Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
EC-Council logo

EC-CouncilNetwork Defense Essentials

Domain 7Objective 3

Network Sniffing Techniques and Traffic Analysis NDE Practice Questions (Page 8)

Part of the Network Traffic Monitoring domain, which makes up ~11% of our current practice bank.

41questions here
9free pages
8concepts

Questions 36–40

  1. 36application · medium

    A network engineer is analyzing a traffic capture and notices that a single host is communicating with multiple external IP addresses on port 443. The engineer wants to determine if this is normal web browsing or a potential data exfiltration. Which analysis step is most useful?

    Select an answer first
  2. 37expert · hard

    A security team suspects that an attacker is performing ARP spoofing on the network. They need to detect the attack without disrupting legitimate traffic. Which detection method is most reliable?

    Select an answer first
  3. 38foundation · easy

    When analyzing a captured packet, which fields are used to identify the endpoints of a TCP connection?

    Select an answer first
  4. 39foundation · easy

    Which countermeasure is effective in preventing ARP spoofing attacks on a switched network?

    Select an answer first
  5. 40expert · hard

    A network administrator is analyzing traffic flows and notices that a server is sending a large amount of data to a single external IP address on port 22. The server is not supposed to have any external SSH connections. What is the most likely security issue?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “NDE” is a trademark of its owner, used for identification only.