Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free EC-Council Certified Network Defender 312-38 Exam Questions

Page: 1 / 25 Total 363 questions

Want more questions? Get Premium Access.

Question 1

Management wants to calculate the risk factor for their organization. Kevin, a network administrator in the organization knows how to calculate the risk factor. Certain parameters are required before calculating risk

factor. What are they? (Select all that apply) Risk factor =.............X...............X...........

Correct Answer: A. Vulnerability
Explanation:

The risk factor for an organization is typically calculated by considering the potential impact of a threat exploiting a vulnerability. The formula often used is Risk = Threat X Vulnerability X Impact. This means that for a risk to exist, there must be a threat that could exploit a vulnerability and cause an impact on the organization. An attack is not a parameter in the risk calculation but rather the act that occurs when a threat exploits a vulnerability.


Question 2

Ryan works as a network security engineer at an organization the recently suffered an attack. As a countermeasure, Ryan would like to obtain more information about the attacker and chooses to deploy a honeypot into the organizations production environment called Kojoney. Using this honeypot, he would like to emulate the network vulnerability that was attacked previously. Which type of honeypot is he trying to implement?

Correct Answer: D. Low-interaction honeypots
Explanation:

A low-interaction honeypot, like Kojoney, is designed to emulate specific network vulnerabilities and gather information about attackers without providing a full-fledged operating environment. These honeypots are typically easier to deploy and maintain compared to high-interaction honeypots. They simulate certain services and responses to attract attackers, allowing the network security team to gather data on attack patterns, tools, and methodologies used by the attackers. This information is crucial for understanding the attack and improving defenses.

High-interaction honeypots: Provide a complete environment that can fully engage with attackers, offering more detailed insights but also posing higher risks.

Pure honeypots: Essentially full-scale, unmodified systems that an attacker interacts with.

Research honeypots: Used primarily for gathering information for research purposes, often involving high-interaction setups.


EC-Council Certified Network Defender (CND) Study Guide

Honeypot deployment and management documentation

Question 3

Henry, head of network security at Gentech, has discovered a general report template that someone has reserved only for the CEO. Since the file has to be editable, viewable, and deletable by everyone, what permission value should he set?

Correct Answer: A. 777
Explanation:

To allow a file to be editable, viewable, and deletable by everyone, Henry needs to set the file permissions to the most permissive value. In Linux and Unix systems, file permissions are represented by three sets of three bits, each set representing permissions for the owner, the group, and others.

The permission value of 777 means:

The first digit (7) grants read (4), write (2), and execute (1) permissions to the owner.

The second digit (7) grants read, write, and execute permissions to the group.

The third digit (7) grants read, write, and execute permissions to others.

Setting the permissions to 777 ensures that everyone (owner, group, and others) can read, write, and execute the file. This aligns with the requirement for the file to be editable, viewable, and deletable by everyone.


EC-Council Certified Network Defender (CND) Study Guide

Linux file permissions documentation and chmod command usage

Question 4

Which of the following connects the SDN controller and SDN networking devices and relays information from network services to network devices such as switches and routers?

Correct Answer: C. Southbound API
Explanation:

In Software Defined Networking (SDN), APIs are used to manage the communication between different components of the network. The Southbound API connects the SDN controller to the networking devices such as switches and routers, enabling the controller to send instructions to the network devices and gather data from them. This API is essential for the controller to enforce policies and ensure the proper functioning of the network infrastructure.

The other APIs are:

Northbound API: Interfaces between the SDN controller and the applications running on the network.

Eastbound API and Westbound API: Generally used for communication between different SDN controllers or other similar systems.


EC-Council Certified Network Defender (CND) Study Guide

SDN architecture documentation

Question 5

Ivan needs to pick an encryption method that is scalable even though it might be slower. He has settled on a method that works where one key is public and the other is private. What encryption method did Ivan settle

on?

