
EC-CouncilCertified Network Defender
Domain 7Objective 2
Threat Assessment with Attack Surface Analysis CND Practice Questions (Page 2)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
52questions here
11free pages
8concepts
Questions 6–10
- 6
A company has a high rate of insider threats, including employees accidentally sharing sensitive files and one case of an employee deliberately exfiltrating data. The security team wants to reduce the social attack surface but must balance employee privacy and productivity. The team is considering several controls.
Select an answer first - 7
What is the first step in performing an attack surface analysis?
Select an answer first - 8
A company recently experienced a data breach where an employee was tricked into transferring funds to a fraudulent account. The attacker used publicly available information about the employee's role and recent projects. The security team is analyzing the attack surface and wants to reduce the likelihood of similar incidents.
Select an answer first - 9
A small business runs a file server that also has an internet-facing FTP service enabled for a legacy partner. The server is patched, but the FTP service is outdated and has known vulnerabilities. The business wants to reduce its attack surface without losing the partner's ability to transfer files.
Select an answer first - 10
A security team is performing an attack surface analysis for a financial institution. Which activities are part of the attack surface analysis process? (Select all that apply.)
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.