
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 2)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 6–10
- 6
A security analyst is reviewing NetFlow data and sees a single internal host communicating with a known malicious IP over port 443 (HTTPS). The traffic is continuous and has been going on for several hours. The host is a web server that normally only receives inbound connections. What is the most likely interpretation?
Select an answer first - 7
What is the purpose of correlating network traffic data with security events?
Select an answer first - 8
A network team is implementing a monitoring solution and wants to detect anomalies such as a sudden spike in DNS queries. They have collected baseline data showing that DNS queries average 100 per minute with a standard deviation of 20. Which threshold would be most appropriate to trigger an alert for a potential anomaly?
Select an answer first - 9
A security team is correlating network traffic with security events. They have IDS alerts, firewall logs, and NetFlow data. They want to identify all hosts that communicated with a known malicious IP in the last 24 hours. Which data source is most efficient for this task?
Select an answer first - 10
What is the primary difference between flow-based monitoring (e.g., NetFlow) and packet capture?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.