
[Oct 19, 2021] Easy4Engine 312-38 dumps & Certified Ethical Hacker sure practice dumps
EC-COUNCIL 312-38 Actual Questions and Braindumps
Topics of Certified Network Defender
Competitors should know the test themes before they start arrangement. Since it will help them in hitting the center. ECCOUNCIL EC 312-38 dumps pdf will incorporate the accompanying themes:
- Network Perimeter Protection
- Incident Prediction
- Application and Data Protection
- Network Defense Management
- Incident Detection
- Enterprise Virtual, Cloud, and Wireless Network Protection
- Incident Response
- Endpoint Protection
EC-Council CND Exam Certification Details:
| Duration | 240 mins |
| Exam Price | $450 (USD) |
| Exam Name | EC-Council Certified Network Defender (CND) |
| Books / Training | Courseware |
| Passing Score | 70% |
| Number of Questions | 100 |
| Schedule Exam | Pearson VUE OR ECC Exam Center |
| Exam Code | 312-38 |
| Sample Questions | EC-Council CND Sample Questions |
NEW QUESTION 55
Which of the following tools is a free laptop tracker that helps in tracking a user's laptop in case it gets stolen?
- A. Adeona
- B. SAINT
- C. Snort
- D. Nessus
Answer: A
Explanation:
Adeona is a free laptop tracker that helps in tracking a user's laptop in case it gets stolen. All it takes is to install the Adeona software client on the user's laptop, pick a password, and make it run in the background. If at one point, the user's laptop gets stolen and is connected to the Internet, the Adeona software sends the criminal's IP address. Using the Adeona Recovery, the IP address can then be retrieved. Knowing the IP address helps in tracking the geographical location of the stolen device. Answer option D is incorrect. Nessus is proprietary comprehensive vulnerability scanning software. It is free of charge for personal use in a non-enterprise environment. Its goal is to detect potential vulnerabilities on tested systems. It is capable of checking various types of vulnerabilities, some of which are as follows:Vulnerabilities that allow a remote cracker to control or access sensitive data on a system Misconfiguration (e.g. open mail relay, missing patches, etc)Default passwords, a few common passwords, and blank/absent passwords on some system accounts. Nessus can also call Hydra (an external tool) to launch a dictionary attack.Denials of service against the TCP/IP stack by using mangled packets Answer option A is incorrect. SAINT stands for System Administrator's Integrated Network Tool. It is computer software used for scanning computer networks for security vulnerabilities, and exploiting found vulnerabilities. The SAINT scanner screens every live system on a network for TCP and UDP services. For each service it finds running, it launches a set of probes designed to detect anything that could allow an attacker to gain unauthorized access, create a denial-ofservice, or gain sensitive information about the network. Answer option C is incorrect. Snort is an open source network intrusion detection system. The Snort application analyzes network traffic in realtime mode. It performs packet sniffing, packet logging, protocol analysis, and a content search to detect a variety of potential attacks.
NEW QUESTION 56
Mark is monitoring the network traffic on his organization's network. He wants to detect a TCP and UDP ping sweep on his network. Which type of filter will be used to detect this on the network?
- A. Tcp.srcport==7 and udp.srcport==7
- B. Tcp.dstport==7 and udp.srcport==7
- C. Tcp.dstport==7 and udp.dstport==7
- D. Tcp.srcport==7 and udp.dstport==7
Answer: C
NEW QUESTION 57
Which of the following is a symmetric 64-bit block cipher that can support key lengths up to 448 bits?
- A. IDEA
- B. XOR
- C. HAVAL
- D. BLOWFISH
Answer: D
NEW QUESTION 58
Which of the following steps of the OPSEC process examines each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then compare those indicators with the adversary's intelligence collection capabilities identified in the previous action?
- A. Analysis of Threats
- B. Assessment of Risk
- C. Analysis of Vulnerabilities
- D. Application of Appropriate OPSEC Measures
- E. Identification of Critical Information
Answer: C
Explanation:
OPSEC is a 5-step process that helps in developing protection mechanisms in order to safeguard sensitive information and preserve essential secrecy.
The OPSEC process has five steps, which are as follows:
1.Identification of Critical Information: This step includes identifying information vitally needed by an adversary, which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to protect all classified or sensitive unclassified information.
2.Analysis of Threats: This step includes the research and analysis of intelligence, counter-intelligence, and open source information to identify likely adversaries to a planned operation.
3.Analysis of Vulnerabilities: It includes examining each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then comparing those indicators with the adversary's intelligence collection capabilities identified in the previous action.
