[Dec 11, 2021] Free EC-COUNCIL 312-38 Exam Questions & Answer
Verified 312-38 dumps Q&As Latest 312-38 Download
NEW QUESTION 17
You just set up a wireless network to customers in the cafe. Which of the following are good security measures implemented? Each correct answer represents a complete solution. Choose all that apply.
- A. WEP encryption
- B. Not broadcasting the SSID
- C. WPA encryption
- D. The MAC-filtering router
Answer: A,C
NEW QUESTION 18
Which NIST Incident category includes any activity that seeks to access or identify a federal agency computer, open ports, protocols, service or any combination for later exploit?
- A. Scans/ Probes/ Attempted Access
- B. Improper usage
- C. Denial-of-Service
- D. Malicious code
Answer: A
NEW QUESTION 19
Which of the following steps are required in an idle scan of a closed port?
Each correct answer represents a part of the solution. Choose all that apply.
- A. The zombie's IP ID increases by 2.
- B. The attacker sends a SYN/ACK to the zombie.
- C. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.
- D. In response to the SYN, the target sends a RST.
- E. The zombie's IP ID increases by only 1.
Answer: B,C,D,E
Explanation:
Following are the steps required in an idle scan of a closed port:
1.Probe the zombie's IP ID: The attacker sends a SYN/ACK to the zombie. The zombie, unaware
of the SYN/ACK, sends back a RST, thus disclosing its IP ID.
2.Forge a SYN packet from the zombie: In response to the SYN, the target sends a RST. The zombie ignores the unsolicited RST, and the IP ID remains unchanged.
3.Probe the zombie's IP ID again: The zombie's IP ID has increased by only 1 since step 1. So the port is closed.
NEW QUESTION 20
Which of the following statements are true about volatile memory? Each correct answer represents a complete solution. Choose all that apply.
- A. A volatile storage device is faster in reading and writing data.
- B. The content is stored permanently and even the power supply is switched off.
- C. Read only memory (ROM) is an example of volatile memory.
- D. It is computer memory that requires power to maintain the stored information.
Answer: A,D
Explanation:
Volatile memory, also known as volatile storage, is computer memory that requires power to maintain the stored information, unlike non-volatile memory which does not require a maintained power supply. It has been less popularly known as temporary memory. Most forms of modern random access memory (RAM) are volatile storage, including dynamic random access memory (DRAM) and static random access memory (SRAM). A volatile storage device is faster in reading and writing data. Answer options A and C are incorrect. Non-volatile memory, nonvolatile memory, NVM, or nonvolatile storage, in the most basic sense, is computer memory that can retain the stored information even when not powered. Examples of non-volatile memory include read-only memory, flash memory, most types of magnetic computer storage devices (e.g. hard disks, floppy disks, and magnetic tape), optical discs, and early computer storage methods such as paper tape and punched cards.
NEW QUESTION 21
Which of the following is a software tool used in passive attacks for capturing network traffic?
- A. Warchalking
- B. Sniffer
- C. Intrusion detection system
- D. Intrusion prevention system
Answer: B
Explanation:
A sniffer is a software tool that is used to capture any network traffic. Since a sniffer changes the NIC of the
LAN card into promiscuous mode, the NIC begins to record incoming and outgoing data traffic across the
network. A sniffer attack is a passive attack because the attacker does not directly connect with the target host.
This attack is most often used to grab logins and passwords from network traffic. Tools such as Ethereal,
Snort, Windump, EtherPeek, Dsniff are some good examples of sniffers. These tools provide many facilities to
users such as graphical user interface, traffic statistics graph, multiple sessions tracking, etc.
Answer option A is incorrect. An intrusion prevention system (IPS) is a network security device that monitors
network and/or system activities for malicious or unwanted behavior and can react, in real-time, to block or
prevent those activities. When an attack is detected, it can drop the offending packets while still allowing all
other traffic to pass.
Answer option B is incorrect. An IDS (Intrusion Detection System) is a device or software application that
monitors network and/or system activities for malicious activities or policy violations and produces reports to a
Management Station. Intrusion prevention is the process of performing intrusion detection and attempting to
stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on
identifying possible incidents, logging information about them, attempting to stop them, and reporting them to
security administrators.
