QuestionQ36

Network Forensics and Traffic Analysis

Which of the following programs can be used to identify stealth port scans carried out by a malicious hacker?

Each correct answer represents a complete solution. Choose all that apply.

Choose two
  • A portsentry
  • B libnids
  • C nmap
  • D scanlogd
Explanation

PortSentry provides dedicated stealth TCP and UDP scan-detection modes. Scanlogd detects and logs TCP port scans from captured packet traffic. Libnids is a supporting library, whereas Nmap is a port-scanning tool that can perform stealth SYN scans rather than detect them.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!