nerdexam
EC-Council

EC0-350 · Question #473

The following excerpt is taken from a honeyput log. The log captures activities across three days. There are several intrusion attempts; however, a few are successful. Study the log given below and…

The correct answer is A. The system is a windows system which is being scanned unsuccessfully. See the full explanation below for the reasoning.

Question

The following excerpt is taken from a honeyput log. The log captures activities across three days. There are several intrusion attempts; however, a few are successful. Study the log given below and answer the following question:

(Note: The objective of this questions is to test whether the student has learnt about passive OS fingerprinting (which should tell them the OS from log captures): can they tell a SQL injection attack signature; can they infer if a user ID has been created by an attacker and whether they can read plain source - destination entries from log entries.) What can you infer from the above log?

Exhibit

EC0-350 question #473 exhibit

Options

  • AThe system is a windows system which is being scanned unsuccessfully.
  • BThe system is a web application server compromised through SQL injection.
  • CThe system has been compromised and backdoored by the attacker.
  • DThe actual IP of the successful attacker is 24.9.255.53.

How the community answered

(29 responses)
  • A
    72% (21)
  • B
    3% (1)
  • C
    17% (5)
  • D
    7% (2)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice