Practice CND Enterprise Cloud Virtual And Wireless Network Protection questions with full explanations on every answer.
Start practicing
Enterprise Cloud Virtual And Wireless Network Protection — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
An enterprise cloud architect is designing multi-region disaster recovery for Azure Virtual Machines. The requirement is to replicate virtual machine disks asynchronously across regions without keeping secondary VMs running constantly. Which Azure service feature should be utilized?
2A network administrator suspects that an unauthorized rogue access point is operating within the enterprise office environment, spoofing the corporate SSID to capture user credentials. Which tool or technique should be used to detect and locate the physical source of the rogue AP?
3A security administrator is deploying a Microsoft Azure Virtual Network and needs to ensure that all outbound traffic from a specific subnet to the public internet is filtered using fully qualified domain name (FQDN) rules rather than IP addresses. Which Azure resource should be deployed to achieve this?
4An organization is utilizing Google Cloud Platform (GCP) and needs to restrict network traffic between specific Google Kubernetes Engine (GKE) pods based on labels rather than IP addresses. Which GCP security feature should be configured?
5A cloud security engineer is hardening an Amazon EC2 instance running in a private subnet. The instance needs to securely communicate with an Amazon S3 bucket without traffic traversing the public internet. Which VPC configuration must be implemented to meet this requirement?
6An enterprise is hardening its enterprise wireless network and migrating legacy authentication protocols. To protect against offline dictionary attacks and provide forward secrecy during the 4-way handshake, which Wi-Fi standard must be deployed?
7A security analyst is auditing an AWS environment and needs to identify which IAM users or roles have assumed administrative privileges across AWS accounts using AWS CloudTrail. Which event source and name should the analyst search for?
8An enterprise administrator needs to configure AWS Security Hub to automatically ingest and centralize security findings across all organizational accounts in AWS. Which service must be enabled first to create the organizational management structure before enabling Security Hub?
9An enterprise cloud security architect is hardening an Azure Kubernetes Service (AKS) cluster. The requirement is to ensure that node-to-node communication within the cluster is encrypted in transit. Which feature must be enabled during cluster creation or configuration?
10An administrator needs to secure management access to Azure virtual machines by eliminating open management ports (such as RDP port 3389 and SSH port 22) on the public internet. Which Azure feature should be configured?
11A network engineer is configuring an enterprise wireless network and wants to prevent clients from connecting to unauthorized rogue access points that broadcast the corporate SSID. Which client-side and infrastructure technology should be deployed?
12A cloud security team is reviewing GCP VPC configurations. To ensure that virtual machine instances without external IP addresses can still reach Google APIs and services (such as Cloud Storage and BigQuery) securely, which feature must be configured?
13An organization is implementing enterprise wireless security using WPA3-Enterprise. To ensure maximum cryptographic strength and protection against downgrade attacks, which security mode and key derivation function must be enforced?
14An enterprise security administrator needs to isolate a compromised AWS EC2 instance for forensic investigation without terminating the instance or losing its volatile memory state. Which action should the administrator take?
15An enterprise is deploying a zero-trust architecture for its AWS cloud workloads. Services must communicate across VPCs without exposing traffic to the public internet or traversing VPC peerings that open full subnet access. Which feature should be implemented?
16An administrator managing an enterprise AWS environment wants to ensure that all newly created S3 buckets across all accounts automatically block public access. Which feature should be configured at the AWS account level?
17An enterprise administrator is setting up an AWS Site-to-Site VPN connection between an on-premises data center and an AWS VPC. To ensure maximum data confidentiality and integrity across the public internet, which IPsec cryptographic parameters should be enforced in the VPN tunnel configuration?
18A network security engineer is tasked with securing corporate Wi-Fi clients against Evil Twin attacks where an attacker sets up a fake access point with identical SSID parameters. Which enterprise wireless security practice effectively mitigates client association to fake APs?
19An enterprise IT security team wants to monitor AWS API calls and receive alerts whenever an unauthorized user attempts to modify critical IAM policies or security group rules. Which combination of AWS services should be configured?
