
EC-CouncilCertified Security Specialist
Domain 2Objective 5
Network Traffic Monitoring ECSS Practice Questions (Page 4)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
7concepts
Questions 16–20
- 16
A network administrator needs to capture traffic between two core switches for security analysis. The switches support port mirroring, but the administrator is concerned about the impact on the production traffic flowing through the switches. Which approach best addresses the concern while still providing the needed capture?
Select an answer first - 17
A security analyst is examining a packet capture and sees a series of TCP packets with the PSH and ACK flags set, carrying small payloads, sent at regular intervals to an external IP. The traffic is not typical for the internal host. The analyst suspects data exfiltration. Which additional analysis would best confirm the suspicion?
Select an answer first - 18
Which element is typically included in a network traffic monitoring report?
Select an answer first - 19
An analyst is monitoring network traffic and sees a sudden spike in outbound traffic from a single workstation to multiple external IPs on port 80. The workstation normally has low traffic. What should the analyst do?
Select an answer first - 20
What is a common optimization technique to reduce the load on a network monitoring system?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.