
Unique Top-selling 312-38 Exams - New 2021 EC-COUNCIL Pratice Exam
Certified Ethical Hacker Dumps 312-38 Exam for Full Questions - Exam Study Guide
NEW QUESTION 43
Jason works as a System Administrator for www.company.com Inc. The company has a Windows-based network. Sam, an employee of the company, accidentally changes some of the applications and system settings. He complains to Jason that his system is not working properly. To troubleshoot the problem, Jason diagnoses the internals of his computer and observes that some changes have been made in Sam's computer registry. To rectify the issue, Jason has to restore the registry. Which of the following utilities can Jason use to accomplish the task? Each correct answer represents a complete solution. Choose all that apply.
- A. Reg.exe
- B. EventCombMT
- C. Regedit.exe
- D. Resplendent registrar
Answer: A,C,D
Explanation:
The resplendent registrar is a tool that offers a complete and safe solution to administrators and power users for maintaining the registry. It can be used for maintaining the registry of desktops and remote computers on the network. It offers a solution for backing up and restoring registries, fast background search and replace, adding descriptions to the registry keys, etc. This program is very attractive and easy to use, as it comes in an explorer-style interface. It can be used for Windows 2003/XP/2K/NT/ME/9x. Reg.exe is a command-line utility that is used to edit the Windows registry. It has the ability to import, export, back up, and restore keys, as well as to compare, modify, and delete keys. It can perform almost all tasks that can be done using the Windows-based Regedit.exe tool. Registry Editor (REGEDIT) is a registry editing utility that can be used to look at information in the registry. REGEDIT.EXE enables users to search for strings, values, keys, and subkeys and is useful to find a specific value or string. Users can also use REGEDIT.EXE to add, delete, or modify registry entries. Answer option D is incorrect. EventCombMT is a multithreaded tool that is used to search the event logs of several different computers for specific events, all from one central location. It is a little-known Microsoft tool to run searches for event IDs or text strings against Windows event logs for systems, applications, and security, as well as File Replication Service (FRS), domain name system (DNS), and Active Directory (AD) logs where applicable. The MT stands for multi-threaded. The program is part of the Account Lockout and Management Tools program package for Windows 2000, 2003, and XP.
NEW QUESTION 44
Which of the following flags is set when a closed port responds to an Xmas tree scan?
- A. RST
- B. PUSH
- C. FIN
- D. ACK
Answer: A
NEW QUESTION 45
CORRECT TEXT
Fill in the blank with the appropriate term. The_______________ is typically considered as the top InfoSec officer in the organization and helps in maintaining current and appropriate body of knowledge required to perform InfoSec management functions.
Answer:
Explanation:
CISO
Explanation:
The Chief InfoSec Officer (CISO) is typically considered as the top InfoSec officer in the organization, though the CISO is usually not an executive-level position and commonly reports to the CIO. Following are the job competencies for the Chief InfoSec Officer (CISO): Maintaining current & appropriate body of knowledge required to perform InfoSec management functionsEffectively applying InfoSec management knowledge for improving security of open network and associated systems and services Maintaining working knowledge of external legislative & regulatory initiativesInterpreting and translating requirements for implementationDeveloping appropriate InfoSec policies, standards, guidelines, and proceduresProviding meaningful input, preparing effective presentations, and communicating InfoSec objectivesParticipating in short and long term planning
NEW QUESTION 46
FILL BLANK
Fill in the blank with the appropriate term.
______________ is an enumeration technique used to glean information about computer systems on a
network and the services running its open ports.
Answer:
Explanation:
Banner grabbing
Explanation:
Banner grabbing is an enumeration technique used to glean information about computer systems on a network
and the services running its open ports. Administrators can use this to take inventory of the systems and
services on their network. An intruder however can use banner grabbing in order to find network hosts that are
running versions of applications and operating systems with known exploits.
Some examples of service ports used for banner grabbing are those used by Hyper Text Transfer Protocol
(HTTP), File Transfer Protocol (FTP), and Simple Mail Transfer Protocol (SMTP); ports 80, 21, and 25
respectively. Tools commonly used to perform banner grabbing are Telnet, which is included with most
operating systems, and Netcat.
