Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 5Objective 1

Network Traffic Monitoring and Analysis CND Practice Questions (Page 7)

Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.

48questions here
10free pages
8concepts

Questions 31–35

  1. 31foundation · easy

    Which flow-based monitoring protocol is commonly used to export traffic statistics from network devices to a collector?

    Select an answer first
  2. 32application · medium

    A network administrator wants to monitor traffic patterns across a large campus network without storing full packet captures due to storage constraints. The goal is to detect sudden increases in traffic to a specific server. Which technology is most appropriate?

    Select an answer first
  3. 33foundation · easy

    Which of the following is an example of correlating traffic data with a security event?

    Select an answer first
  4. 34application · medium

    A company's security team wants to detect anomalies in their network traffic. They have been collecting NetFlow data for three months. What is the most effective first step to establish a baseline for anomaly detection?

    Select an answer first
  5. 35expert · hard

    A network administrator is using NetFlow to monitor traffic and notices that a particular internal host is communicating with an external IP on port 53 (DNS) but the packet sizes are consistently large (e.g., 1400 bytes). This is unusual because DNS queries are typically small. What does this suggest?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.