
EC-CouncilNetwork Defense Essentials
Domain 7Objective 4
Monitoring and Analyzing Network Protocol Traffic NDE Practice Questions (Page 4)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
40questions here
8free pages
8concepts
Questions 16–20
- 16
A network analyst has completed a packet capture and identified a series of anomalous TCP connections that may indicate a data exfiltration attempt. The analyst needs to document the findings for a security incident report. What is the most important information to include in the report?
Select an answer first - 17
What is the primary role of the Domain Name System (DNS) in network communication?
Select an answer first - 18
An analyst sees a TCP session where the client sends a SYN packet, the server responds with a SYN-ACK, but the client never sends the final ACK. The server retransmits the SYN-ACK several times. What is the most likely explanation?
Select an answer first - 19
An analyst needs to capture traffic on a busy interface but wants to exclude all traffic to and from a backup server (192.168.1.50) to reduce the capture size. Which tcpdump capture filter should be used?
Select an answer first - 20
A network administrator is responsible for a 1 Gbps link that is frequently congested. The administrator needs to identify the top bandwidth consumers and produce a monthly report. The administrator has limited budget and cannot deploy new hardware. Which approach is the most practical?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.