exam questions

Exam 312-50v11 All Questions

View all questions & answers for the 312-50v11 exam

Exam 312-50v11 topic 1 question 79 discussion

Actual exam question from ECCouncil's 312-50v11
Question #: 79
Topic #: 1
[All 312-50v11 Questions]

You are a Network Security Officer. You have two machines. The first machine (192.168.0.99) has snort installed, and the second machine (192.168.0.150) has kiwi syslog installed. You perform a syn scan in your network, and you notice that kiwi syslog is not receiving the alert message from snort. You decide to run wireshark in the snort machine to check if the messages are going to the kiwi syslog machine. What Wireshark filter will show the connections from the snort machine to kiwi syslog machine?

  • A. tcp.srcport= = 514 && ip.src= = 192.168.0.99
  • B. tcp.srcport= = 514 && ip.src= = 192.168.150
  • C. tcp.dstport= = 514 && ip.dst= = 192.168.0.99
  • D. tcp.dstport= = 514 && ip.dst= = 192.168.0.150
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
victorfs
5 months, 3 weeks ago
Selected Answer: D
Option D is correct! tcp.dstport= = 514 && ip.dst= = 192.168.0.150
upvoted 2 times
...
juliosc
8 months, 2 weeks ago
"check if the messages are going to the kiwi syslog machine" Snort is the source and Kiwi the destination.
upvoted 1 times
...
Daniel8660
1 year ago
Selected Answer: D
Port and Service Discovery syslog 514/udp (P.296/280)
upvoted 3 times
...
baskan
1 year, 2 months ago
D. to kiwi syslog machine means it is Destination.
upvoted 2 times
...
noblethic
1 year, 4 months ago
D. Is the one
upvoted 2 times
...
Mileke
1 year, 5 months ago
Kiwi syslog is not receiving the connection so you can only check the snort system using a filter of where it is sending it to, hence, the destination filters
upvoted 1 times
...
AjaxFar
1 year, 10 months ago
Correct
upvoted 1 times
...
ANDRESCB1988
2 years, 3 months ago
correct
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago