- (Topic 3)
James is testing the ability of his routers to withstand DoS attacks. James sends ICMP ECHO requests to the broadcast address of his network. What type of DoS attack is James testing against his network?
Correct Answer:
B
The Fraggle attack is like a smurf attack, but uses UDP packets and not ICMP.
- (Topic 1)
What is the goal of forensic science?
Correct Answer:
A
- (Topic 3)
Which Intrusion Detection System (IDS) usually produces the most false alarms due to the unpredictable behaviors of users and networks?
Correct Answer:
BC
NIDS and HIDS are types of IDS systems, Host or Network, and addresses placement of the probe. Anomaly detection is based on behavior analysis, and if you read the question, the question says “behavior” and if the behavior is unporedictable, then the IDS won’t know what is normal and what is bad.
- (Topic 3)
An Expert witness gives an opinion if:
Correct Answer:
A
- (Topic 3)
Before you are called to testify as an expert, what must an attorney do first?
Correct Answer:
D