312-38: Comprehensive Test Bank with 200 Verified
Questions and Detailed Rationales Covering
Network Defense, Perimeter Security, Endpoint
Protection, and Incident Response for 2026/2027
CND (312-38) Practice Questions
Domain 1: Network Defense Management (10%)
Q1. Which statement BEST describes the concept
of "defense in depth"?
A. Using one perimeter firewall as the primary
security control
B. Applying multiple layered controls so that one
failure does not expose the entire environment
C. Encrypting every packet on the network with the
same shared key
D. Blocking all outbound traffic from user
workstations
, ☑VERIFIED ANSWER: B
Rationale: Defense in depth involves building
overlapping preventive, detective, and corrective
controls at different layers. If one control fails, other
controls still reduce the chance of compromise or
limit impact .
Q2. Which of the following is true regarding any
attack surface?
A. The attack surface refers to the sum of all
potential points where an unauthorized user can try
to enter or extract data
B. The attack surface is only related to physical
access points
C. The attack surface cannot be reduced
D. Attack surfaces are limited to software
vulnerabilities only
☑VERIFIED ANSWER: A
Rationale: The attack surface is the sum of all
potential points where an unauthorized user can
attempt to enter or extract data from an
,environment. It includes all vulnerabilities, entry
points, and potential attack vectors .
Q3. Which Internet access policy starts with all
services blocked, requiring the administrator to
enable safe and necessary services individually?
A. Permissive policy
B. Prudent policy
C. Internet access policy
D. Paranoid policy
☑VERIFIED ANSWER: D
Rationale: The Paranoid policy is characterized by
blocking all services by default and selectively
enabling only those that are necessary. This
approach minimizes potential vulnerabilities and
ensures maximum security .
Q4. Management decides to implement a risk
management system. What is the correct order in
the risk management phase?
A. Risk assessment → Risk mitigation → Risk
evaluation → Risk monitoring
, B. Risk identification → Risk analysis → Risk
evaluation → Risk treatment
C. Risk planning → Risk execution → Risk review →
Risk closure
D. Risk discovery → Risk classification → Risk
response → Risk audit
☑VERIFIED ANSWER: B
Rationale: The standard risk management process
follows: Risk identification → Risk analysis → Risk
evaluation → Risk treatment (mitigation). This
structured approach ensures all risks are properly
identified, assessed, and addressed .
Q5. Which of the following refers to the clues,
artifacts, or evidence that indicate a potential
intrusion or malicious activity in an organization's
infrastructure?
A. Indicators of attack
B. Key risk indicators
C. Indicators of compromise
D. Indicators of exposure