
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 5)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 21–25
- 21
During a packet capture analysis, an analyst sees a series of TCP SYN packets sent to a server, followed by SYN-ACK responses, but no final ACK from the client. This pattern repeats thousands of times from different source IP addresses. What does this indicate?
Select an answer first - 22
A security analyst needs to investigate a security incident that occurred two weeks ago. The company's logging policy only retains firewall logs for 7 days. What is the most appropriate action to improve the ability to investigate future incidents?
Select an answer first - 23
During routine traffic analysis, a defender notices a large number of TCP SYN packets sent to a single server from many different source IPs, but no completed handshakes. This pattern is consistent with which type of activity?
Select an answer first - 24
An analyst is investigating a slow network issue and has a packet capture from the core switch. The capture shows many TCP retransmissions and duplicate ACKs for connections to a database server. What is the most likely cause?
Select an answer first - 25
A security analyst is reviewing NetFlow data and notices that a single internal host is communicating with a large number of external IP addresses on port 445 (SMB) within a short time frame. The host is a user workstation, not a server. What is the most likely interpretation?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.