Pass Your Next 312-38 Certification Exam Easily & Hassle Free
Free EC-COUNCIL 312-38 Exam Question Practice Exams
The EC-COUNCIL 312-38 (EC-Council Certified Network Defender CND) Certification Exam is designed for individuals who want to pursue a career in network security. This certification exam tests the knowledge and skills required to protect computer networks from unauthorized access, data breaches, and other security threats. It covers various topics such as network security protocols, firewalls, intrusion detection and prevention, cryptography, and more.
The exam covers a wide range of topics including network security, network protocols, network defense, network perimeter security, network topologies, and network devices. It also includes hands-on practical exercises, which will test the candidate's ability to apply their knowledge in real-world scenarios. The exam is conducted online and consists of 100 multiple-choice questions, which must be completed within four hours.
NEW QUESTION # 97
Alice wants to prove her identity to Bob. Bob requests her password as proof of identity, which Alice dutifully provides (possibly after some transformation like a hash function); meanwhile, Eve is eavesdropping the conversation and keeps the password. After the interchange is over, Eve connects to Bob posing as Alice; when asked for a proof of identity, Eve sends Alice's password read from the last session, which Bob accepts. Which of the following attacks is being used by Eve?
- A. Replay
- B. Session fixation
- C. Fire walking
- D. Cross site scripting
Answer: A
NEW QUESTION # 98
Which of the following are the various methods that a device can use for logging information on a Cisco router? Each correct answer represents a complete solution. Choose all that apply.
- A. SNMP logging
- B. Buffered logging
- C. Terminal logging
- D. Console logging
- E. Syslog logging
- F. NTP logging
Answer: A,B,C,D,E
NEW QUESTION # 99
Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?
- A. Nmap
- B. NetRanger
- C. Hping
- D. PSAD
Answer: D
Explanation:
PSAD is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic. It includes many signatures from the IDS to detect probes for various backdoor programs such as EvilFTP, GirlFriend, SubSeven, DDoS tools (mstream, shaft), and advanced port scans (FIN, NULL, XMAS). If it is combined with fwsnort and the Netfilter string match extension, it detects most of the attacks described in the Snort rule set that involve application layer data. Answer option C is incorrect. NetRanger is the complete network configuration and information toolkit that includes the following tools: a Ping tool, Trace Route tool, Host Lookup tool, Internet time synchronizer, Whois tool, Finger Unix hosts tool, Host and port scanning tool, check multiple POP3 mail accounts tool, manage dialup connections tool, Quote of the day tool, and monitor Network Settings tool. These tools are integrated in order to use an application interface with full online help. NetRanger is designed for both new and experienced users. This tool is used to help diagnose network problems and to get information about users, hosts, and networks on the Internet or on a user computer network. NetRanger uses multi-threaded and multi-connection technologies in order to be very fast and efficient. Answer option B is incorrect. Hping is a free packet generator and analyzer for the TCP/IP protocol. Hping is one of the de facto tools for security auditing and testing of firewalls and networks. The new version of hping, hping3, is scriptable using the Tcl language and implements an engine for string based, human readable description of TCP/IP packets, so that the programmer can write scripts related to low level TCP/IP packet manipulation and analysis in very short time. Like most tools used in computer security, hping is useful to both system administrators and crackers (or script kiddies). Answer option A is incorrect. Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows, etc.
NEW QUESTION # 100
Which of the following is a device that receives a digital signal on an electromagnetic or optical transmission medium and regenerates the signal along the next leg of the medium?
- A. Transceiver
- B. Network adapter
- C. Gateway
- D. Repeater
Answer: D
Explanation:
A repeater is an electronic device that receives a signal and retransmits it at a higher level and/or higher power, or onto the other side of an obstruction, so that the signal can cover longer distances. A repeater is a device that receives a digital signal on an electromagnetic or optical transmission medium and regenerates the signal along the next leg of the medium. In electromagnetic media, repeaters overcome the attenuation caused by free-space electromagnetic-field divergence or cable loss. A series of repeaters make possible the extension of a signal over a distance. Repeaters remove the unwanted noise in an incoming signal. Unlike an analog signal, the original digital signal, even if weak or distorted, can be clearly perceived and restored. With analog transmission, signals are restrengthened with amplifiers which unfortunately also amplify noise as well as information. An example of a wireless repeater is shown in the figure below:
Answer option D is incorrect. A transceiver is a device that has both a transmitter and a receiver in a single package.
Answer option A is incorrect. A gateway is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies. It provides greater functionality than a router or bridge because a gateway functions both as a translator and a router. Gateways are slower than bridges and routers. A gateway is an application layer device.
Answer option C is incorrect. A network adapter is used to interface a computer to a network. "Device driver" is a piece of software through which Windows and other operating systems support both wired and wireless network adapters. Network drivers allow application software to communicate with the adapter hardware.
Network device drivers are often installed automatically when adapter hardware is first powered on.
NEW QUESTION # 101
Which of the following is the best known Windows tool for finding open wireless access points?
- A. Netstumbler
- B. Snort
- C. Dsniff
- D. Netcat
Answer: A
NEW QUESTION # 102
Simon had all his systems administrators implement hardware and software firewalls to ensure network security. They implemented IDS/IPS systems throughout the network to check for and stop any unauthorized traffic that may attempt to enter. Although Simon and his administrators believed they were secure, a hacker group was able to get into the network and modify files hosted on the company's website. After searching through the firewall and server logs, no one could find how the attackers were able to get in. He decides that the entire network needs to be monitored for critical and essential file changes. This monitoring tool alerts administrators when a critical file is altered. What tool could Simon and his administrators implement to accomplish this?
