312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 491:

    Sean has built a site-to-site VPN architecture between the head office and the branch office of his company. When users in the branch office and head office try to communicate with each other, the traffic is encapsulated. As the traffic passes though the gateway, it is encapsulated again. The header and payload both are encapsulated. This second encapsulation occurs only in the __________ implementation of a VPN.

    A. Point-to-Point Mode
    B. Transport Mode
    C. Tunnel Mode
    D. Full Mesh Mode

  • Question 492:

    Cindy is the network security administrator for her company. She just got back from a security conference in Las Vegas where they talked about all kinds of old and new security threats; many of which she did not know of. She is worried about the current security state of her company's network so she decides to start scanning the network from an external IP address. To see how some of the hosts on her network react, she sends out SYN packets to an IP range. A number of IPs respond with a SYN/ACK response. Before the connection is established, she sends RST packets to those hosts to stop the session. She has done this to see how her intrusion detection system will log the traffic. What type of scan is Cindy attempting here?

    A. The type of scan she is using is called a NULL scan.
    B. Cindy is attempting to find live hosts on her company's network by using a XMAS scan.
    C. Cindy is using a half-open scan to find live hosts on her network.
    D. She is utilizing a RST scan to find live hosts that are listening on her network.

  • Question 493:

    Which of the following filters can be used to detect UDP scan attempts using Wireshark?

    A. icmp.type==3 and icmp.code==3
    B. icmp.type==13
    C. icmp.type==8 or icmp.type==0
    D. icmp.type==15

  • Question 494:

    Which of the following is a software tool used in passive attacks for capturing network traffic?

    A. Sniffer
    B. Intrusion detection system
    C. Intrusion prevention system
    D. Warchalking

  • Question 495:

    Which of the following steps will NOT make a server fault tolerant? Each correct answer represents a complete solution. (Choose two.)

    A. Adding a second power supply unit
    B. Performing regular backup of the server
    C. Adding one more same sized disk as mirror on the server
    D. Implementing cluster servers' facility
    E. Encrypting confidential data stored on the server

  • Question 496:

    In which of the following conditions does the system enter ROM monitor mode? Each correct answer represents a complete solution. Choose all that apply.

    A. The router does not have a configuration file.
    B. There is a need to set operating parameters.
    C. The user interrupts the boot sequence.
    D. The router does not find a valid operating system image.

  • Question 497:

    During the recovery process, RTO and RPO should be the main parameters of your disaster recovery plan. What does RPO refer to?

    A. The encryption feature, acting as add-on security to the data
    B. The hot plugging technique used to replace computer components
    C. The duration required to restore the data
    D. The interval after which the data quality is lost

  • Question 498:

    Which of the following protocols is described as a connection-oriented and reliable delivery transport layer protocol?

    A. UDP
    B. IP
    C. SSL
    D. TCP

  • Question 499:

    John has planned to update all Linux workstations in his network. The organization is using various Linux distributions including Red hat, Fedora and Debian. Which of following commands will he use to update each respective Linux distribution?

    A. 1-ii, 2-i,3-iv,4-iii
    B. 1-v,2-iii,3-i,4-iv
    C. 1-iv,2-v,3-iv,4-iii
    D. 1-iii,2-iv,3-ii,4-v

  • Question 500:

    Which of the following types of transmission is the process of sending one bit at a time over a single transmission line?

    A. Unicast transmission
    B. Serial data transmission
    C. Multicast transmission
    D. Parallel data transmission

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.