Courseiva

CND · domain

Endpoint Protection

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Endpoint Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

37 questions7 easy16 medium14 hard

Focused practice

Practice Endpoint Protection questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Endpoint Protection

IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.

IPv6 address types and their scopes (link-local, global unicast, multicast, ULA).

SLAAC vs DHCPv6 vs stateful assignment.

Neighbor Discovery Protocol replacing ARP.

IPv6 routing differences and dual-stack coexistence.

Watch out for

Common Endpoint Protection exam traps

  • Link-local addresses are not routable beyond the local link.
  • SLAAC uses EUI-64 or random interface IDs — not a DHCP server.
  • NDP uses ICMPv6, not ARP.
  • An IPv6 prefix is /64 for most host subnets, not /24.

Question index

All Endpoint Protection questions (37)

Click any question to see the full explanation, or start a practice session above.

1

A security analyst is reviewing endpoint telemetry for signs of lateral movement and credential dumping. Which THREE of the following event log indicators or telemetry artifacts suggest potential credential dumping activity targeting LSASS? (Choose THREE)

Hard
2

A security administrator needs to configure Windows Defender Firewall with Advanced Security via Group Policy Object (GPO) to block all outbound connections except those explicitly permitted by a rule. Where should the administrator configure this setting?

Medium
3

An administrator is configuring Mobile Device Management (MDM) for corporate tablets. Which TWO of the following security policies are standard capabilities enforceable via MDM? (Choose TWO)

Medium
4

A security administrator is evaluating Mobile Threat Defense (MTD) solutions for corporate Android devices. The administrator needs a solution that can detect rogue Wi-Fi access points and Man-in-the-Middle (MitM) attacks at the network layer. Which capability must the MTD solution provide?

Medium
5

A security administrator is preparing a security baseline for iOS and iPadOS devices using an MDM solution. To protect corporate data at rest on managed mobile devices, which setting must be verified?

Medium
6

A security analyst is investigating an EDR alert where a process spawned a suspicious child process. The analyst needs to review the process lineage tree. Which EDR capability is most useful for this task?

Easy
7

A security engineer is configuring Linux Auditd on enterprise servers to log all attempts to modify user and group databases. Which audit rule should be added to /etc/audit/audit.rules?

Medium
8

An enterprise endpoint security policy requires that all USB mass storage devices be blocked on workstations, while allowing encrypted company-issued smart cards and input devices. Which configuration approach should an administrator take using Group Policy?

Easy
9

An IoT device deployed in an industrial environment runs a minimal Linux kernel and needs its attack surface reduced by disabling unnecessary kernel modules like USB storage and Bluetooth. Where should the administrator configure module blacklisting?

Easy
10

An organization's Endpoint Detection and Response (EDR) platform flags a suspicious PowerShell command line executing an encoded script block. Which Windows logging subsystem should the security analyst inspect for the decoded script contents?

Easy
11

A security architect is configuring Linux Unified Key Setup (LUKS) disk encryption on enterprise laptops. To ensure that the encryption key can be decrypted automatically during boot via a Trusted Platform Module (TPM) 2.0 chip without manual passphrase entry, which tool should be integrated?

Hard
12

An organization's security team is deploying an EDR agent across corporate endpoints. During testing, the agent's kernel-mode driver causes a Blue Screen of Death (BSOD) during boot on systems running a third-party disk encryption filter driver. Which administrative action should be taken first to isolate and remediate the driver conflict?

Hard
13

An administrator is deploying Windows Server Update Services (WSUS) for internal patch management. Which TWO of the following tasks are essential for maintaining a healthy WSUS environment? (Choose TWO)

Medium
14

A security architect is designing a Linux endpoint hardening baseline. Which THREE of the following configurations help enforce Mandatory Access Control (MAC) and restrict process privileges? (Choose THREE)

Hard
15

An Incident Responder analyzing a compromised Linux server suspects a rootkit has modified system binaries. The responder runs the package manager verification command on Debian/Ubuntu to check installed packages against the package database. Which command is appropriate?

Hard
16

An enterprise environment uses Microsoft Endpoint Configuration Manager (MECM) for patch management. An administrator needs to ensure that critical patches are installed on workstations with minimal user disruption outside of active hours. Which MECM feature should be configured?

Medium
17

A security analyst is preparing to harden a fleet of corporate Windows 10 endpoints against pass-the-hash attacks. Which built-in Windows feature should be enabled and configured to isolate LSASS memory using virtualization?

