nerdexam
EC-Council

EC0-350 · Question #460

Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal?…

The correct answer is B. This is back orifice activity as the scan comes from port 31337. See the full explanation below for the reasoning.

Question

Snort has been used to capture packets on the network. On studying the packets, the penetration tester finds it to be abnormal. If you were the penetration tester, why would you find this abnormal? What is odd about this attack? (Choose the most appropriate statement)

Options

  • AThis is not a spoofed packet as the IP stack has increasing numbers for the three flags.
  • BThis is back orifice activity as the scan comes from port 31337.
  • CThe attacker wants to avoid creating a sub-carrier connection that is not normally valid.
  • DThere packets were created by a tool; they were not created by a standard IP stack.

How the community answered

(49 responses)
  • A
    8% (4)
  • B
    69% (34)
  • C
    18% (9)
  • D
    4% (2)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice