Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC GSNA Exam - Topic 6 Question 83 Discussion

Actual exam question for GIAC's GSNA exam
Question #: 83
Topic #: 6
[All GSNA Questions]

John used to work as a Network Administrator for We-are-secure Inc. Now he has resigned from the company for personal reasons. He wants to send out some secret information of the company. To do so, he takes an image file and simply uses a tool image hide and embeds the secret file within an image file of the famous actress, Jennifer Lopez, and sends it to his Yahoo mail id. Since he is using the image file to send the data, the mail server of his company is unable to filter this mail. Which of the following techniques is he performing to accomplish his task?

Show Suggested Answer Hide Answer
Suggested Answer: B

According to the scenario, John is performing the Steganography technique for sending malicious data. Steganography is an art and science of

hiding information by embedding harmful messages within other seemingly harmless messages. It works by replacing bits of unused data,

such as graphics, sound, text, and HTML, with bits of invisible information in regular computer files. This hidden information can be in the form

of plain text, cipher text, or even in the form of images.

Answer A is incorrect. Web ripping is a technique in which the attacker copies the whole structure of a Web site to the local disk and

obtains all files of the Web site. Web ripping helps an attacker to trace the loopholes of the Web site.

Answer D is incorrect. Social engineering is the art of convincing people and making them disclose useful information such as account

names and passwords. This information is further exploited by hackers to gain access to a user's computer or network. This method involves

mental ability of the people to trick someone rather than their technical skills. A user should always distrust people who ask him for his

account name or password, computer name, IP address, employee ID, or other information that can be misused.

Answer C is incorrect. John is not performing email spoofing. In email spoofing, an attacker sends emails after writing another person's

mailing address in the from field of the email id.


Contribute your Thoughts:

0/2000 characters
Dottie
18 days ago
Agreed, that's a classic method!
upvoted 0 times
...
Shawna
23 days ago
He's definitely using steganography.
upvoted 0 times
...
Ivette
1 month ago
I was confused about whether it could be social engineering, but that seems more about manipulating people rather than hiding data.
upvoted 0 times
...
Stefany
1 month ago
This reminds me of a practice question we did on data hiding techniques, and steganography was the answer there too.
upvoted 0 times
...
Jaclyn
2 months ago
I'm not entirely sure, but I remember something about email spoofing being related to disguising the sender's identity, which doesn't seem to fit here.
upvoted 0 times
...
Denny
2 months ago
I think this is definitely about steganography since he's hiding the secret file within an image.
upvoted 0 times
...

Save Cancel