Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-COUNCIL

EC-Council Certified Network Defender

CNDCertified Network Defender

The EC-Council Certified Network Defender (CND) certification validates the skills IT and systems administrators need to defend networks with a security-first mindset. This vendor-neutral, hands-on program covers network attacks, perimeter and endpoint security, data protection, and incident response across local, cloud, and OT environments. Earning CND demonstrates your ability to apply blue-team defense and countermeasure strategies that prevent, detect, and remediate threats.

980 practice questions · Updated 2026-07-30

7Domains
20Objectives
186Concepts
980Questions

CND Curriculum

Every domain, objective, and concept the CND exam measures.

Network Attacks and Defense Strategies

12 concepts · 53 questions
  1. Network Attack Classification
  2. Reconnaissance Techniques
  3. Access Attacks
  4. Denial of Service (DoS) and Distributed DoS (DDoS)
  5. Malware and Network Propagation
  6. Social Engineering in Network Attacks
  7. Wireless Network Attacks
  8. Web Application Attacks
  9. Network Defense Strategies
  10. Intrusion Detection and Prevention
  11. Security Monitoring and Analysis
  12. Incident Response and Mitigation

Administrative Network Security

10 concepts · 55 questions
  1. Administrative Network Security Overview
  2. Security Policies and Procedures
  3. Risk Management in Network Administration
  4. Access Control Administration
  5. Patch and Vulnerability Management
  6. Configuration and Change Management
  7. Security Awareness and Training
  8. Incident Response and Reporting
  9. Compliance and Auditing
  10. Business Continuity and Disaster Recovery

Technical Network Security

7 concepts · 45 questions
  1. Network Security Fundamentals
  2. Defense-in-Depth Strategy
  3. Technical Security Controls
  4. Network Security Policies and Procedures
  5. Security Architecture Design
  6. Network Monitoring and Analysis
  7. Incident Response and Recovery

Network Perimeter Security

7 concepts · 39 questions
  1. Perimeter Security Fundamentals
  2. Perimeter Security Technologies
  3. Firewall Configuration and Management
  4. Intrusion Detection and Prevention
  5. VPN and Remote Access Security
  6. Perimeter Network Design
  7. Perimeter Security Monitoring and Response

Endpoint Security Windows Systems

12 concepts · 45 questions
  1. Windows Security Architecture
  2. User Account Control (UAC)
  3. Windows Firewall with Advanced Security
  4. Windows Defender Antivirus and Exploit Guard
  5. BitLocker Drive Encryption
  6. AppLocker and Windows Defender Application Control
  7. Credential Guard and Device Guard
  8. Windows Update and Patch Management
  9. Security Policies and Group Policy
  10. Event Logging and Auditing
  11. Endpoint Detection and Response (EDR) Integration
  12. Hardening Windows Services and Registry

Endpoint Security Linux Systems

9 concepts · 47 questions
  1. Linux Endpoint Security Fundamentals
  2. Linux User and Group Management
  3. Linux File System Security
  4. Linux Authentication and PAM
  5. Linux Network Security
  6. Linux Logging and Auditing
  7. Linux Hardening Techniques
  8. Linux Malware Protection
  9. Linux Endpoint Monitoring and Response

Endpoint Security Mobile Devices

11 concepts · 52 questions
  1. Mobile Device Security Fundamentals
  2. Mobile Device Management (MDM)
  3. Mobile Application Management (MAM)
  4. BYOD Security Policies
  5. Mobile Device Encryption
  6. Mobile Device Authentication
  7. Mobile Device Remote Wipe and Lock
  8. Mobile Threat Defense (MTD)
  9. Secure Mobile Application Development
  10. Mobile Device Network Security
  11. Mobile Device Compliance and Auditing

Endpoint Security IoT Devices

9 concepts · 53 questions
  1. IoT Device Architecture
  2. IoT Communication Protocols
  3. IoT Threat Landscape
  4. IoT Device Hardening
  5. IoT Network Segmentation
  6. IoT Monitoring and Logging
  7. IoT Firmware Security
  8. IoT Physical Security
  9. IoT Compliance and Standards

Administrative Application Security

10 concepts · 41 questions
  1. Administrative Application Security Overview
  2. Security Policies and Procedures
  3. User Access Management
  4. Authentication and Authorization Controls
  5. Auditing and Logging
  6. Patch and Update Management
  7. Configuration Management
  8. Data Protection and Privacy
  9. Incident Response and Recovery
  10. Security Awareness and Training

