Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilCertified Security Specialist

Domain 2Objective 5

Network Traffic Monitoring ECSS Practice Questions (Page 9)

Part of the Network Defense Systems and Monitoring domain, which makes up ~14% of our current practice bank.

43questions here
9free pages
7concepts

Questions 41–43

  1. 41expert · medium

    A network analyst is using Wireshark to analyze a capture and needs to filter for all HTTP requests from a specific internal IP address to any external IP. Which display filter should the analyst use?

    Select an answer first
  2. 42expert · medium

    A security analyst is investigating a potential data exfiltration. The monitoring system shows a workstation sending a large amount of data to an external IP on port 443 during off-hours. The traffic is encrypted, and the analyst cannot inspect the payload. The analyst needs to determine if this is malicious. Which approach would be most effective?

    Select an answer first
  3. 43application · medium

    An analyst is examining a packet capture and sees a series of DNS queries for random subdomains under a legitimate domain, each with a different IP address in the response. The queries occur every few seconds. What should the analyst suspect?

    Select an answer first
Finished these 3 questions?

Review the revealed explanations, or continue through the curriculum.

No more pagesBack to ECSS

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “ECSS” is a trademark of its owner, used for identification only.