Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 5Objective 2

Network Logs Monitoring and Analysis CND Practice Questions (Page 4)

Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.

47questions here
10free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    What is the primary benefit of aggregating logs from multiple sources into a central repository?

    Select an answer first
  2. 17application · medium

    A small company cannot afford a full SIEM but needs to centralize logs from multiple servers and perform basic pattern searches for anomalies. Which tool combination would be most appropriate?

    Select an answer first
  3. 18foundation · easy

    What is the primary purpose of establishing a log retention policy?

    Select an answer first
  4. 19application · medium

    A company has a mix of Linux servers, Windows servers, and network devices. The security team wants to centralize log collection without installing agents on every system. Which collection method is most appropriate for this heterogeneous environment?

    Select an answer first
  5. 20expert · hard

    A company must retain security logs for at least one year to meet a regulatory requirement. The SIEM storage is limited, and the compliance team wants to reduce costs. The security team needs to be able to search logs from the past 90 days quickly for incident response. Which storage strategy best balances compliance, cost, and operational needs?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.