Get The Important Preparation Guide With 312-38 Dumps
Get Totally Free Updates on 312-38 Dumps PDF Questions
The EC-Council 312-38 test is the required exam for obtaining the Certified Network Defender certification. This certificate covers the individuals’ skills in detecting, responding, and protecting against threats on networks. The candidates interested in this path are required to demonstrate their understanding of data transfer, software technologies, and network technologies. They should be able to use their skills to evaluate the subject material and understand the specific software that should be automated.
This certification exam evaluates the applicants’ competence in various network defense fundamentals, network security application controls, as well as perimeter appliances, protocols, and VPNs. To succeed in the test, you should also have knowledge of firewall configurations, secure IDS, network traffic signature intricacies, vulnerability, and analysis scanning.
NEW QUESTION 31
Blake is working on the company's updated disaster and business continuity plan. The last section of the plan covers computer and data incidence response. Blake is outlining the level of severity for each type of incident in the plan. Unsuccessful scans and probes are at what severity level?
- A. Low severity level
- B. Mid severity level
- C. Extreme severity level
- D. High severity level
Answer: A
NEW QUESTION 32
Which of the following statements holds true in terms of virtual machines?
- A. OS-level virtualization takes place in VMs
- B. All VMs share the host OS
- C. Hardware-level virtualization takes place in VMs
- D. VMs are light weight than containers
Answer: C
NEW QUESTION 33
Which of the following provide an "always on" Internet access service when connecting to an ISP? Each
correct answer represents a complete solution. (Choose two.)
- A. Analog modem
- B. Cable modem
- C. Digital modem
- D. DSL
Answer: B,D
Explanation:
DSL and Cable modems are used in remote-access WAN technology for connecting to the Internet. Both
provide an "always on" Internet access service.
Answer options C and A are incorrect. Analog and Digital modems are not always in 'ON' mode when
connecting to an ISP. Analog modems transmit analog voice signals, while Digital modems transmit digital
signals over a link.
NEW QUESTION 34
Attacks are classified into which of the following? Each correct answer represents a complete solution. Choose all that apply.
- A. Session hijacking
- B. Passive attack
- C. Replay attack
- D. Active attack
Answer: B,D
NEW QUESTION 35
You just set up a wireless network to customers in the cafe. Which of the following are good security measures implemented? Each correct answer represents a complete solution. Choose all that apply.
- A. The MAC-filtering router
- B. Not broadcasting the SSID
- C. WEP encryption
- D. WPA encryption
Answer: C,D
NEW QUESTION 36
Which of the following OSI layers establishes, manages, and terminates the connections between the local and
remote applications?
- A. Session layer
- B. Application layer
- C. Data Link layer
- D. Network layer
Answer: A
Explanation:
The session layer of the OSI/RM controls the dialogues (connections) between computers. It establishes,
manages and terminates the connections between the local and remote application. It provides for full-duplex,
half-duplex, or simplex operation, and establishes checkpointing, adjournment, termination, and restart
procedures. The OSI model made this layer responsible for graceful close of sessions, which is a property of
the Transmission Control Protocol, and also for session checkpointing and recovery, which is not usually used
in the Internet Protocol Suite. The Session Layer is commonly implemented explicitly in application
environments that use remote procedure calls.
Answer option C is incorrect. The Application Layer of TCP/IP model refers to the higher-level protocols used
by most applications for network communication. Examples of application layer protocols include the File
Transfer Protocol (FTP) and the Simple Mail Transfer Protocol (SMTP). Data coded according to application
layer protocols are then encapsulated into one or more transport layer protocols, which in turn use lower layer
protocols to affect actual data transfer.
Answer option A is incorrect. The Data Link Layer is Layer 2 of the seven-layer OSI model of computer
networking. It corresponds to or is part of the link layer of the TCP/IP reference model. The Data Link Layer is
the protocol layer which transfers data between adjacent network nodes in a wide area network or between
nodes on the same local area network segment. The Data Link Layer provides the functional and procedural
means to transfer data between network entities and might provide the means to detect and possibly correct
errors that may occur in the Physical Layer. Examples of data link protocols are Ethernet for local area
networks (multi-node), the Point-to-Point Protocol (PPP), HDLC, and ADCCP for point-to-point (dual-node)
connections.
