EC-Council · CND
Validates the ability to protect, detect, and respond to network security threats, covering network perimeter protection, endpoint security, firewall and IDS/VPN configuration, network traffic analysis, vulnerability scanning, and incident response.
Practice Questions
562
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
AssociateLast Updated
Feb 2026
Use this CND practice exam to prepare for Certified Network Defender (CND) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 562 questions for EC-Council CND, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The EC-Council Certified Network Defender (CND) is a vendor-neutral, skills-based certification that validates a professional's ability to protect, detect, respond to, and predict network security threats. Exam code 312-38, the certification covers a broad range of network defense disciplines including network perimeter protection, endpoint security across Windows, Linux, mobile, and IoT platforms, firewall and IDS/VPN configuration, network traffic and log analysis, vulnerability scanning, and incident response. The program was updated with a v4 exam blueprint effective April 10, 2024, which introduced new topic segmentation and refreshed domain content while maintaining the same exam format and eligibility criteria.
Built on the cybersecurity education framework established by the National Initiative of Cybersecurity Education (NICE) and mapped to Department of Defense (DoD) work roles for system and network administrators, CND emphasizes real-world, job-task-aligned competencies. The certification spans 20 knowledge domains that collectively address the full lifecycle of enterprise network defense — from administrative governance and compliance to cloud security, wireless security, threat intelligence, and business continuity. It holds accreditation from ANSI, GCHQ, and is approved under the DoD 8570/8140 directive.
CND is designed primarily for network and security professionals who are responsible for the day-to-day protection of enterprise network infrastructure. Core target roles include Network Administrators, Security Administrators, Network Security Engineers, Security Analysts, and Network Defense Technicians. The certification is also relevant to IT professionals transitioning into security-focused roles who already have a foundational understanding of networking.
The program is particularly well-suited for individuals working in environments requiring regulatory compliance or DoD-aligned security frameworks. Those seeking to formalize their hands-on network defense skills with a recognized credential, or professionals aiming to qualify for cybersecurity roles within U.S. government contractors and defense agencies, will find the CND especially applicable.
EC-Council does not impose formal academic prerequisites for the CND exam, but candidates must meet one of two eligibility paths. The first is to complete an official EC-Council-authorized CND training course, after which candidates may sit for the exam without further application. The second path allows candidates to attempt the exam without attending official training, provided they can demonstrate at least two years of work experience in the information security domain. Self-study candidates must submit an eligibility application form along with a non-refundable $100 USD processing fee.
In terms of recommended knowledge, candidates should have a solid understanding of TCP/IP networking fundamentals, familiarity with common network devices and protocols, and basic exposure to operating system administration (Windows and Linux). Prior experience with network monitoring tools, firewall configuration, or security operations will provide a meaningful advantage when preparing for the exam.
The CND certification exam (312-38) consists of 100 multiple-choice questions and must be completed within 4 hours (240 minutes). The exam is delivered through the EC-Council ECC Exam Portal and is available at authorized testing centers as well as via online proctoring. The passing score is set at 70%, though EC-Council notes that cut scores can range from 60% to 85% depending on the specific exam form administered, as each form is independently calibrated by subject matter experts to ensure consistent difficulty across versions.
The exam uses multiple exam forms with varied question banks to maintain exam integrity. There are no unscored pilot questions disclosed. Candidates who do not pass may retake the exam immediately for the second attempt using an ECC Exam Center voucher; a 14-day waiting period is enforced starting from the third attempt onward. The current exam is aligned to the CND v4 blueprint, which became effective on April 10, 2024.
The CND certification qualifies holders for network defense and security operations roles in both private industry and government sectors. Common job titles pursued after earning CND include Network Security Engineer, Security Operations Center (SOC) Analyst, Network Administrator (security-focused), and Information Systems Security Officer (ISSO). The certification satisfies DoD 8570.01-M/DoD 8140 requirements for IAT Level II roles, making it directly applicable for personnel seeking positions with U.S. federal agencies or defense contractors. The average salary for a network security engineer in the United States is approximately $125,000 per year.
