nerdexam
EC-Council

212-82 · Question #151

A major metropolitan municipal corporation had deployed an extensive loT network for managing various facilities in the city. A recent cyber attack has paralyzed the city's vital services, bringing…

The correct answer is D. Forest_Fire_Alert444. Explanation Option D (Forest_Fire_Alert444) is correct because analyzing the IoT_capture.pcapng file using a packet analysis tool like Wireshark would reveal the actual command string Forest_Fire_Alert444 transmitted to the IoT devices during the cyberattack, which paralyzed…

Submitted by hassan_iq· Mar 6, 2026Cloud Security Operations & Incident Response

Question

A major metropolitan municipal corporation had deployed an extensive loT network for managing various facilities in the city. A recent cyber attack has paralyzed the city's vital services, bringing them to a complete halt. The Security Operations Center (SOC) has captured the network traffic during the attack and stored It as loT_capture.pcapng in the Documents folder of the Attacker Machine-1. Analyze the capture file and identify the command that was sent to the loT devices over the network. (Practical Question)

Options

  • AWoodland_Blaze_ Warninggil
  • BWoodland_Blaze_Warning999
  • CNature_Blaze_Warning555
  • DForest_Fire_Alert444

How the community answered

(50 responses)
  • A
    10% (5)
  • B
    6% (3)
  • C
    22% (11)
  • D
    62% (31)

Explanation

Explanation

Option D (Forest_Fire_Alert444) is correct because analyzing the IoT_capture.pcapng file using a packet analysis tool like Wireshark would reveal the actual command string Forest_Fire_Alert444 transmitted to the IoT devices during the cyberattack, which paralyzed the city's vital services. This command was embedded within the network traffic payload and can be identified by filtering and inspecting the packet contents in the capture file.

Options A (Woodland_Blaze_Warning gil), B (Woodland_Blaze_Warning999), and C (Nature_Blaze_Warning555) are distractors that use similar thematic naming conventions (nature-related emergency alerts) but contain incorrect keyword combinations - "Woodland" and "Nature" are not the prefix used in the actual command, and the numeric suffixes (gil, 999, 555) do not match the captured traffic payload.

Memory Tip: Think "F-F-A-4" - Forest_Fire_Alert444. The "Forest Fire" theme aligns with a realistic IoT attack scenario targeting city emergency systems, and the triple-4 suffix (444) distinguishes it from the distractor numbers (999, 555). When facing practical pcap questions, always use Wireshark's Follow TCP/UDP Stream or String Search feature to locate embedded command strings quickly.

Topics

#IoT Security#Network Traffic Analysis#Incident Response#Digital Forensics

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice