
EC-CouncilNetwork Defense Essentials
Domain 7Objective 3
Network Sniffing Techniques and Traffic Analysis NDE Practice Questions (Page 2)
Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.
41questions here
9free pages
8concepts
Questions 6–10
- 6
A network analyst is reviewing a capture and notices a large amount of ICMP echo requests and replies between two hosts. The analyst suspects a possible covert channel. Which additional analysis would best confirm this suspicion?
Select an answer first - 7
While analyzing a packet capture, an analyst sees a TCP packet with the SYN flag set and the ACK flag set, coming from a server to a client. What does this indicate about the communication?
Select an answer first - 8
What is the purpose of port mirroring on a managed switch?
Select an answer first - 9
A network engineer needs to capture traffic between two servers on a switched network for troubleshooting. The engineer has administrative access to the switch. Which technique should be used to ensure the capture is passive and does not alter the traffic flow?
Select an answer first - 10
Which of the following is a common indicator that ARP spoofing may be occurring on a network?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.