ECCouncil Related Exams
312-38 Exam
Which of the following Wireshark filters allows an administrator to detect SYN/FIN DDoS attempt on
the network?
Frank installed Wireshark at all ingress points in the network. Looking at the logs he notices an odd packet source. The odd source has an address of 1080:0:FF:0:8:800:200C:4171 and is using port 21. What does this source address signify?
Rick has implemented several firewalls and IDS systems across his enterprise network. What should he do to effectively correlate all incidents that pass through these security controls?