EC-Council · CND
Validates the ability to protect, detect, and respond to network security threats, covering network perimeter protection, endpoint security, firewall and IDS/VPN configuration, network traffic analysis, vulnerability scanning, and incident response.
Practice Questions
562
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Feb 2026
Use this CND practice exam to prepare for Certified Network Defender (CND) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 562 questions for EC-Council CND, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The EC-Council Certified Network Defender (CND) is a vendor-neutral, skills-based certification that validates a professional's ability to protect, detect, respond to, and predict network security threats. Exam code 312-38, the certification covers a broad range of network defense disciplines including network perimeter protection, endpoint security across Windows, Linux, mobile, and IoT platforms, firewall and IDS/VPN configuration, network traffic and log analysis, vulnerability scanning, and incident response. The program was updated with a v4 exam blueprint effective April 10, 2024, which introduced new topic segmentation and refreshed domain content while maintaining the same exam format and eligibility criteria.
Built on the cybersecurity education framework established by the National Initiative of Cybersecurity Education (NICE) and mapped to Department of Defense (DoD) work roles for system and network administrators, CND emphasizes real-world, job-task-aligned competencies. The certification spans 20 knowledge domains that collectively address the full lifecycle of enterprise network defense — from administrative governance and compliance to cloud security, wireless security, threat intelligence, and business continuity. It holds accreditation from ANSI, GCHQ, and is approved under the DoD 8570/8140 directive.
CND is designed primarily for network and security professionals who are responsible for the day-to-day protection of enterprise network infrastructure. Core target roles include Network Administrators, Security Administrators, Network Security Engineers, Security Analysts, and Network Defense Technicians. The certification is also relevant to IT professionals transitioning into security-focused roles who already have a foundational understanding of networking.
The program is particularly well-suited for individuals working in environments requiring regulatory compliance or DoD-aligned security frameworks. Those seeking to formalize their hands-on network defense skills with a recognized credential, or professionals aiming to qualify for cybersecurity roles within U.S. government contractors and defense agencies, will find the CND especially applicable.
EC-Council does not impose formal academic prerequisites for the CND exam, but candidates must meet one of two eligibility paths. The first is to complete an official EC-Council-authorized CND training course, after which candidates may sit for the exam without further application. The second path allows candidates to attempt the exam without attending official training, provided they can demonstrate at least two years of work experience in the information security domain. Self-study candidates must submit an eligibility application form along with a non-refundable $100 USD processing fee.
In terms of recommended knowledge, candidates should have a solid understanding of TCP/IP networking fundamentals, familiarity with common network devices and protocols, and basic exposure to operating system administration (Windows and Linux). Prior experience with network monitoring tools, firewall configuration, or security operations will provide a meaningful advantage when preparing for the exam.
The CND certification exam (312-38) consists of 100 multiple-choice questions and must be completed within 4 hours (240 minutes). The exam is delivered through the EC-Council ECC Exam Portal and is available at authorized testing centers as well as via online proctoring. The passing score is set at 70%, though EC-Council notes that cut scores can range from 60% to 85% depending on the specific exam form administered, as each form is independently calibrated by subject matter experts to ensure consistent difficulty across versions.
The exam uses multiple exam forms with varied question banks to maintain exam integrity. There are no unscored pilot questions disclosed. Candidates who do not pass may retake the exam immediately for the second attempt using an ECC Exam Center voucher; a 14-day waiting period is enforced starting from the third attempt onward. The current exam is aligned to the CND v4 blueprint, which became effective on April 10, 2024.
The CND certification qualifies holders for network defense and security operations roles in both private industry and government sectors. Common job titles pursued after earning CND include Network Security Engineer, Security Operations Center (SOC) Analyst, Network Administrator (security-focused), and Information Systems Security Officer (ISSO). The certification satisfies DoD 8570.01-M/DoD 8140 requirements for IAT Level II roles, making it directly applicable for personnel seeking positions with U.S. federal agencies or defense contractors. The average salary for a network security engineer in the United States is approximately $125,000 per year.
Compared to alternatives such as CompTIA Security+ (broader but less network-defense-specific) or the Cisco CyberOps Associate (more SOC-focused), CND occupies a distinct niche in hands-on, defender-oriented network security. It complements offensive certifications like CEH and is often pursued alongside or as a precursor to more advanced credentials such as CISSP or CCNP Security. The certification's ANSI accreditation and GCHQ endorsement give it international recognition beyond the U.S. market.
