
EC-CouncilCertified Security Specialist
Domain 2Objective 5
Network Traffic Monitoring ECSS Practice Questions (Page 2)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
7concepts
Questions 6–10
- 6
Which tool is commonly used to capture and interactively analyze network packets?
Select an answer first - 7
What is the purpose of configuring alerts in a network monitoring system?
Select an answer first - 8
A security analyst is monitoring network traffic and notices that a workstation is sending large amounts of data to an external IP address on port 443 during off-hours. The traffic volume is significantly higher than the workstation's normal behavior. The analyst needs to determine if this is a security threat. Which action should the analyst take first?
Select an answer first - 9
During protocol analysis, which layer of the OSI model would you examine to identify the source and destination IP addresses?
Select an answer first - 10
A network operations team wants to be notified immediately when a specific server's outbound traffic volume exceeds a threshold, but they do not want to be overwhelmed by alerts during normal fluctuations. What should they configure?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.