首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
admin
2013-12-19
79
问题
The following scenario will be used for questions 29 and 30.
John is a network administrator and has been told by one of his network staff members that two servers on the network have recently had suspicious traffic traveling to them and then from them in a sporadic manner. The traffic has been mainly ICMP, but the patterns were unusual compared to other servers over the last 30 days. John lists the directories and subdirectories on the systems and finds nothing unusual. He inspects the running processes and again finds nothing suspicious. He sees that the systems’ NICs are not in promiscuous mode, so he is assured that sniffers have not been planted.
Which of the following describes the most likely situation as described in this scenario?
选项
A、Servers are not infected, but the traffic illustrates attack attempts.
B、Servers have been infected with rootkits.
C、Servers are vulnerable and need to be patched.
D、Servers have been infected by spyware.
答案
B
解析
B正确。一旦取得了某个访问等级,攻击者就可以上传一大堆工具,即rootkit。rootkit是实现了隐身能力,即为了隐藏某些进程或程序的存在性,而设计的程序。对rootkit进行检测非常困难,因为rootkit能够破坏打算找到该rootkit的软件。A不正确。因为从这个场景中描述的情况看,该系统很有可能被病毒感染了。ICMP流量可能是攻击者和被破坏的系统之间发送的命令和状态数据。
C不正确。因为这不是最佳答案。服务器可能很脆弱,需要打补丁,但这并不是本题所问。打补丁也不会根除受感染系统中的rootkit。
D不正确。因为这不是最佳答案。这个场景很好地描述了安装了rootkit的情况。间谍软件可能是rootkit的一个组成部分,但是特洛伊木马的文件很有可能已经被安装了,而这只可能使用rootkit实现,而不是恶意软件。
转载请注明原文地址:https://kaotiyun.com/show/0AhZ777K
0
CISSP认证
相关试题推荐
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Theterme-commercereferstoallcommercialtransactionsconductedovertheInternet,includingtransactionsbyconsumersandb
Nano-sizedtoothbrushesthatcancleanverysmallsurfaceshavebeendevelopedbyresearchers.Fabricatedoutofmillionsofcar
Severaltypesoffinancialriskareencounteredininternationalmarketing;themajorproblemsincludecommercial,political,an
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
YouaredoingyourUCLAapplicationforgraduateadmission,andyouneedtworeferenceletters.Pleaseemailyourformerforeign
Apairofdice,rolledagainandagain,willeventuallyproducetwosixes.Similarly,thevirusthatcausesinfluenzaisconstan
Clothesplayacriticalpartintheconclusionswereachbyprovidingcluestowhopeopleare,whotheyarenot,andwhotheywo
JudithVogtli,directorofanupstateNewYork-basedabstinence(thepracticeofrefrainingfromsex,alcohol,etc)organization
随机试题
我国1998年国务院机构改革方案提出政府职能转变的努力方面是:
血证的治疗可归纳为
患者,女性,72岁。便秘多日,护士告其多吃水果能帮助排便,水果中能起通便作用的营养素是
单纯滑膜结核的X线表现是
“世界这么大,我想去看看。”在情怀至上的人眼里,“世界”一定是远方,远方让人充满向往,“看世界”便是去远方。然而,并不是人人都得去远方。其实,从完善认知的角度来说,“世界”未必就只有远方,“世界”也在身边。远方固然神秘,但身边一样充满了未知——就像很多时候
证券投资基金的收益主要有()。
良好的绩效管理在组织管理中的作用包括()。
在社会政治经济等活动中,各类人员对有关信息的了解是有差异的,一些成员拥有其他成员无法拥有的信息,由此造成信息的不对称。掌握信息比较充分的人员,往往处于比较有利的地位,而信息贫乏的人员,则处于比较不利的地位。根据上述定义,下列不属于信息不对称的是:
法学研究的基本方法有哪些?
【B1】【B20】
最新回复
(
0
)