
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 10)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 46–48
- 46
A security team is designing a log retention strategy. They have limited storage and need to balance the need for forensic investigation with cost. Which approach is most effective?
Select an answer first - 47
A security analyst is correlating network traffic with a security event. The event log shows a successful login from an internal IP at 10:00 AM, but the user was physically in another building. To determine if this was a remote login or a compromised account, which additional data would be most useful?
Select an answer first - 48
A security analyst is setting up anomaly detection for a corporate network. To identify deviations from normal behavior, the analyst first needs to establish a baseline. Which action is most appropriate?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CND
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.