
EC-Council Certified Network Defender
The EC-Council Certified Network Defender (CND) certification validates the skills IT and systems administrators need to defend networks with a security-first mindset. This vendor-neutral, hands-on program covers network attacks, perimeter and endpoint security, data protection, and incident response across local, cloud, and OT environments. Earning CND demonstrates your ability to apply blue-team defense and countermeasure strategies that prevent, detect, and remediate threats.
980 practice questions · Updated 2026-07-30
7Domains
20Objectives
186Concepts
980Questions
CND Curriculum
Every domain, objective, and concept the CND exam measures.
- Network Attack Classification
- Reconnaissance Techniques
- Access Attacks
- Denial of Service (DoS) and Distributed DoS (DDoS)
- Malware and Network Propagation
- Social Engineering in Network Attacks
- Wireless Network Attacks
- Web Application Attacks
- Network Defense Strategies
- Intrusion Detection and Prevention
- Security Monitoring and Analysis
- Incident Response and Mitigation
- Administrative Network Security Overview
- Security Policies and Procedures
- Risk Management in Network Administration
- Access Control Administration
- Patch and Vulnerability Management
- Configuration and Change Management
- Security Awareness and Training
- Incident Response and Reporting
- Compliance and Auditing
- Business Continuity and Disaster Recovery
- Network Security Fundamentals
- Defense-in-Depth Strategy
- Technical Security Controls
- Network Security Policies and Procedures
- Security Architecture Design
- Network Monitoring and Analysis
- Incident Response and Recovery
- Perimeter Security Fundamentals
- Perimeter Security Technologies
- Firewall Configuration and Management
- Intrusion Detection and Prevention
- VPN and Remote Access Security
- Perimeter Network Design
- Perimeter Security Monitoring and Response
- Windows Security Architecture
- User Account Control (UAC)
- Windows Firewall with Advanced Security
- Windows Defender Antivirus and Exploit Guard
- BitLocker Drive Encryption
- AppLocker and Windows Defender Application Control
- Credential Guard and Device Guard
- Windows Update and Patch Management
- Security Policies and Group Policy
- Event Logging and Auditing
- Endpoint Detection and Response (EDR) Integration
- Hardening Windows Services and Registry
- Linux Endpoint Security Fundamentals
- Linux User and Group Management
- Linux File System Security
- Linux Authentication and PAM
- Linux Network Security
- Linux Logging and Auditing
- Linux Hardening Techniques
- Linux Malware Protection
- Linux Endpoint Monitoring and Response
- Mobile Device Security Fundamentals
- Mobile Device Management (MDM)
- Mobile Application Management (MAM)
- BYOD Security Policies
- Mobile Device Encryption
- Mobile Device Authentication
- Mobile Device Remote Wipe and Lock
- Mobile Threat Defense (MTD)
- Secure Mobile Application Development
- Mobile Device Network Security
- Mobile Device Compliance and Auditing
- IoT Device Architecture
- IoT Communication Protocols
- IoT Threat Landscape
- IoT Device Hardening
- IoT Network Segmentation
- IoT Monitoring and Logging
- IoT Firmware Security
- IoT Physical Security
- IoT Compliance and Standards
- Administrative Application Security Overview
- Security Policies and Procedures
- User Access Management
- Authentication and Authorization Controls
- Auditing and Logging
- Patch and Update Management
- Configuration Management
- Data Protection and Privacy
- Incident Response and Recovery
- Security Awareness and Training
- Data Security Fundamentals
- Data Classification
- Data States and Protection
- Data Encryption
- Data Masking and Tokenization
- Data Loss Prevention (DLP)
- Data Backup and Recovery
- Data Retention and Disposal
- Data Privacy and Compliance
- Data Security in Cloud and Virtual Environments
- Virtual Network Fundamentals
- Virtual Network Security Threats
- Virtual Network Segmentation
- Virtual Network Security Controls
- Virtual Network Monitoring and Management
- Cloud Security Fundamentals
- Cloud Deployment Models
- Cloud Security Threats and Risks
- Cloud Security Controls
- Cloud Compliance and Legal Issues
- Cloud Security Best Practices
- Wireless Network Fundamentals
- Wireless Threats and Attacks
- Wireless Security Controls
- Wireless Network Monitoring
- Wireless Network Hardening
- Network Traffic Monitoring Fundamentals
- Traffic Monitoring Tools and Techniques
- Packet Capture and Analysis
- Flow Data Analysis
- Network Traffic Baselining
- Anomaly Detection in Traffic
- Traffic Logging and Retention
- Correlating Traffic with Security Events
- Log Sources and Types
- Log Collection Methods
- Log Management and Storage
- Log Analysis Techniques
- Log Correlation and Aggregation
- Log Monitoring Tools
- Log Review and Reporting
- Incident Detection via Logs
- Incident Response Fundamentals
- Incident Response Phases
- Incident Response Team Roles
- Incident Classification and Triage
- Evidence Collection and Preservation
- Forensic Imaging and Duplication
- Forensic Analysis Techniques
- Log Analysis and Correlation
- Memory and Volatile Data Analysis
- Network Forensics
- Malware Analysis Basics
- Forensic Reporting and Documentation
- Legal and Ethical Considerations
- Incident Recovery and Remediation
- Lessons Learned and Post-Incident Review
- Business Continuity Planning (BCP) Fundamentals
- Disaster Recovery Planning (DRP) Fundamentals
- Business Impact Analysis (BIA)
- Risk Assessment for BCP/DRP
- Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
- BCP/DRP Strategy Development
- BCP/DRP Implementation
- BCP/DRP Testing and Maintenance
- Incident Response Integration with BCP/DRP
- Emergency Response and Crisis Management
- Backup and Recovery Procedures
- Alternate Site Strategies (Hot, Warm, Cold)
- Communication and Notification Plans
- BCP/DRP Documentation and Training
- Regulatory and Compliance Considerations
- Risk Management Fundamentals
- Risk Management Frameworks
- Risk Identification
- Risk Assessment
- Risk Analysis
- Risk Evaluation
- Risk Treatment
- Risk Monitoring and Review
- Risk Communication and Documentation
- Attack Surface Definition
- Attack Surface Components
- Digital Attack Surface
- Physical Attack Surface
- Social Attack Surface
- Attack Surface Analysis Process
- Attack Surface Reduction
- Attack Surface Monitoring
- Cyber Threat Intelligence Fundamentals
- Threat Intelligence Sources
- Threat Intelligence Lifecycle
- Threat Intelligence Data Collection
- Threat Intelligence Analysis
- Threat Intelligence Dissemination
- Threat Intelligence Integration
- Threat Prediction Techniques
- Indicators of Compromise (IoCs)
- Threat Intelligence Sharing
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CND, so none is invented.