312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 231:

    The Circuit-level gateway firewall technology functions at which of the following OSI layer?

    A. Transport layer
    B. Data-link layer
    C. Session layer
    D. Network layer

  • Question 232:

    James wants to implement certain control measures to prevent denial-of-service attacks against the organization. Which of the following control measures can help James?

    A. Strong passwords
    B. Reduce the sessions time-out duration for the connection attempts
    C. A honeypot in DMZ
    D. Provide network-based anti-virus

  • Question 233:

    Which of the following protocols is a method for implementing virtual private networks?

    A. SSL
    B. PPTP
    C. TLS
    D. SNMP

  • Question 234:

    John works as an Ethical Hacker for www.company.com Inc. He wants to find out the ports that are open in www.company.com's server using a port scanner. However, he does not want to establish a full TCP connection. Which of the following scanning techniques will he use to accomplish this task?

    A. TCP SYN
    B. Xmas tree
    C. TCP SYN/ACK
    D. TCP FIN

  • Question 235:

    Mark is monitoring the network traffic on his organization's network. He wants to detect TCP and UDP ping sweeps on his network. Which type of filter will be used to detect this?

    A. tcp.dstport==7 and udp.srcport==7
    B. tcp.srcport==7 and udp.dstport==7
    C. tcp.dstport==7 and udp.dstport==7
    D. tcp.srcport==7 and udp.srcport==7

  • Question 236:

    Chris is a senior network administrator. Chris wants to measure the Key Risk Indicator (KRI) to assess the organization. Why is Chris calculating the KRI for his organization? It helps Chris to:

    A. Identifies adverse events
    B. Facilitates backward viewing
    C. Notifies when risk has reached threshold levels
    D. Facilitates post incident management

  • Question 237:

    Which of the following statements are TRUE about Demilitarized zone (DMZ)? Each correct answer represents a complete solution. Choose all that apply.

    A. The purpose of a DMZ is to add an additional layer of security to the Local Area Network of an organization.
    B. Hosts in the DMZ have full connectivity to specific hosts in the internal network.
    C. Demilitarized zone is a physical or logical sub-network that contains and exposes external services of an organization to a larger un-trusted network.
    D. In a DMZ configuration, most computers on the LAN run behind a firewall connected to a public network like the Internet.

  • Question 238:

    Which of the following is a physical security device designed to entrap a person on purpose?

    A. Mantrap
    B. Trap
    C. War Flying
    D. War Chalking

  • Question 239:

    Liza was told by her network administrator that they will be implementing IPsec VPN tunnels to connect the branch locations to the main office. What layer of the OSI model do IPsec tunnels function on?

    A. The data link layer
    B. The session layer
    C. The network layer
    D. The application and physical layers

  • Question 240:

    Steven's company has recently grown from 5 employees to over 50. Every workstation has a public IP address and navigated to the Internet with little to no protection. Steven wants to use a firewall. He also wants IP addresses to be private

    addresses, to prevent public Internet devices direct access to them. What should Steven implement on the firewall to ensure this happens?

    A. Steven should use Open Shortest Path First (OSPF).
    B. Steven should enable Network Address Translation (NAT).
    C. Steven should use a Demilitarized Zone (DMZ).
    D. Steven should use IPsec.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.