The default port for TFTP
What is 69?
Attacker type that hacks using the phone system
What is phreaker?
This guide is primarily used for incident response activities within the DoD
What is CJCSM 6510.01B?
Type type of network tap provides full-duplex traffic to a single monitoring port.
What is an aggregation tap?
This type of event occurs when a malicious attack occurs and the IDS alerts.
What is a true positive?
The default for IRC
What is 6667?
Indicator type that can't be broken down any further without loosing meaning
These objectives include regaining control of all systems involved and deny intruder access
This device is usually used on modern networks for capturing network traffic.
What is a tap?
This type of network IDS bypass involves breaking apart TCP/IP's Internet layer to avoid detection.
What is fragmentation?
The default well-known port for legacy AIM services
What is 531?
Type of attack a firewall is traditionally used to prevent
What is service-side (or server-side)?
This type of encryption methodology uses a single key to encrypt and decrypt data.
What is symmetric (or secret)?
This mode allows a host to capture network traffic not specifically addressed to it.
What is promiscuous?
This type of network IDS bypass involves breaking apart TCP/IP's Transport layer to avoid detection.
What is segmentation?
The default NetBIOS name resolution port
What is 137?
This analysis and tracking technique includes seven phases
What is the Cyber Kill Chain?
This access control type implements authorized user decisions.
What is discretionary?
This type of interface is used by tcpdump for capturing and analyzing packets network traffic.
What is command line?
This is the most likely reason for disabling zone transfers on a primary DNS server.
What is prevent attacks from exfiltrating data?
The well-known default DHCP port for Microsoft servers
What is 67?
This type of attack usually requires an end user to take some action
What is client-side?
This access control model is the basis for a multilevel security system.
What is Bell-LaPadula?
This type of filter is used in Wireshark to narrow down packets from a loaded PCAP file.
What is Display?
These three analysis techniques are used to detect attacks in network IDSs.