Courseiva
Endpoint ProtectionhardMultiple SelectObjective-mapped

CND Endpoint Protection Practice Question

An organization is implementing comprehensive endpoint hardening for Windows 10/11 endpoints. Which THREE of the following measures directly contribute to reducing the attack surface against memory-based exploits and credential theft? (Choose THREE)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enabling Windows Defender Exploit Protection system settings (e.g., CFG, DEP, ASLR)

Credential Guard, Attack Surface Reduction (ASR) rules, and Exploit Protection (EMET successor) directly mitigate memory corruption and credential theft vectors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enabling Windows Defender Exploit Protection system settings (e.g., CFG, DEP, ASLR)

    Why this is correct

    Exploit Protection enforces mitigations like Control Flow Guard (CFG) and Data Execution Prevention (DEP).

  • Disabling Universal Plug and Play (UPnP) service on endpoints

    Why it's wrong here

    UPnP is a network discovery service, not a direct endpoint memory exploit mitigation.

  • Enabling Windows Defender Credential Guard

    Why this is correct

    Credential Guard protects NTLM hashes and Kerberos tickets from theft by isolating LSASS memory.

  • Configuring Attack Surface Reduction (ASR) rules

    Why this is correct

    ASR rules block common malware vectors such as Office macro abuse and suspicious process spawns.

  • Disabling the Server Message Block v1 (SMBv1) protocol

    Why it's wrong here

    While important for network hardening against vulnerabilities like EternalBlue, SMBv1 is a network protocol, not a direct memory exploit mitigation.

About these practice questions

One of 323 original CND practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.