Correct Answer: C. Ivan settled on the asymmetric encryption method
Explanation:

Asymmetric encryption, also known as public-key cryptography, involves two keys: a public key, which can be shared widely, and a private key, which is kept confidential. The public key is used for encryption, and the private key is used for decryption. This method is scalable because it allows for secure communication over an open network without the need for the parties to share secret keys in advance.While asymmetric encryption is generally slower than symmetric encryption due to the complex mathematical computations involved, it provides a high level of security and is essential for tasks such as digital signatures and establishing secure connections over the internet1234.


GeeksforGeeks provides a detailed explanation of asymmetric key cryptography, including its characteristics and how it addresses key distribution and digital signatures1.

Dashlane's blog offers a complete guide to asymmetric encryption, its definition, uses, and how it works2.

Kiteworks explains the difference between public and private key encryption and the use of asymmetric encryption on the internet3.

Cloudflare discusses asymmetric encryption and its role in securing web communications through protocols like TLS4.

Question 6

John is working as a network defender at a well-reputed multinational company. He wanted to implement security that can help him identify any future attacks that can be targeted toward his organization and

take appropriate security measures and actions beforehand to defend against them. Which one of the following security defense techniques should be implement?

Correct Answer: C. Proactive security approach
Explanation:

John should implement aProactive security approach.This approach is part of the adaptive security strategy that is built on a 4-pronged approach --- Protect, Detect, Respond, and Predict1. By being proactive, John can anticipate potential threats and vulnerabilities and take steps to mitigate them before they can be exploited. This is in contrast to reactive or retrospective approaches, which deal with threats after they have occurred.The proactive approach is aligned with the Certified Network Defender (CND) program's emphasis on preparing network defenders to identify parts of an organization that need to be reviewed and tested for security vulnerabilities, and how to reduce, prevent, and mitigate risks in the network2345.


EC-Council's Certified Network Defender (CND) course outline and key features2.

Information on the CND certification and its focus on proactive defense strategies3.

Description of the adaptive security strategy, including the proactive approach, from the CND program1.

Details on the protect, detect, respond, and predict approach to network security covered in the CND program4.

Additional insights into the CND training and its emphasis on proactive security measures5.

Question 7

Consider a scenario consisting of a tree network. The root Node N is connected to two man nodes N1 and N2. N1 is connected to N11 and N12. N2 is connected to N21 and N22. What will happen if any one of the main

nodes fail?

Correct Answer: C. Failure of the main node will affect all related child nodes connected to the main node
Explanation:

In a tree network, each node is connected in a hierarchical manner, with the root node at the top. If a main node (such as N1 or N2) fails, all the child nodes connected to it (N11, N12 for N1 and N21, N22 for N2) will be affected because the tree structure relies on the connectivity of the parent node to its children. The failure of a main node will disrupt the transmission path from the root to the child nodes, leading to a loss of connectivity for those child nodes. This is consistent with the principles of network resilience and fault tolerance as outlined in the EC-Council's Certified Network Defender (CND) program, which emphasizes the importance of each node in maintaining the network's overall integrity.


Question 8

Which of the following statements holds true in terms of virtual machines?

Correct Answer: A. Hardware-level virtualization takes place in VMs
Explanation:

Virtual machines (VMs) operate based on hardware-level virtualization, which means they emulate entire hardware systems, including CPUs, memory, and network interfaces, allowing multiple operating systems to run on a single physical machine. Each VM includes a full copy of an operating system, the application, necessary binaries, and libraries - taking up tens of GBs. VMs are completely isolated from the host OS, which is why they do not share the host OS. This is in contrast to containers, which share the host system's kernel and are more lightweight as they do not require a full OS within each container.


Question 9

Which encryption algorithm h used by WPA5 encryption?

Correct Answer: C. AES-GCMP 256
Explanation:

WPA5 is not a standard term used in the industry, and there seems to be a confusion or typo in the question. However, based on the context of Wi-Fi security and encryption, the closest relevant standard is WPA3, which uses AES-GCMP 256 as its encryption algorithm. WPA3 is the successor to WPA2 and provides enhanced security features. It uses the Advanced Encryption Standard (AES) with Galois/Counter Mode Protocol (GCMP) 256-bit encryption, which offers a higher level of security than the previous encryption methods used in WPA2, such as AES-CCMP. AES-GCMP 256 provides robust protection against various attacks and is designed to work efficiently on a wide range of devices, including those with limited processing capabilities.


