[Feb 17, 2022] Get to the Top with 312-38 Practice Exam Questions [Q92-Q107]

Share

[Feb 17, 2022] Get to the Top with 312-38 Practice Exam Questions

Use Real 312-38 Dumps Free Sample Questions and Practice Test Engine

NEW QUESTION 92
What is the location of honeypot on a network?

  • A. Honeynet
  • B. Hub
  • C. DMZ
  • D. Honeyfarm

Answer: C

 

NEW QUESTION 93
Which of the following is a type of scam that entices a user to disclose personal information?

  • A. Phishing
  • B. Smurfing
  • C. Sniffing
  • D. Spamming

Answer: A

 

NEW QUESTION 94
Identify the minimum number of drives required to setup RAID level 5.

Multiple

  • A. 0
  • B. 1
  • C. 2

Answer: A

 

NEW QUESTION 95
DRAG DROP
George works as a Network Administrator for Blue Soft Inc. The company uses Windows Vista operating system. The network of the company is continuously connected to the Internet. What will George use to protect the network of the company from intrusion?

ECCouncil 312-38 Exam

Answer:

Explanation:

Explanation:

A firewall is a set of related programs configured to protect private networks connected to the Internet from intrusion. It is used to regulate the network traffic between different computer networks. It permits or denies the transmission of a network packet to its destination based on a set of rules. A firewall is often installed on a separate computer so that an incoming packet does not get into the network directly.

 

NEW QUESTION 96
Which of the following organizations is responsible for managing the assignment of domain names and IP addresses?

  • A. W3C
  • B. ISO
  • C. ANSI
  • D. ICANN

Answer: D

Explanation:
ICANN stands for Internet Corporation for Assigned Names and Numbers. ICANN is responsible for managing the assignment of domain names and IP addresses. ICANN's tasks include responsibility for IP address space allocation, protocol identifier assignment, top-level domain name system management, and root server system management functions.
Answer option A is incorrect. The International Organization for Standardization, widely known as ISO, is an international-standard-setting body composed of representatives from various national standards organizations. Founded on 23 February 1947, the organization promulgates worldwide proprietary industrial and commercial standards. It has its headquarters in Geneva, Switzerland. While ISO defines itself as a non- governmental organization, its ability to set standards that often become law, either through treaties or national standards, makes it more powerful than most non-governmental organizations. In practice, ISO acts as a consortium with strong links to governments.
Answer option C is incorrect. The World Wide Web Consortium (W3C) is an international industry consortium that develops common standards for the World Wide Web to promote its evolution and interoperability. It was founded in October 1994 by Tim Berners-Lee, the inventor of the Web, at the Massachusetts Institute of Technology, Laboratory for Computer Science [MIT/LCS] in collaboration with CERN, where the Web had originated, with support from DARPA and the European Commission.
Answer option D is incorrect. ANSI (American National Standards Institute) is the primary organization for fostering the development of technology standards in the United States. ANSI works with industry groups and is the U.S. member of the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). Long-established computer standards from ANSI include the American Standard Code for Information Interchange (ASCII) and the Small Computer System Interface (SCSI).

 

NEW QUESTION 97
Which of the following strategies is used to minimize the effects of a disruptive event on a company, and is created to prevent interruptions to normal business activity?

  • A. Continuity of Operations Plan
  • B. Contingency Plan
  • C. Disaster Recovery Plan
  • D. Business Continuity Plan

