
EC-CouncilCertified Network Defender
Domain 1Objective 1
Network Attacks and Defense Strategies CND Practice Questions (Page 3)
Part of the Network Security Fundamentals and Defense Strategy domain, which makes up ~16% of our current practice bank.
53questions here
11free pages
12concepts
Questions 11–15
- 11
A network defender is reviewing firewall logs and notices a series of failed SSH login attempts from a single external IP address, followed by a successful login from the same IP. What should the defender do first?
Select an answer first - 12
A network defender notices an unusual pattern of outbound DNS queries from a single internal host to a domain that has never been resolved before. The queries occur at regular intervals and the domain name appears to be a random string. Which classification best describes this activity?
Select an answer first - 13
A network defender is reviewing logs and notices that a server has been sending outbound traffic to a known malicious IP address at regular intervals. The traffic is encrypted and appears to be command-and-control communication. What should the defender do first?
Select an answer first - 14
What is the primary goal of a cross-site scripting (XSS) attack?
Select an answer first - 15
A security analyst is investigating a potential man-in-the-middle (MITM) attack on the corporate network. The analyst notices that the ARP cache on several workstations contains entries mapping the gateway IP address to an unknown MAC address. The analyst also sees that the switch's MAC address table has multiple entries for the same port. What is the most likely attack, and what is the best immediate response?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.