
EC-CouncilCertified Network Defender
Domain 7Objective 2
Threat Assessment with Attack Surface Analysis CND Practice Questions (Page 5)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
52questions here
11free pages
8concepts
Questions 21–25
- 21
A security auditor is assessing the physical attack surface of a data center. The data center has a mantrap entrance, CCTV cameras, and a biometric access control system. However, the auditor notices that a contractor badge is left unattended at the front desk, and a delivery person is allowed to enter the server floor without an escort. Which physical attack surface element is most directly exploited in this scenario?
Select an answer first - 22
Which of the following is an example of a social attack surface element?
Select an answer first - 23
A company has a web application that frequently adds new features. The security team wants to continuously monitor the attack surface for new vulnerabilities and misconfigurations. Which approach best achieves this?
Select an answer first - 24
Which method is commonly used to continuously monitor the attack surface?
Select an answer first - 25
A network defender is tasked with performing an attack surface analysis for a company that uses a mix of on-premises servers and cloud-based SaaS applications. Which sequence of steps best follows the attack surface analysis process?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.