Answer option B is incorrect. The network layer controls the operation of subnet, deciding which physical path
the data should take, based on network conditions, priority of service, and other factors. Routers work on the
Network layer of the OSI stack.
NEW QUESTION 37
Which of the following is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies?
- A. Router
- B. Switch
- C. Bridge
- D. Gateway
Answer: D
Explanation:
A gateway is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies. It provides greater functionality than a router or bridge because a gateway functions both as a translator and a router. Gateways are slower than bridges and routers. A gateway is an application layer device. Answer option B is incorrect. A router is an electronic device that interconnects two or more computer networks. It selectively interchanges packets of data between them. It is a networking device whose software and hardware are customized to the tasks of routing and forwarding information. It helps in forwarding data packets between networks. Answer option C is incorrect. A bridge is an interconnectivity device that connects two local area networks (LANs) or two segments of the same LAN using the same communication protocols, and provides address filtering between them. Users can use this device to divide busy networks into segments and reduce network traffic. A bridge broadcasts data packets to all the possible destinations within a specific segment. Bridges operate at the data-link layer of the OSI model. Answer option D is incorrect. A switch is a network device that selects a path or circuit for sending a data unit to its next destination. It is not required in smaller networks, but is required in large inter-networks, where there can be many possible ways of transmitting a message from a sender to destination. The function of switch is to select the best possible path. On an Ethernet local area network (LAN), a switch determines from the physical device (Media Access Control or MAC) address in each incoming message frame which output port to forward it to and out of. In a wide area packet-switched network, such as the Internet, a switch determines from the IP address in each packet which output port to use for the next part of its trip to the intended destination.
NEW QUESTION 38
CORRECT TEXT
Fill in the blank with the appropriate term. ______________is a free open-source utility for network exploration and security auditing that is used to discover computers and services on a computer network, thus creating a "map" of the network.
Answer:
Explanation:
Nmap
Explanation:
Nmap is a free open-source utility for network exploration and security auditing. It is used to discover computers and services on a computer network, thus creating a "map" of the network. Just like many simple port scanners, Nmap is capable of discovering passive services. In addition, Nmap may be able to determine various details about the remote computers. These include operating system, device type, uptime, software product used to run a service, exact version number of that product, presence of some firewall techniques and, on a local area network, even vendor of the remote network card. Nmap runs on Linux, Microsoft Windows, etc.
NEW QUESTION 39
Which of the following is NOT a WEP authentication method?
- A. Shared key authentication
- B. Media access authentication
- C. Open system authentication
- D. Kerberos authentication
Answer: D
NEW QUESTION 40
Which of the following is an Internet application protocol used for transporting Usenet news articles between news servers and for reading and posting articles by end-user client applications?
- A. DCAP
- B. NNTP
- C. NTP
- D. BOOTP
Answer: B
Explanation:
The Network News Transfer Protocol (NNTP) is an Internet application protocol used for transporting Usenet news articles (netnews) between news servers and for reading and posting articles by end user client applications. NNTP is designed so that news articles are stored in a central database, allowing the subscriber to select only those items that he wants to read.
Answer option D is incorrect. Network Time Protocol (NTP) is used to synchronize the timekeeping among the number of distributed time servers and clients. It is used for the time management in a large and diverse network that contains many interfaces. In this protocol, servers define the time, and clients have to be synchronized with the defined time. These clients can choose the most reliable source of time defined from the several NTP servers for their information transmission. Answer option C is incorrect. The Data Link Switching Client Access Protocol (DCAP) is an application layer protocol that is used between workstations and routers for transporting SNA/NetBIOS traffic over TCP sessions. It was introduced in order to address a few deficiencies by the Data Link Switching Protocol (DLSw). The DLSw raises the important issues of scalability and efficiency, and since DLSw is a switch-to-switch protocol, it is not efficient when implemented on workstations. DCAP was introduced in order to address these issues.
