L7: Adv. Network Monitoring Flashcards
1
Q
A bot is often called a:
A
Zombie
2
Q
Botnets account for more than 95% of all spam.
A
True
3
Q
All distributed denial of service (DDoS) attacks are done through botnets.
A
True
4
Q
Botnets are often set-up for short-term uses.
A
False
5
Q
A coordinated group of malware instances that are controlled via C&C channels is called a:
A
Botnet
6
Q
Which of the following behaviors are indicative of botnets?
- Linking to an established C&C server
- Generating Internet Relay Chat (IRC) traffic using a specific range of ports
- Generating DNS requests
- Generating SMTP emails/traffic
Reducing workstation performance/internet access to the level that it is noticeable by users
A
- Linking to an established C&C server
- Generating Internet Relay Chat (IRC) traffic using a specific range of ports
- Generating SMTP emails/traffic
Reducing workstation performance/internet access to the level that it is noticeable by users
7
Q
What can botnets do to evade C-plane clustering?
A
Manipulate communication patterns
8
Q
What can botnets do to evade A-plane clustering?
A
Perform slow spamming
Use undetectable activities
9
Q
What should be considered in order to identify the source (perpetrator) of an APT attack?
A
Source IP Coding style of Malware Inclusion of Special Libraries Motives of the attack Language encoding