312-38 Dumps PDF - 312-38 Real Exam Questions Answers [Q26-Q44]

Share

312-38 Dumps PDF - 312-38 Real Exam Questions Answers

Get Started: 312-38 Exam [2022] Dumps EC-COUNCIL PDF Questions


Understanding functional and technical aspects of Certified Network Defender Business Principles and Practices

The following will be discussed in ECCOUNCIL EC 312-38 exam dumps:

  • Perform network monitoring and analysis for suspicious traffic using Wireshark
  • Understand incident response concept
  • Understand the Insights of Cloud Security
  • Discuss log monitoring and analysis on Windows systems
  • Learn to reduce the attack surface
  • Learn to identify Indicators of Exposures (IoE)
  • Discuss centralized log monitoring and analysis
  • Discuss network performance and bandwidth monitoring concepts
  • Understand the attack surface analysis
  • Discuss general security best practices and tools for cloud security
  • Learn to leverage/consume threat intelligence for proactive defense
  • Understand the role of cyber threat intelligence in network defense
  • Understand the layers of Threat Intelligence
  • Learn to manage vulnerabilities through vulnerability management program
  • Understand the need and advantages of network traffic monitoring
  • Learn to manage risk though risk management program
  • Discuss security in Amazon Cloud (AWS)
  • Understand logging concepts
  • Introduction to Business Continuity (BC) and Disaster Recovery (DR)
  • Understand wireless network fundamentals
  • Determine baseline traffic signatures for normal and suspicious network traffic
  • Discuss Do's and Don't in first response
  • Understand wireless network encryption mechanisms
  • Understand and visualize your attack surface
  • Evaluate CSP for Security before Consuming Cloud Service
  • Learn different Risk Management Frameworks (RMF)
  • Discuss BC/DR Activities
  • Understand risk management concepts
  • Understand wireless network authentication methods
  • Understand the Indicators of Threat Intelligence: Indicators of Compromise (IoCs) and Indicators of Attack (IoA)
  • Discuss Security in Google Cloud Platform (GCP)
  • Describe forensics investigation process
  • Understand the role of first responder in incident response
  • Discuss log monitoring and analysis on Linux
  • Discuss various BC/DR Standards

 

NEW QUESTION 26
Which of the following protocols supports source-specific multicast (SSM)?

  • A. DNS
  • B. ARP
  • C. BGMP
  • D. DHCP

Answer: C

 

NEW QUESTION 27
Daniel is giving training on designing and implementing a security policy in the organization. He is explaining the hierarchy of the security policy which demonstrates how policies are drafted, designed and implemented.
What is the correct hierarchy for a security policy implementation?

  • A. Regulations, Policies, Laws, Standards and Procedures
  • B. Laws, Regulations, Policies, Standards and Procedures
  • C. Laws, Policies, Regulations, Procedures and Standards
  • D. Procedures, Policies, Laws, Standards and Regulations

Answer: B

 

NEW QUESTION 28
Which of the following is designed to detect unwanted changes by observing the flame of the environment associated with combustion?

  • A. Fire extinguishing system
  • B. sprinkler
  • C. None
  • D. Smoke alarm system
  • E. Gaseous fire-extinguishing systems

Answer: D

 

NEW QUESTION 29
John is working as a network defender at a well-reputed multinational company. He wanted to implement security that can help him identify any future attacks that can be targeted toward his organization and take appropriate security measures and actions beforehand to defend against them. Which one of the following security defense techniques should be implement?

  • A. Preventive security approach
  • B. Reactive security approach
  • C. Retrospective security approach
  • D. Proactive security approach

Answer: D

 

NEW QUESTION 30
What is the response of an Xmas scan if a port is either open or filtered?

  • A. RST
  • B. FIN
  • C. PUSH
  • D. No response

Answer: D

 

NEW QUESTION 31
Which of the following fields in the IPv6 header is decremented by 1 for each router that forwards the packet?

