
EC-CouncilCertified Network Defender
Domain 5Objective 2
Network Logs Monitoring and Analysis CND Practice Questions (Page 9)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
47questions here
10free pages
8concepts
Questions 41–45
- 41
A defender wants to detect a slow and low brute-force attack that spreads attempts across many IP addresses over several days. Which SIEM feature would be most effective for this?
Select an answer first - 42
A security analyst wants to search through large volumes of log data using a query language to find specific events. Which type of tool would be most appropriate?
Select an answer first - 43
A defender is analyzing logs and finds that a user account was created on a server, then used to log in, and then the account was added to the local administrators group. The account name matches a pattern used by a known threat actor. What is the most likely conclusion?
Select an answer first - 44
Which element is most important to include in a log report intended for compliance auditors?
Select an answer first - 45
A network defender is investigating a possible malware infection on a workstation. Which log source would provide the most direct evidence of the initial execution of the malware?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.