,C,D

Explanation:
The resplendent registrar is a tool that offers a complete and safe solution to administrators and power users for maintaining the registry. It can be used for maintaining the registry of desktops and remote computers on the network. It offers a solution for backing up and restoring registries, fast background search and replace, adding descriptions to the registry keys, etc. This program is very attractive and easy to use, as it comes in an explorer-style interface. It can be used for Windows 2003/XP/2K/NT/ME/9x.
Reg.exe is a command-line utility that is used to edit the Windows registry. It has the ability to import, export, back up, and restore keys, as well as to compare, modify, and delete keys. It can perform almost all tasks that can be done using the Windows-based Regedit.exe tool.
Registry Editor (REGEDIT) is a registry editing utility that can be used to look at information in the registry.
REGEDIT.EXE enables users to search for strings, values, keys, and subkeys and is useful to find a specific value or string. Users can also use REGEDIT.EXE to add, delete, or modify registry entries.
Answer option D is incorrect. EventCombMT is a multithreaded tool that is used to search the event logs of several different computers for specific events, all from one central location. It is a little-known Microsoft tool to run searches for event IDs or text strings against Windows event logs for systems, applications, and security, as well as File Replication Service (FRS), domain name system (DNS), and Active Directory (AD) logs where applicable. The MT stands for multi-threaded. The program is part of the Account Lockout and Management Tools program package for Windows 2000, 2003, and XP.

 

NEW QUESTION 82
Which of the following is the process of managing incidents in an enterprise?

  • A. Log analysis
  • B. Incident handling
  • C. Patch management
  • D. Incident response

Answer: B

 

NEW QUESTION 83
FILL BLANK
Fill in the blank with the appropriate term. ________________________ is the complete network configuration
and information toolkit that uses multi-threaded and multi-connection technologies in order to be very fast and
efficient.

Answer:

Explanation:
NetRanger
Explanation:
NetRanger is the complete network configuration and information toolkit that includes the following tools: a
Ping tool, Trace Route tool, Host Lookup tool, Internet time synchronizer, Whois tool, Finger Unix hosts tool,
Host and port scanning tool, check multiple POP3 mail accounts tool, manage dialup connections tool, Quote
of the day tool, and monitor Network Settings tool. These tools are integrated in order to use an application
interface with full online help. NetRanger is designed for both new and experienced users. This tool is used to
help diagnose network problems and to get information about users, hosts, and networks on the Internet or on
a user computer network. NetRanger uses multi-threaded and multi-connection technologies in order to be
very fast and efficient.

 

NEW QUESTION 84
Which of the following is a software tool used in passive attacks for capturing network traffic?

  • A. Warchalking
  • B. Sniffer
  • C. Intrusion detection system
  • D. Intrusion prevention system

Answer: B

Explanation:
A sniffer is a software tool that is used to capture any network traffic. Since a sniffer changes the NIC of the
LAN card into promiscuous mode, the NIC begins to record incoming and outgoing data traffic across the
network. A sniffer attack is a passive attack because the attacker does not directly connect with the target host.
This attack is most often used to grab logins and passwords from network traffic. Tools such as Ethereal,
Snort, Windump, EtherPeek, Dsniff are some good examples of sniffers. These tools provide many facilities to
users such as graphical user interface, traffic statistics graph, multiple sessions tracking, etc.
Answer option C is incorrect. An intrusion prevention system (IPS) is a network security device that monitors
network and/or system activities for malicious or unwanted behavior and can react, in real-time, to block or
prevent those activities. When an attack is detected, it can drop the offending packets while still allowing all
other traffic to pass.
Answer option B is incorrect. An IDS (Intrusion Detection System) is a device or software application that
monitors network and/or system activities for malicious activities or policy violations and produces reports to a
Management Station. Intrusion prevention is the process of performing intrusion detection and attempting to
stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on
identifying possible incidents, logging information about them, attempting to stop them, and reporting them to
security administrators.
Answer option D is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi
wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such
as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing
and war driving.

 

NEW QUESTION 85
If there is a fire incident caused by an electrical appliance short-circuit, which fire suppressant should be used to control it?

  • A. Water
  • B. Wet chemical
  • C. Dry chemical
  • D. Raw chemical

Answer: C

 

NEW QUESTION 86
DRAG DROP
Drag and drop the terms to match with their descriptions.

Answer:

Explanation:

Explanation:

Following are the terms with their descriptions:
A Trojan horse is a malicious software program that contains hidden code and masquerades itself as a normal program. When a Trojan horse program is run, its hidden code runs to destroy or scramble data on the hard disk. An example of a Trojan horse is a program that masquerades as a computer logon to retrieve user names and password information. The developer of a Trojan horse can use this information later to gain unauthorized access to computers. Trojan horses are normally spread by e-mail attachments. Ping sweep is a technique used to determine which of a range of IP addresses map to live hosts. It consists of ICMP ECHO requests sent to multiple hosts. If a given address is live, it will return an ICMP ECHO reply. A ping is often used to check that a network device is functioning. To disable ping sweeps on a network, administrators can block ICMP ECHO requests from outside sources. However, ICMP TIMESTAMP and ICMP INFO can be used in a similar manner. Spamware is software designed by or for spammers to send out automated spam e-mail. Spamware is used to search for e-mail addresses to build lists of e-mail addresses to be used either for spamming directly or to be sold to spammers. The spamware package also includes an e-mail harvesting tool. A backdoor is any program that allows a hacker to connect to a computer without going through the normal authentication process. The main advantage of this type of attack is that the network traffic moves from inside a network to the hacker's computer. The traffic moving from inside a network to the outside world is typically the least restrictive, as companies are more concerned about what comes into a network, rather than what leaves it. It, therefore, becomes hard to detect backdoors.

 

NEW QUESTION 87
Which of the following attacks comes under the category of an active attack?

  • A. Passive Eavesdropping
  • B. Replay attack
  • C. Traffic analysis
  • D. Wireless footprinting

Answer: B

 

NEW QUESTION 88
Which of the following OSI layers formats and encrypts data to be sent across the network?

  • A. Transport layer
  • B. Network layer
  • C. Presentation layer
  • D. Physical layer

Answer: C

 

NEW QUESTION 89
DRAG DROP
Drag and drop the Response management plans to match up with their respective purposes.
Select and Place:

Answer:

Explanation:

 

NEW QUESTION 90
FILL BLANK
Fill in the blank with the appropriate term. ______________ is the use of sensitive words in e-mails to jam the
authorities that listen in on them by providing a form of a red herring and an intentional annoyance.

Answer:

Explanation:
Email jamming
Explanation: Email jamming is the use of sensitive words in e-mails to jam the authorities that listen in on them
by providing a form of a red herring and an intentional annoyance. In this attack, an attacker deliberately
includes "sensitive" words and phrases in otherwise innocuous emails to ensure that these are picked up by
the monitoring systems. As a result the senders of these emails will eventually be added to a "harmless" list
and their emails will be no longer intercepted, hence it will allow them to regain some privacy.

 

NEW QUESTION 91
Which of the following protocols is used for E-mail?

  • A. SSH
  • B. MIME
  • C. SMTP
  • D. TELNET

Answer: C

 

NEW QUESTION 92
......

Best updated resource for 312-38 Online Practice Exam: https://www.practicevce.com/EC-COUNCIL/312-38-practice-exam-dumps.html

Realistic Practice 312-38 EC-Council Certified Network Defender CND Exam Braindumps: https://drive.google.com/open?id=1j3oMRRX0KwovsRHi3Pk9tQI-z9PMA-xF