
EC-CouncilCertified Network Defender
Domain 7Objective 2
Threat Assessment with Attack Surface Analysis CND Practice Questions (Page 6)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
52questions here
11free pages
8concepts
Questions 26–30
- 26
What is the purpose of continuous attack surface monitoring?
Select an answer first - 27
A network defender is responsible for continuously monitoring the attack surface of a cloud-hosted application. The application's public IP address, load balancer, and security groups are managed by the cloud provider. The defender wants to detect new exposure as soon as it appears, such as an accidentally opened security-group port or a new public endpoint.
Select an answer first - 28
Which of the following is a step in the attack surface analysis process?
Select an answer first - 29
A company's security team is conducting an attack surface analysis and wants to reduce the social attack surface. Employees frequently receive phishing emails, and a recent incident involved an employee sharing credentials over the phone with someone posing as IT support. The team has limited budget and must choose the most effective control to reduce this surface.
Select an answer first - 30
A cloud-native company runs hundreds of microservices in a Kubernetes cluster. Each microservice exposes an API endpoint, and the company uses a service mesh for internal communication. The security team wants to continuously monitor the attack surface for new API endpoints and misconfigurations. They have a DevOps culture and want to integrate monitoring into their CI/CD pipeline.
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.