Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GAQM CPEH-001 Exam - Topic 6 Question 51 Discussion

Joe the Hacker breaks into XYZ's Linux system and plants a wiretap program in order to sniff passwords and user accounts off the wire. The wiretap program is embedded as a Trojan horse in one of the network utilities. Joe is worried that network administrator might detect the wiretap program by querying the interfaces to see if they are running in promiscuous mode.What can Joe do to hide the wiretap program from being detected by ifconfig command?
C) Replace original ifconfig utility with the rootkit version of ifconfig hiding Promiscuous information being displayed on the console.
A) Block output to the console whenever the user runs ifconfig command by running screen capture utiliyu
B) Run the wiretap program in stealth mode from being detected by the ifconfig command.
D) You cannot disable Promiscuous mode detection on Linux systems.

GAQM CPEH-001 Exam - Topic 6 Question 51 Discussion

Actual exam question for GAQM's CPEH-001 exam
Question #: 51
Topic #: 6
[All CPEH-001 Questions]

Joe the Hacker breaks into XYZ's Linux system and plants a wiretap program in order to sniff passwords and user accounts off the wire. The wiretap program is embedded as a Trojan horse in one of the network utilities. Joe is worried that network administrator might detect the wiretap program by querying the interfaces to see if they are running in promiscuous mode.

What can Joe do to hide the wiretap program from being detected by ifconfig command?

Show Suggested Answer Hide Answer
Suggested Answer: C

The normal way to hide these rogue programs running on systems is the use crafted commands like ifconfig and ls.


Contribute your Thoughts:

0/2000 characters
Merlyn
10 months ago
B seems like a solid choice, stealth mode is key.
upvoted 0 times
...
Veronika
10 months ago
Surprised that people think you can’t disable detection at all!
upvoted 0 times
...
Harris
10 months ago
A sounds too risky, blocking output could raise suspicion.
upvoted 0 times
...
Jin
11 months ago
I think D is misleading, there are ways to hide it.
upvoted 0 times
...
Raymon
11 months ago
C is the best option, definitely a classic rootkit move.
upvoted 0 times
...
Julene
11 months ago
I feel like I've read that you can't completely disable Promiscuous mode detection on Linux. That makes this question tricky!
upvoted 0 times
...
Karma
11 months ago
I practiced a question like this where stealth mode was mentioned. I wonder if that's what Joe should consider doing.
upvoted 0 times
...
Boris
11 months ago
I'm not entirely sure, but I think blocking output to the console could be a temporary fix. It seems risky though.
upvoted 0 times
...
Elenora
11 months ago
I remember something about rootkits being able to replace system utilities. That might be a way to hide the wiretap from ifconfig.
upvoted 0 times
...
Iluminada
11 months ago
This seems like a straightforward question about email marketing terminology. I'm pretty confident I know the answer, but I'll double-check my notes just to be sure.
upvoted 0 times
...
Ceola
11 months ago
Hmm, I'm a bit confused here. I'm not sure if the kubectl logs command would work for all the clusters, or if I need to do something else to get the logs from multiple clusters. Maybe B or D would be a better option?
upvoted 0 times
...
Harrison
11 months ago
I'm a bit unsure about this one. All of these project management concepts seem related to schedule development, so it's hard for me to quickly identify which one is the odd one out. I'll have to carefully consider the definitions of each input to make the right call.
upvoted 0 times
...
Leonida
11 months ago
This is a tricky one. I'm leaning towards C, since employees would need to follow the local privacy regulations where they're working. But the BCRs are the main thing, so I'm a bit conflicted. Guess I'll have to make an educated guess on this one.
upvoted 0 times
...

Save Cancel