
EC-CouncilCertified Network Defender
Domain 7Objective 2
Threat Assessment with Attack Surface Analysis CND Practice Questions (Page 7)
Part of the Risk and Threat Management domain, which makes up ~16% of our current practice bank.
52questions here
11free pages
8concepts
Questions 31–35
- 31
A security consultant is explaining the concept of attack surface to a client. The client asks for examples of each category. Which set of examples correctly maps to the three main categories?
Select an answer first - 32
A network administrator is reducing the attack surface of a Windows server that runs a legacy application. The application requires only TCP port 443 for HTTPS and uses a local database. Which set of actions best reduces the attack surface without breaking the application?
Select an answer first - 33
A security team is conducting an attack surface analysis for a company that recently migrated to a cloud environment. They discover that several cloud storage buckets are publicly accessible. The team must decide how to address this. Which action is most aligned with the attack surface analysis process?
Select an answer first - 34
A network defender is mapping the digital attack surface of a web application. Which element should be included in the mapping?
Select an answer first - 35
A hospital's network includes networked medical devices, such as infusion pumps and patient monitors, connected to the same VLAN as administrative workstations. The security team is performing an attack surface analysis. Which physical attack surface element should they address first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CND” is a trademark of its owner, used for identification only.