For example, one could establish a connection to a target host running a Web service with netcat, then send a
bad html request in order to get information about the service on the host:
[root@prober] nc www.targethost.com 80
HEAD / HTTP/1.1
HTTP/1.1 200 OK
Date: Mon, 11 May 2009 22:10:40 EST
Server: Apache/2.0.46 (Unix) (Red Hat/Linux)
Last-Modified: Thu, 16 Apr 2009 11:20:14 PST
ETag: "1986-69b-123a4bc6"
Accept-Ranges: bytes
Content-Length: 1110
Connection: close
Content-Type: text/html
The administrator can now catalog this system or an intruder now knows what version of Apache to look for
exploits.
NEW QUESTION 47
Which of the following procedures is designed to enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as unauthorized access to a system or data, denial-of-service, or unauthorized changes to system hardware, software, or data?
- A. Disaster Recovery Plan
- B. Occupant Emergency Plan
- C. Crisis Communication Plan
- D. Cyber Incident Response Plan
Answer: D
Explanation:
The Cyber Incident Response Plan is used to address cyber attacks against an organization's IT system through various procedures. These procedures enable security personnel to identify, mitigate, and recover from malicious computer incidents, such as denial-of-service attacks, unauthorized accessing of a system or data, or unauthorized changes to system hardware, software, or data. Answer option C is incorrect. A disaster recovery plan should contain data, hardware, and software that can be critical for a business. It should also include the plan for sudden loss such as hard disc crash. The business should use backup and data recovery utilities to limit the loss of data. Answer option D is incorrect. The Occupant Emergency Plan (OEP) is used to reduce the risk to personnel, property, and other assets while minimizing work disorders in the event of an emergency. It is the response procedure for occupants of a facility on the occurrence of a situation, which is posing a potential threat to the health and safety of personnel, the environment, or property. OEPs are developed at the facility level, speci?c to the geographic site and structural design of the building. Answer option B is incorrect. The crisis communication plan can be broadly defined as the plan for the exchange of information before, during, or after a crisis event. It is considered as a subspecialty of the public relations profession that is designed to protect and defend an individual, company, or organization facing a public challenge to its reputation. The aim of crisis communication plan is to assist organizations to achieve continuity of critical business processes and information flows under crisis, disaster or event driven circumstances.
NEW QUESTION 48
Ivan needs to pick an encryption method that is scalable even though it might be slower. He has settled on a method that works where one key is public and the other is private. What encryption method did Ivan settle on?
- A. Ivan settled on the symmetric encryption method.
- B. Ivan settled on the asymmetric encryption method
- C. Ivan settled on the private encryption method.
- D. Ivan settled on the hashing encryption method
Answer: B
NEW QUESTION 49
Which of the following commands is used for port scanning?
- A. nc -t
- B. nc -d
- C. nc -z
- D. nc -v
Answer: C
NEW QUESTION 50
Which of the following tools is an open source network intrusion prevention and detection system that operates as a network sniffer and logs activities of the network that is matched with the predefined signatures?
- A. Dsniff
- B. KisMAC
- C. Snort
- D. Kismet
Answer: C
Explanation:
Snort is an open source network intrusion prevention and detection system that operates as a network sniffer. It logs activities of the network that is matched with the predefined signatures. Signatures can be designed for a wide range of traffic, including Internet Protocol (IP), Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Internet Control Message Protocol (ICMP). The three main modes in which Snort can be configured are as follows: Sniffer mode: It reads the packets of the network and displays them in a continuous stream on the console. Packet logger mode: It logs the packets to the disk. Network intrusion detection mode: It is the most complex and configurable configuration, allowing Snort to analyze network traffic for matches against a user-defined rule set. Answer option A is incorrect. Dsniff is a set of tools that are used for sniffing passwords, e-mail, and HTTP traffic. Some of the tools of Dsniff include dsniff, arpredirect, macof, tcpkill, tcpnice, filesnarf, and mailsnarf. Dsniff is highly effective for sniffing both switched and shared networks. It uses the arpredirect and macof tools for switching across switched networks. It can also be used to capture authentication information for FTP, telnet, SMTP, HTTP, POP, NNTP, IMAP, etc. Answer option D is incorrect. Kismet is a Linux-based 802.11 wireless network sniffer and intrusion detection system. It can work with any wireless card that supports raw monitoring (rfmon) mode. Kismet can sniff 802.11b, 802.11a, 802.11g, and 802.11n traffic. Kismet can be used for the following tasks: To identify networks by passively collecting packets To detect standard named networks To detect masked networks To collect the presence of non-beaconing networks via data traffic Answer option B is incorrect. KisMAC is a wireless network discovery tool for Mac OS X.
