Chapter 3 – Network Traffic Signatures
TRUE/FALSE
1. All devices interpret attack signatures uniformly.
2. An atomic attack is a barrage of hundreds of packets directed at a host.
3. The signature of a normal FTP connection includes a three-way handshake.
4. Newer Trojans listen at a predetermined port on the target computer so that detection is more difficult.
5. Packet fragmentation is not normal, and can only occur if an attack has been initiated.
MULTIPLE CHOICE
1. How does the CVE standard make network security devices and tools more effective?
the layered approach makes attacks nearly
impossible
it requires you to use compatible devices
from one vendor
they can share information about attack
signatures
it warns an attacker that your site is being
monitored
2. Which of the following is NOT among the items of information that a CVE reference reports?
description of vulnerability
name of the vulnerability
reference in other databases
3. Which of the following is an accurate set of characteristics you would find in an attack signature?
IP address, attacker’s alias, UDP options
IP address, TCP flags, port numbers
protocol options, TCP ports, region of
origin
IP number, MAC address, TCP options
4. What is the term used when an IDPS doesn’t recognize that an attack is underway?