Data Security

10 concepts · 53 questions
  1. Data Security Fundamentals
  2. Data Classification
  3. Data States and Protection
  4. Data Encryption
  5. Data Masking and Tokenization
  6. Data Loss Prevention (DLP)
  7. Data Backup and Recovery
  8. Data Retention and Disposal
  9. Data Privacy and Compliance
  10. Data Security in Cloud and Virtual Environments

Enterprise Virtual Network Security

5 concepts · 41 questions
  1. Virtual Network Fundamentals
  2. Virtual Network Security Threats
  3. Virtual Network Segmentation
  4. Virtual Network Security Controls
  5. Virtual Network Monitoring and Management

Enterprise Cloud Security

6 concepts · 43 questions
  1. Cloud Security Fundamentals
  2. Cloud Deployment Models
  3. Cloud Security Threats and Risks
  4. Cloud Security Controls
  5. Cloud Compliance and Legal Issues
  6. Cloud Security Best Practices

Enterprise Wireless Network Security

5 concepts · 39 questions
  1. Wireless Network Fundamentals
  2. Wireless Threats and Attacks
  3. Wireless Security Controls
  4. Wireless Network Monitoring
  5. Wireless Network Hardening

Network Traffic Monitoring and Analysis

8 concepts · 48 questions
  1. Network Traffic Monitoring Fundamentals
  2. Traffic Monitoring Tools and Techniques
  3. Packet Capture and Analysis
  4. Flow Data Analysis
  5. Network Traffic Baselining
  6. Anomaly Detection in Traffic
  7. Traffic Logging and Retention
  8. Correlating Traffic with Security Events

Network Logs Monitoring and Analysis

8 concepts · 47 questions
  1. Log Sources and Types
  2. Log Collection Methods
  3. Log Management and Storage
  4. Log Analysis Techniques
  5. Log Correlation and Aggregation
  6. Log Monitoring Tools
  7. Log Review and Reporting
  8. Incident Detection via Logs

  1. Incident Response Fundamentals
  2. Incident Response Phases
  3. Incident Response Team Roles
  4. Incident Classification and Triage
  5. Evidence Collection and Preservation
  6. Forensic Imaging and Duplication
  7. Forensic Analysis Techniques
  8. Log Analysis and Correlation
  9. Memory and Volatile Data Analysis
  10. Network Forensics
  11. Malware Analysis Basics
  12. Forensic Reporting and Documentation
  13. Legal and Ethical Considerations
  14. Incident Recovery and Remediation
  15. Lessons Learned and Post-Incident Review
  1. Business Continuity Planning (BCP) Fundamentals
  2. Disaster Recovery Planning (DRP) Fundamentals
  3. Business Impact Analysis (BIA)
  4. Risk Assessment for BCP/DRP
  5. Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
  6. BCP/DRP Strategy Development
  7. BCP/DRP Implementation
  8. BCP/DRP Testing and Maintenance
  9. Incident Response Integration with BCP/DRP
  10. Emergency Response and Crisis Management
  11. Backup and Recovery Procedures
  12. Alternate Site Strategies (Hot, Warm, Cold)
  13. Communication and Notification Plans
  14. BCP/DRP Documentation and Training
  15. Regulatory and Compliance Considerations

Risk Anticipation with Risk Management

9 concepts · 45 questions
  1. Risk Management Fundamentals
  2. Risk Management Frameworks
  3. Risk Identification
  4. Risk Assessment
  5. Risk Analysis
  6. Risk Evaluation
  7. Risk Treatment
  8. Risk Monitoring and Review
  9. Risk Communication and Documentation
  1. Attack Surface Definition
  2. Attack Surface Components
  3. Digital Attack Surface
  4. Physical Attack Surface
  5. Social Attack Surface
  6. Attack Surface Analysis Process
  7. Attack Surface Reduction
  8. Attack Surface Monitoring
  1. Cyber Threat Intelligence Fundamentals
  2. Threat Intelligence Sources
  3. Threat Intelligence Lifecycle
  4. Threat Intelligence Data Collection
  5. Threat Intelligence Analysis
  6. Threat Intelligence Dissemination
  7. Threat Intelligence Integration
  8. Threat Prediction Techniques
  9. Indicators of Compromise (IoCs)
  10. Threat Intelligence Sharing
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CND, so none is invented.