nerdexam
GIAC

GSNA · Question #290

You are concerned about rootkits on your network communicating with attackers outside your network. Without using an IDS how can you detect this sort of activity?

The correct answer is D. By examining your firewall logs. Firewall logs will show all incoming and outgoing traffic. By examining those logs you can detect anomalous traffic, which can indicate the presence of malicious code such as rootkits. Answer: B is incorrect. While an IDS might be the most obvious solution in this scenario, it…

Network & Perimeter Auditing

Question

You are concerned about rootkits on your network communicating with attackers outside your network. Without using an IDS how can you detect this sort of activity?

Options

  • ABy setting up a DMZ.
  • BYou cannot, you need an IDS.
  • CBy examining your domain controller server logs.
  • DBy examining your firewall logs.

How the community answered

(33 responses)
  • A
    6% (2)
  • B
    12% (4)
  • C
    3% (1)
  • D
    79% (26)

Explanation

Firewall logs will show all incoming and outgoing traffic. By examining those logs you can detect anomalous traffic, which can indicate the presence of malicious code such as rootkits. Answer: B is incorrect. While an IDS might be the most obvious solution in this scenario, it is not Answer: C is incorrect. It is very unlikely that anything in your domain controller logs will show the presence of a rootkit, unless that rootkit is on the domain controller itself. Answer: A is incorrect. A DMZ is an excellent firewall configuration but will not aid in detecting

Topics

#rootkit detection#firewall logs#network monitoring#outbound traffic

Community Discussion

No community discussion yet for this question.

Full GSNA Practice