
EC-CouncilCertified Network Defender
Domain 5Objective 1
Network Traffic Monitoring and Analysis CND Practice Questions (Page 8)
Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.
48questions here
10free pages
8concepts
Questions 36–40
- 36
A network team is establishing a baseline for a new cloud-based application that will be used by employees worldwide. The application's traffic varies significantly by time zone and day of week. What is the most appropriate baselining strategy?
Select an answer first - 37
What is the primary goal of anomaly detection in network traffic monitoring?
Select an answer first - 38
A network team is choosing between NetFlow and sFlow for monitoring a high-speed backbone. They need to detect volumetric anomalies and also want to see per-flow details like TCP flags. The backbone carries 10 Gbps of traffic. Which choice is more appropriate and why?
Select an answer first - 39
A security analyst is examining a packet capture and sees a series of TCP packets with the SYN flag set, followed by a RST from the same source IP to different destination ports on the same target. This pattern is characteristic of which activity?
Select an answer first - 40
A network administrator is using NetFlow data to investigate a possible data exfiltration. The administrator notices a flow with a large amount of data transferred from an internal server to an external IP during off-hours. Which characteristic of the flow would be most suspicious?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.