Courseiva
Back to EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) questions

Scenario-based practice

Troubleshooting Scenario Questions

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

5
scenario questions
CND
exam code
EC-Council
vendor

Scenario guide

How to approach troubleshooting scenario questions

These questions describe a network symptom and ask you to identify the root cause or the correct fix. They appear across all certification exams and reward systematic thinking over memorisation. The best candidates follow a consistent troubleshooting framework even under time pressure.

Quick answer

Troubleshooting Scenario Questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Related practice questions

Related CND topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1hardmultiple choice
Full question →

An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Which command should the administrator run to temporarily switch the profile for this specific daemon to complain mode without affecting the rest of the system?

Question 2mediummultiple choice
Full question →

A network engineer is troubleshooting an enterprise Next-Generation Firewall (NGFW) and notices that encrypted HTTPS traffic is bypassing Deep Packet Inspection (DPI) signatures. What feature must be configured on the NGFW to inspect the payload of these encrypted sessions?

Question 3hardmulti select
Full question →

An enterprise network administrator is troubleshooting persistent packet drops at the perimeter firewall. Which THREE diagnostic tools or commands are most effective for identifying where and why traffic is being dropped? (Choose THREE)

Question 4hardmulti select
Full question →

An incident responder is investigating a suspected malware infection on a Windows machine. The malware is suspected of injecting code into a legitimate running process (Process Hollowing). Which THREE techniques or forensic artifacts should the analyst investigate to detect process injection? (Choose THREE)

Question 5hardmultiple choice
Read the full VPN explanation →

A security analyst is troubleshooting an IPsec site-to-site VPN tunnel failure on a Linux-based StrongSwan gateway. The logs indicate an 'ESP packet decryption failed' error. Upon reviewing the security association parameters, the analyst notices a mismatch in the cryptographic checksum algorithm. Which IPsec protocol component is responsible for providing data integrity and authentication for the inner packet?

These CND practice questions are part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style CND questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.