Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 2Objective 1

Network Perimeter Security CND Practice Questions (Page 8)

Part of the Perimeter and Endpoint Security domain, which makes up ~24% of our current practice bank.

39questions here
8free pages
7concepts

Questions 36–39

  1. 36expert · hard

    A security analyst is investigating a potential breach. The firewall logs show a large amount of outbound data transferred from an internal server to an external IP over the past week. The IDS has not alerted. The analyst needs to determine if this is a data exfiltration. Which action is most appropriate?

    Select an answer first
  2. 37expert · hard

    An IPS is deployed inline at the perimeter. The security team is experiencing a high rate of false positives that are blocking legitimate business traffic. They need to reduce false positives without significantly increasing the risk of missing real attacks. Which approach is most effective?

    Select an answer first
  3. 38application · medium

    A network defender is tuning an IPS that is deployed inline at the perimeter. The IPS is blocking legitimate traffic because a signature is too broad. The defender wants to maintain protection against the underlying attack while reducing false positives. What should they do?

    Select an answer first
  4. 39expert · hard

    A company has a remote-access VPN that uses IPsec. The security team wants to enforce a policy that only allows VPN connections from company-issued laptops. The VPN concentrator supports certificate-based authentication. Which configuration best enforces the policy?

    Select an answer first
Finished these 4 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to CND

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.