Answer option C is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi
wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such
as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing
and war driving.
NEW QUESTION 22
CORRECT TEXT
Fill in the blank with the appropriate term. In the ______________method, a device or computer that transmits data needs to first listen to the channel for an amount of time to check for any activity on the channel.
Answer:
Explanation:
CSMA
/CA
Explanation:
Carrier Sense Multiple Access/Collision Avoidance (CSMA/CA) is an access method used by wireless networks (IEEE 802.11). In this method, a device or computer that transmits data needs to first listen to the channel for an amount of time to check for any activity on the channel. If the channel is sensed as idle, the device is allowed to transmit data. If the channel is busy, the device postpones its transmission. Once the channel is clear, the device sends a signal telling all other devices not to transmit data, and then sends its packets. In Ethernet (IEEE 802.3) networks that use CSMA/CD, the device or computer continues to wait for a time and checks if the channel is still free. If the channel is free, the device transmits packets and waits for an acknowledgment signal indicating that the packets were received.
NEW QUESTION 23
Larry is a network administrator working for a manufacturing company in Detroit. Larry is responsible for the entire company's network which consists of 300 workstations and 25 servers. After using a hosted email service for a year, the company wants to cut back on costs and bring the email control internal. Larry likes this idea because it will give him more control over email. Larry wants to purchase a server for email but he does not want the server to be on the internal network because this might cause security risks. He decides to place the email server on the outside of the company's internal firewall. There is another firewall connected directly to the Internet that will protect some traffic from accessing the email server; the server will essentially be place between the two firewalls. What logical area is Larry going to place the new email server into?
- A. For security reasons, Larry is going to place the email server in the company's Logical Buffer Zone (LBZ).
- B. Larry is going to put the email server in a hot-server zone.
- C. He is going to place the server in a Demilitarized Zone (DMZ).
- D. He will put the email server in an IPSec zone.
Answer: C
NEW QUESTION 24
Token Ring is standardized by which of the following IEEE standards?
- A. 802.4
- B. 802.1
- C. 802.2
- D. 802.3
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 25
Which of the following is a device that receives a digital signal on an electromagnetic or optical transmission medium and regenerates the signal along the next leg of the medium?
- A. Transceiver
- B. Repeater
- C. Gateway
- D. Network adapter
Answer: B
Explanation:
A repeater is an electronic device that receives a signal and retransmits it at a higher level and/or higher power, or onto the other side of an obstruction, so that the signal can cover longer distances. A repeater is a device that receives a digital signal on an electromagnetic or optical transmission medium and regenerates the signal along the next leg of the medium. In electromagnetic media, repeaters overcome the attenuation caused by free-space electromagnetic-field divergence or cable loss. A series of repeaters make possible the extension of a signal over a distance. Repeaters remove the unwanted noise in an incoming signal. Unlike an analog signal, the original digital signal, even if weak or distorted, can be clearly perceived and restored. With analog transmission, signals are restrengthened with amplifiers which unfortunately also amplify noise as well as information. An example of a wireless repeater is shown in the figure below:
Answer option D is incorrect. A transceiver is a device that has both a transmitter and a receiver in a single package.
Answer option A is incorrect. A gateway is a network interconnectivity device that translates different communication protocols and is used to connect dissimilar network technologies. It provides greater functionality than a router or bridge because a gateway functions both as a translator and a router. Gateways are slower than bridges and routers. A gateway is an application layer device.
Answer option C is incorrect. A network adapter is used to interface a computer to a network. "Device driver" is a piece of software through which Windows and other operating systems support both wired and wireless network adapters. Network drivers allow application software to communicate with the adapter hardware.
Network device drivers are often installed automatically when adapter hardware is first powered on.
NEW QUESTION 26
Stephanie is currently setting up email security so all company data is secured when passed through email.
Stephanie first sets up encryption to make sure that a specific user's email is protected. Next, she needs to ensure that the incoming and the outgoing mail has not been modified or altered using digital signatures. What is Stephanie working on?
- A. Confidentiality
- B. Availability
- C. Data Integrity
- D. Usability
Answer: C
NEW QUESTION 27
John works as a professional Ethical Hacker. He has been assigned the project of testing the security of www.we-are-secure.com. He is using a tool to crack the wireless encryption keys. The description of the tool is as follows:
Which of the following tools is John using to crack the wireless encryption keys?
