20+ practice questions focused on Network Attacks And Defense Strategies — one of the most tested topics on the EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Network Attacks And Defense Strategies PracticeAn attacker performs a cross-site scripting (XSS) attack against a web application, successfully stealing sensitive session cookies from victim browsers. The security team is tasked with updating the application's cookie configuration attributes. Which two cookie flags must be set to protect session cookies against theft via XSS and network sniffing?
Explanation: The HttpOnly flag prevents client-side scripts (such as JavaScript in XSS attacks) from accessing document.cookie. The Secure flag ensures that the cookie is transmitted only over encrypted (HTTPS) connections, preventing network sniffing.
During an incident response engagement, a security analyst discovers that an attacker executed a Server-Side Request Forgery (SSRF) vulnerability on an internal web application to access cloud instance metadata services (IMDS). Which remediation step should be applied immediately to the cloud application architecture to prevent future SSRF exploitation against IMDS?
Explanation: Cloud providers (such as AWS) utilize IMDSv2, which requires session tokens, putting an explicit protection barrier against standard SSRF attacks. Additionally, restricting outbound application network calls and using IMDSv2 limits exposure.
A wireless security audit reveals that an unauthorized rogue access point has been deployed within the corporate perimeter, configured with the exact same SSID as the corporate enterprise network to perform an evil twin attack. Which enterprise wireless feature should the network administrator configure on the Wireless LAN Controller (WLC) to automatically detect and contain this rogue AP?
Explanation: Cisco Wireless LAN Controllers feature Rogue AP Detection and Automatic Containment (using Rogue Management and Adaptive Wireless Intrusion Prevention System - wIPS) which detects unauthorized APs broadcasting corporate SSIDs and sends deauthentication frames to isolate associated clients.
An enterprise network utilizes 802.1X port-based authentication with a RADIUS server. An attacker performs a port-stealing attack by spoofing the MAC address of an authenticated, active wired client to gain network access on a different switch port. Which switch security feature should be enabled to prevent this attack?
Explanation: Port security on Cisco switches allows an administrator to limit the number of valid MAC addresses allowed on a port and secure it against MAC spoofing and port stealing by learning specific addresses or setting maximum limits. Additionally, Dynamic ARP Inspection (DAI) and IP Source Guard help, but port security specifically addresses MAC duplication and port stealing across switch ports.
A security analyst suspects that an internal host has been compromised and is communicating via an encrypted Command and Control (C2) channel utilizing DNS tunneling. Which Wireshark filter and analysis technique should the analyst employ to definitively identify this anomaly?
Explanation: DNS tunneling embeds arbitrary data within DNS queries (typically in the subdomain labels). Filtering for DNS traffic and analyzing exceptionally long query names containing high entropy or Base64-encoded strings is the standard methodology to detect DNS tunneling.
+15 more Network Attacks And Defense Strategies questions available
Practice all Network Attacks And Defense Strategies questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Network Attacks And Defense Strategies. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Network Attacks And Defense Strategies questions on the CND frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Network Attacks And Defense Strategies is tested as part of the EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) blueprint. Practicing with targeted Network Attacks And Defense Strategies questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CND practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Network Attacks And Defense Strategies is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Network Attacks And Defense Strategies practice session with instant scoring and detailed explanations.
Start Network Attacks And Defense Strategies Practice →