Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Eccouncil 312-38 Exam - Topic 1 Question 115 Discussion

Which of the following filters can be used to detect UDP scan attempts using Wireshark?
A) icmp.type==3 and icmp.code==3
B) icmp.type==13
C) icmp.type==8 or icmp.type==0
D) icmp.type==15

Eccouncil 312-38 Exam - Topic 1 Question 115 Discussion

Actual exam question for Eccouncil's 312-38 exam
Question #: 115
Topic #: 1
[All 312-38 Questions]

Which of the following filters can be used to detect UDP scan attempts using Wireshark?

Show Suggested Answer Hide Answer
Suggested Answer: A

The correct filter to detect UDP scan attempts using Wireshark is not listed among the options provided. To detect UDP scan attempts, a Wireshark filter that targets UDP traffic specifically would be used, rather than an ICMP type and code filter. A common method to detect a UDP scan is to look for a large amount of UDP packets sent to different ports, which can be indicative of a scanning activity. The filter would typically include parameters that isolate UDP traffic, such asudp.portorudp.dstportcombined with a range or list of ports.


Contribute your Thoughts:

0/2000 characters
Tess
2 months ago
D is less useful. It’s for information requests, not scans.
upvoted 0 times
...
Yuki
2 months ago
C is more relevant. It captures echo requests, which can indicate scans.
upvoted 0 times
...
Jeanice
3 months ago
I disagree, A seems too specific. What about B? It detects timestamp requests.
upvoted 0 times
...
Jeanice
3 months ago
I think option A is the best choice. It shows unreachable ports.
upvoted 0 times
...
Theresia
3 months ago
C) is just for ping, not UDP scans!
upvoted 0 times
...
Daniel
3 months ago
Wait, are we sure about A)? Seems too simple.
upvoted 0 times
...
Herminia
3 months ago
Definitely A), no doubt about it!
upvoted 0 times
...
Tammy
4 months ago
I thought B) was for timestamp requests?
upvoted 0 times
...
Willard
4 months ago
A) is correct for detecting unreachable ports.
upvoted 0 times
...
Valentine
4 months ago
Lol, this question is a real head-scratcher. I'm just going to go with A and hope for the best.
upvoted 0 times
...
Barrett
4 months ago
Wait, why would we use ICMP to detect a UDP scan? Shouldn't we be looking for UDP packets instead?
upvoted 0 times
...
Nicolette
5 months ago
Haha, I bet the exam writer is trying to trick us with these options. A is the only logical choice here.
upvoted 0 times
...
Lynette
5 months ago
I think option C is the way to go. ICMP type 8 and 0 should catch the UDP scans.
upvoted 0 times
...
Louann
5 months ago
The correct answer is A. ICMP type 3 code 3 is the way to detect UDP scan attempts.
upvoted 0 times
...
Yolande
5 months ago
I thought ICMP type 8 and 0 were for echo requests and replies, so they probably wouldn't help with UDP scans, right?
upvoted 0 times
...
Felix
5 months ago
I practiced a question similar to this, and I feel like A is definitely the most relevant option for detecting UDP scans.
upvoted 0 times
...
Suzan
6 months ago
I'm not entirely sure, but I remember something about ICMP type 3 indicating unreachable errors, which could relate to UDP scans.
upvoted 0 times
...
Jamika
6 months ago
I think UDP scans might show up as ICMP unreachable messages, so maybe A is the right choice?
upvoted 0 times
...
Lilli
6 months ago
B seems like the best option, but I want to double-check the ICMP message types to be sure.
upvoted 0 times
...
Bobbye
6 months ago
I'm a bit confused on the difference between UDP scans and other types of scans. I'll need to review that before answering.
upvoted 0 times
...
Dona
6 months ago
C looks promising, since ICMP echo request/reply could be used to detect some types of scans.
upvoted 0 times
...
Ruthann
6 months ago
Hmm, I'm not sure about this one. I'll need to think through the ICMP message types more carefully.
upvoted 0 times
...
Rene
7 months ago
I think the answer is B, since UDP scans would trigger ICMP port unreachable messages.
upvoted 0 times
Louisa
14 days ago
I thought about A too, but B is more relevant for UDP.
upvoted 0 times
...
Rhea
19 days ago
Yeah, B makes sense. ICMP port unreachable is key.
upvoted 0 times
...
Goldie
2 months ago
I agree, B seems right. UDP scans trigger those messages.
upvoted 0 times
...
...

Save Cancel