- A. Cain
- B. PsPasswd
- C. AirSnort
- D. Kismet
Answer: C
Explanation:
AirSnort is a Linux-based WLAN WEP cracking tool that recovers encryption keys. AirSnort operates by passively monitoring transmissions. It uses Ciphertext Only Attack and captures approximately 5 to 10 million packets to decrypt the WEP keys. Answer option B is incorrect. Kismet is a Linux-based 802.11 wireless network sniffer and intrusion detection system. It can work with any wireless card that supports raw monitoring (rfmon) mode. Kismet can sniff 802.11b, 802.11a, 802.11g, and 802.11n traffic. Kismet can be used for the following tasks: To identify networks by passively collecting packets To detect standard named networks To detect masked networks To collect the presence of non-beaconing networks via data traffic Answer option D is incorrect. Cain is a multipurpose tool that can be used to perform many tasks such as Windows password cracking, Windows enumeration, and VoIP session sniffing. This password cracking program can perform the following types of password cracking attacks: Dictionary attack Brute force attack Rainbow attack Hybrid attack Answer option A is incorrect. PsPasswd is a tool that helps Network Administrators change an account password on the local or remote system. The command syntax of PsPasswd is as follows: pspasswd [\\computer[,computer[,..] | @file [-u user [-p psswd]] Username [NewPassword]
NEW QUESTION 28
Which of the following IEEE standards defines the demand priority access method?
- A. 802.12
- B. 802.15
- C. 802.3
- D. 802.11
Answer: A
NEW QUESTION 29
Rick has implemented several firewalls and IDS systems across his enterprise network. What should he do to effectively correlate all incidents that pass through these security controls?
- A. Implement Simple Network Management Protocol (SNMP)
- B. Use firewalls in Network Address Transition (NAT) mode
- C. Implement IPsec
- D. Use Network Time Protocol (NTP)
Answer: D
NEW QUESTION 30
Which of the following are the common security problems involved in communications and email?Each correct answer represents a complete solution. Choose all that apply.
- A. False message
- B. Message modification
- C. Eavesdropping
- D. Message replay
- E. Identity theft
- F. Message repudiation
- G. Message digest
Answer: A,B,C,D,E,F
Explanation:
Following are the common security problems involved in communications and email:
Eavesdropping: It is the act of secretly listening to private information through telephone lines, e-
mail, instant messaging, and any other method of communication considered private.
Identity theft: It is the act of obtaining someone's username and password to access his/her email
servers for reading email and sending false email messages. These credentials can be obtained
by eavesdropping on SMTP, POP, IMAP, or Webmail connections.
Message modification: The person who has system administrator permission on any of the SMTP
servers can visit anyone's message and can delete or change the message before it continues on
to its destination. The recipient has no way of telling that the email message has been altered.
False message: It the act of constructing messages that appear to be sent by someone else.
Message replay: In a message replay, messages are modified, saved, and re-sent later.
Message repudiation: In message repudiation, normal email messages can be forged. There is no
way for the receiver to prove that someone had sent him/her a particular message. This means
that even if someone has sent a message, he/she can successfully deny it.
Answer option D is incorrect. A message digest is a number that is created algorithmically from a
file and represents that file uniquely.
NEW QUESTION 31
Which of the following types of RAID is also known as disk striping?
- A. RAID 3
- B. RAID 1
- C. RAID 0
- D. RAID 2
Answer: C
NEW QUESTION 32
Which of the following is the type of documented business rule for protecting information and the systems, which store and process the information
- A. Information storage policy
- B. Information protection document
- C. Information protection policy
- D. Information security policy
Answer: D
NEW QUESTION 33
Assume that you are working as a network administrator in the head office of a bank. One day a bank employee informed you that she is unable to log in to her system. At the same time, you get a call from another network administrator informing you that there is a problem connecting to the main server. How will you prioritize these two incidents?
- A. Based on the type of response needed for the incident
- B. Based on approval from management
- C. Based on a potential technical effect of the incident
- D. Based on a first come first served basis
Answer: C
NEW QUESTION 34
Which of the following are the various methods that a device can use for logging information on a Cisco router?
