New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 212-82 Exam - Topic 14 Question 45 Discussion

Actual exam question for Eccouncil's 212-82 exam
Question #: 45
Topic #: 14
[All 212-82 Questions]

An IoT device that has been placed in a hospital for safety measures, it has sent an alert command to the server. The network traffic has been captured and stored in the Documents folder of the Attacker Machine-1. Analyze the loTdeviceTraffic.pcapng file and select the appropriate command that was sent by the IoT device over the network.

Show Suggested Answer Hide Answer
Suggested Answer: A, A

TCP Timestamps is the vulnerability with a severity score of 8.0. This can be verified by performing a vulnerability assessment of the web server located at IP address 20.20.10.26 using the OpenVAS vulnerability scanner, available with the Parrot Security machine, with credentials admin/password. To perform the vulnerability assessment, one can follow these steps:

Launch the Parrot Security machine and open a terminal.

Enter the command sudo openvas-start to start the OpenVAS service and wait for a few minutes until it is ready.

Open a web browser and navigate to https://127.0.0.1:9392 to access the OpenVAS web interface.

Enter the credentials admin/password to log in to OpenVAS.

Click on Scans -> Tasks from the left menu and then click on the blue icon with a star to create a new task.

Enter a name and a comment for the task, such as ''Web Server Scan''.

Select ''Full and fast'' as the scan config from the drop-down menu.

Click on the icon with a star next to Target to create a new target.

Enter a name and a comment for the target, such as ''Web Server''.

Enter 20.20.10.26 as the host in the text box and click on Save.

Select ''Web Server'' as the target from the drop-down menu and click on Save.

Click on the green icon with a play button next to the task name to start the scan and wait for it to finish.

Click on the task name to view the scan report and click on Results from the left menu to see the list of vulnerabilities found.

Sort the list by Severity in descending order and look for the vulnerability with a severity score of 8.0. The screenshot below shows an example of performing these steps: The vulnerability with a severity score of 8.0 is TCP Timestamps, which is an option in TCP packets that can be used to measure round-trip time and improve performance, but it can also reveal information about the system's uptime, clock skew, or TCP sequence numbers, which can be used by attackers to launch various attacks, such as idle scanning, OS fingerprinting, or TCP hijacking1. The vulnerability report provides more details about this vulnerability, such as its description, impact, solution, references, and CVSS score2. Reference: Screenshot of OpenVAS showing TCP Timestamps vulnerability, TCP Timestamps Vulnerability, Vulnerability Report


Contribute your Thoughts:

0/2000 characters
Marge
3 months ago
I agree with A, it makes the most sense for a safety alert.
upvoted 0 times
...
Kattie
3 months ago
I’m surprised they’d use such a confusing command like D, High_Tempe.
upvoted 0 times
...
Art
3 months ago
B, Low_Tempe seems off to me.
upvoted 0 times
...
Vanna
4 months ago
Nah, I’m leaning towards C, Temp_High.
upvoted 0 times
...
Haydee
4 months ago
I think it’s definitely A, Tempe_Low.
upvoted 0 times
...
Adelina
4 months ago
I’m torn between Low_Tempe and High_Tempe. I just wish I could remember the specific syntax we covered in class!
upvoted 0 times
...
Lilli
4 months ago
I feel like "Tempe_Low" sounds off, but I can't recall the exact format we discussed for alert commands.
upvoted 0 times
...
Coleen
4 months ago
I think we had a similar question about temperature alerts in our last mock exam. I might lean towards Temp_High, but I’m not completely confident.
upvoted 0 times
...
Yoko
5 months ago
I remember we practiced analyzing pcap files, but I’m not entirely sure which command corresponds to a safety alert.
upvoted 0 times
...
Lura
5 months ago
I'm a bit confused by this question. How do I know which command is the "appropriate" one? I'll need to carefully examine the traffic and try to determine the context of the alert.
upvoted 0 times
...
Tora
5 months ago
Okay, I've got this. The question is asking for the specific command sent by the IoT device, so I'll dig into the packet data and look for any clear command strings or patterns.
upvoted 0 times
...
Brock
5 months ago
Hmm, I'm not too familiar with analyzing network captures. I'll need to review my notes on common IoT device commands and see if I can spot anything obvious in the traffic.
upvoted 0 times
...
Arlene
5 months ago
This looks like a classic network traffic analysis question. I'll start by opening the pcapng file in Wireshark and looking for any suspicious packets or commands.
upvoted 0 times
...
Bonita
10 months ago
Hold on, is this a trick question? What if the IoT device was actually sending a command to lower the temperature, like 'Low_Tempe'? Gotta keep an open mind here.
upvoted 0 times
Georgiana
8 months ago
Agreed, 'B) Low_Tempe' seems like the most logical choice.
upvoted 0 times
...
Elizabeth
8 months ago
Yeah, that makes sense. Let's go with 'B) Low_Tempe'.
upvoted 0 times
...
Tiara
8 months ago
I think you might be onto something with 'Low_Tempe'.
upvoted 0 times
...
Gregoria
8 months ago
D) High_Tempe
upvoted 0 times
...
Colette
8 months ago
C) Temp_High
upvoted 0 times
...
Celeste
8 months ago
B) Low_Tempe
upvoted 0 times
...
Corazon
9 months ago
A) Tempe_Low
upvoted 0 times
...
...
Alpha
10 months ago
I don't know about you, but I'm getting a bit hungry just reading these options. Maybe the IoT device was actually sending a command to order some 'High_Tempe' pizza for the hospital staff.
upvoted 0 times
William
8 months ago
D) High_Tempe
upvoted 0 times
...
Arletta
9 months ago
C) Temp_High
upvoted 0 times
...
Renay
10 months ago
B) Low_Tempe
upvoted 0 times
...
Arlie
10 months ago
A) Tempe_Low
upvoted 0 times
...
...
William
10 months ago
I think I'll go with 'Temp_High' - it just sounds more like the kind of command an IoT device would send. Plus, 'Tempe' seems a bit too casual for a hospital setting.
upvoted 0 times
Chantell
10 months ago
I think 'Temp_High' is the most appropriate command for a safety measure in a hospital setting.
upvoted 0 times
...
Laurel
10 months ago
I agree, 'Temp_High' does sound like a command an IoT device in a hospital would send.
upvoted 0 times
...
...
Wei
10 months ago
Hmm, 'Tempe' and 'Temp' look a bit suspicious. I bet the real answer is 'High_Tempe' - the IoT device is probably monitoring temperature in the hospital.
upvoted 0 times
...
Daniel
10 months ago
I agree with Donette, Temp_High makes more sense for a safety alert in a hospital.
upvoted 0 times
...
Alesia
11 months ago
The packet capture file should contain the specific command sent by the IoT device. I'll analyze it carefully to find the correct answer.
upvoted 0 times
...
Maddie
11 months ago
I disagree, I believe the command sent was Tempe_Low.
upvoted 0 times
...
Donette
11 months ago
I think the command sent by the IoT device was Temp_High.
upvoted 0 times
...

Save Cancel