Easy
18

A security engineer is configuring mobile device management (MDM) for corporate-owned iOS devices. To prevent users from installing unauthorized apps while still allowing access to enterprise applications, which feature should be deployed?

Medium
19

An organization is enforcing device hardening standards across all corporate laptops. Which TWO of the following controls should be implemented to secure client endpoints against physical and BIOS/UEFI tampering? (Choose TWO)

Medium
20

A security analyst configuring Endpoint Detection and Response (EDR) behavioral rules needs to monitor for living-off-the-land binaries (LotLB) executing reconnaissance commands. Which legitimate Windows utility is frequently abused by attackers for network discovery and should be monitored?

Medium
21

An administrator wants to ensure that critical system files on Windows endpoints are automatically monitored for unauthorized modifications and that any changes trigger an alert. Which built-in Windows tool or feature should be utilized?

Easy
22

An administrator is managing mobile devices via an Enterprise Mobility Management (EMM) platform. Which TWO of the following features are characteristic of a Containerized Work Profile (such as Android Enterprise)? (Choose TWO)

Medium
23

An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Which command should the administrator run to temporarily switch the profile for this specific daemon to complain mode without affecting the rest of the system?

Hard
24

An administrator needs to enforce mandatory password complexity, minimum length, and account lockout policies for local user accounts on standalone Windows Server endpoints that are not joined to an Active Directory domain. Which tool should be used?

Medium
25

An organization is implementing comprehensive endpoint hardening for Windows 10/11 endpoints. Which THREE of the following measures directly contribute to reducing the attack surface against memory-based exploits and credential theft? (Choose THREE)

Hard
26

A system administrator is hardening a fleet of Linux servers by setting strict umask values for all users to ensure newly created files are not readable by others. Where should this default system-wide umask be configured?

Medium
27

An Incident Response team is investigating a Linux server where a persistent backdoor is suspected of hiding process IDs (PIDs) using user-space hooks. Which utility should the responder use to compare process lists returned by the kernel system call table against direct kernel memory inspection?

Hard
28

A security engineer is hardening an industrial IoT gateway running Linux. Which THREE of the following steps are recognized hardening practices for securing embedded Linux IoT endpoints? (Choose THREE)

Hard
29

An administrator is hardening a Linux system against privilege escalation via SUID binaries. The administrator wants to find all files on the root partition that have the SUID bit set. Which find command should be executed?

Hard
30

An enterprise Incident Response team is investigating a compromised endpoint using EDR telemetry and live response tools. Which THREE of the following actions can typically be performed directly from an enterprise EDR console during active triage? (Choose THREE)

Hard
31

An organization is hardening Android enterprise devices and wants to prevent users from installing applications from unknown sources while ensuring corporate apps update automatically. Which policy configuration in the EMM/MDM console achieves this?

Hard
32

An organization is experiencing a ransomware outbreak on an endpoint. The Incident Response team decides to immediately disconnect the infected machine from the network without shutting it down, in order to preserve volatile memory. Which EDR feature should the responder trigger?

Easy
33

A security analyst is reviewing vulnerability assessment reports for a fleet of Windows endpoints and notes that third-party software (such as browsers and PDF readers) accounts for most missing patches. Which deployment strategy should the organization implement to streamline third-party patch management?

Medium
34

An Incident Response team analyzing an enterprise endpoint discovers evidence of a fileless malware attack leveraging Windows Management Instrumentation (WMI). Which THREE of the following WMI artifacts or logging mechanisms should the investigator examine? (Choose THREE)

Hard
35

An organization's security policy states that all Windows 10/11 endpoints must enforce AppLocker rules to block unauthorized executables. An administrator creates an Executable Rule allowing signed applications from a trusted software publisher, but users are still able to run unsigned tools from user-writable directories like C:\Users\Public. What is the most likely reason?

Hard
36

An administrator needs to harden an IoT gateway running Linux by disabling core dumps globally to prevent sensitive application memory from being written to disk if a process crashes. Which configuration should be applied?

Medium
37

A security administrator is hardening Linux servers against local privilege escalation and unauthorized access. Which TWO of the following configurations should be implemented? (Choose TWO)

Medium

Frequently asked questions

What does the Endpoint Protection domain cover on the CND exam?
IPv6 questions usually test address types (link-local, global unicast, ULA), autoconfiguration (SLAAC), Neighbor Discovery Protocol and the differences from IPv4.
How many questions are in this domain?
This page lists all 37 Endpoint Protection questions in the CND question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Endpoint Protection questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
eccouncil-cnd ECCOUNCIL-CND endpoint protection Practice Questions