Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

GIAC Exam GCED Topic 7 Question 39 Discussion

Actual exam question for GIAC's GCED exam
Question #: 39
Topic #: 7
[All GCED Questions]

A compromised router is reconfigured by an attacker to redirect SMTP email traffic to the attacker's server before sending packets on to their intended destinations. Which IP header value would help expose anomalies in the path outbound SMTP/Port 25 traffic takes compared to outbound packets sent to other ports?

Show Suggested Answer Hide Answer
Suggested Answer: C

In a case study of a redirect tunnel set up on a router, some anomalies were noticed while watching network traffic with the TCPdump packet sniffer.

Packets going to port 25 (Simple Mail Transfer Protocol [SMTP] used by mail servers and other Mail Transfer Agents [MTAs] to send and receive e-mail) were apparently taking a different network path. The TLs were consistently three less than other destination ports, indicating another three network hops were taken.

Other IP header values listed, such as fragment offset. The acknowledgement number is a TCP, not IP, header field.


Contribute your Thoughts:

Louann
6 months ago
I agree with TTL would change if packets take a different path.
upvoted 0 times
...
Maricela
6 months ago
Not sure. Could it be B) Acknowledgement number? But TTL seems more logical.
upvoted 0 times
...
Willard
7 months ago
TTL makes sense. Higher or lower TTL could indicate extra hops through the attacker's server.
upvoted 0 times
...
Cherelle
7 months ago
I'd say C) Time to live. Anomalous paths would likely have different TTL values.
upvoted 0 times
...
Louann
7 months ago
Exactly. It's asking which IP header value will show anomalies for outbound SMTP traffic.
upvoted 0 times
...
Willard
7 months ago
This question seems tricky; it's about a compromised router and SMTP redirection.
upvoted 0 times
...

Save Cancel