4.Assessment of Risk: Firstly, planners analyze the vulnerabilities identified in the previous action and identify possible OPSEC measures for each vulnerability. Secondly, specific OPSEC measures are selected for execution based upon a risk assessment done by the commander and staff.
5.Application of Appropriate OPSEC Measures: The command implements the OPSEC measures selected in the assessment of risk action or, in the case of planned future operations and activities, includes the measures in specific OPSEC plans.
NEW QUESTION 59
Which of the following is a type of VPN that involves a single VPN gateway?
- A. Extranet-based VPN
- B. PPTP VPN
- C. Remote-access VPN
- D. Intranet-based VPN
Answer: A
NEW QUESTION 60
Which of the following TCP/IP state transitions represents no connection state at all?
- A. Fin-wait-1
- B. Close-wait
- C. Closed
- D. Closing
Answer: C
NEW QUESTION 61
What is the best way to describe a mesh network topology?
- A. A network that is extremely cost efficient, offering the best option for allowing computers to communicate amongst each other.
- B. A network in which every computer in the network can communicate with a single central computer.
- C. A network in which every computer meshes together to form a hybrid between a star and bus topology.
- D. A network in which every computer in the network has a connection to each and every computer in the network.
Answer: D
NEW QUESTION 62
Which of the following representatives in the incident response process are included in the incident response team? Each correct answer represents a complete solution. Choose all that apply.
- A. Information security representative
- B. Human resources
- C. Sales representative
- D. Technical representative
- E. Lead investigator
- F. Legal representative
Answer: A,B,D,E,F
Explanation:
Incident response is a process that detects a problem, determines the cause of an issue, minimizes the damages, resolves the problem, and documents each step of process for future reference. To perform all these roles, an incident response team is needed. The incident response team includes the following representatives who are involved in the incident response process: Lead investigator: The lead investigator is the manager of an incident response team. He is always involved in the creation of an incident response plan. The duties of a lead investigator are as follows:Keep the management updated.Ensure that the incident response moves smoothly and efficiently.Interview and interrogate the suspects and witnesses. Information security representative: The information security representative is a member of the incident response team who alerts the team about possible security safeguards that can impact their ability to respond to an incident. Legal representative: The legal representative is a member of the incident response team who ensures that the process follows all the laws during the response to an incident. Technical representative: Technical representative is a representative of the incident response team. More than one technician can be deployed to an incident. The duties of a technical representative are as follows:Perform forensic backups of the systems that are involved in an incident. Provide more information about the configuration of the network or system. Human resources: Human resources personnel ensure that the policies of the organization are enforced during the incident response process. They suspend access to a suspect if it is needed. Human resources personnel are closely related with the legal representatives and cover up the organization's legal responsibility.
NEW QUESTION 63
John works as a C programmer. He develops the following C program:
#include <stdlib.h>
#include <stdio.h>
#include <string.h>
int buffer(char *str) {
char buffer1[10];
strcpy(buffer1, str);
return 1;
}
int main(int argc, char *argv[]) {
buffer (argv[1]);
printf("Executed\n");
return 1;
}
His program is vulnerable to a __________ attack.
- A. SQL injection
- B. Buffer overflow
- C. Cross site scripting
- D. Denial-of-Service
Answer: B
Explanation:
This program takes a user-supplied string and copies it into 'buffer1', which can hold up to 10 bytes of data. If a user sends more than 10 bytes, it would result in a buffer overflow.
NEW QUESTION 64
Which of the following ranges of addresses can be used in the first octet of a Class C network address?
- A. 128-191
- B. 192-223
- C. 0-127
- D. 224-255
Answer: B
NEW QUESTION 65
Which of the following fields in the IPv6 header is decremented by 1 for each router that forwards the packet?
- A. Next header
- B. Traffic class
- C. Hop limit
- D. Flow label
Answer: C
Explanation:
The hop limit field in the IPv6 header is decremented by 1 for each router that forwards a packet. The packet is
discarded when the hop limit field reaches zero.
Answer option B is incorrect. Next header is an 8-bit field that specifies the next encapsulated protocol.
Answer option A is incorrect. Flow label is a 20-bit field that is used for specifying special router handling from
source to destination for a sequence of packets.
Answer option C is incorrect. Traffic class is an 8-bit field that specifies the Internet traffic priority delivery value.
NEW QUESTION 66
Which of the following is designed to detect unwanted changes by observing the flame of the environment
associated with combustion?
- A. Fire extinguishing system
- B. sprinkler
- C. Smoke alarm system
- D. Gaseous fire-extinguishing systems
- E. None
Answer: C
NEW QUESTION 67
Which of the following layers is closest to the end user?