It has a wide range of features, similar to those of Kismet, its Linux/BSD namesake and far exceeding those of NetStumbler, its closest equivalent on Windows. The program is geared towards the network security professionals, and is not as novice-friendly as the similar applications. KisMAC will scan for networks passively on supported cards, including Apple's AirPort, AirPort Extreme, and many third-party cards. It will scan for networks actively on any card supported by Mac OS X itself. Cracking of WEP and WPA keys, both by brute force, and exploiting flaws, such as weak scheduling and badly generated keys is supported when a card capable of monitor mode is used, and when packet reinsertion can be done with a supported card. The GPS mapping can be performed when an NMEA compatible GPS receiver is attached. Data can also be saved in pcap format and loaded into programs, such as Wireshark.
NEW QUESTION 51
Which of the following is a distributed multi-access network that helps in supporting integrated communications
using a dual bus and distributed queuing?
- A. CSMA/CA
- B. Distributed-queue dual-bus
- C. Token Ring network
- D. Logical Link Control
Answer: B
Explanation:
In telecommunication, a distributed-queue dual-bus network (DQDB) is a distributed multi-access network that
helps in supporting integrated communications using a dual bus and distributed queuing, providing access to
local or metropolitan area networks, and supporting connectionless data transfer, connection-oriented data
transfer, and isochronous communications, such as voice communications. IEEE 802.6 is an example of a
network providing DQDB access methods. Answer option B is incorrect. A Token Ring network is a local area
network (LAN) in which all computers are connected in a ring or star topology and a bit- or token-passing
scheme is used in order to prevent the collision of data between two computers that want to send messages at
the same time. The Token Ring protocol is the second most widely-used protocol on local area networks after
Ethernet. The IBM Token Ring protocol led to a standard version, specified as IEEE 802.5. Both protocols are
used and are very similar. The IEEE 802.5 Token Ring technology provides for data transfer rates of either 4 or
16 megabits per second.
Answer option A is incorrect. The IEEE 802.2 standard defines Logical Link Control (LLC). LLC is the upper
portion of the data link layer for local area networks.
Answer option D is incorrect. Carrier Sense Multiple Access/Collision Avoidance (CSMA/CA) is an access
method used by wireless networks (IEEE 802.11). In this method, a device or computer that transmits data
needs to first listen to the channel for an amount of time to check for any activity on the channel. If the channel
is sensed as idle, the device is allowed to transmit data. If the channel is busy, the device postpones its
transmission. Once the channel is clear, the device sends a signal telling all other devices not to transmit data,
and then sends its packets. In Ethernet (IEEE 802.3) networks that use CSMA/CD, the device or computer
continues to wait for a time and checks if the channel is still free. If the channel is free, the device transmits
packets and waits for an acknowledgment signal indicating that the packets were received.
NEW QUESTION 52
Which of the following steps of the OPSEC process examines each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then compare those indicators with the adversary's intelligence collection capabilities identified in the previous action?
- A. Analysis of Vulnerabilities
- B. Assessment of Risk
- C. Identification of Critical Information
- D. Analysis of Threats
- E. Application of Appropriate OPSEC Measures
Answer: A
Explanation:
OPSEC is a 5-step process that helps in developing protection mechanisms in order to safeguard sensitive information and preserve essential secrecy. The OPSEC process has five steps, which are as follows: 1.Identification of Critical Information: This step includes identifying information vitally needed by an adversary, which focuses the remainder of the OPSEC process on protecting vital information, rather than attempting to protect all classified or sensitive unclassified information. 2.Analysis of Threats: This step includes the research and analysis of intelligence, counterintelligence, and open source information to identify likely adversaries to a planned operation. 3.Analysis of Vulnerabilities: It includes examining each aspect of the planned operation to identify OPSEC indicators that could reveal critical information and then comparing those indicators with the adversary's intelligence collection capabilities identified in the previous action. 4.Assessment of Risk: Firstly, planners analyze the vulnerabilities identified in the previous action and identify possible OPSEC measures for each vulnerability. Secondly, specific OPSEC measures are selected for execution based upon a risk assessment done by the commander and staff. 5.Application of Appropriate OPSEC Measures: The command implements the OPSEC measures selected in the assessment of risk action or, in the case of planned future operations and activities, includes the measures in specific OPSEC plans.
