Exam Details

  • Exam Code
    :312-38
  • Exam Name
    :EC-Council Certified Network Defender (CND)
  • Certification
    :EC-COUNCIL Certifications
  • Vendor
    :EC-COUNCIL
  • Total Questions
    :653 Q&As
  • Last Updated
    :Apr 12, 2025

EC-COUNCIL EC-COUNCIL Certifications 312-38 Questions & Answers

  • Question 151:

    Simon had all his systems administrators implement hardware and software firewalls to ensure network security. They implemented IDS/IPS systems throughout the network to check for and stop any unauthorized traffic that may attempt to enter. Although Simon and his administrators believed they were secure, a hacker group was able to get into the network and modify files hosted on the company's website. After searching through the firewall and server logs, no one could find how the attackers were able to get in. He decides that the entire network needs to be monitored for critical and essential file changes. This monitoring tool alerts administrators when a critical file is altered. What tool could Simon and his administrators implement to accomplish this?

    A. They need to use Nessus.

    B. Snort is the best tool for their situation.

    C. They could use Tripwire.

    D. They can implement Wireshark.

  • Question 152:

    Chris is a senior network administrator. Chris wants to measure the Key Risk Indicator (KRI) to assess the organization. Why is Chris calculating the KRI for his organization? It helps Chris to:

    A. Identifies adverse events

    B. Facilitates backward viewing

    C. Notifies when risk has reached threshold levels

    D. Facilitates post incident management

  • Question 153:

    Which Event Correlation Approach checks and compares all the fields systematically and intentionally for positive and negative correlation with each other to determine the correlation across one or multiple fields?

    A. Rule-Based Approach

    B. Graph-Based Approach

    C. Field-Based Approach

    D. Automated Field Correlation

  • Question 154:

    Bryson is the IT manager and sole IT employee working for a federal agency in California. The agency was just given a grant and was able to hire on 30 more employees for a new extended project. Because of this, Bryson has hired on two more IT employees to train up and work. Both of his new hires are straight out of college and do not have any practical IT experience. Bryson has spent the last two weeks teaching the new employees the basics of computers, networking, troubleshooting techniques etc. To see how these two new hires are doing, he asks them at what layer of the OSI model do Network Interface Cards (NIC) work on. What should the new employees answer?

    A. They should answer with the Presentation layer.

    B. NICs work on the Session layer of the OSI model.

    C. They should tell Bryson that NICs perform on the Physical layer.

    D. The new employees should say that NICs perform on the Network layer.

  • Question 155:

    A US-based organization decided to implement a RAID storage technology for their data backup plan. John wants to setup a RAID level that requires a minimum of six drives but will meet high fault tolerance and with a high speed for the data read and write operations. What RAID level will John need to choose to meet this requirement?

    A. RAID level 50

    B. RAID level 1

    C. RAID level 10

    D. RAID level 5

  • Question 156:

    Ivan needs to pick an encryption method that is scalable even though it might be slower. He has settled on a method that works where one key is public and the other is private. What encryption method did Ivan settle on?

    A. Ivan settled on the hashing encryption method.

    B. Ivan settled on the asymmetric encryption method.

    C. Ivan settled on the private encryption method.

    D. Ivan settled on the symmetric encryption method.

  • Question 157:

    Identify the spread spectrum technique that multiplies the original data signal with a pseudo random noise spreading code.

    A. ISM

    B. FHSS

    C. DSSS

    D. OFDM

  • Question 158:

    Katie has implemented the RAID level that splits data into blocks and evenly writes the data to multiple hard drives but does not provide data redundancy. This type of RAID level requires a minimum of __________ in order to setup.

    A. Two drives

    B. Three drives

    C. Six drives

    D. Four drives

  • Question 159:

    Geon Solutions INC., had only 10 employees when it started. But as business grew, the organization had to increase the amount of staff. The network administrator is finding it difficult to accommodate an increasing number of employees in the existing network topology. So the organization is planning to implement a new topology where it will be easy to accommodate an increasing number of employees. Which network topology will help the administrator solve the problem of needing to add new employees and expand?

    A. Mesh

    B. Ring

    C. Bus

    D. Star

  • Question 160:

    The agency Jacob works for stores and transmits vast amounts of sensitive government data that cannot be compromised. Jacob has implemented Encapsulating Security Payload (ESP) to encrypt IP traffic. Jacob wants to encrypt the IP traffic by inserting the ESP header in the IP datagram before the transport layer protocol header. What mode of ESP does Jacob need to use to encrypt the IP traffic?

    A. Jacob should use ESP in pass-through mode.

    B. Jacob should utilize ESP in tunnel mode.

    C. He should use ESP in gateway mode.

    D. He should use ESP in transport mode.

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only EC-COUNCIL exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your 312-38 exam preparations and EC-COUNCIL certification application, do not hesitate to visit our Vcedump.com to find your solutions here.