Question 10

Which of the following helps prevent executing untrusted or untested programs or code from untrusted or unverified third-parties?

Correct Answer: A. Application sandboxing
Explanation:

Application sandboxing is a security mechanism that helps prevent the execution of untrusted or untested programs or code from untrusted or unverified third-parties. It does this by running such programs in a restricted environment, known as a sandbox, where they have limited access to files and system resources. This containment ensures that any malicious code or behavior is isolated from the host system, thereby protecting it from potential harm. Sandboxing is a proactive security measure that can significantly reduce the attack surface and mitigate the risk of security breaches.


Question 11

Which of the following provides a set of voluntary recommended cyber security features to include in network-capable loT devices?

Correct Answer: C. NIST
Explanation:

The National Institute of Standards and Technology (NIST) has released a guide that identifies a set of voluntary recommended cybersecurity features to include in network-capable IoT devices. This guide, known as the ''Core Baseline,'' is intended to assist manufacturers and users by providing practical advice for securing IoT devices that connect to computer networks. The recommendations are designed to mitigate risks to IoT security and are not mandatory rules but rather best practices to follow.


Question 12

Harry has sued the company claiming they made his personal information public on a social networking site in the United States. The company denies the allegations and consulted a/an ______for legal advice to defend

them against this allegation.

Correct Answer: B. Attorney
Explanation:

In the context of legal proceedings, especially when facing allegations of making personal information public, a company would seek the expertise of an attorney. An attorney is qualified to provide legal advice, represent the company in court, and help navigate the complexities of the law regarding data protection and privacy. They would also assist in formulating a defense strategy and ensure that the company's rights are protected throughout the legal process.


Question 13

Which BC/DR activity includes action taken toward resuming all services that are dependent on business-critical applications?

Correct Answer: C. Resumption
Explanation:

In the context of Business Continuity/Disaster Recovery (BC/DR), the activity that includes actions taken toward resuming all services that are dependent on business-critical applications is referred to asResumption. This phase focuses on the steps necessary to bring critical functions back into operation after a disruption. Recovery, on the other hand, is more about the actions taken to return the business to normal operating conditions post-disaster, which may include repairs, restorations, and return to normalcy. Response is the immediate reaction to an incident, and Restoration is the process of rebuilding or restoring IT systems and operations.Reference: The information aligns with the objectives and documents of the EC-Council's Certified Network Defender (CND) program, which emphasizes understanding and implementing proper BC/DR activities.


Question 14

Xenon is a leading real estate firm located in Australi

a. Recently, the company had decided a bid

amount for a prestigious construction project and was sure of being awarded the project. Unfortunately,

the company lost the tender to one of its competitors. A few days later, while performing a network

scan, the network admin identified that somebody had captured the confidential e-mails conversions

related to the tender. Upon further investigation, the admin discovered that one of the switch ports was

left open and an employee had plugged into the network using an Ethernet cable.

Which attack did the employee perform in the above situation?

Correct Answer: A. Network Sniffing
Explanation:

In the scenario described, the employee performed aNetwork Sniffingattack. This type of attack involves capturing and analyzing packets traveling through a network. Since the admin discovered that confidential emails related to the tender were captured and that an open switch port was used to connect to the network, it indicates that the data was intercepted as it traveled across the network, which is characteristic of a sniffing attack. Network sniffing can be either passive or active; however, the scenario suggests a passive approach where the packets were monitored and captured without altering the network traffic.


Question 15

An IT company has just been hit with a severe external security breach. To enhance the company's security posture, the network admin has decided to first block all the services and then individually

enable only the necessary services. What is such an Internet access policy called?

Correct Answer: D. Paranoid Policy
Explanation:

The Paranoid Policy is a type of Internet access policy that is characterized by initially blocking all services and then selectively enabling only those that are necessary. This approach is often taken as a security measure following a severe external breach, as it allows the network administrator to ensure that only essential and secure services are accessible, minimizing potential vulnerabilities.