NEW QUESTION 53
This is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a, 802.11b,
and 802.11g standards. The main features of these tools are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
This tool is known as __________.
- A. NetStumbler
- B. Kismet
- C. Absinthe
- D. THC-Scan
Answer: A
Explanation:
NetStumbler is a Windows-based tool that is used for the detection of wireless LANs using the IEEE 802.11a,
802.11b, and 802.11g standards. The main features of NetStumbler are as follows:
It displays the signal strength of a wireless network, MAC address, SSID, channel details, etc.
It is commonly used for the following purposes:
a.War driving
b.Detecting unauthorized access points
c.Detecting causes of interference on a WLAN
d.WEP ICV error tracking
e.Making Graphs and Alarms on 802.11 Data, including Signal Strength
Answer option A is incorrect. Kismet is an IEEE 802.11 layer2 wireless network detector, sniffer, and intrusion
detection system.
Answer option C is incorrect. THC-Scan is a war-dialing tool.
Answer option B is incorrect. Absinthe is an automated SQL injection tool.
NEW QUESTION 54
A network administrator is monitoring the network traffic with Wireshark. Which of the following filters will she use to view the packets moving without setting a flag to detect TCP Null Scan attempts?
- A. Tcp.flags==0X029
- B. TCRflags==0x000
- C. Tcp.flags==0x003
- D. Tcp.dstport==7
Answer: B
NEW QUESTION 55
You are advising a school district on disaster recovery plans. In case a disaster affects the main IT centers for the district they will need to be able to work from an alternate location. However, budget is an issue. Which of the following is most appropriate for this client?
- A. Cold site
- B. Warm site
- C. Off site
- D. Hot site
Answer: A
Explanation:
A cold site provides an office space, and in some cases basic equipment. However, you will need to restore your data to that equipment in order to use it. This is a much less expensive solution than the hot site. Answer option C is incorrect. A hot site has equipment installed, configured and ready to use. This may make disaster recovery much faster, but will also be more expensive. And a school district can afford to be down for several hours before resuming IT operations, so the less expensive option is more appropriate. Answer option A is incorrect. A warm site is between a hot and cold site. It has some equipment ready and connectivity ready. However, it is still significantly more expensive than a cold site, and not necessary for this scenario. Answer option D is incorrect. Off site is not any type of backup site terminology.
NEW QUESTION 56
FILL BLANK
Fill in the blank with the appropriate term. ______________is a protocol used to synchronize the timekeeping
among the number of distributed time servers and clients.
Answer:
Explanation:
NTP
Explanation:
Network Time Protocol (NTP) is used to synchronize the timekeeping among the number of distributed time
servers and clients. It is used for the time management in a large and diverse network that contains many
interfaces. In this protocol, servers define the time, and clients have to be synchronized with the defined time.
These clients can choose the most reliable source of time defined from the several NTP servers for their
information transmission.
NEW QUESTION 57
Harry has sued the company claiming they made his personal information public on a social networking site in the United States. The company denies the allegations and consulted a/an ______for legal advice to defend them against this allegation.
- A. Incident Handler
- B. Attorney
- C. Evidence Manager
- D. PR Specialist
Answer: B
NEW QUESTION 58
Which of the following provide an "always on" Internet access service when connecting to an ISP?Each correct answer represents a complete solution. Choose two.
- A. Analog modem
- B. DSL
- C. Cable modem
- D. Digital modem
Answer: B,C
Explanation:
DSL and Cable modems are used in remote-access WAN technology for connecting to the Internet. Both provide an "always on" Internet access service. Answer options C and A are incorrect. Analog and Digital modems are not always in 'ON' mode when connecting to an ISP. Analog modems transmit analog voice signals, while Digital modems transmit digital signals over a link.
NEW QUESTION 59
Which of the following is the standard protocol that provides VPN security at the highest level?
- A. P.M
- B. None
- C. IPSec
- D. L2TP
- E. PPP
Answer: C
NEW QUESTION 60
......
Best way to practice test for EC-COUNCIL 312-38: https://www.pass4guide.com/312-38-exam-guide-torrent.html
312-38 Dump Ready - Exam Questions and Answers: https://drive.google.com/open?id=1ZtILpGciJPUfly8ELc2D9d0FNYzDXJRC