ExamGecko
Question list
Search
Search

Related questions











Question 141 - 312-50v12 discussion

Report
Export

The following is an entry captured by a network IDS. You are assigned the task of analyzing this entry.

You notice the value 0x90, which is the most common NOOP instruction for the Intel processor. You figure that the attacker is attempting a buffer overflow attack.

You also notice "/bin/sh" in the ASCII part of the output.

As an analyst what would you conclude about the attack?

A.
The buffer overflow attack has been neutralized by the IDS
Answers
A.
The buffer overflow attack has been neutralized by the IDS
B.
The attacker is creating a directory on the compromised machine
Answers
B.
The attacker is creating a directory on the compromised machine
C.
The attacker is attempting a buffer overflow attack and has succeeded
Answers
C.
The attacker is attempting a buffer overflow attack and has succeeded
D.
The attacker is attempting an exploit that launches a command-line shell
Answers
D.
The attacker is attempting an exploit that launches a command-line shell
Suggested answer: D
asked 18/09/2024
Ada Galilea
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first