Sample questions
EC-Council Certified Network Defender (CND, 312-38, Blueprint v4.0) (CND) practice questions
A security engineer is configuring Linux Auditd on enterprise servers to log all attempts to modify user and group databases. Which audit rule should be added to /etc/audit/audit.r…
An enterprise security architect is deploying Digital Guardian DLP to protect intellectual property on Windows endpoints. An employee attempts to upload proprietary source code to…
A security analyst is hardening an Apache HTTP Server against web attacks. Which TWO directives or modules should be configured to enhance application security and mitigate common…
A systems administrator needs to secure data at rest on an enterprise Linux server by encrypting an entire secondary disk partition (e.g., /dev/sdb1) using LUKS (Linux Unified Key…
An administrator is troubleshooting a Linux endpoint running Ubuntu where AppArmor is operating in enforcing mode, but a critical daemon keeps failing to write to its log file. Whi…
An enterprise database administrator is configuring Microsoft SQL Server Always On Availability Groups and needs to ensure that database traffic transmitted between replicas across…
A cybersecurity analyst is auditing a Linux server running Apache Tomcat. To prevent attackers from exploiting directory traversal vulnerabilities to download sensitive configurati…
An administrator needs to configure Microsoft BitLocker Drive Encryption via Group Policy to require a startup PIN on a Trusted Platform Module (TPM) equipped system. Which specifi…
A cybersecurity architect is designing an enterprise Data Loss Prevention (DLP) deployment strategy across endpoint, network, and storage vectors. Which THREE technical capabilitie…
An administrator is deploying Windows Server Update Services (WSUS) for internal patch management. Which TWO of the following tasks are essential for maintaining a healthy WSUS env…
A security engineer is performing a security audit on an enterprise PostgreSQL database server. Which THREE hardening steps should be implemented to secure database access and data…
An organization is deploying a Data Loss Prevention (DLP) solution to protect sensitive intellectual property. Which TWO locations or data states must a comprehensive DLP architect…
An enterprise security auditor is reviewing an Elasticsearch cluster configuration. To prevent unauthorized access to stored indices containing sensitive PII and financial records,…
An organization wants to secure data in transit between microservices communicating within a Kubernetes cluster. Which service mesh technology provides mutual TLS (mTLS) encryption…
A security analyst is hardening an enterprise Microsoft Exchange email server and needs to prevent Server-Side Request Forgery (SSRF) and insecure deserialization attacks targeting…
An organization is implementing database transparent data encryption (TDE) and needs to understand its architectural security boundaries. Which THREE security characteristics or li…
An enterprise is implementing Zero Trust Network Access (ZTNA) for remote workers accessing cloud-hosted virtual desktops in Azure. To ensure that user identity, device compliance,…
Enterprise Cloud Virtual And Wireless Network ProtectionhardSee the answer and why each option is right or wrong →An administrator is configuring Mobile Device Management (MDM) for corporate tablets. Which TWO of the following security policies are standard capabilities enforceable via MDM? (C…
A security architect is designing a Linux endpoint hardening baseline. Which THREE of the following configurations help enforce Mandatory Access Control (MAC) and restrict process…
An administrator needs to harden an IoT gateway running Linux by disabling core dumps globally to prevent sensitive application memory from being written to disk if a process crash…
An organization is utilizing Google Cloud Platform (GCP) and needs to restrict network traffic between specific Google Kubernetes Engine (GKE) pods based on labels rather than IP a…
Enterprise Cloud Virtual And Wireless Network ProtectioneasySee the answer and why each option is right or wrong →A security analyst is reviewing endpoint telemetry for signs of lateral movement and credential dumping. Which THREE of the following event log indicators or telemetry artifacts su…
An enterprise administrator needs to configure AWS Security Hub to automatically ingest and centralize security findings across all organizational accounts in AWS. Which service mu…
Enterprise Cloud Virtual And Wireless Network ProtectioneasySee the answer and why each option is right or wrong →An administrator is managing mobile devices via an Enterprise Mobility Management (EMM) platform. Which TWO of the following features are characteristic of a Containerized Work Pro…