Which of the following filters can be used to detect UDP scan attempts using Wireshark?
A.
icmp.type==3 and icmp.code==3
B.
icmp.type==13
C.
icmp.type==8 or icmp.type==0
D.
icmp.type==15
The Answer Is:
A
This question includes an explanation.
Explanation:
The correct filter to detect UDP scan attempts using Wireshark is not listed among the options provided. To detect UDP scan attempts, a Wireshark filter that targets UDP traffic specifically would be used, rather than an ICMP type and code filter. A common method to detect a UDP scan is to look for a large amount of UDP packets sent to different ports, which can be indicative of a scanning activity. The filter would typically include parameters that isolate UDP traffic, such as udp.port or udp.dstport combined with a range or list of ports.
References: The information provided is based on standard practices for using Wireshark to detect network scanning activities, as outlined in resources like the InfosecMatter guide on detecting network attacks with Wireshark1. While the EC-Council’s Certified Network Defender (CND) course materials would provide detailed methodologies for network defense, including the use of tools like Wireshark, the specific filters for detecting UDP scans would align with the general usage of Wireshark as described in various online resources and documentation1.
312-38 PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 60% Discount on All Products,
Use Coupon: "8w52ceb345"