Certified Network Defender (CND) (312-38) Exam Blueprint

312-38

100Questions
240 minDuration
70/60% to 85%Passing Score
$450Price
3 yearsValid For
1Languages
Practice Certified Network Defender (CND) on QuizForge

Exam Domains

1.0 Network Attacks and Defense Strategies Weight not published
  • 1.1Attack, threat, threats sources, threat actors, vulnerability, risk, network attacks, application attacks, social engineering attacks, email attacks, mobile attacks, cloud attacks, supply chain attacks, wireless attacks, hacking methodologies and frameworks, adaptive security strategy, and defense-in-depth security.
    Hands-on lab exercises to understand the modus operandi of different attacks at network, application, and host levels.
2.0 Administrative Network Security Weight not published
  • 2.1Compliance, regulatory frameworks, security policies, security awareness, asset management, and recent cybersecurity trends.
    Hands-on lab exercises to demonstrate skills in security policy implementation, asset management, employee monitoring, etc.
3.0 Technical Network Security Weight not published
  • 3.1Access controls, Authentication, Authorization, and Accounting (AAA), Identity and Access Management (IAM), cryptography, network segmentation, zero trust, network security controls, and network security protocols.
    Hands-on lab exercises to demonstrate skills in implementing access controls, VPN, etc.
4.0 Network Perimeter Security Weight not published
  • 4.1Firewalls, firewall types, firewall topologies, firewall selection, firewall implementation and deployment, firewall administration, IDS/IPS, IDS/IPS classification, IDS/IPS selection, false positives, false negatives, router security, switch security, software-defined perimeter (SDP).
    Hands-on lab exercises to demonstrate skills in perimeter security, which includes how to configure and implement firewalls and IDS/IPS with the help of well-known tools such as pfSense, Smoothwall, Windows Firewall, iptables, Suricata, Wazuh, ModSecurity, etc.
5.0 Endpoint Security – Windows Systems Weight not published
  • 5.1Windows security risks, Windows security components, Windows security features, Windows security baseline configurations, user account and password management, Windows patch management, Windows user access management, active directory security, Windows network services and protocol security, and Windows security best practices.
    Hands-on lab exercises to demonstrate Windows security skills, including but not limited to Windows patch management, Windows file integrity, Windows endpoint protection, Windows security configuration baseline, active directory security, security troubleshooting, permissions, etc.
6.0 Endpoint Security – Linux Systems Weight not published
  • 6.1Linux security risks, Linux installation and patching, Linux user access and password management, Linux OS hardening techniques, Linux network and remote access security, and Linux security tools and frameworks.
    Hands-on lab exercises to demonstrate skills in Linux security, including but not limited to system hardening, system security auditing, file integrity monitoring, permissions, access controls, etc.
7.0 Endpoint Security – Mobile Devices Weight not published
  • 7.1Bring Your Own Device (BYOD), Choose Your Own Device (CYOD), Corporate Owned, Personally Enabled (COPE), Company Owned, Business Only (COBO), Mobile Device Management (MDM), Mobile Application Management (MAM), Mobile Threat Defense (MTD), Unified Endpoint Management (UEM), Mobile Email Management (MEM), Mobile Content Management (MCM), Enterprise Mobility Management (EMM), mobile device security, android security, and iPhone security.
    Hands-on lab exercises to demonstrate skills in implementing MDM solutions and various mobile security measures.
8.0 Endpoint Security – IoT Devices Weight not published
  • 8.1IoT devices, IoT application areas, IoT ecosystem, IoT communication models, IoT-enabled environments, IoT security risk and challenges, IoT security in IoT-enabled IT environments, IoT security tools, IoT security best practices, IoT security standards, initiatives, and efforts.
    Hands-on lab exercises to demonstrate skills to secure IoT device communication.
9.0 Administrative Application Security Weight not published
  • 9.1Application whitelisting, application blacklisting, application sandboxing, application patch management, and web application firewalls (WAFs).
    Hands-on lab exercises to demonstrate skills in application whitelisting, application sandboxing, WAF, etc.
10.0 Data Security Weight not published
  • 10.1Data security, data encryption data at rest, data encryption at transit, data masking, data backup, data retention, data destruction, data loss prevention (DLP), and data integrity.
    Hands-on lab exercises to demonstrate skills in data encryption at rest, data encryption at transit, database encryption, email encryption, data backup, data recovery, disk encryption, etc.
