
EC-CouncilNetwork Defense Essentials
Domain 7Objective 4
Monitoring and Analyzing Network Protocol Traffic NDE Practice Questions (Page 7)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
40questions here
8free pages
8concepts
Questions 31–35
- 31
What is the primary purpose of documenting network traffic monitoring findings?
Select an answer first - 32
An analyst is reviewing a packet capture and notices a TCP session with the following characteristics: the client sends a SYN, the server responds with SYN-ACK, the client sends ACK, then immediately sends a RST. This pattern repeats for multiple ports on the same server. Select all that apply: What could this pattern indicate?
Select an answer first - 33
An analyst is reviewing a packet capture and sees a TCP connection where the client sends a SYN packet, the server responds with SYN-ACK, but the client never sends the final ACK. Instead, the client sends another SYN packet. This pattern repeats several times. What is the most likely explanation?
Select an answer first - 34
In a TCP segment, which field identifies the application or service on the source device?
Select an answer first - 35
Which behavior in a network traffic capture would most likely indicate anomalous activity?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.