Courseiva

CND · topic practice

Network Attacks And Defense Strategies practice questions

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Network Attacks And Defense Strategies practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Network Attacks And Defense Strategies

What the exam tests

What to know about Network Attacks And Defense Strategies

Network Attacks And Defense Strategies questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Attacks And Defense Strategies exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Network Attacks And Defense Strategies questions

20 questions · select your answer, then reveal the explanation

An attacker performs a cross-site scripting (XSS) attack against a web application, successfully stealing sensitive session cookies from victim browsers. The security team is tasked with updating the application's cookie configuration attributes. Which two cookie flags must be set to protect session cookies against theft via XSS and network sniffing?

During an incident response engagement, a security analyst discovers that an attacker executed a Server-Side Request Forgery (SSRF) vulnerability on an internal web application to access cloud instance metadata services (IMDS). Which remediation step should be applied immediately to the cloud application architecture to prevent future SSRF exploitation against IMDS?

Question 3easymultiple choice
Read the full wireless explanation →

A wireless security audit reveals that an unauthorized rogue access point has been deployed within the corporate perimeter, configured with the exact same SSID as the corporate enterprise network to perform an evil twin attack. Which enterprise wireless feature should the network administrator configure on the Wireless LAN Controller (WLC) to automatically detect and contain this rogue AP?

Question 4hardmultiple choice
Study the full AAA explanation →

An enterprise network utilizes 802.1X port-based authentication with a RADIUS server. An attacker performs a port-stealing attack by spoofing the MAC address of an authenticated, active wired client to gain network access on a different switch port. Which switch security feature should be enabled to prevent this attack?

Question 5mediummultiple choice
Read the full DNS explanation →

A security analyst suspects that an internal host has been compromised and is communicating via an encrypted Command and Control (C2) channel utilizing DNS tunneling. Which Wireshark filter and analysis technique should the analyst employ to definitively identify this anomaly?

An organization's Security Information and Event Management (SIEM) system alerts on suspicious Active Directory enumeration activity. An internal workstation is executing frequent unauthenticated LDAP queries requesting large numbers of user and group attributes. Which protocol mechanism and defensive configuration should be implemented to mitigate this reconnaissance technique?

Question 7easymultiple choice
Review the full subnetting walkthrough →

A security team receives alerts indicating that an attacker is performing ARP cache poisoning on the local subnet to conduct a Man-in-the-Middle (MitM) attack. Which switch feature should the network administrator enable to mitigate this threat?

Question 8mediummultiple choice
Read the full DNS explanation →

An organization is hardening its public-facing email infrastructure against spoofing and phishing attacks. The security engineer needs to configure a DNS record that specifies which mail servers are authorized to send email on behalf of the domain. Which DNS record type must be created?

A network administrator observes continuous SYN flooding targeting a primary public-facing web server on a Cisco ASA 5500-X firewall. To mitigate this attack without disrupting legitimate traffic, which specific feature should the administrator enable globally via the command-line interface?

A company's intrusion detection system (IDS) flags multiple suspicious packets containing shellcode signatures destined for an internal database server. However, the security team determines that the application was updated and the traffic was a false positive. Which action should the security analyst take within the Snort configuration to prevent this specific signature from generating future alerts?

An attacker attempts a Kerberoasting attack by requesting a Service Ticket (TGS) for a service account running with a Service Principal Name (SPN) from a compromised domain user account, then attempts to crack the service account's password offline. Which security hardening practice should be implemented in Active Directory to mitigate this risk?

An administrator notices unusual traffic volume exiting an internal server toward an unknown external IP address on TCP port 4443. Further investigation reveals data exfiltration. Which firewall feature should be configured at the perimeter to inspect and block unauthorized outbound application traffic and unknown protocols?

An attacker compromises an internal workstation and attempts to perform lateral movement using PsExec. The security team wants to detect and block this activity across the internal Windows domain. Which Windows Defender Firewall with Advanced Security rule or Group Policy setting should be deployed?

A security analyst is hardening a Linux-based web server and wants to implement mandatory access control (MAC) to restrict processes to only the resources necessary for their function. Which built-in Linux kernel security module should the analyst configure?

An enterprise network is subjected to a distributed denial-of-service (DDoS) volumetric UDP reflection and amplification attack utilizing Network Time Protocol (NTP) monlist queries. Which configuration change should be applied to enterprise NTP servers to prevent them from participating in amplification attacks?

A security engineer is configuring a Snort Intrusion Prevention System (IPS) rule to detect ICMP echo requests with payloads larger than 1000 bytes, which may indicate covert channel data exfiltration. Which rule header and options combination is correct?

An organization's web application is vulnerable to SQL injection (SQLi). An attacker is using union-based queries to extract database contents. Which defensive technology placed in front of the web application can inspect HTTP parameters and block SQLi signatures dynamically?

A network security analyst observes an ongoing brute-force attack against an SSH service running on a Linux server. Which tool can the analyst configure to automatically inspect authentication failure logs and dynamically block attacker IP addresses via iptables?

Question 19easymultiple choice
Read the full wireless explanation →

An enterprise wireless network uses WPA2-Enterprise for authentication. A security administrator wants to upgrade the security posture to protect against offline dictionary attacks on handshakes and provide enhanced cryptographic cipher suites. Which standard should be implemented?

An attacker performs a pass-the-hash attack to move laterally across an enterprise network using compromised NTLM hashes. The security architecture team wants to implement host-based mitigations to render harvested NTLM hashes unusable for authentication. Which Windows security feature should be enabled?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Attacks And Defense Strategies sessions

Start a Network Attacks And Defense Strategies only practice session

Every question in these sessions is drawn from the Network Attacks And Defense Strategies domain — nothing else.

Related practice questions

Related CND topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CND exam test about Network Attacks And Defense Strategies?
Network Attacks And Defense Strategies questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Attacks And Defense Strategies questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Attacks And Defense Strategies domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CND topics?
Use the topic links above to move to related areas, or go back to the CND question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CND exam covers. They are not copied from any real exam or dump site.