Compared to alternatives such as CompTIA Security+ (broader but less network-defense-specific) or the Cisco CyberOps Associate (more SOC-focused), CND occupies a distinct niche in hands-on, defender-oriented network security. It complements offensive certifications like CEH and is often pursued alongside or as a precursor to more advanced credentials such as CISSP or CCNP Security. The certification's ANSI accreditation and GCHQ endorsement give it international recognition beyond the U.S. market.
5 sample questions with answers and explanations. The full bank has 562 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A disaster recovery plan for a financial services application specifies Recovery Time Objective (RTO) of 2 hours and Work Recovery Time (WRT) of 1 hour. What is the Maximum Tolerable Downtime (MTD) for this application? (Select one!)
Explanation
Maximum Tolerable Downtime equals RTO plus WRT. MTD equals 2 hours plus 1 hour equals 3 hours total allowable downtime. RTO represents time to restore systems and data, while WRT covers verification and resumption of normal operations. The relationship MTD equals RTO plus WRT ensures business continuity planning accounts for complete recovery including testing. Organizations must design disaster recovery solutions where RTO meets business requirements with sufficient buffer for work recovery activities. Financial services typically require low MTD values due to regulatory requirements and revenue impact. Understanding this relationship guides selection of hot, warm, or cold site strategies and backup technologies to meet recovery objectives.
2. A security analyst investigates a compromised Windows workstation and discovers that malware established persistence using the registry. Which Windows Event ID would most likely indicate that a new Run key was created for persistence? (Select one!)
Explanation
Event ID 4657 indicates that a registry value was modified, which would capture the creation of persistence mechanisms in registry Run keys like HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run. Event ID 4624 indicates successful logon. Event ID 4688 indicates process creation but not registry modifications. Event ID 1102 indicates audit log clearing, which is evidence tampering rather than persistence establishment. Monitoring registry modifications is critical for detecting persistence mechanisms.
3. A security architect performs quantitative risk assessment for a database server valued at $800,000. A flood event would destroy 70% of the server value and occurs on average once every 5 years. What is the Annual Loss Expectancy (ALE) for this risk? (Select one!)
Explanation
Annual Loss Expectancy is calculated using the formula ALE = SLE × ARO. First calculate Single Loss Expectancy: SLE = Asset Value × Exposure Factor = $800,000 × 0.70 = $560,000. The flood occurs once every 5 years, so Annualized Rate of Occurrence = 1/5 = 0.20. Therefore ALE = $560,000 × 0.20 = $112,000 per year. This represents the average annual cost of this risk. $160,000 would be incorrect calculations. $560,000 is the SLE, not ALE. $800,000 is the total asset value.
4. A security operations center deploys OSSEC HIDS across 200 Linux and Windows servers. The SOC manager needs to configure centralized log collection and analysis. Which port and protocol does OSSEC use for agent-to-manager communication? (Select one!)
Explanation
OSSEC uses port 1514 UDP for agent-to-manager communication to send log data, file integrity monitoring events, and security alerts to the central OSSEC manager server. This UDP-based protocol provides efficient transmission of security events from distributed agents. Port 514 UDP is used by traditional syslog protocol. Ports 5514 and 10514 TCP are not standard OSSEC communication ports. The manager aggregates data from all agents, applies correlation rules, and generates consolidated security alerts for the SOC team.
5. A security analyst uses Wireshark to investigate potential DNS tunneling exfiltration. Which display filter will identify DNS queries with suspiciously long domain names typically used for data exfiltration? (Select one!)
Explanation
DNS tunneling encodes data within subdomain labels creating abnormally long query names often exceeding 50 characters. The filter dns.qry.name.len greater than 50 identifies queries with excessive length characteristic of tunneling tools encoding data as subdomain strings. The dns.flags.response filter shows DNS responses not queries making it unsuitable for detecting outbound tunneling. The dns.qry.type == 16 filter shows TXT record queries which can be used for tunneling but misses A record tunneling and generates false positives from legitimate TXT queries. The frame.len filter examines total packet size not specifically domain name length.
Certified EC-Council Instructor (CEI)
CEI · 611 questions
Computer Hacking Forensic Investigator (CHFI)
CHFI · 589 questions
Certified Cloud Security Engineer (CCSE)
CCSE · 624 questions
Certified Cybersecurity Technician (CCT)
212-82 · 630 questions
EC-Council Certified DevSecOps Engineer (ECDE) v2
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
$17.99
One-time access to this exam