312-38 Free Study Guide! with New Update 232 Exam Questions [Q97-Q120]

Share

312-38 Free Study Guide! with New Update 232 Exam Questions

Get up-to-date Real Exam Questions for 312-38 UPDATED [2023]

NEW QUESTION # 97
Which of the following recovery plans includes specific strategies and actions to deal with specific variances to assumptions resulting in a particular security problem, emergency, or state of affairs?

  • A. Continuity of Operations Plan
  • B. Contingency plan
  • C. Disaster recovery plan
  • D. Business continuity plan

Answer: B

Explanation:
A contingency plan is a plan devised for a specific situation when things could go wrong. Contingency plans are often devised by governments or businesses who want to be prepared for anything that could happen.
Contingency plans include specific strategies and actions to deal with specific variances to assumptions resulting in a particular problem, emergency, or state of affairs. They also include a monitoring process and
"triggers" for initiating planned actions. They are required to help governments, businesses, or individuals to recover from serious incidents in the minimum time with minimum cost and disruption.
Answer option D is incorrect. It includes the plans and procedures documented that ensure the continuity of critical operations during any period where normal operations are impossible.
Answer option B is incorrect. Disaster recovery planning is a subset of a larger process known as business continuity planning and should include planning for resumption of applications, data, hardware, communications (such as networking), and other IT infrastructure. A business continuity plan (BCP) includes planning for non-IT related aspects such as key personnel, facilities, crisis communication, and reputation protection, and should refer to the disaster recovery plan (DRP) for IT-related infrastructure recovery/continuity.
Answer option C is incorrect. Business continuity planning (BCP) is the creation and validation of a practiced logistical plan for how an organization will recover and restore partially or completely interrupted critical (urgent) functions within a predetermined time after a disaster or extended disruption. The logistical plan is called a business continuity plan. The BCP lifecycle is as follows:


NEW QUESTION # 98
Which of the following is a non-profit organization that oversees the allocation of IP addresses, management of
the DNS infrastructure, protocol parameter assignment, and root server system management?

  • A. ICANN
  • B. ANSI
  • C. IEEE
  • D. ITU

Answer: A

Explanation:
ICANN stands for Internet Corporation for Assigned Names and Numbers. ICANN is responsible for managing
the assignment of domain names and IP addresses. ICANN's tasks include responsibility for IP address space
allocation, protocol identifier assignment, top-level domain name system management, and root server system
management functions. Internet Corporation for Assigned Names and Numbers (ICANN) is a non-profit
organization that oversees the allocation of IP addresses, management of the DNS infrastructure, protocol
parameter assignment, and root server system management.
Answer option B is incorrect. Institute of Electrical and Electronics Engineers (IEEE) is an organization of
engineers and electronics professionals who develop standards for hardware and software.
Answer option C is incorrect. The International Telecommunication Union is an agency of the United Nations
which regulates information and communication technology issues. ITU coordinates the shared global use of
the radio spectrum, promotes international cooperation in assigning satellite orbits, works to improve
telecommunication infrastructure in the developing world and establishes worldwide standards. ITU is active in
areas including broadband Internet, latest-generation wireless technologies, aeronautical and maritime
navigation, radio astronomy, satellite-based meteorology, convergence in fixed-mobile phone, Internet access,
data, voice, TV broadcasting, and next-generation networks.
Answer option A is incorrect. ANSI (American National Standards Institute) is the primary organization for
fostering the development of technology standards in the United States. ANSI works with industry groups and
is the U.S. member of the International Organization for Standardization (ISO) and the International
Electrotechnical Commission (IEC). Long-established computer standards from ANSI include the American
Standard Code for Information Interchange (ASCII) and the Small Computer System Interface (SCSI).


NEW QUESTION # 99
What is needed for idle scan a closed port the next steps? Each correct answer represents a part of the solution. Choose all that apply.

  • A. The attacker sends a SYN/ACK zombie.
  • B. In response to the SYN, the target to send RST.
  • C. Zombie ignores unsolicited RST, and IP ID remains unchanged.
  • D. Zombie IP ID will increase by only 1.
  • E. Zombie IP ID 2 rises.

Answer: A,B,C,D


NEW QUESTION # 100
Fill in the blank with the appropriate term. A______________________ network is a local area network (LAN) in which all computers are connected in a ring or star topology and a bit- or token- passing scheme is used for preventing the collision of data between two computers that want to send messages at the same time.

