
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 3)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 11–15
- 11
While analyzing a packet capture, a defender sees a series of TCP packets with the FIN and PSH flags set, followed by a RST. This pattern is often associated with which type of activity?
Select an answer first - 12
Which of the following is a common method for establishing a network traffic baseline?
Select an answer first - 13
A company's security policy requires that network traffic logs be retained for at least one year to support incident investigations. The logs are currently stored on a local server with limited disk space. What is the best practice to meet this requirement?
Select an answer first - 14
What is the primary function of a network traffic monitoring tool like tcpdump?
Select an answer first - 15
Which statement best describes how network traffic monitoring contributes to network security?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.