20An enterprise cloud architect is configuring Google Cloud VPC Network Service Tiers to optimize cost and security for sensitive internal database traffic. Which service tier should be selected to ensure traffic stays entirely within Google's private global backbone network without touching the public internet?
21An auditor is reviewing an enterprise Azure environment and wants to ensure that all Azure Storage accounts enforce encryption of data at rest using customer-managed keys (CMK) stored in a secure hardware security module. Which Azure service should be integrated with Storage Accounts?
22A security engineer is hardening a GCP environment and needs to ensure that compute instances cannot be accessed directly via SSH from the public internet, even if they have external IP addresses. Which mechanism should be implemented?
23A security administrator is configuring Azure Network Security Groups (NSGs) to protect a multi-tier application. Which rule evaluation principle does Azure apply when processing network traffic through an NSG?
24An organization is implementing virtual network segmentation in an enterprise Azure environment. The requirement is to inspect all inter-subnet traffic between different virtual networks (East-West traffic) using centralized next-generation firewalls. Which Azure networking architecture should be deployed?
25An enterprise security engineer needs to analyze VPC traffic flows in AWS to identify anomalous outbound communication from internal EC2 instances to unknown external IP addresses. Which AWS feature should be enabled and analyzed?
26A cloud security specialist is hardening a Google Cloud Storage bucket. The enterprise requirement mandates that once an object is written, it cannot be modified or deleted by any user, including root administrators, for a compliance retention period of 5 years. Which GCP storage feature must be configured?
27An enterprise is implementing Zero Trust Network Access (ZTNA) for remote workers accessing cloud-hosted virtual desktops in Azure. To ensure that user identity, device compliance, and location risk are evaluated before establishing a network session, which Azure service integration should be deployed?
28An enterprise cloud security architect is hardening an AWS environment to protect against unauthorized data exfiltration from S3 buckets. Which TWO preventative security measures should be implemented? (Choose TWO)
29A network security engineer is designing a secure enterprise wireless network architecture to mitigate modern wireless attacks. Which THREE security configurations and protocols should be mandated? (Choose THREE)
30A GCP cloud security team is auditing a Kubernetes cluster running in Google Kubernetes Engine (GKE). Which THREE security hardening steps should be verified to ensure robust cluster security? (Choose THREE)
31An enterprise security engineer is investigating potential AWS IAM privilege escalation paths and misconfigurations. Which TWO AWS IAM actions or conditions represent known high-risk misconfigurations that can lead to privilege escalation? (Choose TWO)
32An Azure cloud administrator needs to secure communication channels between on-premises datacenters and Azure Virtual Networks. Which TWO connectivity methods provide encrypted, secure transit over public or private connections? (Choose TWO)
33A cloud architect is designing network security controls for multi-tier applications hosted in AWS. Which THREE AWS services and features are used to enforce network isolation and traffic filtering? (Choose THREE)
34An enterprise is securing its enterprise wireless infrastructure against unauthorized devices and wireless sniffing. Which THREE administrative and technical controls should be implemented? (Choose THREE)
35An enterprise administrator is configuring Azure Storage security. Which TWO features should be enabled to ensure comprehensive protection against data exfiltration and unauthorized access? (Choose TWO)
36A GCP cloud administrator is setting up Cloud VPN to connect an on-premises datacenter to a GCP VPC. Which TWO components must be configured to establish a functional High Availability (HA) VPN gateway? (Choose TWO)
37An enterprise security team is hardening an Azure environment. Which THREE actions should be implemented to secure Azure Virtual Machines and management planes? (Choose THREE)
38A cloud security auditor is reviewing a Google Cloud Platform (GCP) project for identity and access management hygiene. Which TWO security practices should be enforced to prevent unauthorized privilege escalation and credential theft? (Choose TWO)
The Enterprise Cloud Virtual And Wireless Network Protection domain covers the key concepts tested in this area of the CND exam blueprint published by EC-Council. Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all CND domains — no account required.
The Courseiva CND question bank contains 38 questions in the Enterprise Cloud Virtual And Wireless Network Protection domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Enterprise Cloud Virtual And Wireless Network Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included