Simulate the real EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) exam with full-length timed sessions. Questions drawn proportionally from all 8 official blueprint domains — the same mix you'll face on test day.
Simulate real exam conditions
For the most realistic CND simulation, start a 60 or 120-question session, put away all notes, set a timer matching the real exam duration (120 minutes), and commit to each answer before moving forward. This trains the time management and decision-making skills the real exam tests.
This free CND mock exam uses the same question distribution as the real EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) exam. Each session draws questions proportionally from all 8 official blueprint domains published by EC-Council, so the topic mix you see accurately reflects what you'll face on test day.
CND Domain Distribution
Endpoint Protection
Enterprise Cloud Virtual And Wireless Network Protection
Network Security Controls Protocols And Devices
Incident Detection Response And Threat Prediction
Network Attacks And Defense Strategies
Network Defense Management
Application And Data Protection
Network Perimeter Protection
Every question is written by certified engineers against the 2026 CND exam objectives. These are original practice questions — not dumps — so you build real understanding rather than memorising answers.
Both the mock exam and practice test use the same question bank. The difference is in how you use them — and when to use each during your CND study plan.
Practice test — for learning
Use the CND practice test when you are studying a domain. Answer questions, read every explanation immediately, and build understanding. Do 10–30 questions per domain per session. This is your primary study tool for the first 4 weeks.
Go to practice test →Mock exam — for simulation
Use the CND mock exam in the final 1–2 weeks before your test date. Complete a 60 or 120-question session without stopping, manage your time, then review all results at the end. This builds exam-day stamina and surfaces final weak spots.
Start 120-question mock →Try these sample questions from the mock exam bank. Commit to an answer before revealing the explanation.
An Incident Responder analyzing a compromised Linux server suspects a rootkit has modified system binaries. The responder runs the package manager verification command on Debian/Ubuntu to check installed packages against the package database. Which command is appropriate?
Select an answer to reveal the explanation
An enterprise cloud architect is designing multi-region disaster recovery for Azure Virtual Machines. The requirement is to replicate virtual machine disks asynchronously across regions without keeping secondary VMs running constantly. Which Azure service feature should be utilized?
Select an answer to reveal the explanation
An enterprise network uses an Intrusion Detection System (IDS) deployed in passive monitoring mode via a switch span port. The security operations center (SOC) notices that the IDS generates high volumes of alerts for internal vulnerability scanning activities, obscuring real attacks. Which network design modification should be implemented to reduce false positive alert fatigue without disabling the detection signatures?
Select an answer to reveal the explanation
A network defender is configuring an enterprise SIEM using Splunk to alert on abnormal outbound data volumes. Which Splunk processing command should be used to aggregate total outbound bytes grouped by destination IP address?
Select an answer to reveal the explanation
During an incident response engagement, a security analyst discovers that an attacker executed a Server-Side Request Forgery (SSRF) vulnerability on an internal web application to access cloud instance metadata services (IMDS). Which remediation step should be applied immediately to the cloud application architecture to prevent future SSRF exploitation against IMDS?
Select an answer to reveal the explanation
An enterprise network defense team is establishing the first phase of the Network Defense Lifecycle Management process. Which primary activity must occur during the initial 'Assessment and Analysis' phase?
Select an answer to reveal the explanation
An enterprise network administrator needs to enforce data loss prevention rules across corporate endpoints. They deploy McAfee Data Loss Prevention Endpoint. Which client component inspects and blocks data movement to USB mass storage devices locally on the workstation?
Select an answer to reveal the explanation
An administrator needs to configure a Linux firewall using UFW (Uncomplicated Firewall) to allow incoming SSH traffic from a specific subnet (192.168.100.0/24). Which command should be executed?
Select an answer to reveal the explanation
Answer all 8 questions to see your domain score breakdown
Sitting the CND under real exam conditions is a skill in itself. Candidates who underperform often do so not because of knowledge gaps, but because of poor time management or test anxiety. Use your final mock exam sessions to address both.
The CND exam lasts 120 minutes. Do not spend more than 90 seconds on any single question on the first pass. Flag difficult ones and return to them after completing the rest.
On every question, immediately eliminate obviously wrong choices. Even if you are unsure between two options, narrowing to two doubles your odds. Most CND distractors contain a subtle error — re-read the scenario constraint before committing to the answer that sounds most familiar.
EC-Council writes many CND questions as realistic scenarios. Read the final sentence first — it tells you what is being asked. Then re-read the scenario with the question in mind to avoid wasting time on irrelevant details.
The real CND is a mental marathon lasting 120 minutes. In the week before your exam, complete at least two full timed mock sessions on separate days to build concentration stamina. If you cannot stay focused for 120 minutes in practice, you will struggle on exam day.
Questions
200
On the real exam
Time limit
120 min
0.6 min per question
Passing score
700/1000
Scaled scoring
The CND uses scaled scoring — your raw percentage correct is converted to a score out of 1000. Consistently scoring above 80% on mock exams puts you well above the 700/1000 threshold, giving you a buffer for any unexpected question types on the real exam.
Yes. Courseiva provides free CND mock exam questions across all official exam domains. The platform includes timed simulation, per-domain score breakdown, missed-question review, and readiness tracking. No account required — free forever, supported by advertising.
The practice test is optimised for learning: you see explanations after each question immediately. The mock exam is optimised for simulation: you answer all questions under time pressure and review at the end. Use practice tests for studying and mock exams for benchmarking.
Aim for consistent scores of 80% or above on full-length CND mock exams before booking your test date. The official passing score of 700/1000 corresponds to roughly 72–75% correct answers, so an 80% buffer accounts for difficulty variation and question styles on the real exam.
Most candidates who pass CND on their first attempt complete 3–5 full-length mock exams in the two weeks before their test. This is enough to identify final weak spots, build stamina, and verify readiness without over-stressing or running out of fresh questions.
No — all Courseiva questions are original, written by certified engineers against public EC-Council exam blueprints. Exam dumps are memorised real exam questions shared illegally. Using dumps violates your EC-Council certification agreement and can result in your certification being revoked. Our questions make you genuinely competent, not just test-day lucky.
Track your mock exam scores, see per-domain analytics, and benchmark readiness across every certification.
Sign Up FreeFree forever · Every certification included