CND Endpoint Protection Practice Question
An organization is implementing comprehensive endpoint hardening for Windows 10/11 endpoints. Which THREE of the following measures directly contribute to reducing the attack surface against memory-based exploits and credential theft? (Choose THREE)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enabling Windows Defender Exploit Protection system settings (e.g., CFG, DEP, ASLR)
Credential Guard, Attack Surface Reduction (ASR) rules, and Exploit Protection (EMET successor) directly mitigate memory corruption and credential theft vectors.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enabling Windows Defender Exploit Protection system settings (e.g., CFG, DEP, ASLR)
Why this is correct
Exploit Protection enforces mitigations like Control Flow Guard (CFG) and Data Execution Prevention (DEP).
- ✗
Disabling Universal Plug and Play (UPnP) service on endpoints
Why it's wrong here
UPnP is a network discovery service, not a direct endpoint memory exploit mitigation.
- ✓
Enabling Windows Defender Credential Guard
Why this is correct
Credential Guard protects NTLM hashes and Kerberos tickets from theft by isolating LSASS memory.
- ✓
Configuring Attack Surface Reduction (ASR) rules
Why this is correct
ASR rules block common malware vectors such as Office macro abuse and suspicious process spawns.
- ✗
Disabling the Server Message Block v1 (SMBv1) protocol
Why it's wrong here
While important for network hardening against vulnerabilities like EternalBlue, SMBv1 is a network protocol, not a direct memory exploit mitigation.
About these practice questions
One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.