Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 5Objective 2

Network Logs Monitoring and Analysis CND Practice Questions (Page 9)

Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.

47questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A defender wants to detect a slow and low brute-force attack that spreads attempts across many IP addresses over several days. Which SIEM feature would be most effective for this?

    Select an answer first
  2. 42foundation · easy

    A security analyst wants to search through large volumes of log data using a query language to find specific events. Which type of tool would be most appropriate?

    Select an answer first
  3. 43expert · hard

    A defender is analyzing logs and finds that a user account was created on a server, then used to log in, and then the account was added to the local administrators group. The account name matches a pattern used by a known threat actor. What is the most likely conclusion?

    Select an answer first
  4. 44foundation · easy

    Which element is most important to include in a log report intended for compliance auditors?

    Select an answer first
  5. 45application · medium

    A network defender is investigating a possible malware infection on a workstation. Which log source would provide the most direct evidence of the initial execution of the malware?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.