Practice CND Endpoint Protection questions with full explanations on every answer.
Start practicing
Endpoint Protection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An Incident Responder analyzing a compromised Linux server suspects a rootkit has modified system binaries. The responder runs the package manager verification command on Debian/Ubuntu to check installed packages against the package database. Which command is appropriate?
2An organization's Endpoint Detection and Response (EDR) platform flags a suspicious PowerShell command line executing an encoded script block. Which Windows logging subsystem should the security analyst inspect for the decoded script contents?
3A security engineer is configuring mobile device management (MDM) for corporate-owned iOS devices. To prevent users from installing unauthorized apps while still allowing access to enterprise applications, which feature should be deployed?
4A security analyst is preparing to harden a fleet of corporate Windows 10 endpoints against pass-the-hash attacks. Which built-in Windows feature should be enabled and configured to isolate LSASS memory using virtualization?
5An enterprise environment uses Microsoft Endpoint Configuration Manager (MECM) for patch management. An administrator needs to ensure that critical patches are installed on workstations with minimal user disruption outside of active hours. Which MECM feature should be configured?
6An administrator needs to enforce mandatory password complexity, minimum length, and account lockout policies for local user accounts on standalone Windows Server endpoints that are not joined to an Active Directory domain. Which tool should be used?
7An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Which command should the administrator run to temporarily switch the profile for this specific daemon to complain mode without affecting the rest of the system?
8A security administrator needs to configure Windows Defender Firewall with Advanced Security via Group Policy Object (GPO) to block all outbound connections except those explicitly permitted by a rule. Where should the administrator configure this setting?
9An IoT device deployed in an industrial environment runs a minimal Linux kernel and needs its attack surface reduced by disabling unnecessary kernel modules like USB storage and Bluetooth. Where should the administrator configure module blacklisting?
10A security architect is configuring Linux Unified Key Setup (LUKS) disk encryption on enterprise laptops. To ensure that the encryption key can be decrypted automatically during boot via a Trusted Platform Module (TPM) 2.0 chip without manual passphrase entry, which tool should be integrated?
11A security administrator is evaluating Mobile Threat Defense (MTD) solutions for corporate Android devices. The administrator needs a solution that can detect rogue Wi-Fi access points and Man-in-the-Middle (MitM) attacks at the network layer. Which capability must the MTD solution provide?
12An enterprise endpoint security policy requires that all USB mass storage devices be blocked on workstations, while allowing encrypted company-issued smart cards and input devices. Which configuration approach should an administrator take using Group Policy?
13A system administrator is hardening a fleet of Linux servers by setting strict umask values for all users to ensure newly created files are not readable by others. Where should this default system-wide umask be configured?
14An organization's security team is deploying an EDR agent across corporate endpoints. During testing, the agent's kernel-mode driver causes a Blue Screen of Death (BSOD) during boot on systems running a third-party disk encryption filter driver. Which administrative action should be taken first to isolate and remediate the driver conflict?
15An Incident Response team is investigating a Linux server where a persistent backdoor is suspected of hiding process IDs (PIDs) using user-space hooks. Which utility should the responder use to compare process lists returned by the kernel system call table against direct kernel memory inspection?
16A security analyst is reviewing vulnerability assessment reports for a fleet of Windows endpoints and notes that third-party software (such as browsers and PDF readers) accounts for most missing patches. Which deployment strategy should the organization implement to streamline third-party patch management?
17An administrator wants to ensure that critical system files on Windows endpoints are automatically monitored for unauthorized modifications and that any changes trigger an alert. Which built-in Windows tool or feature should be utilized?
18A security engineer is configuring Linux Auditd on enterprise servers to log all attempts to modify user and group databases. Which audit rule should be added to /etc/audit/audit.rules?
19An organization is hardening Android enterprise devices and wants to prevent users from installing applications from unknown sources while ensuring corporate apps update automatically. Which policy configuration in the EMM/MDM console achieves this?
20A security analyst is investigating an EDR alert where a process spawned a suspicious child process. The analyst needs to review the process lineage tree. Which EDR capability is most useful for this task?
21An organization's security policy states that all Windows 10/11 endpoints must enforce AppLocker rules to block unauthorized executables. An administrator creates an Executable Rule allowing signed applications from a trusted software publisher, but users are still able to run unsigned tools from user-writable directories like C:\Users\Public. What is the most likely reason?
22An administrator needs to harden an IoT gateway running Linux by disabling core dumps globally to prevent sensitive application memory from being written to disk if a process crashes. Which configuration should be applied?
23A security administrator is preparing a security baseline for iOS and iPadOS devices using an MDM solution. To protect corporate data at rest on managed mobile devices, which setting must be verified?
24An organization is experiencing a ransomware outbreak on an endpoint. The Incident Response team decides to immediately disconnect the infected machine from the network without shutting it down, in order to preserve volatile memory. Which EDR feature should the responder trigger?
25An administrator is hardening a Linux system against privilege escalation via SUID binaries. The administrator wants to find all files on the root partition that have the SUID bit set. Which find command should be executed?
26A security analyst configuring Endpoint Detection and Response (EDR) behavioral rules needs to monitor for living-off-the-land binaries (LotLB) executing reconnaissance commands. Which legitimate Windows utility is frequently abused by attackers for network discovery and should be monitored?
27An organization is implementing comprehensive endpoint hardening for Windows 10/11 endpoints. Which THREE of the following measures directly contribute to reducing the attack surface against memory-based exploits and credential theft? (Choose THREE)
28A security administrator is hardening Linux servers against local privilege escalation and unauthorized access. Which TWO of the following configurations should be implemented? (Choose TWO)
29An enterprise Incident Response team is investigating a compromised endpoint using EDR telemetry and live response tools. Which THREE of the following actions can typically be performed directly from an enterprise EDR console during active triage? (Choose THREE)
30A security engineer is hardening an industrial IoT gateway running Linux. Which THREE of the following steps are recognized hardening practices for securing embedded Linux IoT endpoints? (Choose THREE)
31An administrator is managing mobile devices via an Enterprise Mobility Management (EMM) platform. Which TWO of the following features are characteristic of a Containerized Work Profile (such as Android Enterprise)? (Choose TWO)
32An administrator is deploying Windows Server Update Services (WSUS) for internal patch management. Which TWO of the following tasks are essential for maintaining a healthy WSUS environment? (Choose TWO)
33A security analyst is reviewing endpoint telemetry for signs of lateral movement and credential dumping. Which THREE of the following event log indicators or telemetry artifacts suggest potential credential dumping activity targeting LSASS? (Choose THREE)
34An organization is enforcing device hardening standards across all corporate laptops. Which TWO of the following controls should be implemented to secure client endpoints against physical and BIOS/UEFI tampering? (Choose TWO)
35An administrator is configuring Mobile Device Management (MDM) for corporate tablets. Which TWO of the following security policies are standard capabilities enforceable via MDM? (Choose TWO)
36A security architect is designing a Linux endpoint hardening baseline. Which THREE of the following configurations help enforce Mandatory Access Control (MAC) and restrict process privileges? (Choose THREE)
37An Incident Response team analyzing an enterprise endpoint discovers evidence of a fileless malware attack leveraging Windows Management Instrumentation (WMI). Which THREE of the following WMI artifacts or logging mechanisms should the investigator examine? (Choose THREE)
The Endpoint Protection domain covers the key concepts tested in this area of the CND exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CND domains — no account required.
The Courseiva CND question bank contains 37 questions in the Endpoint Protection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Endpoint Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included