Prepare Important Exam with 312-38 Exam Dumps(2023) [Q120-Q142]

Share

Prepare Important Exam with 312-38 Exam Dumps(2023) 

Pass Exam Questions Efficiently With 312-38 Questions


EC-Council Certified Network Defender (CND) is a globally recognized certification program designed to validate the skills and knowledge of network administrators, network security professionals, and other IT professionals responsible for network security. EC-Council Certified Network Defender CND certification is awarded by the International Council of Electronic Commerce Consultants (EC-Council), a leading provider of certification programs in the field of cybersecurity. The EC-Council Certified Network Defender (CND) certification program is designed to equip IT professionals with the skills and knowledge required to secure their organization's network infrastructure against a wide range of cyber threats.


The EC-COUNCIL 312-38 exam is divided into several sections, each of which covers a specific area of network defense. The sections include network security, network protocols, network defense technologies, and network perimeter defense. 312-38 exam is designed to be challenging and comprehensive, and candidates are required to demonstrate their understanding of each section to earn the certification.

 

NEW QUESTION # 120
Which of the following layers provides communication session management between host computers?

  • A. Transport layer
  • B. Link layer
  • C. Internet layer
  • D. Application layer

Answer: A


NEW QUESTION # 121
The company has implemented a backup plan. James is working as a network administrator for the company and is taking full backups of the data every time a backup is initiated. Alex who is a senior security manager talks to him about using a differential backup instead and asks him to implement this once a full backup of the data is completed. What is/are the reason(s) Alex is suggesting that James use a differential backup?
(Select all that apply)

  • A. Faster than a full backup
  • B. Less storage space is required
  • C. Slower than a full backup
  • D. Less expensive than full backup
  • E. Father restoration

Answer: A,B


NEW QUESTION # 122
Which of the following types of information can be obtained through network sniffing? (Choose all that apply.)

  • A. Syslog traffic
  • B. DNS traffic
  • C. Telnet passwords
  • D. Programming errors

Answer: A,B,D


NEW QUESTION # 123
Network security is the specialist area, which consists of the provisions and policies adopted by the Network Administrator to prevent and monitor unauthorized access, misuse, modification, or denial of the computer network and network-accessible resources. For which of the following reasons is network security needed?
Each correct answer represents a complete solution. Choose all that apply.

  • A. To protect information from loss and deliver it to its destination properly
  • B. To protect information from unwanted editing, accidentally or intentionally by unauthorized users
  • C. To prevent a user from sending a message to another user with the name of a third person
  • D. To protect private information on the Internet

Answer: A,B,C,D

Explanation:
Network security is needed for the following reasons:
To protect private information on the Internet
To protect information from unwanted editing, accidentally or intentionally by unauthorized users To protect information from loss and deliver it to its destination properly To prevent a user from sending a message to another user with the name of a third person


NEW QUESTION # 124
Which of the following is a computer networking protocol used by hosts to retrieve IP address assignments and other configuration information?

  • A. SNMP
  • B. Telnet
  • C. DHCP
  • D. ARP

Answer: C

Explanation:
The Dynamic Host Configuration Protocol (DHCP) is a computer networking protocol used by hosts (DHCP clients) to retrieve IP address assignments and other configuration information. DHCP uses a client-server architecture. The client sends a broadcast request for configuration information. The DHCP server receives the request and responds with configuration information from its configuration database. In the absence of DHCP, all hosts on a network must be manually configured individually - a time-consuming and often error-prone undertaking. DHCP is popular with ISP's because it allows a host to obtain a temporary IP address. Answer option B is incorrect. Address Resolution Protocol (ARP) is a network maintenance protocol of the TCP/IP protocol suite. It is responsible for the resolution of IP addresses to media access control (MAC) addresses of a network interface card (NIC). The ARP cache is used to maintain a correlation between a MAC address and its corresponding IP address. ARP provides the protocol rules for making this correlation and providing address conversion in both directions. ARP is limited to physical network systems that support broadcast packets. Answer option A is incorrect. The Simple Network Management Protocol (SNMP) allows a monitored device (for example, a router or a switch) to run an SNMP agent. This protocol is used for managing many network devices remotely. When a monitored device runs an SNMP agent, an SNMP server can then query the SNMP agent running on the device to collect information such as utilization statistics or device configuration information. An SNMP-managed network typically consists of three components: managed devices, agents, and one or more network management systems. Answer option D is incorrect. Telnet (Telecommunication network) is a network protocol used on the Internet or local area networks to provide a bidirectional interactive communications facility. Typically, Telnet provides access to a command-line interface on a remote host via a virtual terminal connection which consists of an 8-bit byte oriented data connection over the Transmission Control Protocol (TCP). User data is interspersed in-band with TELNET control information. Typically, the Telnet protocol is used to establish a connection to Transmission Control Protocol (TCP) port number 23.


