312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 101:

    Daniel is monitoring network traffic with the help of a network monitoring tool to detect any abnormalities. What type of network security approach is Daniel adopting?

    A. Preventative
    B. Reactive
    C. Retrospective
    D. Defense-in-depth

  • Question 102:

    Which of the following is an intrusion detection system that monitors and analyzes the internals of a computing system rather than the network packets on its external interfaces?

    A. IPS
    B. HIDS
    C. DMZ
    D. NIDS

  • Question 103:

    John works Incident Director of Tech World Inc. His job is to set up a wireless network in his organization. For this purpose, he needs to decide on appropriate equipment and policies need to set up a network. Which of the following stages of the incident handling process to help him accomplish the task?

    A. Preparation
    B. None
    C. Recovery
    D. the eradication of
    E. containment

  • Question 104:

    What should an administrator do while installing a sniffer on a system to listen to all data transmitted over the network?

    A. Set the system's NIC to managed mode
    B. Set the system's NIC to master mode
    C. Set the system's NIC to ad-hoc mode
    D. Set the system's NIC to promiscuous mode

  • Question 105:

    The attacks are classified as which of the following? Each correct answer represents a complete solution. Choose all that apply.

    A. replay attack
    B. active attack
    C. session hijacking
    D. passive attack

  • Question 106:

    Ivan needs to pick an encryption method that is scalable even though it might be slower. He has settled on a method that works where one key is public and the other is private. What encryption method did Ivan settle on?

    A. Ivan settled on the hashing encryption method.
    B. Ivan settled on the asymmetric encryption method.
    C. Ivan settled on the private encryption method.
    D. Ivan settled on the symmetric encryption method.

  • Question 107:

    Which of the following is a presentation layer protocol?

    A. TCP
    B. RPC
    C. BGP
    D. LWAPP

  • Question 108:

    You are responsible for network functions and logical security throughout the corporation. Your company has over 250 servers running Windows Server 2012, 5000 workstations running Windows 10, and 200 mobile users working from laptops on Windows 8. Last week 10 of your company's laptops were stolen from a salesman, while at a conference in Barcelona. These laptops contained proprietary company information. While doing a damage assessment, a news story leaks about a blog post containing information about the stolen laptops and the sensitive information. What built-in Windows feature could you have implemented to protect the sensitive information on these laptops?

    A. You should have used 3DES.
    B. You should have implemented the Distributed File System (DFS).
    C. If you would have implemented Pretty Good Privacy (PGP).
    D. You could have implemented the Encrypted File System (EFS)

  • Question 109:

    Kyle is an IT consultant working on a contract for a large energy company in Houston. Kyle was hired on to do contract work three weeks ago so the company could prepare for an external IT security audit. With suggestions from upper management, Kyle has installed a network-based IDS system. This system checks for abnormal behavior and patterns found in network traffic that appear to be dissimilar from the traffic normally recorded by the IDS. What type of detection is this network-based IDS system using?

    A. This network-based IDS system is using anomaly detection.
    B. This network-based IDS system is using dissimilarity algorithms.
    C. This system is using misuse detection.
    D. This network-based IDS is utilizing definition-based detection.

  • Question 110:

    Which of the following tools is an open source protocol analyzer that can capture traffic in real time?

    A. NetResident
    B. Wireshark
    C. Bridle
    D. NetWitness
    E. None

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.