GAQM
CPEH-001 · Question #976
Dayn, an attacker, wanted to detect if any honeypots are installed in a target network. For this purpose, he used a time-based TCP fingerprinting method to validate the response to a normal computer…
The correct answer is B. Detecting the presence of Honeyd honeypots. See the full explanation below for the reasoning.
Question
Dayn, an attacker, wanted to detect if any honeypots are installed in a target network. For this purpose, he used a time-based TCP fingerprinting method to validate the response to a normal computer and the response of a honeypot to a manual SYN request. Which of the following techniques is employed by Dayn to detect honeypots?
Options
- ADetecting honeypots running on VMware
- BDetecting the presence of Honeyd honeypots
- CA Detecting the presence of Snort_inline honeypots
- DDetecting the presence of Sebek-based honeypots
How the community answered
(27 responses)- A4% (1)
- B74% (20)
- C15% (4)
- D7% (2)
Community Discussion
No community discussion yet for this question.