ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 36 - 212-82 discussion

Report
Export

Anderson, a security engineer, was Instructed to monitor all incoming and outgoing traffic on the organization's network to identify any suspicious traffic. For this purpose, he employed an analysis technique using which he analyzed packet header fields such as IP options, IP protocols, IP fragmentation flags, offset, and identification to check whether any fields are altered in transit.

Identify the type of attack signature analysis performed by Anderson in the above scenario.

A.
Context-based signature analysis
Answers
A.
Context-based signature analysis
B.
Atomic-signature-based analysis
Answers
B.
Atomic-signature-based analysis
C.
Composite-signature-based analysis
Answers
C.
Composite-signature-based analysis
D.
Content-based signature analysis
Answers
D.
Content-based signature analysis
Suggested answer: D

Explanation:

Content-based signature analysis is the type of attack signature analysis performed by Anderson in the above scenario. Content-based signature analysis is a technique that analyzes packet header fields such as IP options, IP protocols, IP fragmentation flags, offset, and identification to check whether any fields are altered in transit. Content-based signature analysis can help detect attacks that manipulate packet headers to evade detection or exploit vulnerabilities . Context-based signature analysis is a technique that analyzes packet payloads such as application data or commands to check whether they match any known attack patterns or signatures. Atomic-signature-based analysis is a technique that analyzes individual packets to check whether they match any known attack patterns or signatures. Composite-signature-based analysis is a technique that analyzes multiple packets or sessions to check whether they match any known attack patterns or signatures.

asked 18/09/2024
Tim Pass
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first