
EC-CouncilNetwork Defense Essentials
Domain 7Objective 4
Monitoring and Analyzing Network Protocol Traffic NDE Practice Questions (Page 8)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
40questions here
8free pages
8concepts
Questions 36–40
- 36
While reviewing a Wireshark capture, an analyst sees a TCP session with the following packets: SYN, SYN-ACK, ACK, then a series of packets with the PSH and ACK flags, followed by a FIN, ACK, ACK. What does this sequence indicate?
Select an answer first - 37
While analyzing a packet capture, a security analyst notices a TCP session with a three-way handshake followed by a large data transfer, but the session ends with a RST packet instead of a FIN. The source IP is an internal workstation and the destination is an external server. What should the analyst conclude from this pattern?
Select an answer first - 38
Which element is typically included in a network traffic monitoring report?
Select an answer first - 39
A network administrator is analyzing a packet capture and sees a large amount of UDP traffic on port 53 between an internal host and an external DNS server. The internal host is sending many queries for the same domain name in a short period. What should the administrator suspect?
Select an answer first - 40
After completing a packet capture analysis, an analyst must write a report for management. The report should highlight a potential security incident. Which approach is most effective?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to NDE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.