
EC-CouncilEthical Hacking Essentials
Domain 5Objective 4
Network Attack Detection and Countermeasures EHE Practice Questions (Page 4)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
4concepts
Questions 16–20
- 16
During incident response, which step involves isolating affected systems to prevent the attack from spreading further?
Select an answer first - 17
A network administrator notices unusual outbound traffic from a single workstation at 3:00 AM. The traffic consists of small packets sent to many different external IP addresses on port 53. What is the most appropriate immediate action?
Select an answer first - 18
After a ransomware attack, a company has restored its systems from backups. The incident response team is now conducting a post-incident review. What is the primary goal of this review?
Select an answer first - 19
A security analyst wants to correlate login failures from the firewall, malware alerts from endpoints, and outbound connection logs from the proxy to identify a coordinated attack. Which tool is designed for this type of correlation?
Select an answer first - 20
A network administrator notices unusual spikes in traffic to a single server from many different IP addresses. The administrator wants to determine if this is a distributed denial-of-service (DDoS) attack or a legitimate flash crowd. Which analysis technique would provide the most useful information?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.