- A. Presentation layer
- B. Application layer
- C. Session layer
- D. Physical layer
Answer: B
Explanation:
Explanation
NEW QUESTION 68
Identify the spread spectrum technique that multiplies the original data signal with a pseudo random noise spreading code.
- A. ISM
- B. FHSS
- C. DSSS
- D. OFDM
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 69
Which of the following network devices operate at the network layer of the OSI model? Each correct answer represents a complete solution. Choose all that apply.
- A. Bridge
- B. Router
- C. Repeater
- D. Gateway
Answer: B,D
Explanation:
A router is a device that routes data packets between computers in different networks. It is used to connect multiple networks, and it determines the path to be taken by each data packet to its destination computer. A router maintains a routing table of the available routes and their conditions. By using this information, along with distance and cost algorithms, the router determines the best path to be taken by the data packets to the destination computer. A router can connect dissimilar networks, such as Ethernet, FDDI, and Token Ring, and route data packets among them. Routers operate at the network layer (layer 3) of the Open Systems Interconnection (OSI) model. A gateway is a network point that acts as an entrance to another network. On the Internet, a node or stopping point can be either a gateway node or a host (end-point) node. Both the computers of Internet users and the computers that serve pages to users are host nodes. The computers that control traffic within a company's network or at a local Internet service provider (ISP) are gateway nodes. In the network for an enterprise, a computer server acting as a gateway node is often also acting as a proxy server and a firewall server. A gateway is often associated with both a router, which knows where to direct a given packet of data that arrives at the gateway, and a switch, which furnishes the actual path in and out of the gateway for a given packet. Most of the gateways operate at the application layer, but can operate at the network or session layer of the OSI model. Answer option C is incorrect. A repeater operates only at the physical layer of the OSI model. Answer option B is incorrect. A bridge operates at the data link layer of the OSI model.
NEW QUESTION 70
Paul is a network security technician working on a contract for a laptop manufacturing company in Chicago.
He has focused primarily on securing network devices, firewalls, and traffic traversing in and out of the network. He just finished setting up a server a gateway between the internal private network and the outside public network. This server will act as a proxy, limited amount of services, and will filter packets. What is this type of server called?
- A. SOCKS hsot
- B. Edge transport server
- C. Bastion host
- D. Session layer firewall
Answer: C
NEW QUESTION 71
Elden is working as a network administrator at an IT company. His organization opted for a virtualization technique in which the guest OS is aware of the virtual environment in which it is running and communicates with the host machines for requesting resources. Identify the virtualization technique implemented by Elden's organization.
- A. Full virtualization
- B. Hybrid virtualization
- C. Para virtualization
- D. Hardware-assisted virtualization
Answer: D
NEW QUESTION 72
Which of the following is an intrusion detection system that monitors and analyzes the internals of a computing system rather than the network packets on its external interfaces?
- A. NIDS
- B. DMZ
- C. IPS
- D. HIDS
Answer: D
Explanation:
A host-based intrusion detection system (HIDS) produces a false alarm because of the abnormal behavior of users and the network. A host-based intrusion detection system (HIDS) is an intrusion detection system that monitors and analyses the internals of a computing system rather than the network packets on its external interfaces. A host-based Intrusion Detection System (HIDS) monitors all or parts of the dynamic behavior and the state of a computer system. HIDS looks at the state of a system, its stored information, whether in RAM, in the file system, log files or elsewhere; and checks that the contents of these appear as expected.
Answer option D is incorrect. A network intrusion detection system (NIDS) is an intrusion detection system that tries to detect malicious activity such as denial of service attacks, port scans or even attempts to crack into computers by monitoring network traffic. A NIDS reads all the incoming packets and tries to find suspicious patterns known as signatures or rules. It also tries to detect incoming shell codes in the same manner that an ordinary intrusion detection system does.
Answer option A is incorrect. IPS (Intrusion Prevention Systems), also known as Intrusion Detection and Prevention Systems (IDPS), are network security appliances that monitor network and/or system activities for malicious activity. The main functions of "intrusion prevention systems" are to identify malicious activity, log information about said activity, attempt to block/stop activity, and report activity. An IPS can take such actions as sending an alarm, dropping the malicious packets, resetting the connection and/or blocking the traffic from the offending IP address. An IPS can also correct CRC, unfragment packet streams, prevent TCP sequencing issues, and clean up unwanted transport and network layer options.
Answer option C is incorrect. DMZ, or demilitarized zone, is a physical or logical subnetwork that contains and exposes an organization's external services to a larger untrusted network, usually the Internet. The term is normally referred to as a DMZ by IT professionals. It is sometimes referred to as a Perimeter Network. The purpose of a DMZ is to add an additional layer of security to an organization's Local Area Network (LAN); an external attacker only has access to equipment in the DMZ rather than any other part of the network.
