
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 3)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 11–15
- 11
A defender notices the following in logs: a user account was locked out three times in one hour, then successfully logged in from a new IP address, and shortly after, a scheduled task was created on the same machine. The user denies any unusual activity. What is the most likely interpretation?
Select an answer first - 12
A security analyst notices a log entry showing a user logging in at 3:00 AM from an IP address in a foreign country, while the user is known to be on vacation. Which log analysis technique would best help identify this as an anomaly?
Select an answer first - 13
An analyst is reviewing firewall logs and notices a series of outbound connections from an internal server to a known malicious IP address on port 53 (DNS) at regular 5-minute intervals. The server is not configured as a DNS server. Which analysis technique would best confirm whether this is a DNS tunnel?
Select an answer first - 14
What is the primary purpose of generating regular log reports for management?
Select an answer first - 15
A network engineer needs to collect logs from a router that supports standard logging. Which protocol is commonly used to transmit these logs to a central log server?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.