
EC-CouncilCertified Security Specialist
Domain 2Objective 5
Network Traffic Monitoring ECSS Practice Questions (Page 8)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
7concepts
Questions 36–40
- 36
An analyst is investigating a potential data exfiltration incident. The packet capture shows encrypted TLS traffic to an external IP, but the analyst cannot decrypt it. However, the analyst notices that the TLS handshake includes a Server Name Indication (SNI) field with a domain name that is not related to the company's business. What should the analyst do?
Select an answer first - 37
A SOC team is overwhelmed by alerts from the network monitoring system. Most alerts are false positives. The team wants to improve the signal-to-noise ratio without missing real threats. Which strategy would be most effective?
Select an answer first - 38
A security analyst is reviewing a packet capture and sees a series of ARP requests from one MAC address claiming to be the gateway IP. The requests are broadcast to all hosts. What should the analyst suspect?
Select an answer first - 39
What is the primary purpose of network traffic monitoring in a network defense strategy?
Select an answer first - 40
A security analyst is reviewing a packet capture and notices a large number of TCP SYN packets sent to a single internal server from many different source IP addresses, but no corresponding SYN-ACK replies. The analyst wants to confirm whether this is a SYN flood attack. Which additional observation would most strongly support that conclusion?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.