ECCouncil Certified Network Defender (CND) 312-38 Question # 40 Topic 5 Discussion

ECCouncil Certified Network Defender (CND) 312-38 Question # 40 Topic 5 Discussion

312-38 Exam Topic 5 Question 40 Discussion:
Question #: 40
Topic #: 5

Which of the following Wireshark filters can a network administrator use to view the packets without any flags set in order to detect TCP Null Scan attempts?


A.

TCP.flags==0x000


B.

tcp.flags==0X029


C.

tcp.flags==0x003


D.

tcp.dstport==7


Get Premium 312-38 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.