Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 7Objective 3

Network Sniffing Techniques and Traffic Analysis NDE Practice Questions (Page 4)

Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.

41questions here
9free pages
8concepts

Questions 16–20

  1. 16application · medium

    A network administrator wants to detect if any host on the network is running a packet sniffer in promiscuous mode. Which technique is most effective?

    Select an answer first
  2. 17foundation · easy

    Which TCP flag is set in the first packet of a connection establishment handshake?

    Select an answer first
  3. 18expert · hard

    A security engineer needs to capture traffic on a switched network for a forensic investigation. The switch supports port mirroring, but the engineer is concerned that the attacker might detect the mirroring. Which approach minimizes the risk of detection while still capturing the needed traffic?

    Select an answer first
  4. 19application · easy

    A network administrator notices that a single workstation is generating a large amount of UDP traffic to a remote server on port 53. What is the most likely explanation?

    Select an answer first
  5. 20application · medium

    While analyzing a pcap, an analyst sees a TCP packet with the SYN flag set and the ACK flag set. What does this indicate about the TCP handshake?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.