312-38 Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :May 29, 2026

EC-COUNCIL 312-38 Online Questions & Answers

  • Question 501:

    Which of the following is a management process that provides a framework for promoting quick recovery and the capability for an effective response to protect the interests of its brand, reputation, and stakeholders?

    A. Log analysis
    B. Patch management
    C. Incident handling
    D. Business Continuity Management

  • Question 502:

    Which among the following filter is used to detect a SYN/FIN attack?

    A. tcp.flags==0x002
    B. tcp.flags==0x004
    C. tcp.flags==0x003
    D. tcp.flags==0x001

  • Question 503:

    Which of the following systems includes an independent NAS Head and multiple storage arrays?

    A. FreeNAS
    B. None of these
    C. Gateway NAS System
    D. Integrated NAS System

  • Question 504:

    John wants to implement a firewall service that works at the session layer of the OSI model. The firewall must also have the ability to hide the private network information. Which type of firewall service is John thinking of implementing?

    A. Packet Filtering
    B. Circuit level gateway
    C. Application level gateway
    D. Stateful Multilayer Inspection

  • Question 505:

    Management wants to bring their organization into compliance with the ISO standard for information security risk management. Which ISO standard will management decide to implement?

    A. ISO/IEC 27005
    B. ISO/IEC 27006
    C. ISO/IEC 27002
    D. ISO/IEC 27004

  • Question 506:

    Based on which of the following registry key, the Windows Event log audit configurations are recorded?

    A. HKEY_LOCAL_MACHINE\SYSTEM\Services\EventLog\ < ErrDev >
    B. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\EventLog\ < EntAppsvc >
    C. HKEY_LOCAL_MACHINE\CurrentControlSet\Services\EventLog\< ESENT >
    D. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\ < Event Log >

  • Question 507:

    Which of the following is the type of documented business rule for protecting information and the systems, which store and process the information

    A. Information protection policy
    B. Information protection document
    C. Information storage policy
    D. Information security policy

  • Question 508:

    Which of the following is a tool that runs on the Windows OS and analyzes iptables log messages to detect port scans and other suspicious traffic?

    A. PSAD
    B. Hping
    C. NetRanger
    D. Nmap

  • Question 509:

    Which of the following UTP cables supports transmission up to 20MHz?

    A. Category 2
    B. Category 5e
    C. Category 4
    D. Category 1

  • Question 510:

    Which of the following protocols supports source-specific multicast (SSM)?

    A. DHCP
    B. ARP
    C. DNS
    D. BGMP

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.