EC-Council
412-79V10 · Question #26
Peter is a lead penetration tester in a security service firm named Xsecurity. Recently, Peter was assigned a white-box pen test assignment testing the security of an IDS system deployed by a…
The correct answer is D. Peter is trying to bypass the IDS system using inconsistent packets. See the full explanation below for the reasoning.
Question
Peter is a lead penetration tester in a security service firm named Xsecurity. Recently, Peter was assigned a white-box pen test assignment testing the security of an IDS system deployed by a client. During the preliminary information gathering, Peter discovered the TTL to reach the IDS system from his end is 30. From his end, to reach the firewall, the TTL is 28. Peter performed a traceroute to the IDS system from his end, then used a packet flooding prior to test/reach the IDS system, which he controlled packets with the destination address of a target host behind the IDS whose TTL is 35. What is Peter trying to achieve?
Options
- APeter is trying to bypass the IDS system using a Trojan
- BPeter is trying to bypass the IDS system using the broadcast address
- CPeter is trying to bypass the IDS system using the insertion attack
- DPeter is trying to bypass the IDS system using inconsistent packets
How the community answered
(51 responses)- A4% (2)
- B8% (4)
- C16% (8)
- D73% (37)
Community Discussion
No community discussion yet for this question.