  • A. Flow label
  • B. Hop limit
  • C. Traffic class
  • D. Next header

Answer: B

Explanation:
The hop limit field in the IPv6 header is decremented by 1 for each router that forwards a packet. The packet is discarded when the hop limit field reaches zero.
Answer option B is incorrect. Next header is an 8-bit field that specifies the next encapsulated protocol.
Answer option A is incorrect. Flow label is a 20-bit field that is used for specifying special router handling from source to destination for a sequence of packets.
Answer option C is incorrect. Traffic class is an 8-bit field that specifies the Internet traffic priority delivery value.

 

NEW QUESTION 32
George was conducting a recovery drill test as a part of his network operation. Recovery drill tests are conducted on the______________.

  • A. Archived data
  • B. Deleted data
  • C. Backup data
  • D. Data in transit

Answer: C

 

NEW QUESTION 33
Which of the following help in estimating and totaling up the equivalent money value of the benefits and costs to the community of projects for establishing whether they are worthwhile?
Each correct answer represents a complete solution. Choose all that apply.

  • A. Benefit-Cost Analysis
  • B. Cost-benefit analysis
  • C. Disaster recovery
  • D. Business Continuity Planning

Answer: A,B

Explanation:
Cost-benefit analysis is a process by which business decisions are analyzed. It is used to estimate and total up the equivalent money value of the benefits and costs to the community of projects for establishing whether they are worthwhile. It is a term that refers both to:
helping to appraise, or assess, the case for a project, program, or policy proposal; an approach to making economic decisions of any kind. Under both definitions, the process involves, whether explicitly or implicitly, weighing the total expected costs against the total expected benefits of one or more actions in order to choose the best or most profitable option. The formal process is often referred to as either CBA (Cost-Benefit Analysis) or BCA (Benefit-Cost Analysis).
Answer option A is incorrect. Business Continuity Planning (BCP) is the creation and validation of a practiced logistical plan that defines how an organization will recover and restore partially or completely interrupted critical (urgent) functions within a predetermined time after a disaster or extended disruption. The logistical plan is called a Business Continuity Plan.
Answer option C is incorrect. Disaster recovery is the process, policies, and procedures related to preparing for recovery or continuation of technology infrastructure critical to an organization after a natural or human-induced disaster. Disaster recovery planning is a subset of a larger process known as business continuity planning and should include planning for resumption of applications, data, hardware, communications (such as networking) and other IT infrastructure. A business continuity plan (BCP) includes planning for non-IT related aspects such as key personnel, facilities, crisis communication and reputation protection, and should refer to the disaster recovery plan (DRP) for IT related infrastructure recovery / continuity.

 

NEW QUESTION 34
Which of the following systems is formed by a group of honeypots?

  • A. Honeynet
  • B. Honeyfarm
  • C. Research honeypot
  • D. Production honeypot

Answer: A

 

NEW QUESTION 35
Which of the following layers of the TCP/IP model maintains data integrity by ensuring that messages are delivered in the order in which they are sent and that there is no loss or duplication?

  • A. Transport layer
  • B. Internet layer
  • C. Link layer
  • D. Application layer

Answer: A

Explanation:
Explanation
Explanation:
The transport layer ensures that messages are delivered in the order in which they are sent and that there is no loss or duplication. Transport layer maintains data integrity.
Answer option C is incorrect. The Internet Layer of the TCP/IP model solves the problem of sending packets across one or more networks. Internetworking requires sending data from the source network to the destination network. This process is called routing. IP can carry data for a number of different upper layer protocols.
Answer option B is incorrect. The Link Layer of TCP/IP model is the networking scope of the local network connection to which a host is attached. This is the lowest component layer of the Internet protocols, as TCP/IP is designed to be hardware independent. As a result, TCP/IP has been implemented on top of virtually any hardware networking technology in existence. The Link Layer is used to move packets between the Internet Layer interfaces of two different hosts on the same link. The processes of transmitting and receiving packets on a given link can be controlled both in the software device driver for the network card, as well as on firmware or specialized chipsets.
Answer option D is incorrect. The Application Layer of TCP/IP model refers to the higher-level protocols used by most applications for network communication. Examples of application layer protocols include the File Transfer Protocol (FTP) and the Simple Mail Transfer Protocol (SMTP). Data coded according to application layer protocols are then encapsulated into one or more transport layer protocols, which in turn use lower layer protocols to affect actual data transfer.

