
EC-CouncilNetwork Defense Essentials
Domain 7Objective 4
Monitoring and Analyzing Network Protocol Traffic NDE Practice Questions (Page 3)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
40questions here
8free pages
8concepts
Questions 11–15
- 11
In a TCP connection, which sequence of flags is used during the three-way handshake to establish a connection?
Select an answer first - 12
Which command-line tool is commonly used to capture packets on a specified network interface in Linux?
Select an answer first - 13
An analyst needs to capture only HTTP traffic on a network interface, but the network uses a non-standard port for HTTP (port 8080). Which capture filter should be used in tcpdump?
Select an answer first - 14
A security analyst is investigating a potential data exfiltration. The capture shows a client sending large amounts of data to an external server on port 53 using UDP. The DNS queries are for random subdomains under a domain controlled by the attacker. What is the most likely technique being used?
Select an answer first - 15
Which Wireshark display filter expression would show only packets sent to or from IP address 192.168.1.10?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.