Answer:

Explanation:
Token Ring


NEW QUESTION # 101
Which of the following is a distributed application architecture that partitions tasks or workloads between
service providers and service requesters? Each correct answer represents a complete solution. Choose all that
apply.

  • A. Peer-to-peer (P2P) computing
  • B. Client-server networking
  • C. Peer-to-peer networking
  • D. Client-server computing

Answer: B,D

Explanation:
Client-server networking is also known as client-server computing. It is a distributed application architecture
that partitions tasks or workloads between service providers (servers) and service requesters, called clients.
Often clients and servers operate over a computer network on separate hardware. A server machine is a high-
performance host that is running one or more server programs which share its resources with clients. A client
does not share any of its resources, but requests a server's content or service function. Clients therefore
initiate
communication sessions with servers which await (listen to) incoming requests.
Answer options D and B are incorrect. Peer-to-peer (P2P) computing or networking is a distributed application
architecture that partitions tasks or workloads between peers. Peers are equally privileged, equipotent
participants in the application. They are said to form a peer-to-peer network of nodes. Peer-to-peer networking
(also known simply as peer networking) differs from client-server networking, where certain devices have the
responsibility to provide or "serve" data, and other devices consume or otherwise act as "clients" of those
servers.


NEW QUESTION # 102
Which of the following systems monitors the operating system detecting inappropriate activity, writing to log files, and triggering alarms?

  • A. Network-based ID system
  • B. Host-based ID system
  • C. Signature-Based ID system
  • D. Behavior-based ID system

Answer: B


NEW QUESTION # 103
Which of the following protocols is used for inter-domain multicast routing and natively supports "source-
specific multicast" (SSM)?

  • A. EIGRP
  • B. BGMP
  • C. OSPF
  • D. DVMRP

Answer: B

Explanation:
BGMP stands for border gateway multicast protocol. It is used for inter-domain multicast routing and natively
supports "source-specific multicast" (SSM). In order to support "any-source multicast" (ASM), BGMP builds
shared trees for active multicast groups. This allows domains to build source-specific, inter-domain, distribution
branches where needed. BGMP uses TCP as its transport protocol, which helps in eliminating the need to
implement message fragmentation, retransmission, acknowledgement, and sequencing.
Answer option B is incorrect. The Distance Vector Multicast Routing Protocol (DVMRP) is used to share
information between routers to transport IP Multicast packets among networks. It uses a reverse path-flooding
technique and is used as the basis for the Internet's multicast backbone (MBONE). In particular, DVMRP is
notorious for poor network scaling, resulting from reflooding, particularly with versions that do not implement
pruning. DVMRP's flat unicast routing mechanism also affects its capability to scale.
Answer option D is incorrect. EIGRP is a Cisco proprietary protocol. It is an enhanced version of IGRP. It has
faster convergence due to use of triggered update and saving neighbor's routing table locally. It supports VLSM
and routing summarization. As EIGRP is a distance vector protocol, it automatically summarizes routes across
Class A, B, and C networks. It also supports multicast and incremental updates and provides routing for three
routed protocols, i.e., IP, IPX, and AppleTalk.
Answer option C is incorrect. Open Shortest Path First (OSPF) is a routing protocol that is used in large
networks. Internet Engineering Task Force (IETF) designates OSPF as one of the Interior Gateway Protocols.
A host uses OSPF to obtain a change in the routing table and to immediately multicast updated information to
all the other hosts in the network.


NEW QUESTION # 104
Which of the following standards is a proposed enhancement to the 802.11a and 802.11b wireless LAN
(WLAN) specifications that offers quality of service (QoS) features, including the prioritization of data, voice,
and video transmissions?

  • A. 802.15
  • B. 802.11h
  • C. 802.11e
  • D. 802.11n

Answer: C

Explanation:
The 802.11e standard is a proposed enhancement to the 802.11a and 802.11b wireless LAN (WLAN)
specifications. It offers quality of service (QoS) features, including the prioritization of data, voice, and video
transmissions. 802.11e enhances the 802.11 Media Access Control layer (MAC layer) with a coordinated time
division multiple access (TDMA) construct, and adds error-correcting mechanisms for delay-sensitive
applications such as voice and video. Answer option D is incorrect. 802.11h refers to the amendment added to
the IEEE 802.11 standard for Spectrum and Transmit Power Management Extensions.
Answer option B is incorrect. 802.11n is an amendment to the IEEE 802.11-2007 wireless networking standard
to improve network throughput over the two previous standards - 802.11a and 802.11g - with a significant
increase in the maximum raw data rate from 54 Mbit/s to 600 Mbit/s with the use of four spatial streams at a
channel width of 40 MHz. Answer option A is incorrect. IEEE 802.15 is a working group of the IEEE 802 and
specializes in Wireless PAN (Personal Area Network) standards. It includes seven task groups, which are as
follows:
1.Task group 1 (WPAN/Bluetooth)
2.Task group 2 (Coexistence)
3.Task group 3 (High Rate WPAN)
4.Task group 4 (Low Rate WPAN)
5.Task group 5 (Mesh Networking)
6.Task Group 6 (BAN)
7.Task group 7 (VLC)


