ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 242 - CAS-004 discussion

Report
Export

Users are claiming that a web server is not accessible. A security engineer logs for the site. The engineer connects to the server and runs netstat -an and receives the following output:

A.
Port scanning
Answers
A.
Port scanning
B.
ARP spoofing
Answers
B.
ARP spoofing
C.
Buffer overflow
Answers
C.
Buffer overflow
D.
Denial of service
Answers
D.
Denial of service
Suggested answer: D

Explanation:

A denial of service (DoS) attack is a malicious attempt to disrupt the normal functioning of a server by overwhelming it with requests or traffic1.One possible indicator of a DoS attack is a large number of connections from a single source IP address1.In this case, the output of netstat -an shows that there are many connections from 213.37.55.67 with different port numbers and in TIME WAIT state23.This suggests that the attacker is sending many SYN packets to initiate connections but not completing them, thus exhausting the server's resources and preventing legitimate users from accessing it1.

asked 02/10/2024
Michael Whitehouse
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first