EC-COUNCIL · 312-38

EC-Council 312-38 CND v3 Exam Practice Questions

718 questionsPDF by emailUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 718 questions in this pack

Question 1

John works as a C programmer. He develops the following C program:

His program is vulnerable to a __________ attack.

Exhibit for question 1

  1. SQL injection
  2. Denial-of-Service
  3. Buffer overflow
  4. Cross site scripting
Show answer and explanation

Correct answer: C. Buffer overflow

The program declares a fixed-size buffer of 10 characters (buffer1[10]) but uses strcpy() to copy user input from argv[1] into it without any bounds checking. The strcpy() function copies the entire input string regardless of the buffer's capacity, allowing an attacker to supply input longer than 10 characters. This causes the excess data to overflow past the buffer boundary into adjacent memory, corrupting the stack and potentially allowing arbitrary code execution. This is a classic buffer overflow vulnerability.

Why the other options are wrong

  • A. SQL injection requires database query construction with user input; this C program has no database operations.
  • B. Denial-of-Service attacks aim to crash or overload a service; while this program could crash from buffer overflow, the vulnerability itself is buffer overflow, not DoS.
  • D. Cross-site scripting is a web application vulnerability involving malicious scripts in HTML; this is a standalone C program with no web or HTML context.

Question 2

Which of the following analyzes network traffic to trace specific transactions and can intercept and log traffic passing over a digital network? Each correct answer represents a complete solution.

Choose all that apply.

  1. Wireless sniffer
  2. Spectrum analyzer
  3. Protocol analyzer
  4. Performance Monitor
Show answer and explanation

Correct answer: A, C

A. Wireless sniffer C. Protocol analyzer A wireless sniffer captures and analyzes network traffic on wireless networks, intercepting and logging data packets. A protocol analyzer examines network traffic at the protocol level to trace transactions and intercept communications. Both tools perform packet capture and analysis functions. A spectrum analyzer measures signal strength and frequency characteristics but does not intercept application-level traffic or trace transactions. Performance Monitor is a Windows utility for monitoring system resources, not network traffic analysis.

Why the other options are wrong

  • B. Spectrum analyzers measure radio frequency signals and frequency distributions, not application transaction data.
  • D. Performance Monitor tracks system performance metrics like CPU and memory, not network traffic interception.

Question 3

In which of the following conditions does the system enter ROM monitor mode? Each correct answer represents a complete solution.

Choose all that apply.

  1. The router does not have a configuration file.
  2. There is a need to set operating parameters.
  3. The user interrupts the boot sequence.
  4. The router does not find a valid operating system image.
Show answer and explanation

Correct answer: C, D

C. The user interrupts the boot sequence. D. The router does not find a valid operating system image. ROM monitor (ROMmon) is the low-level bootstrap environment that runs when the IOS image cannot be loaded or when the operator deliberately stops the boot process. The router drops into ROMmon if it cannot locate or load a valid operating system image from flash, TFTP or other configured boot sources, and it also enters ROMmon when the user sends the break sequence during the first seconds of startup. From ROMmon an administrator can change the configuration register, perform password recovery, or TFTP a new image onto the device.

Why the other options are wrong

  • A. A missing or empty startup configuration file causes the router to enter setup mode, not ROM monitor mode, because the operating system has already loaded successfully.
  • B. Setting operating parameters is performed in global configuration mode after IOS loads, so it is a task rather than a condition that forces entry into ROM monitor mode.

See all 10 free questions Get the full pack, US$39

718 practice questions for EC-Council Certified Network Defender v3 (CND), exam 312-38, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 718 questions mapped to the CND v3 exam blueprint
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

A 312-38 attempt costs US$550. This pack is US$39, paid once.

Try 10 questions free before you buy.

Last updated September 2026 · 718 questions

What makes the CND hard

CND is the blue-team counterpart to CEH, and the v3 blueprint is built around a protect, detect, respond, predict model: eight domains, 100 questions, four hours, and a passing score set per exam form between 60% and 85%.

It is broad rather than deep, and the breadth is the difficulty, because the same exam asks about Kubernetes hardening, Windows Active Directory, wireless encryption and business continuity standards.

Network Perimeter Protection is the biggest domain at 16%: access control models, IAM, cryptography, segmentation, firewall types and deployment, IDS and IPS, and Zero Trust with software-defined perimeter. Endpoint Protection at 15% covers Windows security components, AD best practice, Linux hardening and enterprise mobile and IoT security. Incident Detection at 14% covers traffic baselining and log monitoring, and Application and Data Protection at 13% covers whitelisting, sandboxing, WAF and DLP. The remaining domains cover virtual, cloud and wireless protection, network defence management, incident response and incident prediction.

About the exam

312-38 (Certified Network Defender v3) earns the EC-Council CND certification. It covers network defense management, perimeter protection, endpoint protection, application and data protection, virtual, cloud and wireless network protection, incident detection, incident response and incident prediction. There are no prerequisites with official training; self-study candidates need two years of information security experience and an eligibility application.

Exam domains

  • Network Defense Management: 10%
  • Network Perimeter Protection: 16%
  • Endpoint Protection: 15%
  • Application and Data Protection: 13%
  • Enterprise Virtual, Cloud, and Wireless Network Protection: 12%
  • Incident Detection: 14%
  • Incident Response: 10%
  • Incident Prediction: 10%

100 multiple choice questions, 240 minutes, passing score 60% to 85% depending on the exam form, US$550 per attempt, ECC Exam Center, Pearson VUE or remote proctoring, certification valid for three years with EC-Council continuing education.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the EC-Council 312-38 CND v3 pack?

718 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Your PDF is prepared and sent to your email address after checkout, and you get a confirmation as soon as it is on its way.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.