
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 4)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 16–20
- 16
What is the purpose of establishing a network traffic baseline?
Select an answer first - 17
A network defender notices a sudden spike in outbound traffic from a single workstation to a known file-sharing site. The workstation is used for accounting and has no business need for that site. Which tool and technique would provide the most immediate evidence to confirm whether the traffic is malicious or just a user violation?
Select an answer first - 18
Which tool is specifically designed to capture and analyze individual network packets in real time?
Select an answer first - 19
When analyzing a packet capture, what does a large number of TCP SYN packets sent to a single host from many different source IP addresses typically indicate?
Select an answer first - 20
An intrusion detection system (IDS) alerts on a suspicious connection from an internal host to a known malicious IP. The analyst wants to confirm whether any data was exfiltrated. Which data source would provide the most definitive evidence?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.