Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Cybersecurity Technician

Domain 6Objective 2

Network Traffic Monitoring CCT Practice Questions (Page 8)

Part of the Network Monitoring and Troubleshooting domain, which makes up ~14% of our current practice bank.

45questions here
9free pages
8concepts

Questions 36–40

  1. 36expert · hard

    A security analyst is reviewing flow data and sees a sudden increase in outbound DNS traffic from a single workstation. The flows show many queries to different domains, each with a short duration and small packet sizes. The workstation is a standard user machine. Which action is the most appropriate first step?

    Select an answer first
  2. 37expert · hard

    A network administrator is analyzing NetFlow data and sees a sudden spike in traffic from a single internal host to many external IP addresses on port 445 (SMB). The traffic is occurring at 3:00 AM, which is unusual for the organization. The host is a file server that normally has no outbound SMB traffic. What is the most likely explanation?

    Select an answer first
  3. 38application · medium

    A network administrator is monitoring a WAN link that connects two branch offices. The link is rated for 100 Mbps, but users report slow file transfers. The administrator checks the monitoring dashboard and sees an average throughput of 80 Mbps and a packet loss rate of 2%. What is the most likely cause of the slow transfers?

    Select an answer first
  4. 39application · medium

    A network administrator reviews NetFlow data and sees that a particular server has a high number of flows to many different external IP addresses on port 445. The server is a database server that should not be communicating with external hosts on SMB. What should the administrator do first?

    Select an answer first
  5. 40expert · hard

    A network administrator is troubleshooting intermittent connectivity issues between two offices connected by a VPN over the internet. The administrator captures traffic on both ends and notices that the VPN tunnel is established, but data transfer is slow. The capture shows many TCP retransmissions and duplicate ACKs. What is the most likely cause?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CCT” is a trademark of its owner, used for identification only.