- A. Snort is the best tool for their situation
- B. They could use Tripwire
- C. They can implement Wireshark
- D. They need to use Nessus
Answer: B
NEW QUESTION # 103
Which of the following is the main international standards organization for the World Wide Web?
- A. CCITT
- B. ANSI
- C. WASC
- D. W3C
Answer: D
NEW QUESTION # 104
Which of the following attacks is a class of brute force attacks that depends on the higher likelihood of collisions found between random attack attempts and a fixed degree of permutations?
- A. Replay attack
- B. Birthday attack
- C. Phishing attack
- D. Dictionary attack
Answer: B
NEW QUESTION # 105
You are advising a school district on disaster recovery plans. In case a disaster affects the main IT centers for the district they will need to be able to work from an alternate location. However, budget is an issue. Which of the following is most appropriate for this client?
- A. Hot site
- B. Cold site
- C. Warm site
- D. Off site
Answer: B
NEW QUESTION # 106
The Circuit-level gateway firewall technology functions at which of the following OSI layer?
- A. Transport layer
- B. Session layer
- C. Data-link layer
- D. Network layer
Answer: B
NEW QUESTION # 107
Ivan needs to pick an encryption method that is scalable even though it might be slower. He has settled on a method that works where one key is public and the other is private. What encryption method did Ivan settle on?
- A. Ivan settled on the private encryption method.
- B. Ivan settled on the asymmetric encryption method
- C. Ivan settled on the symmetric encryption method.
- D. Ivan settled on the hashing encryption method
Answer: B
NEW QUESTION # 108
Which of the following recovery plans include specific strategies and actions to address the specific variances assumptions lead to a particular safety problem or emergency situation?
- A. Business Continuity Plan
- B. None
- C. The emergency plan
- D. disaster survival plan
Answer: C
NEW QUESTION # 109
Which of the following devices allows wireless communication devices to connect to a wireless network using Wi-Fi, Bluetooth, or related standards?
- A. Express card
- B. WNIC
- C. Wireless repeater
- D. WAP
Answer: D
NEW QUESTION # 110
John has successfully remediated the vulnerability of an internal application that could have caused a threat to the network. He is scanning the application for the existence of a remediated vulnerability, this process is called a________and it has to adhere to the_________
- A. Risk analysis, Risk matrix
- B. Mitigation, Security policies
- C. Verification, Security Policies
- D. Vulnerability scanning, Risk Analysis
Answer: C
NEW QUESTION # 111
In which of the following conditions does the system enter ROM monitor mode? Each correct answer represents a complete solution. Choose all that apply.
- A. The user interrupts the boot sequence.
- B. The router does not find a valid operating system image.
- C. The router does not have a configuration file.
- D. There is a need to set operating parameters.
Answer: A,B
Explanation:
The system enters ROM monitor mode if the router does not find a valid operating system image,
or if a user interrupts the boot sequence. From ROM monitor mode, a user can boot the device or
perform diagnostic tests.
Answer option A is incorrect. If the router does not have a configuration file, it will automatically
enter Setup mode when the user switches it on. Setup mode creates an initial configuration.
Answer option B is incorrect. Privileged EXEC is used for setting operating parameters.
NEW QUESTION # 112
Fill in the blank with the appropriate term. ______________is the use of sensitive words in e- mails to jam the authorities that listen in on them by providing a form of a red herring and an intentional annoyance.
Answer:
Explanation:
Email jamming
NEW QUESTION # 113
Which of the following is a device that provides local communication between the datalogger and a computer?
- A. Acoustic modem
- B. Optical modem
- C. Short haul modem
- D. Controllerless modem
Answer: C
Explanation:
A short haul modem is a device that provides local communication between the datalogger and a computer with an RS-232 serial port. It transmits data up to 6.5 miles over a four-wire unconditioned line (two twisted pairs).
Answer option B is incorrect. An optical modem is a device that is used for converting a computer's electronic signals into optical signals for transmission over optical fiber. It also converts optical signals from an optical fiber cable back into electronic signals. It provides higher data transmission rates because it uses extremely high capacity of the optical fiber cable for transmitting data.
Answer option C is incorrect. An acoustic modem provides wireless communication under water. The optimum performance of a wireless acoustic modem system depends upon the speed of sound, water depth, existence of thermocline zones, ambient noise, and seasonal change.
Answer option A is incorrect. A controllerless modem is a hardware-based modem that does not have the physical communications port controller circuitry. It is also known as WinModem or software modem. A controllerless modem is very inexpensive and can easily be upgraded with new software.
NEW QUESTION # 114
The IR team and the network administrator have successfully handled a malware incident on the network. The team is now preparing countermeasure guideline to avoid a future occurrence of the malware incident.
Which of the following countermeasure(s) should be added to deal with future malware incidents? (Select all that apply)
- A. Implementing strong authentication schemes
- B. Install antivirus software
- C. Complying with the company's security policies
- D. Implementing a strong password policy
Answer: B
NEW QUESTION # 115
......
Ace 312-38 Certification with 171 Actual Questions: https://www.easy4engine.com/312-38-test-engine.html
PASS EC-COUNCIL 312-38 EXAM WITH UPDATED DUMPS: https://drive.google.com/open?id=1kocHVnZUopeMAkeVaWiIvCE1dfztd-Xk

