
EC-CouncilCertified Security Specialist
Domain 2Objective 5
Network Traffic Monitoring ECSS Practice Questions (Page 9)
Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.
43questions here
9free pages
7concepts
Questions 41–43
- 41
A network analyst is using Wireshark to analyze a capture and needs to filter for all HTTP requests from a specific internal IP address to any external IP. Which display filter should the analyst use?
Select an answer first - 42
A security analyst is investigating a potential data exfiltration. The monitoring system shows a workstation sending a large amount of data to an external IP on port 443 during off-hours. The traffic is encrypted, and the analyst cannot inspect the payload. The analyst needs to determine if this is malicious. Which approach would be most effective?
Select an answer first - 43
An analyst is examining a packet capture and sees a series of DNS queries for random subdomains under a legitimate domain, each with a different IP address in the response. The queries occur every few seconds. What should the analyst suspect?
Select an answer first
Finished these 3 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to ECSS
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.