312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 291:

    Eric is receiving complaints from employees that their systems are very slow and experiencing odd issues including restarting automatically and frequent system hangs. Upon investigating, he is convinced the systems are infected with a virus that forces systems to shut down automatically after period of time. What type of security incident are the employees a victim of?

    A. Scans and probes
    B. Malicious Code
    C. Denial of service
    D. Distributed denial of service

  • Question 292:

    What is the response of an Xmas scan if a port is either open or filtered?

    A. RST
    B. No response
    C. FIN
    D. PUSH

  • Question 293:

    Ryan works as a network security engineer at an organization the recently suffered an attack. As a countermeasure, Ryan would like to obtain more information about the attacker and chooses to deploy a honeypot into the organizations production environment called Kojoney. Using this honeypot, he would like to emulate the network vulnerability that was attacked previously. Which type of honeypot is he trying to implement?

    A. High interaction honeypots
    B. Research honeypot
    C. Low interaction honeypots
    D. Pure honeypots

  • Question 294:

    How is a "risk" represented?

    A. Asset + threat
    B. Motive (goal) + method
    C. Asset + threat + vulnerability
    D. Motive (goal) + method + vulnerability

  • Question 295:

    In which of the following types of port scans does the scanner attempt to connect to all 65535 ports?

    A. UDP
    B. Strobe
    C. FTP bounce
    D. Vanilla

  • Question 296:

    A US-based organization decided to implement a RAID storage technology for their data backup plan. John wants to setup a RAID level that requires a minimum of six drives but will meet high fault tolerance and with a high speed for the data read and write operations. What RAID level will John need to choose to meet this requirement?

    A. RAID level 50
    B. RAID level 1
    C. RAID level 10
    D. RAID level 5

  • Question 297:

    Which of the following statements holds true in terms of virtual machines?

    A. Hardware-level virtualization takes place in VMs
    B. OS-level virtualization takes place in VMs
    C. All VMs share the host OS
    D. VMs are light weight than containers

  • Question 298:

    Which of the following is a network analysis tool that sends packets with nontraditional IP stack parameters?

    A. Nessus
    B. COPS
    C. SAINT
    D. HPing

  • Question 299:

    Which of the following is used in conjunction with smoke detectors and fire alarm systems to improve and increase public safety?

    A. Gaseous fire suppression
    B. Gaseous emission system
    C. Fire sprinkler
    D. Fire suppression system

  • Question 300:

    The _________ mechanism works on the basis of a client-server model.

    A. Push-based
    B. Host-based
    C. Pull-based
    D. Network-based

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.