Courseiva

CND · topic practice

Enterprise Cloud Virtual And Wireless Network Protection practice questions

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Enterprise Cloud Virtual And Wireless Network Protection practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Enterprise Cloud Virtual And Wireless Network Protection

What the exam tests

What to know about Enterprise Cloud Virtual And Wireless Network Protection

Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.

IaaS, PaaS and SaaS responsibilities and examples.

Public, private, hybrid and community cloud deployment models.

On-premises vs cloud trade-offs: cost, control, scalability.

How cloud connectivity options (VPN, Direct Connect, ExpressRoute) work.

Watch out for

Common Enterprise Cloud Virtual And Wireless Network Protection exam traps

  • IaaS gives you infrastructure control; SaaS gives you only the application.
  • Hybrid cloud combines on-premises and public cloud — not two public clouds.
  • Cloud does not automatically mean cheaper or more secure.
  • Management responsibility shifts with each service model (IaaSPaaSSaaS).

Practice set

Enterprise Cloud Virtual And Wireless Network Protection questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full wireless explanation →

An enterprise cloud architect is designing multi-region disaster recovery for Azure Virtual Machines. The requirement is to replicate virtual machine disks asynchronously across regions without keeping secondary VMs running constantly. Which Azure service feature should be utilized?

Question 2mediummultiple choice
Read the full wireless explanation →

A network administrator suspects that an unauthorized rogue access point is operating within the enterprise office environment, spoofing the corporate SSID to capture user credentials. Which tool or technique should be used to detect and locate the physical source of the rogue AP?

Question 3mediummultiple choice
Read the full wireless explanation →

A security administrator is deploying a Microsoft Azure Virtual Network and needs to ensure that all outbound traffic from a specific subnet to the public internet is filtered using fully qualified domain name (FQDN) rules rather than IP addresses. Which Azure resource should be deployed to achieve this?

Question 4easymultiple choice
Read the full wireless explanation →

An organization is utilizing Google Cloud Platform (GCP) and needs to restrict network traffic between specific Google Kubernetes Engine (GKE) pods based on labels rather than IP addresses. Which GCP security feature should be configured?

Question 5hardmultiple choice
Read the full wireless explanation →

A cloud security engineer is hardening an Amazon EC2 instance running in a private subnet. The instance needs to securely communicate with an Amazon S3 bucket without traffic traversing the public internet. Which VPC configuration must be implemented to meet this requirement?

Question 6easymultiple choice
Read the full wireless explanation →

An enterprise is hardening its enterprise wireless network and migrating legacy authentication protocols. To protect against offline dictionary attacks and provide forward secrecy during the 4-way handshake, which Wi-Fi standard must be deployed?

Question 7mediummultiple choice
Read the full wireless explanation →

A security analyst is auditing an AWS environment and needs to identify which IAM users or roles have assumed administrative privileges across AWS accounts using AWS CloudTrail. Which event source and name should the analyst search for?

Question 8easymultiple choice
Read the full wireless explanation →

An enterprise administrator needs to configure AWS Security Hub to automatically ingest and centralize security findings across all organizational accounts in AWS. Which service must be enabled first to create the organizational management structure before enabling Security Hub?

Question 9hardmultiple choice
Read the full wireless explanation →

An enterprise cloud security architect is hardening an Azure Kubernetes Service (AKS) cluster. The requirement is to ensure that node-to-node communication within the cluster is encrypted in transit. Which feature must be enabled during cluster creation or configuration?

Question 10easymultiple choice
Read the full wireless explanation →

An administrator needs to secure management access to Azure virtual machines by eliminating open management ports (such as RDP port 3389 and SSH port 22) on the public internet. Which Azure feature should be configured?

Question 11mediummultiple choice
Read the full wireless explanation →

A network engineer is configuring an enterprise wireless network and wants to prevent clients from connecting to unauthorized rogue access points that broadcast the corporate SSID. Which client-side and infrastructure technology should be deployed?

Question 12mediummultiple choice
Read the full wireless explanation →

A cloud security team is reviewing GCP VPC configurations. To ensure that virtual machine instances without external IP addresses can still reach Google APIs and services (such as Cloud Storage and BigQuery) securely, which feature must be configured?

Question 13hardmultiple choice
Read the full wireless explanation →

An organization is implementing enterprise wireless security using WPA3-Enterprise. To ensure maximum cryptographic strength and protection against downgrade attacks, which security mode and key derivation function must be enforced?

Question 14easymultiple choice
Read the full wireless explanation →

An enterprise security administrator needs to isolate a compromised AWS EC2 instance for forensic investigation without terminating the instance or losing its volatile memory state. Which action should the administrator take?

Question 15hardmultiple choice
Read the full wireless explanation →

An enterprise is deploying a zero-trust architecture for its AWS cloud workloads. Services must communicate across VPCs without exposing traffic to the public internet or traversing VPC peerings that open full subnet access. Which feature should be implemented?

Question 16easymultiple choice
Read the full wireless explanation →

An administrator managing an enterprise AWS environment wants to ensure that all newly created S3 buckets across all accounts automatically block public access. Which feature should be configured at the AWS account level?

Question 17hardmultiple choice
Read the full wireless explanation →

An enterprise administrator is setting up an AWS Site-to-Site VPN connection between an on-premises data center and an AWS VPC. To ensure maximum data confidentiality and integrity across the public internet, which IPsec cryptographic parameters should be enforced in the VPN tunnel configuration?

Question 18mediummultiple choice
Read the full wireless explanation →

A network security engineer is tasked with securing corporate Wi-Fi clients against Evil Twin attacks where an attacker sets up a fake access point with identical SSID parameters. Which enterprise wireless security practice effectively mitigates client association to fake APs?

Question 19easymultiple choice
Read the full wireless explanation →

An enterprise IT security team wants to monitor AWS API calls and receive alerts whenever an unauthorized user attempts to modify critical IAM policies or security group rules. Which combination of AWS services should be configured?

Question 20hardmultiple choice
Read the full wireless explanation →

An enterprise cloud architect is configuring Google Cloud VPC Network Service Tiers to optimize cost and security for sensitive internal database traffic. Which service tier should be selected to ensure traffic stays entirely within Google's private global backbone network without touching the public internet?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Enterprise Cloud Virtual And Wireless Network Protection sessions

Start a Enterprise Cloud Virtual And Wireless Network Protection only practice session

Every question in these sessions is drawn from the Enterprise Cloud Virtual And Wireless Network Protection domain — nothing else.

Related practice questions

Related CND topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CND exam test about Enterprise Cloud Virtual And Wireless Network Protection?
Cloud concepts questions usually test the service model (IaaS/PaaS/SaaS) and deployment model (public/private/hybrid/community) appropriate for a given scenario.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Enterprise Cloud Virtual And Wireless Network Protection questions in a focused session?
Yes — the session launcher on this page draws every question from the Enterprise Cloud Virtual And Wireless Network Protection domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CND topics?
Use the topic links above to move to related areas, or go back to the CND question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CND exam covers. They are not copied from any real exam or dump site.