
EC-CouncilCertified Cybersecurity Technician
Domain 6Objective 2
Network Traffic Monitoring CCT Practice Questions (Page 3)
Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.
45questions here
9free pages
8concepts
Questions 11–15
- 11
A network administrator is analyzing a pcap file and sees a packet with the following details: Source IP 192.168.1.10, Destination IP 8.8.8.8, Source port 12345, Destination port 53, Protocol UDP. The packet contains a DNS query for 'example.com'. What is the most likely purpose of this packet?
Select an answer first - 12
What is a network TAP used for?
Select an answer first - 13
Users in the marketing department report that they cannot access the internet, while users in other departments can. A packet capture on the marketing VLAN shows ARP requests for the default gateway going unanswered. What is the most likely cause?
Select an answer first - 14
A security analyst is reviewing NetFlow data and notices that a single internal host is communicating with an external IP address on TCP port 443, sending a consistent 5 Mbps of traffic every hour for the past week. The host is a file server that normally generates less than 1 Mbps of traffic. What should the analyst do first?
Select an answer first - 15
When troubleshooting a connectivity issue, what does a packet capture showing repeated TCP SYN retransmissions to a server indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.