
EC-CouncilNetwork Defense Essentials
Domain 7Objective 2
Baseline Traffic Analysis and Signature Identification NDE Practice Questions (Page 4)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
37questions here
8free pages
8concepts
Questions 16–20
- 16
A network administrator has a baseline that shows normal web traffic is 80% HTTPS and 20% HTTP. Recently, the administrator notices that HTTP traffic has increased to 60% of total web traffic. The administrator suspects a misconfigured application. What is the most appropriate first step?
Select an answer first - 17
A network analyst is comparing current traffic to the baseline and notices that the packet rate has doubled, but the bandwidth usage is unchanged. What is the most likely explanation?
Select an answer first - 18
A security team is deploying an intrusion detection system. They need to detect a known worm that has a fixed signature, but they also want to detect new, unknown worms that may exhibit similar behavior. The team has limited resources and must choose a detection approach. What is the best strategy?
Select an answer first - 19
How are signatures typically created from baseline data?
Select an answer first - 20
A network administrator is setting up a baseline for a new branch office. The office has just been established and will have 20 employees starting next week. There is no historical traffic data. What should the administrator do to establish a baseline?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.