NEW QUESTION # 125
Which of the following protocols is used for inter-domain multicast routing and natively supports "source-
specific multicast" (SSM)?

  • A. OSPF
  • B. BGMP
  • C. EIGRP
  • D. DVMRP

Answer: B

Explanation:
BGMP stands for border gateway multicast protocol. It is used for inter-domain multicast routing and natively
supports "source-specific multicast" (SSM). In order to support "any-source multicast" (ASM), BGMP builds
shared trees for active multicast groups. This allows domains to build source-specific, inter-domain, distribution
branches where needed. BGMP uses TCP as its transport protocol, which helps in eliminating the need to
implement message fragmentation, retransmission, acknowledgement, and sequencing.
Answer option B is incorrect. The Distance Vector Multicast Routing Protocol (DVMRP) is used to share
information between routers to transport IP Multicast packets among networks. It uses a reverse path-flooding
technique and is used as the basis for the Internet's multicast backbone (MBONE). In particular, DVMRP is
notorious for poor network scaling, resulting from reflooding, particularly with versions that do not implement
pruning. DVMRP's flat unicast routing mechanism also affects its capability to scale.
Answer option D is incorrect. EIGRP is a Cisco proprietary protocol. It is an enhanced version of IGRP. It has
faster convergence due to use of triggered update and saving neighbor's routing table locally. It supports VLSM
and routing summarization. As EIGRP is a distance vector protocol, it automatically summarizes routes across
Class A, B, and C networks. It also supports multicast and incremental updates and provides routing for three
routed protocols, i.e., IP, IPX, and AppleTalk.
Answer option C is incorrect. Open Shortest Path First (OSPF) is a routing protocol that is used in large
networks. Internet Engineering Task Force (IETF) designates OSPF as one of the Interior Gateway Protocols.
A host uses OSPF to obtain a change in the routing table and to immediately multicast updated information to
all the other hosts in the network.


NEW QUESTION # 126
Which of the following is an attack on a website that changes the appearance of the site and seriously damage the website trust and reputation?

  • A. website defacement
  • B. Buffer overflow
  • C. None
  • D. spoofing
  • E. Zero-day attack

Answer: A


NEW QUESTION # 127
David is working in a mid-sized IT company. Management asks him to suggest a framework that can be used effectively to align the IT goals to the business goals of the company. David suggests the______framework, as it provides a set of controls over IT and consolidates them to form a framework.

  • A. RMIS
  • B. ISO 27007
  • C. ITIL
  • D. COBIT

Answer: D


NEW QUESTION # 128
Which of the following are the various methods that a device can use for logging information on a Cisco router? Each correct answer represents a complete solution. Choose all that apply.

  • A. Terminal logging
  • B. SNMP logging
  • C. Console logging
  • D. Syslog logging
  • E. NTP logging
  • F. Buffered logging

Answer: A,B,C,D,F

Explanation:
There are different methods that a device can use for logging information on a Cisco router:
Terminal logging: In this method, log messages are sent to the VTY session.
Console logging: In this method, log messages are sent directly to the console port.
Buffered logging: In this method, log messages are kept in the RAM on the router. As the buffer
fills, the older messages are overwritten by the newer messages.
Syslog logging: In this method, log messages are sent to an external syslog server where they are
stored and sorted.
SNMP logging: In this method, log messages are sent to an SNMP server in the network.
Answer option C is incorrect. This is an invalid option.


NEW QUESTION # 129
Which of the following policies is used to add additional information about the overall security posture and serves to protect employees and organizations from inefficiency or ambiguity?

  • A. IT policy
  • B. Issue-Specific Security Policy
  • C. User policy
  • D. Group policy

Answer: B

Explanation:
The Issue-Specific Security Policy (ISSP) is used to add additional information about the overall security posture. It helps in providing detailed, targeted guidance for instructing organizations in the secure use of tech systems. This policy serves to protect employees and organizations from inefficiency or ambiguity. Answer option A is incorrect. A user policy helps in defining what users can and should do to use network and organization's computer equipment. It also defines what limitations are put on users for maintaining the network secure such as whether users can install programs on their workstations, types of programs users are using, and how users can access data. Answer option D is incorrect. IT policy includes general policies for the IT department. These policies are intended to keep the network secure and stable. It includes the following: Virus incident and security incident Backup policy Client update policies Server configuration, patch update, and modification policies (security) Firewall policiesDmz policy, email retention, and auto forwarded email policy Answer option B is incorrect. A group policy specifies how programs, network resources, and the operating system work for users and computers in an organization.