Answer: D

Explanation:
BCP is a strategy to minimize the consequence of the instability and to allow for the continuation of business processes. The goal of BCP is to minimize the effects of a disruptive event on a company, and is formed to avoid interruptions to normal business activity. Business Continuity Planning (BCP) is the creation and validation of a practiced logistical plan for how an organization will recover and restore partially or completely interrupted critical (urgent) functions within a predetermined time after a disaster or extended disruption. The logistical plan is called a business continuity plan. Answer option C is incorrect. A contingency plan is a plan devised for a specific situation when things could go wrong. Contingency plans are often devised by governments or businesses who want to be prepared for anything that could happen. Contingency plans include specific strategies and actions to deal with specific variances to assumptions resulting in a particular problem, emergency, or state of affairs. They also include a monitoring process and "triggers" for initiating planned actions. They are required to help governments, businesses, or individuals to recover from serious incidents in the minimum time with minimum cost and disruption. Answer option A is incorrect. Disaster recovery planning is a subset of a larger process known as business continuity planning and should include planning for resumption of applications, data, hardware, communications (such as networking), and other IT infrastructure. A business continuity plan (BCP) includes planning for non-IT related aspects such as key personnel, facilities, crisis communication, and reputation protection, and should refer to the disaster recovery plan (DRP) for IT-related infrastructure recovery/continuity. Answer option D is incorrect. The Continuity Of Operation Plan (COOP) refers to the preparations and institutions maintained by the United States government, providing survival of federal government operations in the case of catastrophic events. It provides procedures and capabilities to sustain an organization's essential. COOP is the procedure documented to ensure persistent critical operations throughout any period where normal operations are unattainable.

 

NEW QUESTION 98
Which subdirectory in /var/log directory stores information related to Apache web server?

  • A. /var/log/httpd/
  • B. /var/log/lighttpd/
  • C. /var/log/maillog/
  • D. /var/log/apachelog/

Answer: A

 

NEW QUESTION 99
Steven's company has recently grown from 5 employees to over 50. Every workstation has a public IP address and navigated to the Internet with little to no protection. Steven wants to use a firewall. He also wants IP addresses to be private addresses, to prevent public Internet devices direct access to them. What should Steven implement on the firewall to ensure this happens?

  • A. Steven should use Open Shortest Path First (OSPF)
  • B. Steven should use a Demilitarized Zone (DMZ)
  • C. Steven should use IPsec
  • D. Steven should enabled Network Address Translation(NAT)

Answer: D

 

NEW QUESTION 100
Which of the following policies is a set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly?

  • A. Remote access policy
  • B. Information protection policy
  • C. Group policy
  • D. Password policy

Answer: D

Explanation:
A password policy is a set of rules designed to enhance computer security by encouraging users to employ strong passwords and use them properly. Password policies are account policies that are related to the users' accounts. Such policies are password-related settings that provide different constraints for the password's usage. Password policies can be configured to enforce users to provide passwords only in a specific way when they try to log on to their computers. These policies increase the effectiveness of the user's computers. Answer option C is incorrect. A group policy specifies how programs, network resources, and the operating system work for users and computers in an organization. Answer option A is incorrect. An information protection policy ensures that information is appropriately protected from modification or disclosure. Answer option B is incorrect. Remote access policy is a document that outlines and defines acceptable methods of remotely connecting to the internal network.

 

NEW QUESTION 101
Which of the following security models enable strict identity verification for every user or device attempting to access the network resources?
1. Zero-trust network model
2. Castle-and-Moat model

  • A. None
  • B. 1 only
  • C. 2 only
  • D. Both 1 and 2

Answer: B

 

NEW QUESTION 102
Which of the following statements are true about volatile memory? Each correct answer represents a complete solution. Choose all that apply.

  • A. Read only memory (ROM) is an example of volatile memory.
  • B. The content is stored permanently and even the power supply is switched off.
  • C. It is computer memory that requires power to maintain the stored information.
  • D. A volatile storage device is faster in reading and writing data.

Answer: C,D

Explanation:
Volatile memory, also known as volatile storage, is computer memory that requires power to maintain the stored information, unlike non-volatile memory which does not require a maintained power supply. It has been less popularly known as temporary memory. Most forms of modern random access memory (RAM) are volatile storage, including dynamic random access memory (DRAM) and static random access memory (SRAM). A volatile storage device is faster in reading and writing data. Answer options A and C are incorrect. Non-volatile memory, nonvolatile memory, NVM, or nonvolatile storage, in the most basic sense, is computer memory that can retain the stored information even when not powered. Examples of non-volatile memory include read-only memory, flash memory, most types of magnetic computer storage devices (e.g. hard disks, floppy disks, and magnetic tape), optical discs, and early computer storage methods such as paper tape and punched cards.