NEW QUESTION # 105
Which of the following router configuration modes changes terminal settings on a temporary basis, performs basic tests, and lists system information?

  • A. Interface Config
  • B. Privileged EXEC
  • C. User EXEC
  • D. Global Config

Answer: C

Explanation:
User EXEC is one of the router configuration modes that changes terminal settings on a temporary basis, performs basic tests, and lists system information.
Answer option C is incorrect. Privileged EXEC sets operating parameters.
Answer option A is incorrect. Global Config modifies configuration that affects the system as a whole.
Answer option B is incorrect. Interface Config modifies the operation of an interface.


NEW QUESTION # 106
A VPN Concentrator acts as a bidirectional tunnel endpoint among host machines. What are the other f unction(s) of the device? (Select all that apply)

  • A. Enables input/output (I/O) operations
  • B. Provides access memory, achieving high efficiency
  • C. Assigns user addresses
  • D. Manages security keys

Answer: A,C,D


NEW QUESTION # 107
Assume that you are a network administrator and the company has asked you to draft an Acceptable Use Policy (AUP) for employees. Under which category of an information security policy does AUP fall into?

  • A. System Specific Security Policy (SSSP)
  • B. Incident Response Policy (IRP)
  • C. Enterprise Information Security Policy (EISP)
  • D. Issue Specific Security Policy (ISSP)

Answer: A


NEW QUESTION # 108
How many layers are present in the TCP/IP model?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A


NEW QUESTION # 109
Which of the following statements are NOT true about the FAT16 file system?Each correct answer represents a complete solution. Choose all that apply.

  • A. It supports file-level compression.
  • B. It supports the Linux operating system.
  • C. It does not support file-level security.
  • D. It works well with large disks because the cluster size increases as the disk partition size increases.

Answer: A,D

Explanation:
The FAT16 file system was developed for disks larger than 16MB. It uses 16-bit allocation table
entries. The FAT16 file system supports all Microsoft operating systems. It also supports OS/2 and
Linux.
Answer options C and A are incorrect. All these statements are true about the FAT16 file system.


NEW QUESTION # 110
Which of the following is a session layer protocol?

  • A. RDP
  • B. SLP
  • C. ICMP
  • D. RPC

Answer: D


NEW QUESTION # 111
Peter, a malicious hacker, obtains e-mail addresses by harvesting them from postings, blogs, DNS listings, and Web pages. He then sends a large number of unsolicited commercial e-mail (UCE) messages to these addresses. Which of the following e-mail crimes is Peter committing?

  • A. E-mail bombing
  • B. E-mail spam
  • C. E-mail storm
  • D. E-mail spoofing

Answer: B

Explanation:
Peter is performing spamming activity. Spam is a term that refers to the unsolicited e-mails sent to a large number of e-mail users. The number of such e-mails is increasing day by day, as most companies now prefer to use e-mails for promoting their products. Because of these unsolicited e-mails, legitimate e-mails take a much longer time to deliver to their destination. The attachments sent through spam may also contain viruses. However, spam can be stopped by implementing spam filters on servers and e-mail clients. Answer option C is incorrect. Mail bombing is an attack that is used to overwhelm mail servers and clients by sending a large number of unwanted e-mails. The aim of this type of attack is to completely fill the recipient's hard disk with immense, useless files, causing at best irritation, and at worst total computer failure. E-mail filtering and properly configuring email relay functionality on mail servers can be helpful for protection against this type of attack. Answer option B is incorrect. An e-mail storm is a sudden spike of Reply All messages on an e-mail distribution list, usually caused by a controversial or misdirected message. Such storms start when multiple members of the distribution list reply to the entire list at the same time in response to an instigating message. Other members soon respond, usually adding vitriol to the discussion, asking to be removed from the list, or pleading for the cessation of messages. If enough members reply to these unwanted messages, this triggers a chain reaction of e-mail messages. The sheer load of traffic generated by these storms can render the e-mail servers carrying them inoperative, similar to a DDoS attack. Some e-mail viruses also have the capacity to create e-mail storms, by sending copies of themselves to an infected user's contacts, including distribution lists, infecting the contacts in turn. Answer option D is incorrect. E-mail spoofing is a term used to describe e-mail activity in which the sender address and other parts of the e-mail header are altered to appear as though the e-mail originated from a different source. E-mail spoofing is a technique commonly used for spam e-mail and phishing to hide the origin of an e-mail message. By changing certain properties of the e-mail, such as the From, Return-Path, and Reply-To fields (which can be found in the message header), ill-intentioned users can make the e-mail appear to be from someone other than the actual sender. The result is that, although the e-mail appears to come from the address indicated in the From field, it actually comes from another source.


