
EC-CouncilEthical Hacking Essentials
Domain 5Objective 4
Network Attack Detection and Countermeasures EHE Practice Questions (Page 2)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
4concepts
Questions 6–10
- 6
During a security incident, a server is found to be communicating with a known command-and-control (C2) server. The incident response team has isolated the server from the network. What should be the next step in the incident response process?
Select an answer first - 7
An analyst is investigating a potential data breach. The network traffic logs show a large amount of encrypted traffic to an external IP. The analyst suspects data exfiltration but cannot decrypt the traffic. Which approach would provide the most useful evidence?
Select an answer first - 8
After a network intrusion, the incident response team has contained the affected systems and eradicated the malware. What is the next major phase in the incident response process?
Select an answer first - 9
A network administrator wants to limit traffic between two internal departments to only the specific ports required for their business applications. Which countermeasure is most appropriate for this task?
Select an answer first - 10
A network administrator wants to detect a port scan targeting multiple hosts on the internal network. Which detection technique is most appropriate?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.