
EC-CouncilCertified Security Specialist
Domain 2Objective 5
Network Traffic Monitoring ECSS Practice Questions (Page 5)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
7concepts
Questions 21–25
- 21
A security analyst is reviewing a packet capture and notices a large number of TCP SYN packets sent to a single host from many different source IP addresses, with no corresponding SYN-ACK replies. What should the analyst conclude?
Select an answer first - 22
Which command-line tool is specifically designed to capture packets and write them to a file for later analysis?
Select an answer first - 23
Which network traffic pattern would be considered an anomaly that may indicate a security threat?
Select an answer first - 24
A network monitoring system flags a sudden increase in DNS queries from a single internal host to many different external domains. The host is a file server that normally makes few DNS queries. The analyst needs to determine if this is a security threat. Which additional data would be most useful?
Select an answer first - 25
A network analyst is reviewing a packet capture and sees a TCP connection with the SYN flag set, followed by a RST flag from the destination. The source then sends another SYN to the same destination. This pattern repeats. What does this pattern most likely indicate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.