NEW QUESTION # 112
Which of the following steps OPSEC process examines every aspect of the proposed operation to identify the OPSEC indicators that can reveal important information and then compare them with indicators of the opponent's intelligence collection capabilities identified in the previous activity?

  • A. Appropriate OPSEC measures
  • B. Identification of Critical Information
  • C. analysis of threats
  • D. risk assessment
  • E. analysis weakness

Answer: E


NEW QUESTION # 113
FILL BLANK
Fill in the blank with the appropriate term.
______________ is a prime example of a high-interaction honeypot.

Answer:

Explanation:
Honeynet
Explanation:
Honeynet is a prime example of a high-interaction honeypot. Two or more honeypots on a network form a
honeynet. Typically, a honeynet is used for monitoring a larger and/or more diverse network in which one
honeypot may not be sufficient. Honeynets and honeypots are usually implemented as parts of larger network
intrusion-detection systems. A honeyfarm is a centralized collection of honeypots and analysis tools.


NEW QUESTION # 114
Which of the following is the primary international body for fostering cooperative standards for telecommunications equipment and systems?

  • A. CCITT
  • B. IEEE
  • C. ICANN
  • D. NIST

Answer: A


NEW QUESTION # 115
Which of the following is a process of transformation where the old system can no longer be maintained?

  • A. Crisis
  • B. Risk
  • C. Threat
  • D. Disaster

Answer: A


NEW QUESTION # 116
Which of the following is the process of managing incidents in an enterprise?

  • A. Incident handling
  • B. Patch management
  • C. Log analysis
  • D. Incident response

Answer: A


NEW QUESTION # 117
Management decides to implement a risk management system to reduce and maintain the organization's risk to an acceptable level. Which of the following is the correct order in the risk management phase?

  • A. Risk Treatment, Risk Monitoring & Review, Risk Identification, Risk Assessment
  • B. Risk Identification, Risk Assessment, Risk Treatment, Risk Monitoring & Review
  • C. Risk Assessment, Risk Treatment, Risk Monitoring & Review, Risk Identification
  • D. Risk Identification, Risk Assessment, Risk Monitoring & Review, Risk Treatment

Answer: B


NEW QUESTION # 118
Which of the following devices allows wireless communication devices to connect to a wireless network using Wi-Fi, Bluetooth, or related standards?

  • A. Wireless repeater
  • B. WNIC
  • C. Express card
  • D. WAP

Answer: D


NEW QUESTION # 119
Which of the following types of VPN uses the Internet as its main backbone, allowing users, customers, and branch offices to access corporate network resources across various network architectures?

  • A. Extranet-based VPN
  • B. Intranet-based VPN
  • C. PPTP VPN
  • D. Remote access VPN

Answer: A

Explanation:
An extranet-based VPN uses the Internet as its main backbone network, allowing users, customers, and branch offices to access corporate network resources across various network architectures. Extranet VPNs are almost identical to intranet VPNs, except that they are intended for external business partners. Answer option D is incorrect. An intranet-based VPN is an internal, TCP/IP-based, password-protected network usually implemented for networks within a common network infrastructure having various physical locations. Intranet VPNs are secure VPNs that have strong encryption. Answer option B is incorrect. A remote access VPN is one of the types of VPN that involves a single VPN gateway. It allows remote users and telecommuters to connect to their corporate LAN from various points of connections. It provides significant cost savings by reducing the burden of long distance charges associated with dial-up access. Its main security concern is authentication, rather than encryption. Answer option A is incorrect. The PPTP VPN is one of the types of VPN technology.


NEW QUESTION # 120
......

Pass EC-COUNCIL 312-38 Exam in First Attempt Guaranteed: https://latestdumps.actual4exams.com/312-38-real-braindumps.html