Answer option B is incorrect. The BOOTP protocol is used by diskless workstations to collect configuration information from a network server. It is also used to acquire a boot image from the server.
NEW QUESTION 41
Adam works as a Professional Penetration Tester. A project has been assigned to him to test the vulnerabilities of the CISCO Router of Umbrella Inc. Adam finds out that HTTP Configuration Arbitrary Administrative Access Vulnerability exists in the router. By applying different password cracking tools, Adam gains access to the router. He analyzes the router config file and notices the following lines:
logging buffered errors
logging history critical
logging trap warnings
logging 10.0.1.103
By analyzing the above lines, Adam concludes that this router is logging at log level 4 to the syslog server
10.0.1.103. He decides to change the log level from 4 to 0.
Which of the following is the most likely reason of changing the log level?
- A. By changing the log level, Adam can easily perform a SQL injection attack.
- B. Changing the log level from 4 to 0 will result in the termination of logging. This way the modification in the router is not sent to the syslog server.
- C. Changing the log level grants access to the router as an Administrator.
- D. Changing the log level from 4 to 0 will result in the logging of only emergencies. This way the modification in the router is not sent to the syslog server.
Answer: D
Explanation:
The Router Log Level directive is used by the sys log server to specify the level of severity of the log. This directive is used to control the types of errors that are sent to the error log by constraining the severity level.
Eight different levels are present in the Log Level directive, which are shown below in order of their descending significance:
Number Level Description
0emergEmergencies - system is unusable
1alertAction must be taken immediately
2critCritical Conditions
3errorError conditions
4warnWarning conditions
5notice Normal but significant condition
6infoInformational
7debug Debug-level messages
Note: When a certain level is specified, the messages from all other levels of higher significance will also be reported. For example, when Log Level crit is specified, then messages with log levels of alert and emerg will also be reported.
NEW QUESTION 42
Which of the following is a software tool used in passive attacks for capturing network traffic?
- A. Sniffer
- B. Intrusion prevention system
- C. Intrusion detection system
- D. Warchalking
Answer: A
Explanation:
A sniffer is a software tool that is used to capture any network traffic. Since a sniffer changes the NIC of the LAN card into promiscuous mode, the NIC begins to record incoming and outgoing data traffic across the network. A sniffer attack is a passive attack because the attacker does not directly connect with the target host. This attack is most often used to grab logins and passwords from network traffic. Tools such as Ethereal, Snort, Windump, EtherPeek, Dsniff are some good examples of sniffers. These tools provide many facilities to users such as graphical user interface, traffic statistics graph, multiple sessions tracking, etc. Answer option A is incorrect. An intrusion prevention system (IPS) is a network security device that monitors network and/or system activities for malicious or unwanted behavior and can react, in real-time, to block or prevent those activities. When an attack is detected, it can drop the offending packets while still allowing all other traffic to pass. Answer option B is incorrect. An IDS (Intrusion Detection System) is a device or software application that monitors network and/or system activities for malicious activities or policy violations and produces reports to a Management Station. Intrusion prevention is the process of performing intrusion detection and attempting to stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators. Answer option C is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing and war driving.
NEW QUESTION 43
Which OSI layer does a Network Interface Card (NIC) work on?
- A. Presentation layer
- B. Session layer
- C. Physical layer
- D. Network layer
Answer: C
NEW QUESTION 44
Which of the following devices helps in connecting a PC to an ISP via a PSTN?
- A. PCI card
- B. Repeater
- C. Modem
- D. Adapter
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 45
In MacOS, how can the user implement disk encryption?
- A. By enabling FileVault feature
- B. By turning on Device Encryption feature
- C. By executing dm-crypt command
- D. By enabling BitLocker feature
Answer: A
NEW QUESTION 46
You work as a Network Security Analyzer. You got a suspicious email while working on a forensic project. Now, you want to know the IP address of the sender so that you can analyze various information such as the actual location, domain information, operating system being used, contact information, etc. of the email sender with the help of various tools and resources. You also want to check whether this email is fake or real. You know that analysis of email headers is a good starting point in such cases. The email header of the suspicious email is given below:
What is the IP address of the sender of this email?
