試験312-50v13-JPN トピック1 問題466 スレッド
ECCouncil 312-50v13-JPNのリアル試験問題集
問題 #: 466
トピック #: 1
問題 #: 466
トピック #: 1
攻撃者がシーケンス番号と確認応答番号を操作して中間者攻撃を仕掛けようとする場合、次のうちどのプロトコルが使用されますか?
おすすめの解答:B 解答を投票する
The correct answer is B. TCP. Sequence and acknowledgment numbers are key features of the Transmission Control Protocol. In CEH networking and session hijacking concepts, TCP is a connection-oriented protocol that establishes communication using the three-way handshake: SYN, SYN/ACK, and ACK. TCP uses sequence numbers to track byte order and acknowledgment numbers to confirm receipt of data. CEH-aligned references explain that TCP session hijacking depends on tracking session traffic, predicting sequence numbers, desynchronizing the connection, and injecting packets that appear valid to the target system. TCP is therefore the protocol associated with attacks involving manipulation of sequence and acknowledgment values. ICMP is mainly used for control and diagnostic messaging, such as ping and error reporting. UDP is connectionless and does not maintain TCP-style sequence and acknowledgment numbers. IP provides addressing and routing, but it does not manage reliable sessions or acknowledgments. Because the question specifically mentions manipulating sequence and acknowledgment numbers during a MITM/session hijacking scenario, TCP is the best answer.
远藤** 2026-07-23 01:00:19
コメント
他人の解答コメントを賛成するのも、その解答に一票を入れることになります。したがって、すでに同じ意見の投票コメントが存在する場合、新規コメントをする代わりに賛成することもできます。
コメントを通報する
コメント中
今すぐ 新規登録 / ログイン (無料です)。