Each correct answer represents a complete solution. Choose all that apply.
- A. SNMP logging
- B. Buffered logging
- C. Syslog logging
- D. Console logging
- E. NTP logging
- F. Terminal logging
Answer: A,B,C,D,F
Explanation:
There are different methods that a device can use for logging information on a Cisco router:
Terminal logging: In this method, log messages are sent to the VTY session.
Console logging: In this method, log messages are sent directly to the console port.
Buffered logging: In this method, log messages are kept in the RAM on the router. As the buffer fills, the older
messages are overwritten by the newer messages.
Syslog logging: In this method, log messages are sent to an external syslog server where they are stored and
sorted.
SNMP logging: In this method, log messages are sent to an SNMP server in the network.
Answer option C is incorrect. This is an invalid option.
NEW QUESTION 35
Which of the following protocols is described as a connection-oriented and reliable delivery transport layer protocol?
- A. TCP
- B. IP
- C. UDP
- D. SSL
Answer: A
NEW QUESTION 36
Which IEEE standard does wireless network use?
- A. 802.10
- B. 802.18
- C. 802.11
- D. 802.9
Answer: C
NEW QUESTION 37
Which of the following is an example of a network providing DQDB access methods?
- A. IEEE 802.6
- B. IEEE 802.4
- C. IEEE 802.3
- D. IEEE 802.2
Answer: A
NEW QUESTION 38
Which of the following is the main international standards organization for the World Wide Web?
- A. CCITT
- B. WASC
- C. W3C
- D. ANSI
Answer: C
NEW QUESTION 39
Adam, a malicious hacker, is sniffing an unprotected Wi-FI network located in a local store with Wireshark to capture hotmail e-mail traffic. He knows that lots of people are using their laptops for browsing the Web in the store. Adam wants to sniff their e-mail messages traversing the unprotected Wi-Fi network. Which of the following Wireshark filters will Adam configure to display only the packets with hotmail email messages?
- A. (http = "login.pass.com") && (http contains "SMTP")
- B. (http contains "hotmail") && (http contains "Reply-To")
- C. (http contains "email") && (http contains "hotmail")
- D. (http = "login.passport.com") && (http contains "POP3")
Answer: B
Explanation:
Adam will use (http contains "hotmail") && (http contains "Reply-To") filter to display only the packets with hotmail email messages. Each Hotmail message contains the tag Reply-To: and "xxxx-xxx- xxx.xxxx.hotmail.com" in the received tag. Wireshark is a free packet sniffer computer application. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but it has a graphical front-end, and many more information sorting and filtering options. It allows the user to see all traffic being passed over the network (usually an Ethernet network but support is being added for others) by putting the network interface into promiscuous mode.Wireshark uses pcap to capture packets, so it can only capture the packets on the networks supported by pcap. It has the following features: Data can be captured "from the wire" from a live network connection or read from a file that records the already-captured packets. Live data can be read from a number of types of network, including Ethernet, IEEE 802.11, PPP, and loopback. Captured network data can be browsed via a GUI, or via the terminal (command line) version of the utility, tshark. Captured files can be programmatically edited or converted via command-line switches to the "editcap" program. Data display can be refined using a display filter. Plugins can be created for dissecting new protocols. Answer options B, A, and D are incorrect. These are invalid tags.
NEW QUESTION 40
Which protocol could choose the network administrator for the wireless network design, if he need to satisfied the minimum requirement of 2.4 GHz, 22 MHz of bandwidth, 2 Mbits/s stream for data rate and use DSSS for modulation.
- A. 802.11b
- B. 802.11g
- C. 802.11a
- D. 802.11n
Answer: A
NEW QUESTION 41
In which of the following types of port scans does the scanner attempt to connect to all 65,535 ports?
- A. Vanilla
- B. FTP bounce
- C. Strobe
- D. UDP
Answer: A
Explanation:
In a vanilla port scan, the scanner attempts to connect to all 65,535 ports.
Answer option B is incorrect. The scanner attempts to connect to only selected ports.
Answer option A is incorrect. The scanner scans for open User Datagram Protocol ports.