11.0 Enterprise Virtual Network Security Weight not published
  • 11.1Network virtualization (NV), software-defined network (SDN), network function virtualization (NFV) security, OS virtualization security, container security, docker security, and Kubernetes security.
    Hands-on lab exercises to demonstrate skills in docker security audit, SDN communication security, Kubernetes security, etc.
12.0 Enterprise Cloud Security Weight not published
  • 12.1Cloud Computing, cloud security, shared responsibility model, Amazon Cloud (AWS) Security, Microsoft Azure cloud security, and Google Cloud Platform (GCP) security.
    Hands-on lab exercises to demonstrate skills in AWS IAM, AWS KMS, AWS Storage, Azure MFA, GCP IAM, Azure Resource locking, and GCP Cloud IAP.
13.0 Enterprise Wireless Network Security Weight not published
  • 13.1Wireless network, wireless standards, wireless topologies, wireless network components, wireless network encryption, wireless network authentication, wireless network security measures, and Wi-Fi security tools.
    Hands-on lab exercises to demonstrate skills in wireless router security.
14.0 Network Traffic Monitoring and Analysis Weight not published
  • 14.1Network traffic monitoring, baseline traffic signatures, suspicious network traffic signatures, threat detection with Wireshark, bandwidth monitoring, performance monitoring, network anomaly detection, and behavior analysis.
    Hands-on lab exercises to demonstrate skills in packet capturing, traffic monitoring, traffic analysis, threat detection, and bandwidth monitoring with tools such as Wireshark, tcpdump, PRTG, Capsa, NTOP, etc.
15.0 Network Logs Monitoring and Analysis Weight not published
  • 15.1Logs, Windows log analysis, Linux log analysis, Mac log analysis, firewall log analysis, router log analysis, web server log analysis, and centralized log management.
    Hands-on lab exercises to demonstrate skills in configuring, viewing, and analyzing logs in a local as well as a centralized location.
16.0 Incident Response and Forensics Investigation Weight not published
  • 16.1First responder, incident handling and response process, SOAR, endpoint detection and response (EDR), extended detection and response (XDR), and forensics investigation.
    Hands-on lab exercises to demonstrate skills in incident ticketing, reporting, and escalations with OSSIM.
17.0 Business Continuity and Disaster Recovery Weight not published
  • 17.1Business Continuity (BC), Disaster Recovery (DR), Business Continuity Management (BCM), BC/DR Activities, Business Impact Analysis (BIA), Recovery Time Objective (RTO), Recovery Point Objective (RPO), Business Continuity Plan (BCP), and Disaster Recovery Plan (DRP).
    Hands-on lab exercises to demonstrate skills in implementing business continuity and disaster recovery scenarios with NLB.
18.0 Risk Anticipation with Risk Management Weight not published
  • 18.1Risk management, risk identification, risk assessment, risk treatment, risk treatment steps, risk tracking and review, risk management frameworks (RMFs), vulnerability management, vulnerability scanning, vulnerability reporting, and privacy impact assessment (PIA).
    Hands-on lab exercises to demonstrate skills in network security audit, vulnerability management, application vulnerability scanning, and analysis.
19.0 Threat Assessment with Attack Surface Analysis Weight not published
  • 19.1Attack surface, attack surface analysis, system attack surface, network attack surface, software attack surface, physical attack surface, human attack surface, Indicators of Exposures (IoEs), attack simulation, attack surface reduction, attack surface monitoring tools, and cloud and IoT attack surface analysis.
    Hands-on lab exercises to demonstrate skills in system attack surface analysis, application attack surface analysis, attack surface mapping, etc.
20.0 Threat Prediction with Cyber Threat Intelligence Weight not published
  • 20.1Cyber threat intelligence, threat Intelligence types, Indicators of Compromise (IoCs), Indicators of Attack (IoA), threat intelligence layers, threat intelligence sources, threat intelligence feeds, threat intelligence platforms (TIP), and threat hunting.
    Hands-on lab exercises to demonstrate skills in integrating OTX threat feeds, threat hunting, etc.

Exam Details

Question TypesMultiple Choice
FormatLinear
Online ProctoringAvailable
ID RequirementsOne valid, government-issued photo ID with full name and photo. ID must match the name used during registration.
RenewalRequired -- Earn 120 ECE (EC-Council Continuing Education) credits over 3-year cycle. ECE credits earned through courses, conferences, publications, or EC-Council activities.
Retake PolicyNo official waiting period specified between retakes. Full exam fee required for each retake.
LanguagesEnglish

Official Study Resources