
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 5)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 21–25
- 21
A company's compliance team requires that security logs be stored in a way that prevents tampering by attackers who might gain access to the network. The logs are currently stored on the same server that generates them. Which change best addresses this requirement?
Select an answer first - 22
A network administrator needs to collect logs from a legacy network device that does not support syslog or SNMP. The device has a serial console port. The administrator wants to centralize these logs in the SIEM. Which method is most practical?
Select an answer first - 23
Which network device typically generates logs that contain information about allowed and denied connections based on security policies?
Select an answer first - 24
A compliance officer requests a report showing that all security incidents were addressed within the required time frame. The SIEM has incident data with timestamps for detection and resolution. What is the best way to produce this report?
Select an answer first - 25
A security analyst sees a log entry showing a successful login from an IP address that is on a threat intelligence blocklist. What does this indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.