Courseiva

CND · topic practice

Network Security Controls Protocols And Devices practice questions

Practise EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) Network Security Controls Protocols And Devices practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Network Security Controls Protocols And Devices

What the exam tests

What to know about Network Security Controls Protocols And Devices

Network Security Controls Protocols And Devices questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Security Controls Protocols And Devices exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Network Security Controls Protocols And Devices questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Open the full VLAN trunking answer →

A security administrator is hardening a network switch against VLAN hopping attacks. Which two configuration steps must be implemented on all user-facing access ports to neutralize this threat?

An enterprise network uses an Intrusion Detection System (IDS) deployed in passive monitoring mode via a switch span port. The security operations center (SOC) notices that the IDS generates high volumes of alerts for internal vulnerability scanning activities, obscuring real attacks. Which network design modification should be implemented to reduce false positive alert fatigue without disabling the detection signatures?

Question 3mediummultiple choice
Read the full VPN explanation →

An organization's security policy requires that all remote workers connect to the corporate network via a VPN that routes all client internet traffic through the corporate data center security stack. Which type of VPN architecture must the remote client be configured to use?

Question 4hardmultiple choice
Read the full VPN explanation →

A security analyst is troubleshooting an IPsec site-to-site VPN tunnel failure on a Linux-based StrongSwan gateway. The logs indicate an 'ESP packet decryption failed' error. Upon reviewing the security association parameters, the analyst notices a mismatch in the cryptographic checksum algorithm. Which IPsec protocol component is responsible for providing data integrity and authentication for the inner packet?

Question 5mediummultiple choice
Read the full VPN explanation →

An organization is configuring an IPsec VPN tunnel between two branch offices using Cisco IOS routers. The engineering team requires the use of a secure key exchange method that provides perfect forward secrecy (PFS) during the Phase 1 Internet Key Exchange (IKEv1) negotiation. Which Phase 1 mode must be selected?

Question 6easymultiple choice
Study the full ACL explanation →

A corporate network is segmented into multiple zones. The security policy dictates that the Finance department subnet must be completely isolated from the Guest Wi-Fi subnet, and traffic between them must pass through a security device enforcing access control lists. Where should this security device be placed?

A security architect is designing a high-security DMZ architecture. Public-facing web servers must be isolated from the internal database servers, and an intermediary inspection zone is required. Which design pattern should the architect implement?

A network engineer is configuring TLS 1.3 on an enterprise load balancer. During cipher suite selection, the engineer observes that cipher suites like TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 are no longer listed in the configuration menu. What is the primary reason for this change in TLS 1.3?

A network administrator needs to deploy a security device that inspects inbound HTTP and HTTPS traffic at the application layer and drops requests containing SQL injection signatures before they reach the web server. Which device should the administrator deploy?

A security engineer is configuring a stateful inspection firewall and needs to handle incoming traffic for an active FTP data connection operating in passive mode. What specific challenge does passive FTP present to the firewall, and how does the firewall resolve it?

An organization implements IEEE 802.1X port-based authentication across its enterprise switch infrastructure. A new IP security camera is connected to a switch port, but it does not support 802.1X supplicant software. How should the network administrator configure the switch port to authenticate and isolate the camera securely?

Question 12mediummultiple choice
Open the full VLAN trunking answer →

A security engineer is tasked with restricting network access to a sensitive database server so that only the application server VLAN can communicate with it on TCP port 1433. The database server is hosted on a virtualized hypervisor switch. Where should this micro-segmentation control be implemented for optimal enforcement?

Question 13hardmultiple choice
Open the full BGP breakdown →

An enterprise network security team is analyzing BGP routing anomalies at the internet edge. An attacker is attempting to inject malicious routing updates to hijack corporate IP space (BGP prefix hijacking). Which mechanism should the network edge routers implement to cryptographically verify the origin autonomy of IP prefixes?

A network administrator is setting up a secure remote management channel for Linux servers across the public internet. The security policy mandates that Telnet must not be used. Which protocol should be implemented?

Question 15easymultiple choice
Read the full wireless explanation →

An organization wants to deploy a wireless intrusion prevention system (WIPS) sensor to detect unauthorized access points and rogue devices broadcasting corporate SSIDs. Where should the WIPS sensor be deployed?

A company is implementing a next-generation firewall (NGFW) and wants to inspect encrypted HTTPS traffic traversing the network without triggering browser certificate warning errors on corporate-managed endpoints. Which deployment method achieves this?

Question 17hardmultiple choice
Review the full routing breakdown →

A network administrator is configuring a high-availability pair of firewalls in active/passive mode using virtual router redundancy protocol (VRRP). During a failover event, active TCP sessions drop, forcing users to re-authenticate to internal applications. Which firewall feature must be enabled to maintain stateful session continuity across the failover?

An administrator needs to secure SNMP traffic on enterprise network switches so that management queries and responses are both encrypted and authenticated. Which version of SNMP must be configured?

Question 19hardmultiple choice
Read the full VPN explanation →

An enterprise is deploying an IPsec site-to-site VPN. The security team wants to ensure that if an attacker captures today's encrypted network traffic, they cannot decrypt it even if they eventually compromise the long-term preshared keys or private keys used during the initial key exchange. What cryptographic property must be enforced?

Question 20mediummultiple choice
Read the full DNS explanation →

A security analyst observes that an internal host is generating excessive DNS queries containing encoded data within subdomains, indicative of a DNS tunneling attack. The network perimeter firewall allows outbound DNS traffic on UDP port 53 to any external IP. Which network security control should be implemented to mitigate this threat?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Security Controls Protocols And Devices sessions

Start a Network Security Controls Protocols And Devices only practice session

Every question in these sessions is drawn from the Network Security Controls Protocols And Devices domain — nothing else.

Related practice questions

Related CND topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CND exam test about Network Security Controls Protocols And Devices?
Network Security Controls Protocols And Devices questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Security Controls Protocols And Devices questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Security Controls Protocols And Devices domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CND topics?
Use the topic links above to move to related areas, or go back to the CND question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CND exam covers. They are not copied from any real exam or dump site.