
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 2)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 6–10
- 6
Which type of tool is specifically designed to collect, correlate, and analyze security logs from multiple sources in real time?
Select an answer first - 7
A defender sees a log entry showing a successful login to a server from an internal IP at 2:00 AM, followed by the execution of a command that downloads a file from an external site. The user associated with the account is on vacation. What is the most appropriate immediate action?
Select an answer first - 8
A compliance auditor requires a monthly report showing all administrative access to critical servers, including who, when, and from where. The logs are already centralized. What is the most efficient way to produce this report?
Select an answer first - 9
An analyst is reviewing a web server's access log and sees a pattern where a single IP requests the same URL with different query parameters, such as /search?q=test, /search?q=admin, /search?q=password. The requests occur within a few seconds. Which analysis technique would best identify this as a potential information disclosure attempt?
Select an answer first - 10
A security team must retain firewall logs for 12 months to meet a compliance requirement, but storage space is limited. The logs are currently stored in plain text on a local server. Which approach best balances compliance, storage, and security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.