NEW QUESTION 73
Which of the following is a firewall that keeps track of the state of network connections traveling across it?
- A. Application gateway firewall
- B. Stateless packet filter firewall
- C. Stateful firewall
- D. Circuit-level proxy firewall
Answer: C
Explanation:
A stateful firewall is a firewall that keeps track of the state of network connections (such as TCP streams, UDP
communication) traveling across it. The firewall is programmed to distinguish legitimate packets for different
types of connections. Only packets matching a known connection state will be allowed by the firewall; others
will be rejected. Answer option B is incorrect. A stateless packet filter firewall allows direct connections from the
external network to hosts on the internal network and is included with router configuration software or with
Open Source operating systems.
Answer option C is incorrect. It applies security mechanisms when a TCP or UDP connection is established.
Answer option D is incorrect. An application gateway firewall applies security mechanisms to specific
applications, such as FTP and Telnet servers.
NEW QUESTION 74
Which of the following commands is used for port scanning?
- A. nc -d
- B. nc -v
- C. nc -z
- D. nc -t
Answer: C
NEW QUESTION 75
Which of the following steps will NOT make a server fault tolerant? Each correct answer represents a complete
solution. (Choose two.)
- A. Encrypting confidential data stored on the server
- B. Performing regular backup of the server
- C. Adding one more same sized disk as mirror on the server
- D. Adding a second power supply unit
- E. Implementing cluster servers' facility
Answer: A,B
Explanation:
Encrypting confidential data stored on the server and performing regular backup will not make the server fault
tolerant.
Fault tolerance is the ability to continue work when a hardware failure occurs on a system. A fault-tolerant
system is designed from the ground up for reliability by building multiples of all critical components, such as
CPUs, memories, disks and power supplies into the same computer. In the event one component fails, another
takes over without skipping a beat.
Answer options A, C, and D are incorrect. The following steps will make the server fault tolerant:
Adding a second power supply unit
Adding one more same sized disk as a mirror on the server implementing cluster servers facility
NEW QUESTION 76
You are monitoring your network traffic with the Wireshark utility and noticed that your network is experiencing a large amount of traffic from a certain region. You suspect a DoS incident on the network. What will be your first reaction as a first responder?
- A. Communicate the incident
- B. Disable Virus Protection
- C. Make an initial assessment
- D. Avoid Fear, Uncertainty and Doubt
Answer: D
NEW QUESTION 77
Which of the following steps of the OPSEC process examines each aspect of the planned operation to identify
OPSEC indicators that could reveal critical information and then compare those indicators with the adversary's
intelligence collection capabilities identified in the previous action?
- A. Analysis of Threats
- B. Assessment of Risk
- C. Analysis of Vulnerabilities
- D. Application of Appropriate OPSEC Measures
- E. Identification of Critical Information
Answer: C
Explanation:
OPSEC is a 5-step process that helps in developing protection mechanisms in order to safeguard sensitive
information and preserve essential secrecy.
The OPSEC process has five steps, which are as follows:
1.Identification of Critical Information: This step includes identifying information vitally needed by an adversary,
which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to
protect all classified or sensitive unclassified information.
2.Analysis of Threats: This step includes the research and analysis of intelligence, counter-intelligence, and
open source information to identify likely adversaries to a planned operation.
3.Analysis of Vulnerabilities: It includes examining each aspect of the planned operation to identify OPSEC
indicators that could reveal critical information and then comparing those indicators with the adversary's
intelligence collection capabilities identified in the previous action.
4.Assessment of Risk: Firstly, planners analyze the vulnerabilities identified in the previous action and identify
possible OPSEC measures for each vulnerability. Secondly, specific OPSEC measures are selected for
execution based upon a risk assessment done by the commander and staff.
5.Application of Appropriate OPSEC Measures: The command implements the OPSEC measures selected in
the assessment of risk action or, in the case of planned future operations and activities, includes the measures
in specific OPSEC plans.
NEW QUESTION 78
Which of the following attacks, the attacker cannot use the software, which is trying a number of key combinations in order to obtain your password?
- A. Zero-day attack
- B. Buffer overflow
- C. None
- D. Shock brutal force
- E. Smurf attack
Answer: D
Explanation:
Explanation
NEW QUESTION 79
......
Latest 312-38 Pass Guaranteed Exam Dumps with Accurate & Updated Questions: https://www.easy4engine.com/312-38-test-engine.html
Pass 312-38 Exam with Updated 312-38 Exam Dumps PDF 2021: https://drive.google.com/open?id=1kocHVnZUopeMAkeVaWiIvCE1dfztd-Xk

