Certified Network Defender Exam Prep
Free practice questions

Free CND Practice Questions

10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.

Start the free practice test → ★★★★★4.9/5 from 2,400+ candidates · No signup

The CND exam has 100 questions and runs 4 hours.

These 10 free CND questions are organized by exam domain, so you can see how each part of the Certified Network Defender blueprint is tested. Reveal the answer and explanation under each question.

Domain 1: Network Defense Management 10% of exam

Question 1

The Internet provider confirms that a distributed UDP flood is saturating a company's 1-Gbit/s access circuit before traffic reaches the company firewall. The firewall's CPU and connection table remain well below capacity, yet legitimate customers cannot reach the website. Which mitigation addresses the bottleneck responsible for the outage?

Show answer & explanation

Correct answer: D - Activate upstream filtering or traffic scrubbing with the Internet provider.

Domain 2: Network Perimeter Protection 10% of exam

Question 2

Only administrators in 10.40.8.0/24 should reach an internal server over SSH, but users elsewhere in 10.40.0.0/16 can also connect. The firewall applies the first matching rule to each new connection: 10: ALLOW TCP 10.40.0.0/16 -> 10.60.2.10, destination port 22 20: DENY TCP any -> 10.60.2.10, destination port 22 30: DENY all other traffic Which single edit enforces the intended policy without locking out the authorized administrators?

Show answer & explanation

Correct answer: B - Change the source in rule 10 from 10.40.0.0/16 to 10.40.8.0/24.

Domain 3: Endpoint Protection 20% of exam

Question 3

A penetration test shows that a local administrator's password hash recovered from one Windows workstation can authenticate to several others without the password being cracked. Those workstations share the same local administrator password. Remote support still requires a recoverable local administrator account. Which change most directly breaks this credential-reuse path?

Show answer & explanation

Correct answer: D - Manage unique local administrator passwords with Windows LAPS.

Question 4

On a Linux server, /srv/drop is owned by root and group analysts, with mode 0770. Each analyst creates files owned by their own account with mode 0600. The analysts have no elevated privileges, and no additional access-control lists apply. They cannot read one another's files, but they can delete them. Choose the change that prevents deletion of another analyst's files while preserving each analyst's ability to create and remove their own files.

Show answer & explanation

Correct answer: C - Change /srv/drop to mode 1770.

Domain 4: Application and Data Protection 10% of exam

Question 5

An authenticated customer changes only the numeric invoice ID in a request sent directly to a portal and receives another customer's invoice. The endpoint uses parameterized database queries. Which defect explains the unauthorized disclosure?

Show answer & explanation

Correct answer: B - Missing object-level authorization

Domain 5: Enterprise Virtual, Cloud, and Wireless Network Protection 15% of exam

Question 6

During an authorized wireless assessment, a test access point advertises the corporate SSID. Managed laptops accept the test RADIUS server's certificate and proceed to PEAP inner authentication, although the certificate has an unapproved issuer and an unrelated server name. The genuine corporate access points have not been changed. Which configuration change corrects the authentication weakness revealed by the test?

Show answer & explanation

Correct answer: C - Validate the RADIUS server's certificate chain and expected server name.

Question 7

Customer exports in an Amazon S3 bucket are encrypted with S3-managed keys. A private analytics application reads them through a dedicated IAM role. An authorized tester without AWS credentials can also download an export because the bucket policy permits anonymous reads. The analytics application must remain available. How should the team correct the exposed access path?

Show answer & explanation

Correct answer: A - Remove anonymous access while retaining read permission for the application's IAM role.

Domain 6: Incident Detection 10% of exam

Question 8

An intrusion-detection rule is tested against 2,000 labeled network flows. It alerts on 90 of the 100 malicious flows and on 90 of the 1,900 benign flows. A manager cites its 95% overall accuracy as evidence that the alerts will be useful. For the analysts who must investigate those alerts, what proportion actually represents malicious activity?

Show answer & explanation

Correct answer: A - 50%; one of every two generated alerts represents malicious activity.

Domain 7: Incident Response 10% of exam

Question 9

Ransomware on a finance workstation is actively encrypting files on network shares. Responders need to stop access to those shares immediately and preserve RAM for investigation. The workstation does not control a safety-critical process, and the incident commander has authorized containment. Its EDR agent supports network isolation that retains the investigation channel. Which instruction should the responder carry out first?

Show answer & explanation

Correct answer: D - Isolate through EDR without shutting down the workstation.

Domain 8: Incident Prediction 15% of exam

Question 10

Four findings compete for one emergency patch window. All patches have passed testing and require comparable downtime; none affects a safety-critical process. Considering CVSS v4.0 Base severity together with exposure and exploitation evidence, which finding warrants the earliest remediation?

Show answer & explanation

Correct answer: A - CVSS 8.2 on an Internet-facing VPN gateway; exploitation is confirmed in the wild, and no effective mitigation is deployed.

That's 10 of 1,030

The full bank has 1,020 more CND questions with explanations.

Continue in the free practice test →

View plans