ECCouncil Exam Questions

What port number you should enable in Wireshark display filter to view NTP packets?

NTP allows you to set the clocks on your systems very accurately, to within 100ms and
sometimes-even 10ms. Knowing the exact time is extremely important for enterprise security.
Various security protocols depend on an accurate source of time information in order to prevent
“playback” attacks. These protocols tag their communications with the current time, to prevent
attackers from replaying the same communications, e.g., a login/password interaction or even an
entire communication, at a later date. One can circumvent this tagging, if the clock can be set back
to the time the communication was recorded. An attacker attempts to try corrupting the clocks on
devices on your network. You run Wireshark to detect the NTP traffic to see if there are any
irregularities on the network. What port number you should enable in Wireshark display filter to
view NTP packets?

A.
TCP Port 124

B.
UDP Port 125

C.
UDP Port 123

D.
TCP Port 126