 

NEW QUESTION 36
Which of the following protocols uses a control channel over TCP and a GRE tunnel operating to encapsulate
PPP packets?

  • A. LWAPP
  • B. PPTP
  • C. SSTP
  • D. ESP

Answer: B

Explanation:
The Point-to-Point Tunneling Protocol (PPTP) is a method for implementing virtual private networks. PPTP
uses a control channel over TCP and a GRE tunnel operating to encapsulate PPP packets. The PPTP
specification does not describe encryption or authentication features and relies on the PPP protocol being
tunneled to implement security functionality. However, the most common PPTP implementation, shipping with
the Microsoft Windows product families, implements various levels of authentication and encryption natively as
standard features of the Windows PPTP stack. The intended use of this protocol is to provide similar levels of
security and remote access as typical VPN products.
Answer option B is incorrect. Encapsulating Security Payload (ESP) is an IPSec protocol that provides
confidentiality, in addition to authentication, integrity, and anti-replay. ESP can be used alone or in combination
with Authentication Header (AH). It can also be nested with the Layer Two Tunneling Protocol (L2TP). ESP
does not sign the entire packet unless it is being tunneled. Usually, only the data payload is protected, not the
IP header.
Answer option D is incorrect. Secure Socket Tunneling Protocol (SSTP) is a form of VPN tunnel that provides a
mechanism to transport PPP or L2TP traffic through an SSL 3.0 channel. SSL provides transport-level security
with key-negotiation, encryption, and traffic integrity checking. The use of SSL over TCP port 443 allows SSTP
to pass through virtually all firewalls and proxy servers. SSTP servers must be authenticated during the SSL
phase. SSTP clients can optionally be authenticated during the SSL phase, and must be authenticated in the
PPP phase. The use of PPP allows support for common authentication methods, such as EAP-TLS and MS-
CHAP. SSTP is available in Windows Server 2008, Windows Vista SP1, and later operating systems. It is fully
integrated with the RRAS architecture in these operating systems, allowing its use with Winlogon or smart card
authentication, remote access policies, and the Windows VPN client.
Answer option C is incorrect. LWAPP (Lightweight Access Point Protocol) is a protocol used to control multiple
Wi-Fi wireless access points at once. This can reduce the amount of time spent on configuring, monitoring, or
troubleshooting a large network. This also allows network administrators to closely analyze the network.

 

NEW QUESTION 37
Which of the following analyzes network traffic to trace specific transactions and can intercept and log traffic passing over a digital network? Each correct answer represents a complete solution. Choose all that apply.

  • A. Protocol analyzer
  • B. Wireless sniffer
  • C. Spectrum analyzer
  • D. Performance Monitor

Answer: A,B

Explanation:
Protocol analyzer (also known as a network analyzer, packet analyzer or sniffer, or for particular types of networks, an Ethernet sniffer or wireless sniffer) is computer software or computer hardware that can intercept and log traffic passing over a digital network. As data streams flow across the network, the sniffer captures each packet and, if needed, decodes and analyzes its content according to the appropriate RFC or other specifications.
Answer option D is incorrect. Performance Monitor is used to get statistical information about the hardware and software components of a server.
Answer option B is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of an electrical, acoustic, or optical waveform. It may also measure the power spectrum.

 

NEW QUESTION 38
Jason works as a System Administrator for www.company.com Inc. The company has a Windows-based network. Sam, an employee of the company, accidentally changes some of the applications and system settings. He complains to Jason that his system is not working properly. To troubleshoot the problem, Jason diagnoses the internals of his computer and observes that some changes have been made in Sam's computer registry. To rectify the issue, Jason has to restore the registry. Which of the following utilities can Jason use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.

