Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Network Defender

Domain 5Objective 1

Network Traffic Monitoring and Analysis CND Practice Questions (Page 9)

Part of the Traffic and Log Monitoring and Analysis domain, which makes up ~10% of our current practice bank.

48questions here
10free pages
8concepts

Questions 41–45

  1. 41application · medium

    A network administrator notices that a server that normally sends 2 Mbps of traffic is now sending 50 Mbps to a single external IP address. The traffic started at 2:00 AM. What is the most likely explanation and the best next step?

    Select an answer first
  2. 42foundation · easy

    Which of the following traffic patterns is most likely to indicate a security incident?

    Select an answer first
  3. 43application · medium

    A network defender notices a workstation generating continuous outbound TLS connections to a single external IP at odd hours. The connections are small but frequent. To confirm whether this is malicious, the defender needs to see the actual payloads exchanged. Which approach should be used?

    Select an answer first
  4. 44application · medium

    A network defender needs to analyze a specific application's performance issue. The application uses a proprietary protocol on a non-standard port. Which combination of tools would be most effective for this analysis?

    Select an answer first
  5. 45foundation · easy

    What is the purpose of using a promiscuous mode when capturing network packets?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.