Answer option C is incorrect. The scanner goes through a File Transfer Protocol server to disguise
the cracker's location.
NEW QUESTION 42
......
Prerequisites
The potential candidates must fulfill one of two options of eligibility criteria for this certification exam. The first thing is to complete the official training course, which can be taken as instructor-led training, academic learning, or online live training. The second variant is to opt for self-study. However, those who want to consider this option must have a minimum of two years of practical work experience in the domain of Information Technology. They should also have educational background that indicates a specialization in this area. To demonstrate this, they must submit a filled eligibility application form and pay the non-refundable application fee of $100.
Before you start the registration process, you should check if you qualify as one of the target audiences for this path. The intended candidates for EC-Council 312-38 are the security operators, network administrators, security analysts, network defense technicians, network security engineers, network security administrators, as well as any professionals who work with network operations.
EC-Council 312-38 Exam Syllabus Topics:
| Topic | Details | Weights |
|---|---|---|
| Computer Network and Defense Fundamentals | - Understanding computer network - Describing OSI and TCP/IP network Models - Comparing OSI and TCP/IP network Models - Understanding different types of networks - Describing various network topologies - Understanding various network components - Explaining various protocols in TCP/IP protocol stack - Explaining IP addressing concept - Understanding Computer Network Defense (CND) - Describing fundamental CND attributes - Describing CND elements - Describing CND process and Approaches | 5% |
| Secure IDS Configuration and Management | - Understanding different types of intrusions and their indications - Understanding IDPS - Importance of implementing IDPS - Describing role of IDPS in network defense - Describing functions, components, and working of IDPS - Explaining various types of IDS implementation - Describing staged deployment of NIDS and HIDS - Describing fine-tuning of IDS by minimizing false positive and false negative rate - Discussing characteristics of good IDS implementation - Discussing common IDS implementation mistakes and their remedies - Explaining various types of IPS implementation - Discussing requirements for selecting appropriate IDSP product - Technologies complementing IDS functionality | 8% |
| Network Incident Response and Management | - Understanding Incident Handling and Response (IH&R) - Roles and responsibilities of Incident Response Team (IRT) - Describing role of first responder - Describing first response activities for network administrators - Describing Incident Handling and Response (IH&R) process - Understanding forensic investigation - People involved in forensics investigation - Describing forensics investigation methodology | 8% |
| Physical Security | - Understanding physical security - Importance of physical security - Factors affecting physical security - Describing various physical security controls - Understanding the selection of Fire Fighting Systems - Describing various access control authentication techniques - Understanding workplace security - Understanding personnel security - Describing Environmental Controls - Importance of physical security awareness and training | 6% |
| Network Risk and Vulnerability Management | - Understanding risk and risk management - Key roles and responsibilities in risk management - Understanding Key Risk Indicators (KRI) in risk management - Explaining phase involves in risk management - Understanding enterprise network risk management - Describing various risk management frameworks - Discussing best practices for effective implementation of risk management - Understanding vulnerability management - Explaining various phases involve in vulnerability management - Understanding vulnerability assessment and its importance - Discussing requirements for effective network vulnerability assessment - Discussing internal and external vulnerability assessment - Discussing steps for effective external vulnerability assessment - Describing various phases involve in vulnerability assessment - Selection of appropriate vulnerability assessment tool - Discussing best practices and precautions for deploying vulnerability assessment tool - Describing vulnerability reporting, mitigation, remediation and verification | 9% |
| Network Security Threats, Vulnerabilities, and Attacks | - Understanding threat, attack, and vulnerability - Discussing network security concerns - Reasons behind network security concerns - Effect of network security breach on business continuity - Understanding different types of network threats - Understanding different types of network security vulnerabilities - Understanding different types of network attacks - Describing various network attacks | 5% |
| Network Security Policy Design and Implementation | - Understanding security policy - Need of security policies - Describing the hierarchy of security policy - Describing the characteristics of a good security policy - Describing typical content of security policy - Understanding policy statement - Describing steps for creating and implementing security policy - Designing of security policy - Implementation of security policy - Describing various types of security policy - Designing of various security policies - Discussing various information security related standards, laws and acts | 6% |
