Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 5Objective 1

Network Traffic Monitoring and Analysis CND Practice Questions (Page 4)

Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.

48questions here
10free pages
8concepts

Questions 16–20

  1. 16foundation · easy

    What is the purpose of establishing a network traffic baseline?

    Select an answer first
  2. 17application · medium

    A network defender notices a sudden spike in outbound traffic from a single workstation to a known file-sharing site. The workstation is used for accounting and has no business need for that site. Which tool and technique would provide the most immediate evidence to confirm whether the traffic is malicious or just a user violation?

    Select an answer first
  3. 18foundation · easy

    Which tool is specifically designed to capture and analyze individual network packets in real time?

    Select an answer first
  4. 19foundation · easy

    When analyzing a packet capture, what does a large number of TCP SYN packets sent to a single host from many different source IP addresses typically indicate?

    Select an answer first
  5. 20application · medium

    An intrusion detection system (IDS) alerts on a suspicious connection from an internal host to a known malicious IP. The analyst wants to confirm whether any data was exfiltrated. Which data source would provide the most definitive evidence?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.