II0-001 · Question #219
An active traceback detects active network connections to a host.
The correct answer is A. True. Active traceback is a real-time intrusion tracing technique that operates while an attack is in progress, identifying the path and source of malicious traffic by examining live, active network connections to the targeted host. This makes option A correct - the defining…
Question
An active traceback detects active network connections to a host.
Options
- ATrue
- BFalse
How the community answered
(25 responses)- A72% (18)
- B28% (7)
Explanation
Active traceback is a real-time intrusion tracing technique that operates while an attack is in progress, identifying the path and source of malicious traffic by examining live, active network connections to the targeted host. This makes option A correct - the defining characteristic of active traceback is that it requires an ongoing connection to function, as opposed to post-incident analysis.
Option B is wrong because it denies this foundational property: without active connections, there is nothing for active traceback to analyze in real time.
Memory tip: Think of "active" as the key word - active traceback needs an active (live) connection, much like a phone trace that only works while the call is still ongoing. If the attacker hangs up (disconnects), the active trace fails.
Community Discussion
No community discussion yet for this question.