Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil Exam 312-38 Topic 8 Question 87 Discussion

Actual exam question for Eccouncil's 312-38 exam
Question #: 87
Topic #: 8
[All 312-38 Questions]

Which of the following Wireshark filters allows an administrator to detect SYN/FIN DDoS attempt on

the network?

Show Suggested Answer Hide Answer
Suggested Answer: A

According to NIST guidelines, the incident category that includes activities seeking to access or identify a federal agency computer, open ports, protocols, services, or any combination thereof for later exploitation is categorized as 'Scans/Probes/Attempted Access'. This category encompasses any unauthorized attempts to access systems, networks, or data, which may include scanning for vulnerabilities or probing to discover open ports and services.


Contribute your Thoughts:

Shawnna
5 days ago
Ah, the good old tcp.dstport==7. Classic. But I don't think that's going to help me detect a SYN/FIN DDoS attack. I'll have to go with option A on this one.
upvoted 0 times
...
Tracey
7 days ago
I'm not sure, but I think C) TCP.flags==0x300 could also be a possible filter to detect SYN/FIN DDoS attempts.
upvoted 0 times
...
Quentin
7 days ago
Hmm, option B looks interesting, but I'm not sure if tcp.flags==0X029 is the right way to go. I better double-check the Wireshark documentation just to be safe.
upvoted 0 times
...
Eun
8 days ago
TCP.flags==0x300? Really? That's not even a valid Wireshark filter. I think I'll go with option A - tcp.flags==0x003 to detect SYN/FIN DDoS attacks.
upvoted 0 times
...
Gilma
8 days ago
I agree with Dannie, because SYN/FIN DDoS attacks involve specific TCP flags.
upvoted 0 times
...
Dannie
10 days ago
I think the answer is A) tcp.flags==0x003.
upvoted 0 times
...
Ligia
11 days ago
That makes sense, thanks for explaining. I'll reconsider my answer.
upvoted 0 times
...
Chauncey
12 days ago
I disagree, I believe the correct answer is C) TCP.flags==0x300 because it specifically looks for SYN/FIN flags.
upvoted 0 times
...
Ligia
16 days ago
I think the answer is A) tcp.flags==0x003.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77