Courseiva
Network Defense ManagementmediumMultiple ChoiceObjective-mapped

CND Network Defense Management Practice Question

An organization is conducting a mandatory security audit for PCI-DSS compliance regarding its cardholder data environment (CDE). The auditor asks for proof of network segmentation. What should the network security administrator present?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Architecture diagrams and firewall rulebases demonstrating that out-of-scope networks cannot reach the CDE without strict filtering.

To prove PCI-DSS network segmentation, administrators must present current network diagrams showing firewalls effectively isolating the CDE from out-of-scope networks, along with the results of effective penetration testing confirming that isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Antivirus signature update logs from all workstation endpoints.

    Why it's wrong here

    Endpoint protection logs demonstrate malware defense, not boundary control and segmentation.

  • Software asset inventory spreadsheets listing operating system versions.

    Why it's wrong here

    Asset inventories support configuration management but do not verify network traffic isolation.

  • Architecture diagrams and firewall rulebases demonstrating that out-of-scope networks cannot reach the CDE without strict filtering.

    Why this is correct

    PCI-DSS requires documented network diagrams and rule verification showing that cardholder data systems are isolated from flat corporate networks.

  • HR onboarding records showing background checks for all employees with physical access to the building.

    Why it's wrong here

    HR background checks satisfy physical security and personnel security requirements, not network segmentation.

About these practice questions

Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.