
EC-CouncilEthical Hacking Essentials
Domain 5Objective 4
Network Attack Detection and Countermeasures EHE Practice Questions (Page 9)
Part of the Network-Level Attacks and Countermeasures domain, which makes up ~12% of our current practice bank.
44questions here
9free pages
4concepts
Questions 41–44
- 41
A security analyst at a mid-sized company notices that an internal web server has been sending a large volume of outbound traffic to an external IP address at 3:00 AM every day for the past week. The analyst suspects a data exfiltration attempt but is unsure if it is legitimate backup activity. Which combination of actions would best confirm the suspicion while minimizing disruption?
Select an answer first - 42
A network analyst is investigating a possible ARP spoofing attack. Which packet capture observation would most strongly indicate ARP spoofing?
Select an answer first - 43
Which countermeasure is most effective for protecting sensitive data transmitted over an untrusted network, such as the internet?
Select an answer first - 44
A security architect must choose between an IDS and an IPS for a network segment that handles time-sensitive financial transactions. The primary concern is that security controls must not introduce latency or drop legitimate traffic. Which choice best meets this requirement?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to EHE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “EHE” is a trademark of its owner, used for identification only.