Free 312-50 Exam Braindumps (page: 41)

Page 40 of 191

Which of the following represents the initial two commands that an IRC client sends to join an IRC network?

  1. USER, NICK
  2. LOGIN, NICK
  3. USER, PASS
  4. LOGIN, USER

Answer(s): A

Explanation:

A "PASS" command is not required for either client or server connection to be registered, but it must precede the server message or the latter of the NICK/USER combination. (RFC 1459)



What does FIN in TCP flag define?

  1. Used to close a TCP connection
  2. Used to abort a TCP connection abruptly
  3. Used to indicate the beginning of a TCP connection
  4. Used to acknowledge receipt of a previous packet or transmission

Answer(s): A

Explanation:

The FIN flag stands for the word FINished. This flag is used to tear down the virtual connections created using the previous flag (SYN), so because of this reason, the FIN flag always appears when the last packets are exchanged between a connection.



What port number is used by LDAP protocol?

  1. 110
  2. 389
  3. 445
  4. 464

Answer(s): B

Explanation:

Active Directory and Exchange use LDAP via TCP port 389 for clients.



Null sessions are un-authenticated connections (not using a username or password.) to an NT or 2000 system. Which TCP and UDP ports must you filter to check null sessions on your network?

  1. 137 and 139
  2. 137 and 443
  3. 139 and 443
  4. 139 and 445

Answer(s): D

Explanation:

NULL sessions take advantage of “features” in the SMB (Server Message Block) protocol that exist primarily for trust relationships. You can establish a NULL session with a Windows host by logging on with a NULL user name and password. Primarily the following ports are vulnerable if they are accessible:
139
TCP
NETBIOS Session Service 139
UDP
NETBIOS Session Service 445
TCP SMB/CIFS






Post your Comments and Discuss EC-Council 312-50 exam with other Community members:

312-50 Discussions & Posts