Exam 24: Digital Evidence at the Physical and Data-Link Layers

arrow
  • Select Tags
search iconSearch Question
flashcardsStudy Flashcards
  • Select Tags

How many bytes per packet does tcpdump capture by default?

(Multiple Choice)
4.7/5
(41)

One of the drawbacks of copying network traffic using a SPANned port is that a SPANned port copies only valid Ethernet packets.

(True/False)
4.7/5
(39)

What is a "gratuitous ARP request" and why is it dangerous?

(Essay)
4.8/5
(27)

Sniffers put NICs into_________ , forcing them to listen in on all of the communications that are occurring on the network.

(Multiple Choice)
4.8/5
(35)

It is not possible to use a sniffer when connected to a network via a modem.

(True/False)
4.9/5
(36)

Obtain the MAC address of a computer and describe how you did it.

(Essay)
4.7/5
(38)

What is the approximate theoretical maximum number of bytes that can be downloaded in one minute on a 10BaseT network?

(Multiple Choice)
4.9/5
(39)

Which of the following is a valid MAC address?

(Multiple Choice)
4.8/5
(41)

Routers use Ethernet addresses to direct data between networks.

(True/False)
4.9/5
(31)

It is possible to obtain file names from network traffic as well as the file contents.

(True/False)
4.9/5
(22)

DHCP can be configured to assign a static IP address to a particular computer every time it is connected to the network.

(True/False)
4.7/5
(39)

By default, tcpdump captures the entire contents of a packet.

(True/False)
4.7/5
(35)

Describe how a computer obtains the Ethernet address of another computer that it wants to communicate with.

(Short Answer)
4.7/5
(35)

One key point about MAC addresses is that they do not go beyond the router.

(True/False)
4.9/5
(31)
Showing 21 - 34 of 34
close modal

Filters

  • Essay(0)
  • Multiple Choice(0)
  • Short Answer(0)
  • True False(0)
  • Matching(0)