ExamGecko
Question list
Search
Search

Related questions











Question 365 - 312-50v12 discussion

Report
Export

Which of the following scanning method splits the TCP header into several packets and makes it difficult for packet filters to detect the purpose of the packet?

A.
ACK flag probe scanning
Answers
A.
ACK flag probe scanning
B.
ICMP Echo scanning
Answers
B.
ICMP Echo scanning
C.
SYN/FIN scanning using IP fragments
Answers
C.
SYN/FIN scanning using IP fragments
D.
IPID scanning
Answers
D.
IPID scanning
Suggested answer: C

Explanation:

SYN/FIN scanning using IP fragments is a process of scanning that was developed to avoid false positives generated by other scans because of a packet filtering device on the target system. The TCP header splits into several packets to evade the packet filter. For any transmission, every TCP header must have the source and destination port for the initial packet (8-octet, 64-bit). The initialized flags in the next packet allow the remote host to reassemble the packets upon receipt via an Internet protocol module that detects the fragmented data packets using field-equivalent values of the source, destination, protocol, and identification.

asked 18/09/2024
Carl James Carampot
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first