
EC-CouncilNetwork Defense Essentials
Domain 7Objective 3
Network Sniffing Techniques and Traffic Analysis NDE Practice Questions (Page 1)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
41questions here
9free pages
8concepts
Questions 1–5
- 1
An analyst is examining a packet capture and sees a TCP connection with the SYN flag set, followed by a RST flag from the destination, and then a SYN retransmission. What is the most likely cause?
Select an answer first - 2
What is the primary difference between passive and active sniffing?
Select an answer first - 3
An analyst is examining a packet capture and sees a large number of UDP packets from a single source IP to a single destination IP on port 53. What is the most likely protocol and purpose of this traffic?
Select an answer first - 4
In which of the following network environments would passive sniffing be most effective without additional techniques?
Select an answer first - 5
A network engineer is asked to capture traffic on a network segment to verify that a new application is working correctly. The engineer has permission from the application owner. What is the most important ethical consideration?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.