 

NEW QUESTION 103
Which of the following analyzes network traffic to trace specific transactions and can intercept and log traffic passing over a digital network? Each correct answer represents a complete solution. Choose all that apply.

  • A. Wireless sniffer
  • B. Spectrum analyzer
  • C. Performance Monitor
  • D. Protocol analyzer

Answer: A,D

Explanation:
Protocol analyzer (also known as a network analyzer, packet analyzer or sniffer, or for particular types of networks, an Ethernet sniffer or wireless sniffer) is computer software or computer hardware that can intercept and log traffic passing over a digital network. As data streams flow across the network, the sniffer captures each packet and, if needed, decodes and analyzes its content according to the appropriate RFC or other specifications.
Answer option D is incorrect. Performance Monitor is used to get statistical information about the hardware and software components of a server.
Answer option B is incorrect. A spectrum analyzer, or spectral analyzer, is a device that is used to examine the spectral composition of an electrical, acoustic, or optical waveform. It may also measure the power spectrum.

 

NEW QUESTION 104
Which of the following techniques uses a modem in order to automatically scan a list of telephone numbers?

  • A. War driving
  • B. War dialing
  • C. Warkitting
  • D. Warchalking

Answer: B

Explanation:
War dialing is a technique of using a modem to automatically scan a list of telephone numbers, usually dialing every number in a local area code to search for computers, BBS systems, and fax machines. Hackers use the resulting lists for various purposes, hobbyists for exploration, and crackers (hackers that specialize in computer security) for password guessing.
Answer option C is incorrect. Warchalking is the drawing of symbols in public places to advertise an open Wi-Fi wireless network. Having found a Wi-Fi node, the warchalker draws a special symbol on a nearby object, such as a wall, the pavement, or a lamp post. The name warchalking is derived from the cracker terms war dialing and war driving.
Answer option A is incorrect. War driving, also called access point mapping, is the act of locating and possibly exploiting connections to wireless local area networks while driving around a city or elsewhere. To do war driving, one needs a vehicle, a computer (which can be a laptop), a wireless Ethernet card set to work in promiscuous mode, and some kind of an antenna which can be mounted on top of or positioned inside the car.
Because a wireless LAN may have a range that extends beyond an office building, an outside user may be able to intrude into the network, obtain a free Internet connection, and possibly gain access to company records and other resources.
Answer option D is incorrect. Warkitting is a combination of wardriving and rootkitting. In a warkitting attack, a hacker replaces the firmware of an attacked router. This allows them to control all traffic for the victim, and could even permit them to disable SSL by replacing HTML content as it is being downloaded. Warkitting was identified by Tsow, Jakobsson, Yang, and Wetzel in 2006. Their discovery indicated that 10% of the wireless routers were susceptible to WAPjacking (malicious configuring of the firmware settings, but making no modification on the firmware itself) and 4.4% of wireless routers were vulnerable to WAPkitting (subverting the router firmware). Their analysis showed that the volume of credential theft possible through Warkitting exceeded the estimates of credential theft due to phishing.

 

NEW QUESTION 105
Which of the following helps in viewing account activity and events for supported services made by AWS?

  • A. AWS CloudTrial
  • B. AWS Certificate Manager
  • C. AWS CloudFormation
  • D. AWS CloudHSM

Answer: A

 

NEW QUESTION 106
In which of the following transmission modes is data sent and received alternatively?

  • A. Full-duplex mode
  • B. Half-duplex mode
  • C. Simplex mode
  • D. Bridge mode

Answer: B

 

NEW QUESTION 107
......

Pass EC-COUNCIL 312-38 exam - questions - convert Tets Engine to PDF: https://protechtraining.actualtestsit.com/EC-COUNCIL/312-38-exam-prep-dumps.html