CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 23: 300-215: Conducting Forensic Analysis and Incident Response Using Cisco CyberOps Technologies (CBRFIR)

Refer to the exhibit. What should an engineer determine from this Wireshark capture of suspicious network traffic?

Nội dung câu hỏi

Refer to the exhibit. What should an engineer determine from this Wireshark capture of suspicious network traffic?

Minh họa câu hỏi

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. There are signs of SYN flood attack, and the engineer should increase the backlog and recycle the oldest half-open TCP connections. — đáp án hiện tại
  2. B. There are signs of a malformed packet attack, and the engineer should limit the packet size and set a threshold of bytes as a countermeasure.
  3. C. There are signs of a DNS attack, and the engineer should hide the BIND version and restrict zone transfers as a countermeasure.
  4. D. There are signs of ARP spoofing, and the engineer should use Static ARP entries and IP address-to-MAC address mappings as a countermeasure.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề