CND · domain
Endpoint Protection
Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Endpoint Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Endpoint Protection questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Endpoint Protection
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).
SLAAC vs DHCPv6 vs stateful assignment.
Neighbor Discovery Protocol replacing ARP.
IPv6 routing differences and dual-stack coexistence.
Watch out for
Common Endpoint Protection exam traps
- ▸Link-local addresses are not routable beyond the local link.
- ▸SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
- ▸NDP uses ICMPv6, not ARP.
- ▸An IPv6 prefix is /64 for most host subnets, not /24.
Question index
All Endpoint Protection questions (37)
Click any question to see the full explanation, or start a practice session above.
A security analyst is reviewing endpoint telemetry for signs of lateral movement and credential dumping. Which THREE of the following event log indicators or telemetry artifacts suggest potential credential dumping activity targeting LSASS? (Choose THREE)
Hard2A security administrator needs to configure Windows Defender Firewall with Advanced Security via Group Policy Object (GPO) to block all outbound connections except those explicitly permitted by a rule. Where should the administrator configure this setting?
Medium3An administrator is configuring Mobile Device Management (MDM) for corporate tablets. Which TWO of the following security policies are standard capabilities enforceable via MDM? (Choose TWO)
Medium4A security administrator is evaluating Mobile Threat Defense (MTD) solutions for corporate Android devices. The administrator needs a solution that can detect rogue Wi-Fi access points and Man-in-the-Middle (MitM) attacks at the network layer. Which capability must the MTD solution provide?
Medium5A security administrator is preparing a security baseline for iOS and iPadOS devices using an MDM solution. To protect corporate data at rest on managed mobile devices, which setting must be verified?
Medium6A security analyst is investigating an EDR alert where a process spawned a suspicious child process. The analyst needs to review the process lineage tree. Which EDR capability is most useful for this task?
Easy7A security engineer is configuring Linux Auditd on enterprise servers to log all attempts to modify user and group databases. Which audit rule should be added to /etc/audit/audit.rules?
Medium8An enterprise endpoint security policy requires that all USB mass storage devices be blocked on workstations, while allowing encrypted company-issued smart cards and input devices. Which configuration approach should an administrator take using Group Policy?
Easy9An IoT device deployed in an industrial environment runs a minimal Linux kernel and needs its attack surface reduced by disabling unnecessary kernel modules like USB storage and Bluetooth. Where should the administrator configure module blacklisting?
Easy10An organization's Endpoint Detection and Response (EDR) platform flags a suspicious PowerShell command line executing an encoded script block. Which Windows logging subsystem should the security analyst inspect for the decoded script contents?
Easy11A security architect is configuring Linux Unified Key Setup (LUKS) disk encryption on enterprise laptops. To ensure that the encryption key can be decrypted automatically during boot via a Trusted Platform Module (TPM) 2.0 chip without manual passphrase entry, which tool should be integrated?
Hard12An organization's security team is deploying an EDR agent across corporate endpoints. During testing, the agent's kernel-mode driver causes a Blue Screen of Death (BSOD) during boot on systems running a third-party disk encryption filter driver. Which administrative action should be taken first to isolate and remediate the driver conflict?
Hard13An administrator is deploying Windows Server Update Services (WSUS) for internal patch management. Which TWO of the following tasks are essential for maintaining a healthy WSUS environment? (Choose TWO)
Medium14A security architect is designing a Linux endpoint hardening baseline. Which THREE of the following configurations help enforce Mandatory Access Control (MAC) and restrict process privileges? (Choose THREE)
Hard15An Incident Responder analyzing a compromised Linux server suspects a rootkit has modified system binaries. The responder runs the package manager verification command on Debian/Ubuntu to check installed packages against the package database. Which command is appropriate?
Hard16An enterprise environment uses Microsoft Endpoint Configuration Manager (MECM) for patch management. An administrator needs to ensure that critical patches are installed on workstations with minimal user disruption outside of active hours. Which MECM feature should be configured?
Medium17A security analyst is preparing to harden a fleet of corporate Windows 10 endpoints against pass-the-hash attacks. Which built-in Windows feature should be enabled and configured to isolate LSASS memory using virtualization?
Easy18A security engineer is configuring mobile device management (MDM) for corporate-owned iOS devices. To prevent users from installing unauthorized apps while still allowing access to enterprise applications, which feature should be deployed?
Medium19An organization is enforcing device hardening standards across all corporate laptops. Which TWO of the following controls should be implemented to secure client endpoints against physical and BIOS/UEFI tampering? (Choose TWO)
Medium20A security analyst configuring Endpoint Detection and Response (EDR) behavioral rules needs to monitor for living-off-the-land binaries (LotLB) executing reconnaissance commands. Which legitimate Windows utility is frequently abused by attackers for network discovery and should be monitored?
Medium21An administrator wants to ensure that critical system files on Windows endpoints are automatically monitored for unauthorized modifications and that any changes trigger an alert. Which built-in Windows tool or feature should be utilized?
Easy22An administrator is managing mobile devices via an Enterprise Mobility Management (EMM) platform. Which TWO of the following features are characteristic of a Containerized Work Profile (such as Android Enterprise)? (Choose TWO)
Medium23An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Which command should the administrator run to temporarily switch the profile for this specific daemon to complain mode without affecting the rest of the system?
Hard24An administrator needs to enforce mandatory password complexity, minimum length, and account lockout policies for local user accounts on standalone Windows Server endpoints that are not joined to an Active Directory domain. Which tool should be used?
Medium25An organization is implementing comprehensive endpoint hardening for Windows 10/11 endpoints. Which THREE of the following measures directly contribute to reducing the attack surface against memory-based exploits and credential theft? (Choose THREE)
Hard26A system administrator is hardening a fleet of Linux servers by setting strict umask values for all users to ensure newly created files are not readable by others. Where should this default system-wide umask be configured?
Medium27An Incident Response team is investigating a Linux server where a persistent backdoor is suspected of hiding process IDs (PIDs) using user-space hooks. Which utility should the responder use to compare process lists returned by the kernel system call table against direct kernel memory inspection?
Hard28A security engineer is hardening an industrial IoT gateway running Linux. Which THREE of the following steps are recognized hardening practices for securing embedded Linux IoT endpoints? (Choose THREE)
Hard29An administrator is hardening a Linux system against privilege escalation via SUID binaries. The administrator wants to find all files on the root partition that have the SUID bit set. Which find command should be executed?
Hard30An enterprise Incident Response team is investigating a compromised endpoint using EDR telemetry and live response tools. Which THREE of the following actions can typically be performed directly from an enterprise EDR console during active triage? (Choose THREE)
Hard31An organization is hardening Android enterprise devices and wants to prevent users from installing applications from unknown sources while ensuring corporate apps update automatically. Which policy configuration in the EMM/MDM console achieves this?
Hard32An organization is experiencing a ransomware outbreak on an endpoint. The Incident Response team decides to immediately disconnect the infected machine from the network without shutting it down, in order to preserve volatile memory. Which EDR feature should the responder trigger?
Easy33A security analyst is reviewing vulnerability assessment reports for a fleet of Windows endpoints and notes that third-party software (such as browsers and PDF readers) accounts for most missing patches. Which deployment strategy should the organization implement to streamline third-party patch management?
Medium34An Incident Response team analyzing an enterprise endpoint discovers evidence of a fileless malware attack leveraging Windows Management Instrumentation (WMI). Which THREE of the following WMI artifacts or logging mechanisms should the investigator examine? (Choose THREE)
Hard35An organization's security policy states that all Windows 10/11 endpoints must enforce AppLocker rules to block unauthorized executables. An administrator creates an Executable Rule allowing signed applications from a trusted software publisher, but users are still able to run unsigned tools from user-writable directories like C:\Users\Public. What is the most likely reason?
Hard36An administrator needs to harden an IoT gateway running Linux by disabling core dumps globally to prevent sensitive application memory from being written to disk if a process crashes. Which configuration should be applied?
Medium37A security administrator is hardening Linux servers against local privilege escalation and unauthorized access. Which TWO of the following configurations should be implemented? (Choose TWO)
MediumOther domains
All CND exam domains
Frequently asked questions
- What does the Endpoint Protection domain cover on the CND exam?
- IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
- How many questions are in this domain?
- This page lists all 37 Endpoint Protection questions in the CND question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Endpoint Protection questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.