- A. 209.191.91.180
- B. 172.16.10.90
- C. 141.1.1.1
- D. 216.168.54.25
Answer: D
Explanation:
The IP address of the sender of this email is 216.168.54.25. According to the scenario, you want to know the IP address of the sender so that you can analyze various information such as the actual location, domain information, operating system being used, contact information, etc. of the email sender with the help of various tools and resources. You also want to check whether this email is fake or real. You know that analysis of email headers is a good starting point in such cases. Once you start to analyze the email header, you get an entry entitled as X-Originating-IP. You know that in Yahoo, the X-Originating-IP is the IP address of the email sender and in this case, the required IP address is 216.168.54.25. Answer options A, C, and B are incorrect. All these are the IP addresses of the Yahoo and Wetpaint servers.
NEW QUESTION 47
Which of the following statements are true about volatile memory? Each correct answer represents a complete solution. Choose all that apply.
- A. Read only memory (ROM) is an example of volatile memory.
- B. A volatile storage device is faster in reading and writing data.
- C. The content is stored permanently and even the power supply is switched off.
- D. It is computer memory that requires power to maintain the stored information.
Answer: B,D
Explanation:
Volatile memory, also known as volatile storage, is computer memory that requires power to maintain the stored information, unlike non-volatile memory which does not require a maintained power supply. It has been less popularly known as temporary memory. Most forms of modern random access memory (RAM) are volatile storage, including dynamic random access memory (DRAM) and static random access memory (SRAM). A volatile storage device is faster in reading and writing data. Answer options A and C are incorrect. Non-volatile memory, nonvolatile memory, NVM, or nonvolatile storage, in the most basic sense, is computer memory that can retain the stored information even when not powered. Examples of non-volatile memory include read-only memory, flash memory, most types of magnetic computer storage devices (e.g. hard disks, floppy disks, and magnetic tape), optical discs, and early computer storage methods such as paper tape and punched cards.
NEW QUESTION 48
Which of the following ranges of addresses can be used in the first octet of a Class C network address?
- A. 0-127
- B. 192-223
- C. 128-191
- D. 224-255
Answer: B
NEW QUESTION 49
CORRECT TEXT
Fill in the blank with the appropriate term. The _____________is an application layer protocol that is used between workstations and routers for transporting SNA/NetBIOS traffic over TCP sessions.
Answer:
Explanation:
DCAP
Explanation:
The Data Link Switching Client Access Protocol (DCAP) is an application layer protocol that is used between workstations and routers for transporting SNA/NetBIOS traffic over TCP sessions. It was introduced in order to address a few deficiencies by the Data Link Switching Protocol (DLSw). The DLSw raises the important issues of scalability and efficiency, and since DLSw is a switch-toswitch protocol, it is not efficient when implemented on workstations. DCAP was introduced in order to address these issues.
NEW QUESTION 50
Which of the following is a computer network that covers a broad area?
- A. WAN
- B. CAN
- C. PAN
- D. SAN
Answer: A
NEW QUESTION 51
......
Final Thoughts
With the recent technological advancements, computer networks are no longer the simple connection of servers and systems managed by network administrators they used to be. They are complex infrastructures that have reduced the globe to a small village. But with this comes the consistent threat of digital attacks. To evade such incidents, most of the independent certification vendors such as the EC-Council are moving ahead of time to create certification paths to validate security experts who can act as the last line of defense against security incidents. Well, if getting a job in this path makes sense to you, check out the EC-Council Certified Network Defender designation alongside 312-38 evaluation. Simply put, it is a rewarding career track, to say the least.
Prepare With Top Rated High-quality 312-38 Dumps For Success in Exam: https://www.braindumpquiz.com/312-38-exam-material.html
312-38 Free Certification Exam Easy to Download PDF Format 2023: https://drive.google.com/open?id=1jS3aXpcmQxChdVmcPQysau4gY04NGvwK