nerdexam
EC-Council

212-89 · Question #81

Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted…

The correct answer is C. nmap --script=sniffer-detect [Target IP Address/Range of IP addresses]. The GPG18 and Forensic readiness planning (SPF) principles outline various guidelines to enhance an organization's readiness for forensic investigation and response. Principle 5, which suggests that organizations should adopt a scenario-based Forensic Readiness Planning…

Incident Handling and Response Technologies

Question

Darwin is an attacker residing within the organization and is performing network sniffing by running his system in promiscuous mode. He is capturing and viewing all the network packets transmitted within the organization. Edwin is an incident handler in the same organization. In the above situation, which of the following Nmap commands Edwin must use to detect Darwin's system that is running in promiscuous mode?

Options

  • Anmap -sV -T4 -O -F -version-light
  • Bnmap -sU -p 500
  • Cnmap --script=sniffer-detect [Target IP Address/Range of IP addresses]
  • Dnmap --script hostmap

How the community answered

(14 responses)
  • A
    7% (1)
  • C
    79% (11)
  • D
    14% (2)

Explanation

The GPG18 and Forensic readiness planning (SPF) principles outline various guidelines to enhance an organization's readiness for forensic investigation and response. Principle 5, which suggests that organizations should adopt a scenario-based Forensic Readiness Planning approach that learns from experience gained within the business, emphasizes the importance of being prepared for a wide range of potential incidents by leveraging lessons learned from past experiences. This approach helps in continuously improving forensic readiness and response capabilities by adapting to the evolving threat landscape and organizational changes.

Topics

#network sniffing#promiscuous mode#Nmap#sniffer detection

Community Discussion

No community discussion yet for this question.

Full 212-89 Practice