  • A. EventCombMT
  • B. Resplendent registrar
  • C. Reg.exe
  • D. Regedit.exe

Answer: B,C,D

Explanation:
The resplendent registrar is a tool that offers a complete and safe solution to administrators and power users for maintaining the registry. It can be used for maintaining the registry of desktops and remote computers on the network. It offers a solution for backing up and restoring registries, fast background search and replace, adding descriptions to the registry keys, etc. This program is very attractive and easy to use, as it comes in an explorer-style interface. It can be used for Windows 2003/XP/2K/NT/ME/9x.
Reg.exe is a command-line utility that is used to edit the Windows registry. It has the ability to import, export, back up, and restore keys, as well as to compare, modify, and delete keys. It can perform almost all tasks that can be done using the Windows-based Regedit.exe tool.
Registry Editor (REGEDIT) is a registry editing utility that can be used to look at information in the registry.
REGEDIT.EXE enables users to search for strings, values, keys, and subkeys and is useful to find a specific value or string. Users can also use REGEDIT.EXE to add, delete, or modify registry entries.
Answer option D is incorrect. EventCombMT is a multithreaded tool that is used to search the event logs of several different computers for specific events, all from one central location. It is a little-known Microsoft tool to run searches for event IDs or text strings against Windows event logs for systems, applications, and security, as well as File Replication Service (FRS), domain name system (DNS), and Active Directory (AD) logs where applicable. The MT stands for multi-threaded. The program is part of the Account Lockout and Management Tools program package for Windows 2000, 2003, and XP.

 

NEW QUESTION 39
Adam, malicious hacker, has just succeeded in stealing through a secure cookie XSS attack. He is able to play back the cookie even if the session is valid on the server. Which of the following is the most likely cause of this issue?

  • A. Scrambling is performed in the network (layer 1 encryption)
  • B. Encryption is performed at the application level (one encryption key).
  • C. None
  • D. Two-way encryption is used.
  • E. Encryption does not apply.

Answer: B

 

NEW QUESTION 40
Which of the following tools scans the network systems for well-known and often exploited vulnerabilities?

  • A. Nessus
  • B. SAINT
  • C. SATAN
  • D. HPing

Answer: C

 

NEW QUESTION 41
You have just set up a wireless network for customers at a coffee shop. Which of the following are good
security measures to implement? Each correct answer represents a complete solution. (Choose two.)

  • A. Using WEP encryption
  • B. MAC filtering the router
  • C. Using WPA encryption
  • D. Not broadcasting SSID

Answer: A,C

Explanation:
With either encryption method (WEP or WPA), you can give the password to the customers who need it, and
even change it frequently (daily if you like). So this won't be an inconvenience for the customers.

 

NEW QUESTION 42
Which of the following IEEE standards is also called Fast Basic Service Set Transition?

  • A. 802.11e
  • B. 802.11b
  • C. 802.11r
  • D. 802.11a

Answer: C

 

NEW QUESTION 43
Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?

  • A. NetRanger
  • B. Nmap
  • C. PSAD
  • D. Hping

Answer: C

Explanation:
PSAD is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic. It includes many signatures from the IDS to detect probes for various backdoor programs such as EvilFTP, GirlFriend, SubSeven, DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS). If it is combined with fwsnort and the Netfilter string match extension, it detects most of the attacks described in the Snort rule set that involve application layer data. Answer option C is incorrect. NetRanger is the complete network configuration and information toolkit that includes the following tools: a Ping tool, Trace Route tool, Host Lookup tool, Internet time synchronizer, Whois tool, Finger Unix hosts tool, Host and port scanning tool, check multiple POP3 mail accounts tool, manage dialup connections tool, Quote of the day tool, and monitor Network Settings tool. These tools are integrated in order to use an application interface with full online help. NetRanger is designed for both new and experienced users. This tool is used to help diagnose network problems and to get information about users, hosts, and networks on the Internet or on a user computer network. NetRanger uses multi-threaded and multi-connection technologies in order to be very fast and efficient. Answer option D is incorrect. Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows, etc.

 

NEW QUESTION 44
......

312-38 Premium Exam Engine pdf Download: https://pass4sure.testpdf.com/312-38-practice-test.html