nerdexam
EC-Council

312-38 · Question #20

Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?

The correct answer is D. PSAD. PSAD (Port Scan Attack Detector) is the only tool among the choices specifically designed to analyze iptables log messages and detect port scans, half-open scans, and other suspicious traffic patterns - making D the correct answer. Worth noting: PSAD actually runs on Linux (not…

Network Security Monitoring and Analysis

Question

Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?

Options

  • ANmap
  • BHping
  • CNetRanger
  • DPSAD

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    3% (1)
  • D
    87% (27)

Explanation

PSAD (Port Scan Attack Detector) is the only tool among the choices specifically designed to analyze iptables log messages and detect port scans, half-open scans, and other suspicious traffic patterns - making D the correct answer. Worth noting: PSAD actually runs on Linux (not Windows), so the question contains an inaccuracy, but PSAD remains the only viable answer among the options.

Why the distractors are wrong:

  • A. Nmap - an active scanner used to probe networks; it generates traffic rather than analyzing logs.
  • B. Hping - a packet crafting and testing tool used to send custom TCP/IP packets; not a log analyzer.
  • C. NetRanger - Cisco's legacy network intrusion detection system (IDS), a hardware/software appliance that monitors traffic in real time, not an iptables log analyzer.

Memory tip: Think "PSAD = Port Scan Attack Detector" - the name tells you exactly what it does. If a question mentions iptables logs and port scan detection together, PSAD is your answer every time.

Topics

#Port Scan Detection#Firewall Log Analysis#Intrusion Detection#Network Monitoring

Community Discussion

No community discussion yet for this question.

Full 312-38 Practice