20+ practice questions focused on Networking and Protocols — one of the most tested topics on the GIAC Security Essentials exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Networking and Protocols PracticeAn incident responder is analyzing a compromised corporate workstation and finds evidence of DNS poisoning in the local cache. Which THREE indicators or mitigation strategies are most relevant to identifying and preventing this specific threat? (Choose three)
Explanation: DNS poisoning attacks corrupt the local resolver cache, redirecting users to malicious infrastructure. Effective detection involves monitoring for high query volumes and mismatched response IDs, while defense-in-depth relies on enforcing DNSSEC validation and utilizing trusted, encrypted resolvers like DNS over HTTPS to guarantee cryptographic authenticity.
An analyst reviewing packet captures notices that a client completed a TCP handshake with a server, sent a request, and then the server sent a packet with the RST flag set immediately after receiving the request. The client had no prior connection to that port. What is the most likely explanation for the RST?
Explanation: TCP uses the RST flag to abort a connection when a segment arrives that cannot be matched to an existing connection, or when a connection is closed abruptly. Because the handshake completed, a listening socket accepted the connection, but the request may have been processed by a socket that was subsequently closed or the server's state was reset. The stack then responds with RST to any further segment.
A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?
Explanation: DNS tunneling embeds arbitrary data inside standard DNS queries and responses, primarily utilizing TXT, NULL, or subdomains of A records. Analysing query length and entropy helps security professionals detect abnormal payload sizes that deviate from legitimate domain name resolution patterns, protecting enterprise networks from stealthy data exfiltration and C2 channels.
An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?
Explanation: DHCP Snooping builds a trusted binding database by intercepting DHCP messages on untrusted ports, while Dynamic ARP Inspection utilizes this database to drop forged ARP replies. Implementing both mitigates rogue DHCP servers and prevents ARP cache poisoning attacks, securing Layer 2 communications from interception and spoofing without relying solely on static configurations.
During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?
Explanation: Responding to ICMP Timestamp requests leaks the exact system uptime and local clock settings to unauthenticated external entities. Attackers use this timing information to fingerprint operating systems, map network latency anomalies, and design precise timing attacks against time-dependent cryptographic protocols and authentication tokens.
+15 more Networking and Protocols questions available
Practice all Networking and Protocols questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Networking and Protocols. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Networking and Protocols questions on the GSEC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Networking and Protocols is tested as part of the GIAC Security Essentials blueprint. Practicing with targeted Networking and Protocols questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free GSEC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Networking and Protocols is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Networking and Protocols practice session with instant scoring and detailed explanations.
Start Networking and Protocols Practice →