nerdexam
EC-Council

EC0-350 · Question #878

Cyber Criminals have long employed the tactic of masking their true identity. In IP spoofing, an attacker gains unauthorized access to a computer or a network by making it appear that a malicious…

The correct answer is D. Sending a packet to the claimed host will result in a reply. See the full explanation below for the reasoning.

Question

Cyber Criminals have long employed the tactic of masking their true identity. In IP spoofing, an attacker gains unauthorized access to a computer or a network by making it appear that a malicious message has come from a trusted machine, by "spoofing" the IP address of that machine. How would you detect IP spoofing?

Options

  • ACheck the IPID of the spoofed packet and compare it with TLC checksum. If the numbers match
  • BProbe a SYN Scan on the claimed host and look for a response SYN/FIN packet, if the connection
  • CTurn on 'Enable Spoofed IP Detection' in Wireshark, you will see a flag tick if the packet is spoofed
  • DSending a packet to the claimed host will result in a reply.

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    9% (3)
  • C
    3% (1)
  • D
    74% (25)

Community Discussion

No community discussion yet for this question.

Full EC0-350 Practice