首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
admin
2013-12-19
93
问题
The following scenario will be used for questions 29 and 30.
John is a network administrator and has been told by one of his network staff members that two servers on the network have recently had suspicious traffic traveling to them and then from them in a sporadic manner. The traffic has been mainly ICMP, but the patterns were unusual compared to other servers over the last 30 days. John lists the directories and subdirectories on the systems and finds nothing unusual. He inspects the running processes and again finds nothing suspicious. He sees that the systems’ NICs are not in promiscuous mode, so he is assured that sniffers have not been planted.
Which of the following describes the most likely situation as described in this scenario?
选项
A、Servers are not infected, but the traffic illustrates attack attempts.
B、Servers have been infected with rootkits.
C、Servers are vulnerable and need to be patched.
D、Servers have been infected by spyware.
答案
B
解析
B正确。一旦取得了某个访问等级,攻击者就可以上传一大堆工具,即rootkit。rootkit是实现了隐身能力,即为了隐藏某些进程或程序的存在性,而设计的程序。对rootkit进行检测非常困难,因为rootkit能够破坏打算找到该rootkit的软件。A不正确。因为从这个场景中描述的情况看,该系统很有可能被病毒感染了。ICMP流量可能是攻击者和被破坏的系统之间发送的命令和状态数据。
C不正确。因为这不是最佳答案。服务器可能很脆弱,需要打补丁,但这并不是本题所问。打补丁也不会根除受感染系统中的rootkit。
D不正确。因为这不是最佳答案。这个场景很好地描述了安装了rootkit的情况。间谍软件可能是rootkit的一个组成部分,但是特洛伊木马的文件很有可能已经被安装了,而这只可能使用rootkit实现,而不是恶意软件。
转载请注明原文地址:https://kaotiyun.com/show/0AhZ777K
0
CISSP认证
相关试题推荐
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Individualsandbusinesseshavelegalprotectionforintellectualpropertytheycreateandown.Intellectualproper【C1】______fro
Climatechangeissupposedtounfoldslowly,overdecades.Butthatisnottrueupinthegreatwhitenorth,asthoseattending
About3billionpeoplelivewithin100milesofthesea,anumberthatcoulddoubleinthenextdecadeashumansflocktocoasta
Writeanessayof160-200wordsbasedonthefollowingdrawings.Inyouressay,youshould1)describethedrawingsbriefly,
Writeanessayof160-200wordsbasedonthefollowingpictures.Inyouressay,youshould1)describethepicturesbriefly,
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
Clothesplayacriticalpartintheconclusionswereachbyprovidingcluestowhopeopleare,whotheyarenot,andwhotheywo
Howmenfirstlearnedtoinventwordsisunknown;inotherwords,theoriginoflanguageisamystery.Allwereallyknowistha
随机试题
夸张,是指在客观事实的基础上,对事物进行夸大的描述。()
施工作业人员安全生产的权利包括()。
女性生殖器尖锐性湿疣,不适宜的治疗是()
下列与糖异生无关的酶是
将某类人员的绩效特征用图表描绘出来,然后加以分析研究,确定绩效评价要素的方法是()
左边给定的是纸盒的外表面,下面哪一项能由它折叠而成?()
CRT显示器显示图形图像的原理是图形图像()。
下列哪项不属于曲面断层片的应用范围()。
【B1】【B9】
如何理解货币的两个最基本的职能?
最新回复
(
0
)