NEW QUESTION # 130
John, the network administrator and he wants to enable the NetFlow feature in Cisco routers to collect and monitor the IP network traffic passing through the router.
Which command will John use to enable NetFlow on an interface?

  • A. Router IP route
  • B. Router# Netmon enable
  • C. Router(Config-if) # IP route - cache flow
  • D. Router# netflow enable

Answer: C


NEW QUESTION # 131
Which of the following is a network layer protocol used to obtain an IP address for a given hardware (MAC) address?

  • A. RARP
  • B. IP
  • C. PIM
  • D. ARP

Answer: A

Explanation:
Reverse Address Resolution Protocol (RARP) is a Network layer protocol used to obtain an IP address for a given hardware (MAC) address. RARP is sort of the reverse of an ARP. Common protocols that use RARP are BOOTP and DHCP.
Answer option D is incorrect. Address Resolution Protocol (ARP) is a network maintenance protocol of the TCP/IP protocol suite. It is responsible for the resolution of IP addresses to media access control (MAC) addresses of a network interface card (NIC). The ARP cache is used to maintain a correlation between a MAC address and its corresponding IP address. ARP provides the protocol rules for making this correlation and providing address conversion in both directions. ARP is limited to physical network systems that support broadcast packets.
Answer option B is incorrect. Protocol-Independent Multicast (PIM) is a family of multicast routing protocols for Internet Protocol (IP) networks that provide one-to-many and many-to-many distribution of data over a LAN, WAN, or the Internet. It is termed protocol-independent because PIM does not include its own topology discovery mechanism, but instead uses routing information supplied by other traditional routing protocols, such as Border Gateway Protocol (BGP).
Answer option A is incorrect. The Internet Protocol (IP) is a protocol used for communicating data across a packet-switched inter-network using the Internet Protocol Suite, also referred to as TCP/IP.
IP is the primary protocol in the Internet Layer of the Internet Protocol Suite and has the task of delivering distinguished protocol datagrams (packets) from the source host to the destination host solely based on their addresses. For this purpose, the Internet Protocol defines addressing methods and structures for datagram encapsulation. The first major version of addressing structure, now referred to as Internet Protocol Version 4 (IPv4), is still the dominant protocol of the Internet, although the successor, Internet Protocol Version 6 (IPv6), is being deployed actively worldwide.


NEW QUESTION # 132
FILL BLANK
Fill in the blank with the appropriate term. The ______________ layer establishes, manages, and terminates
the connections between the local and remote application.

Answer:

Explanation:
session
Explanation:
The session layer of the OSI/RM controls the dialogues (connections) between computers. It establishes,
manages and terminates the connections between the local and remote application. It provides for full-duplex,
half-duplex, or simplex operation, and establishes checkpointing, adjournment, termination, and restart
procedures. The OSI model made this layer responsible for graceful close of sessions, which is a property of
the Transmission Control Protocol, and also for session check pointing and recovery, which is not usually used
in the Internet Protocol Suite. The Session Layer is commonly implemented explicitly in application
environments that use remote procedure calls.


NEW QUESTION # 133
Which of the following is designed to detect unwanted changes by observing the flame of the environment associated with combustion?

  • A. sprinkler
  • B. None
  • C. Fire extinguishing system
  • D. Gaseous fire-extinguishing systems
  • E. Smoke alarm system

Answer: E


NEW QUESTION # 134
Which of the following is an attack on a website that changes the visual appearance of the site and seriously
damages the trust and reputation of the website?

  • A. Spoofing
  • B. Buffer overflow
  • C. Website defacement
  • D. Zero-day attack

Answer: C

Explanation:
Website defacement is an attack on a website that changes the visual appearance of the site. These are
typically the work of system crackers, who break into a Web server and replace the hosted website with one of
their own. Sometimes, the Defacer makes fun of the system administrator for failing to maintain server
security. Most times, the defacement is harmless; however, it can sometimes be used as a distraction to cover
up more sinister actions such as uploading malware.
A high-profile website defacement was carried out on the website of the company SCO Group following its
assertion that Linux contained stolen code. The title of the page was changed from Red Hat vs. SCO to SCO
vs. World with various satirical content.
Answer option D is incorrect. Buffer overflow is a condition in which an application receives more data than it is
configured to accept. This usually occurs due to programming errors in the application. Buffer overflow can
terminate or crash the application.
Answer option B is incorrect. A zero-day attack, also known as zero-hour attack, is a computer threat that tries
to exploit computer application vulnerabilities which are unknown to others, undisclosed to the software vendor,
or for which no security fix is available. Zero-day exploits (actual code that can use a security hole to carry out
an attack) are used or shared by attackers before the software vendor knows about the vulnerability. User
awareness training is the most effective technique to mitigate such attacks.
Answer option C is incorrect. Spoofing is a technique that makes a transmission appear to have come from an
authentic source by forging the IP address, email address, caller ID, etc. In IP spoofing, a hacker modifies
packet headers by using someone else's IP address to hide his identity. However, spoofing cannot be used
while surfing the Internet, chatting on-line, etc. because forging the source IP address causes the responses to
be misdirected.


