首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
admin
2013-12-19
39
问题
The following scenario will be used for questions 29 and 30.
John is a network administrator and has been told by one of his network staff members that two servers on the network have recently had suspicious traffic traveling to them and then from them in a sporadic manner. The traffic has been mainly ICMP, but the patterns were unusual compared to other servers over the last 30 days. John lists the directories and subdirectories on the systems and finds nothing unusual. He inspects the running processes and again finds nothing suspicious. He sees that the systems’ NICs are not in promiscuous mode, so he is assured that sniffers have not been planted.
Which of the following describes the most likely situation as described in this scenario?
选项
A、Servers are not infected, but the traffic illustrates attack attempts.
B、Servers have been infected with rootkits.
C、Servers are vulnerable and need to be patched.
D、Servers have been infected by spyware.
答案
B
解析
B正确。一旦取得了某个访问等级,攻击者就可以上传一大堆工具,即rootkit。rootkit是实现了隐身能力,即为了隐藏某些进程或程序的存在性,而设计的程序。对rootkit进行检测非常困难,因为rootkit能够破坏打算找到该rootkit的软件。A不正确。因为从这个场景中描述的情况看,该系统很有可能被病毒感染了。ICMP流量可能是攻击者和被破坏的系统之间发送的命令和状态数据。
C不正确。因为这不是最佳答案。服务器可能很脆弱,需要打补丁,但这并不是本题所问。打补丁也不会根除受感染系统中的rootkit。
D不正确。因为这不是最佳答案。这个场景很好地描述了安装了rootkit的情况。间谍软件可能是rootkit的一个组成部分,但是特洛伊木马的文件很有可能已经被安装了,而这只可能使用rootkit实现,而不是恶意软件。
转载请注明原文地址:https://kaotiyun.com/show/0AhZ777K
0
CISSP认证
相关试题推荐
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Theterme-commercereferstoallcommercialtransactionsconductedovertheInternet,includingtransactionsbyconsumersandb
Theterme-commercereferstoallcommercialtransactionsconductedovertheInternet,includingtransactionsbyconsumersandb
Thetranslatormusthaveanexcellent,up-to-dateknowledgeofhis【C1】______languages,fullfacilityinthehandlingofhistarg
DungtoDeathFieldsacrossEuropearecontaminatedwithdangerouslevelsoftheantibioticsgiventofarmanimals.Thedrug
Writeanessayof160-200wordsbasedonthefollowingdrawing.Inyouressay,youshould1)describethedrawingbriefly,
Thefollowingscenarioappliestoquestions27and28.Samisthesecuritymanagerofacompanythatmakesmostofitsrevenuef
随机试题
A、苦笑面容B、伤寒面容C、甲亢面容D、二尖瓣面容E、慢性病面容两颧紫红,口唇发绀,多见于
下列属于设计阶段的进度控制任务的是()。
城市人口的劳动人口按工作性质和服务对象,可分为()。
信用指数期货提供了一个规避公司经营风险的工具。()
()的儿童精力充沛,社会交往的积极性很高,但是因为交往技能差而常出现一些攻击性行为,不被同伴所接纳。
实验小学举办学生书法展,学校的橱窗里展出了每个年级学生的书法作品,其中有28幅不是五年级的,有24幅不是六年级的,五、六年级参展的书法作品共有20幅。一、二年级参展的作品总数比三、四年级参展的作品总数少4幅。一、二年级参展的书法作品共有多少幅?
下列选项中,属于香港特别行政区行政机关的是()
论说文:根据下述材料,写一篇700字左右的论说文,题目自拟。每一个人都应该有这样的信心:人所能负的责任,我必能负;人所不能负的责任,我亦能负。如此,你才能磨炼自己,求得更高的知识而进入更高的境界。
下列给定程序中函数fun的功能是:统计substr所指的字符串在str所指的字符串中出现的次数。例如,若字符串为aaas1kaaas,子字符串为as,则应输出2。请改正程序中的错误,使它能得出正确的结果。注意:不要改动mai
A、 B、 C、 A
最新回复
(
0
)