Question 1
A network security analyst has noticed a flood of Simple Mail Transfer Protocol (SMTP) traffic to internal clients. SMTP traffic should only be allowed to email servers. Which of the following commands would stop this attack? (Choose two.) 
  1. iptables -A INPUT -p tcp –dport 25 -d x.x.x.x -j ACCEPT
  2. iptables -A INPUT -p tcp –sport 25 -d x.x.x.x -j ACCEPT
  3. iptables -A INPUT -p tcp –dport 25 -j DROP
  4. iptables -A INPUT -p tcp –destination-port 21 -j DROP
  5. iptables -A FORWARD -p tcp –dport 6881:6889 -j DROP
Correct answer: AC
Question 2
A Linux system administrator found suspicious activity on host IP This host is also establishing a connection to IP Which of the following commands should the administrator use to capture only the traffic between the two hosts?
  1. # tcpdump -i eth0 host
  2. # tcpdump -i eth0 dst
  3. # tcpdump -i eth0 host
  4. # tcpdump -i eth0 src
Correct answer: B
Question 3
A system administrator identifies unusual network traffic from outside the local network. Which of the following is the BEST method for mitigating the threat?
  1. Malware scanning
  2. Port blocking
  3. Packet capturing
  4. Content filtering
Correct answer: C

