
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 8)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 36–40
- 36
A security operations center (SOC) uses a SIEM with a limited number of alert rules. The team is overwhelmed by false positives from a rule that triggers on any failed login. They need to reduce false positives while still detecting real brute-force attacks. Which approach is most effective?
Select an answer first - 37
An organization wants to collect logs from a Windows server that does not natively support sending logs via syslog. Which method would allow the server to send its logs to a central SIEM?
Select an answer first - 38
An organization's SIEM shows the following correlated events: a firewall log shows a connection from an internal IP to an external IP on port 445; a Windows security log shows a successful logon with a new account named 'support' on a domain controller; and a file integrity monitoring (FIM) log shows that the file C:\Windows\System32\drivers\etc\hosts was modified. Which conclusion is best supported?
Select an answer first - 39
A security manager needs to provide a monthly report to the board about the effectiveness of the company's security monitoring. The report should show trends in security incidents and demonstrate compliance with the company's log retention policy. Which report content is most appropriate?
Select an answer first - 40
Which log entry is most likely to indicate a brute-force attack?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.