
EC-CouncilCertified Cybersecurity Technician
Domain 6Objective 2
Network Traffic Monitoring CCT Practice Questions (Page 6)
Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.
45questions here
9free pages
8concepts
Questions 26–30
- 26
A security analyst is using Wireshark to examine a pcap file. The analyst filters for HTTP traffic and sees a series of GET requests to a single external IP, each requesting a different path that contains a long string of hexadecimal characters. The requests are spaced exactly 2 seconds apart. What should the analyst suspect?
Select an answer first - 27
Which tool is a graphical packet analyzer that allows deep inspection of individual packets?
Select an answer first - 28
A security team needs to monitor all traffic entering and leaving a data center. The data center has multiple 10 Gbps uplinks to the internet. The team wants to capture full packets for forensic analysis, but the budget only allows for a monitoring appliance that can handle 5 Gbps of sustained capture. What is the best approach?
Select an answer first - 29
A network engineer is comparing NetFlow and sFlow to monitor a high-speed backbone. The engineer needs to detect DDoS attacks and also perform capacity planning. Which statement correctly describes the trade-off?
Select an answer first - 30
A network team needs to monitor traffic on a 10 Gbps backbone link between two core switches. They have a monitoring appliance that supports 10 Gbps capture. The team wants to minimize any impact on the production link. Which method should they choose?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.