
EC-CouncilNetwork Defense Essentials
Domain 7Objective 4
Monitoring and Analyzing Network Protocol Traffic NDE Practice Questions (Page 2)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
40questions here
8free pages
8concepts
Questions 6–10
- 6
A network analyst is using Wireshark to investigate a possible DNS exfiltration. The analyst wants to see only DNS queries that contain the string 'exfil' in the query name, and also wants to see the source IP address of each query. Which display filter should be applied?
Select an answer first - 7
In an IPv4 packet header, which field indicates the total length of the IP packet including the header and payload?
Select an answer first - 8
A network engineer is measuring the throughput of a link using a packet capture. The capture shows that the link is 90% utilized, but the application is experiencing poor performance. What additional analysis should the engineer perform to identify the bottleneck?
Select an answer first - 9
A security analyst is reviewing a packet capture and notices a large number of TCP SYN packets sent to a single host from many different source IP addresses, but no SYN-ACK responses are observed. What does this pattern most likely indicate?
Select an answer first - 10
Which protocol behavior would be considered a deviation from the standard and might indicate malicious activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.