NEW QUESTION # 135
Which of the following procedures is intended to provide security personnel to identify, mitigate, and recover from malware events, such as unauthorized access to systems or data, denial-of-service or unauthorized changes to the system hardware, software, or information?

  • A. A resident of the emergency plan
  • B. disaster survival plan
  • C. None
  • D. Cyber Incident Response Plan
  • E. Crisis communications guidelines

Answer: D


NEW QUESTION # 136
Which of the following examines network traffic to identify threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware, and policy violations?

  • A. Host-based Intrusion Prevention
  • B. Network-based Intrusion Prevention
  • C. Wireless Intrusion Prevention System
  • D. Network Behavior Analysis

Answer: D

Explanation:
Network Behavior Analysis examines network traffic to identify threats that generate unusual traffic flows, such as distributed denial of service (DDoS) attacks, certain forms of malware, and policy violations.
Answer option B is incorrect. Network-based Intrusion Prevention (NIPS) monitors the entire network for suspicious traffic by analyzing protocol activity.
Answer option C is incorrect. Wireless Intrusion Prevention System (WIPS) monitors a wireless network for suspicious traffic by analyzing wireless networking protocols.
Answer option D is incorrect. Host-based Intrusion Prevention (HIPS) is an installed software package that monitors a single host for suspicious activity by analyzing events occurring within that host.


NEW QUESTION # 137
Which of the following commands can be used to disable unwanted services on Debian, Ubuntu and other Debian-based Linux distributions?

  • A. # chkconfig [service name] -del
  • B. # chkconfig [service name]off
  • C. # update-rc.d -f [service name] remove
  • D. # service [service name] stop

Answer: C


NEW QUESTION # 138
Which of the following statements are true about security risks? Each correct answer represents a complete solution. (Choose three.)

  • A. They can be analyzed and measured by the risk analysis process.
  • B. They can be mitigated by reviewing and taking responsible actions based on possible risks.
  • C. They are considered an indicator of threats coupled with vulnerability.
  • D. They can be removed completely by taking proper actions.

Answer: A,B,C

Explanation:
In information security, security risks are considered an indicator of threats coupled with vulnerability. In other words, security risk is a probabilistic function of a given threat agent exercising a particular vulnerability and the impact of that risk on the organization. Security risks can be mitigated by reviewing and taking responsible actions based on possible risks. These risks can be analyzed and measured by the risk analysis process.
Answer option B is incorrect. Security risks can never be removed completely but can be mitigated by taking proper actions.


NEW QUESTION # 139
Which of the following are provided by digital signatures?

  • A. Integrity and validation
  • B. Security and integrity
  • C. Identification and validation
  • D. Authentication and identification

Answer: D

Explanation:
Explanation/Reference:


NEW QUESTION # 140
Which of the following is susceptible to a birthday attack?

  • A. Integrity
  • B. Authentication
  • C. Digital signature
  • D. Authorization

Answer: C


NEW QUESTION # 141
Simon had all his systems administrators implement hardware and software firewalls to ensure network security. They implemented IDS/IPS systems throughout the network to check for and stop any unauthorized traffic that may attempt to enter. Although Simon and his administrators believed they were secure, a hacker group was able to get into the network and modify files hosted on the company's website.
After searching through the firewall and server logs, no one could find how the attackers were able to get in. He decides that the entire network needs to be monitored for critical and essential file changes. This monitoring tool alerts administrators when a critical file is altered. What tool could Simon and his administrators implement to accomplish this?

  • A. They can implement Wireshark
  • B. They could use Tripwire
  • C. Snort is the best tool for their situation
  • D. They need to use Nessus

Answer: B


NEW QUESTION # 142
......

312-38 Questions - Truly Beneficial For Your EC-COUNCIL Exam: https://www.examcost.com/312-38-practice-exam.html

Download EC-COUNCIL 312-38 Sample Questions: https://drive.google.com/open?id=1wk1Bu21GIANJHyw5o5QdMHxG4smPdWBO