| Wireless Network Defense | - Understanding wireless network - Discussing various wireless standards - Describing various wireless network topologies - Describing possible use of wireless networks - Explaining various wireless network components - Explaining wireless encryption (WEP, WPA,WPA2) technologies - Describing various authentication methods for wireless networks - Discussing various types of threats on wireless networks - Creation of inventory for wireless network components - Appropriate placement of wireless Access Point (AP) - Appropriate placement of wireless antenna - Monitoring of wireless network traffic - Detection and locating of rogue access points - Prevention of wireless network from RF interference - Describing various security implications for wireless network | 6% |
| Network Security Controls, Protocols, and Devices | - Understanding fundamental elements of network security - Explaining network access control mechanism - Understanding different types of access controls - Explaining network Authentication, Authorization and Auditing (AAA) mechanism - Explaining network data encryption mechanism - Describing Public Key Infrastructure (PKI) - Describing various network security protocols - Describing various network security devices | 8% |
| Data Backup and Recovery | - Understanding data backup - Describing the data backup plan - Describing the identification of data to backup - Determining the appropriate backup medium for data backup - Understanding RAID backup technology and its advantages - Describing RAID architecture - Describing various RAID levels and their use - Selection of appropriate RAID level - Understanding Storage Area Network (SAN) backup technology and its advantages - Best practices of using SAN - Understanding Network Attached Storage (NAS) backup technology and its advantages - Describing various types of NAS implementation | 9% |
| Network Traffic Monitoring and Analysis | - Understanding network traffic monitoring - Importance of network traffic monitoring - Discussing techniques used for network monitoring and analysis - Appropriate position for network monitoring - Connection of network monitoring system with managed switch - Understanding network traffic signatures - Baselining for normal traffic - Disusing the various categories of suspicious traffic signatures - Various techniques for attack signature analysis - Understanding Wireshark components, working and features - Demonstrating the use of various Wireshark filters - Demonstrating the monitoring LAN traffic against policy violation - Demonstrating the security monitoring of network traffic - Demonstrating the detection of various attacks using Wireshark - Discussing network bandwidth monitoring and performance improvement | 9% |
| Host Security | - Understanding host security - Understanding the importance of securing individual hosts - Understanding threats specific to hosts - Identifying paths to host threats - Purpose of host before assessment - Describing host security baselining - Describing OS security baselining - Understanding and describing security requirements for different types of servers - Understanding security requirements for hardening of routers - Understanding security requirements for hardening of switches - Understanding data security concerns when data is at rest, in use, and in motion - Understanding virtualization security | 7% |
| Secure Firewall Configuration and Management | - Understanding firewalls - Understanding firewall security concerns - Describing various firewall technologies - Describing firewall topologies - Appropriate selection of firewall topologies - Designing and configuring firewall ruleset - Implementation of firewall policies - Explaining the deployment and implementation of firewall - Factors to considers before purchasing any firewall solution - Describing the configuring, testing and deploying of firewalls - Describing the management, maintenance and administration of firewall implementation - Understanding firewall logging - Measures for avoiding firewall evasion - Understanding firewall security best practices | 8% |
| Secure VPN Configuration and Management | - Understanding Virtual Private Network (VPN) and its working - Importance of establishing VPN - Describing various VPN components - Describing implementation of VPN concentrators and its functions - Explaining different types of VPN technologies - Discussing components for selecting appropriate VPN technology - Explaining core functions of VPN - Explaining various topologies for implementation of VPN - Discussing various VPN security concerns - Discussing various security implications to ensure VPN security and performance | 6% |
Career Opportunities
The EC-Council 312-38 exam equips the professionals with the fundamental knowledge and skills in networking concepts. Without a doubt, earning the Certified Network Defender certification has a lucrative career outlook. Some of the positions that the certified individuals can consider include IT Administrators, Network Technicians, Data Analysts, Network Administrators, and Network Engineers, among others. The average remuneration for these titles is $94,000 per annum.
Use Real Dumps - 100% Free 312-38 Exam Dumps: https://www.exam4docs.com/312-38-study-questions.html
Updated 100% Cover Real 312-38 Exam Questions - 100% Pass Guarantee: https://drive.google.com/open?id=1iV-N8ymghv6owCeXOG1EuBJHaB2x7R25

