首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
The following scenario will be used for questions 29 and 30. John is a network administrator and has been told by one of his net
admin
2013-12-19
110
问题
The following scenario will be used for questions 29 and 30.
John is a network administrator and has been told by one of his network staff members that two servers on the network have recently had suspicious traffic traveling to them and then from them in a sporadic manner. The traffic has been mainly ICMP, but the patterns were unusual compared to other servers over the last 30 days. John lists the directories and subdirectories on the systems and finds nothing unusual. He inspects the running processes and again finds nothing suspicious. He sees that the systems’ NICs are not in promiscuous mode, so he is assured that sniffers have not been planted.
Which of the following best explains why John does not see anything suspicious on the reported systems?
选项
A、The systems have not yet been infected.
B、He is not running the correct tools. He needs to carry out a penetration test on the two systems.
C、Trojaned files have been loaded and executed.
D、A back door has been installed and the attacker enters the system sporadically.
答案
C
解析
C正确。rootkit中的其他工具可能会不同,但通常都会包含用于掩盖攻击者行踪的实用程序。例如,每个操作系统都会包含一些供根用户或管理员用户用来检测rootki的基本实用程序、已安装的监听器和后门。黑客会使用名称相同的新的实用程序来替换这些默认的实用程序。它们就叫“特洛伊程序”,因为它们将执行预期的功能,在后台进行一些恶意行为。
A不正确。因为这不是最佳答案。因为系统很有可能没有被病毒感染,而这个问题问的是最可能的情况是什么。
B不正确。因为绝大多数rootkit都具有替换这些实用程序的特洛伊程序,因为根用户可以运行ps或top查看是否有后门服务在运行,进而检测出某个攻击。绝大多数rootkit也包含嗅探器,所以攻击者可以捕获并检查数据。要想嗅探器工作,系统的NIC必须被设置为混杂模式,这意味着NIC可以“听到”网络连接上的所有流量。默认的ipconfig实用程序允许根用户使用特定的参数查看NIC是否运行在混杂模式。所以rootkit也会包含一个ipconfig程序,它可以掩盖。NIC处于混杂模式的事实。
D不正确。因为这些服务器上很有可能不只是被安装了后门。rootkit包含允许攻击者远程控制被破坏系统的后门程序,但是rootkit中还包括许多其他工具。
转载请注明原文地址:https://kaotiyun.com/show/MAhZ777K
0
CISSP认证
相关试题推荐
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
AsformercolonistsofGreatBritain,theFoundingFathersoftheUnitedStatesadoptedmuchofthelegalsystemofGreatBritai
Theterme-commercereferstoallcommercialtransactionsconductedovertheInternet,includingtransactionsbyconsumersandb
Nowthattheeconomyisatlastgrowingagain,theburningissueinBritainisthecostofliving.Priceshaveexceededwagesfo
[A]Meetingdifferentneeds[B]Smallerisbetter[C]Betterproductmakesgreaterquantity[D]Qualityvsquantity[E]Chillyc
AUniversityofNebraskaprofessorhasdevelopedroboticconesandbarrels.(41)______Theycanevenbeprogrammedtomoveonthe
[A]Developmentwelcomedbycityplanners[B]Reduceddemandsonspaceandenergy[C]Plansforfuturehomes[D]Worldwideexamp
TheChineseScienceandTechnologyPapersBeingIncludedinSCIA.Studythechartscarefullyandwriteanessayof160-200
DespiteincreasedairportsecuritysinceSeptember11th,2001,thetechnologytoscanbothpassengersandbaggageforweaponsan
Every40seconds,someonediesfromsuicide,andcloseto800,000fatalitiesoccureachyearintheUnitedStates.【T1】WorldMen
随机试题
生成组织液的有效滤过压等于()
2002年底,中国A公司与国外B公司签订粮食买卖合同并支付了全部货款。2003年1月,当C公司货轮将买卖合同项下的货物运抵中国港口时,甲省某市公安局所属的海警支队(属于该局的内部机构)以该批货在该港的存放和装船数量有问题为由将船及货物扣押。1月20日,海警
夜间机动车灯光照射距离由远及近,说明机动车可能已到达伏坡道的低谷。
患者,男性,20岁。在一次体检中发现HBsAg阳性,当时无自觉症状及体征,肝功能正常。次年5月,因突然乏力、恶心、厌食、尿黄而入院。化验:ALT500U,血清总胆红素85μmol/L,抗-HAVIgM(+)。该患者的诊断可能为
一患者车祸后2小时送至医院,诉咳嗽、胸部疼痛。查体:T36.5℃,P130次/分,R30次/分,BP90/60mmHg。神清。右胸部压痛明显,右肺呼吸音低,右下肢骨折征。胸片示右侧液气胸。首先应采取的处理是
62岁妇女,绝经后12年,出现阴道不规则出血,此人,体胖,患有高血压,21/12kPa(158/98mmHg),尿蛋白(-),尿糖(+),妇查:外阴阴道(-),宫颈(+),糜烂质中,无出血,宫体平位稍大,稍软,形态正常,活动好,附件(-),双穹(-)
男孩,3岁,与同龄人相比体质较差,因怀疑先天性心脏病就诊。合并症治愈后,进一步治疗的方法为
生产性毒物的职业接触方式以()为主。
电路的运行分为( )三种状态。
北方某商业工程,建筑面积8000m2,由某施工总承包单位负责施工。框架结构,条形基础,地上4层,檐高18m。南侧与原有钢筋混凝土建筑物部分贴建,原有建筑物高4m,屋面局部高低跨差1.2m。外墙采用双排钢管落地式脚手架,垂直运输工具为塔吊。施工总承包单位组建
最新回复
(
0
)