5 sample questions with answers and explanations. The full bank has 562 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A security architect designs network segmentation for a financial application with web servers in a DMZ, application servers in an internal zone, and database servers in a data tier. Following defense-in-depth and least privilege principles, which firewall rule set provides the most secure configuration? (Select one!)
Explanation
Defense-in-depth requires unidirectional traffic flow with explicit least privilege access. This configuration allows Internet users to access only the DMZ web servers on HTTPS port 443, prevents direct access to internal tiers, permits only necessary communication between adjacent tiers on specific ports, and explicitly denies all other traffic by default. This implements multiple security layers where each tier can only initiate connections to the next tier for required services. Allowing database servers to initiate return connections violates unidirectional flow principles and could allow compromised database servers to attack application servers. Bidirectional rules using double arrows and permitting DMZ Internet access create unnecessary attack surface and potential data exfiltration paths. Allowing direct Internet access to internal application and database tiers completely bypasses the DMZ protection layer and violates network segmentation principles. Any-to-any rules within network segments provide no access control and allow lateral movement after initial compromise.
2. A Windows domain administrator investigates unusual account activity after receiving alerts from the security monitoring system. The investigation focuses on determining if an attacker performed a Pass-the-Hash attack to authenticate using stolen NTLM credentials without cracking the password. Which Windows Security Event ID specifically indicates NTLM authentication attempts that could reveal Pass-the-Hash activity? (Select one!)
Explanation
Event ID 4776 is generated on the authenticating server when NTLM authentication is attempted and specifically logs the workstation name and authentication package used. This event is critical for detecting Pass-the-Hash attacks which rely on NTLM authentication. Event ID 4624 shows successful logons but does not distinguish between Kerberos and NTLM authentication methods. Event ID 4768 indicates Kerberos ticket requests, but Pass-the-Hash attacks bypass Kerberos and use NTLM directly. Event ID 4672 shows privilege assignment but does not reveal the authentication protocol used.
3. A compliance officer ensures GDPR compliance for an EU-based organization processing customer personal data. The organization discovers a data breach affecting 10000 customers' personal information. What is the maximum timeframe for notifying the supervisory authority? (Select one!)
Explanation
GDPR Article 33 requires organizations to notify the supervisory authority within 72 hours of becoming aware of a personal data breach, unless unlikely to result in risk to individuals' rights and freedoms. Affected individuals must be notified without undue delay if the breach poses high risk. The 72-hour timeframe is mandatory, with documentation required if delays occur explaining reasons. HIPAA requires 60 days for individual notification. The tight GDPR timeframe necessitates incident response plans with clear breach identification, assessment, and notification procedures. Non-compliance incurs penalties up to 20 million euros or 4 percent global annual turnover, whichever is higher, emphasizing the importance of rapid breach response capabilities.
4. A security analyst investigates Kerberos authentication logs to detect potential Kerberoasting attacks. The analyst needs to identify when attackers request service tickets for accounts with Service Principal Names to perform offline password cracking. Which Windows Security Event ID indicates a Kerberos service ticket was requested? (Select one!)
Explanation
Event ID 4769 logs when a Kerberos service ticket is requested from the Ticket Granting Server. Kerberoasting attacks generate numerous 4769 events as attackers request service tickets for SPN-enabled accounts to crack offline. Event ID 4768 logs initial TGT requests during user authentication. Event ID 4771 indicates failed Kerberos pre-authentication, often from bad passwords. Event ID 4776 relates to NTLM authentication attempts, not Kerberos.
5. An incident responder uses Volatility Framework to analyze a memory dump from a compromised Windows 10 workstation. The analyst needs to identify malicious processes that may be hidden by rootkit techniques and reconstruct their parent-child relationships. Which two Volatility plugins should the analyst execute to detect process hiding and visualize process hierarchy? (Select two!)
Multiple correct answersExplanation
pstree visualizes parent-child process relationships showing process hierarchy and detecting suspicious process trees indicative of malware spawning mechanisms. psscan performs pool tag scanning to find EPOOL process structures that rootkits hide from normal enumeration, detecting hidden processes that pslist misses. pslist only traverses the standard doubly-linked list which rootkits manipulate to hide processes. netscan identifies network connections but doesn't address process hiding. cmdscan extracts command history, useful for investigation but not for detecting hidden processes or visualizing hierarchy.
Certified EC-Council Instructor (CEI)
CEI · 611 questions
Computer Hacking Forensic Investigator (CHFI)
CHFI · 589 questions
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
Certified Cybersecurity Technician (CCT)
CCT · 630 questions
Certified DevSecOps Engineer (ECDE)
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
$17.99
One-time access to this exam