Please answer all parts (2-3 lines answer only) for Upvote. 1. a) What is Grey L
ID: 3903427 • Letter: P
Question
Please answer all parts (2-3 lines answer only) for Upvote.
1. a) What is Grey Listing?
b) Why is important to periodically monitor and provide a baseline of the top 5000 domain names being accessed by your organization?
c) Assume that alter the grep command to search the var/log/messages file for the IP address of 5.79.11.202. For example;
What type of network forensic evidence can we discover about IP address 5.79.11.202 from the preceding grep example?
d)
Linux will store DNS network forensic evidence in /var/log/messages file. Since Linux stores a lot of evidence, the grep commands is used to filter the message log and will search for www.reddit.com
The following is a sample of one DNS forward lookup.
Describe and explain the network forensic evidence for each field of this entry using the following table
# grep 5 . 79. 11. 202 /var/log/messages 1457131141.17235911192.168.75.4511192.168.75.111INI Idcs.cb.philips.com. I JA115.79.11.2021119101 11Explanation / Answer
1. a) What is Grey Listing?
Answer:
A graylist (also spelled greylist) is a list of e-mail addresses or domain names a spam filtercan use to identify suspected spam. If a message arrives from an address or domain on the list, it will be quarantined and then delivered to the subscriber only if the sender attempts to send the message again within a certain period of time. Once a sender has been recognized as legitimate, its address is removed from the list and future messages from that address can pass through the filter unhindered
The chief advantage of graylisting is the fact that it eliminates most spam while giving desired e-mail traffic a chance to get through. It requires no special configuration efforts on the part of the end user and places no additional burden on the resources of the end user's computer. However, unless a sender transmits its first message to a graylist user twice from the same e-mail address within the prescribed time, the filter will reject the message. Graylisting can also cause annoying delays in the receipt of initial messages.
The term graylist arises from the fact that its mode of operation is between that of a blacklistand a whitelist. A blacklist is a list of e-mail addresses or domain names known to be sources of spam. After filtering, traffic from an address or domain on the list disappears forever. A whitelist works in the opposite way; it is a list of e-mail addresses or domain names from which an e-mail filter allows messages to be received
Related Questions
drjack9650@gmail.com
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.