Be able to match protocols (ARP, TCP, TLS, SSH) and devices (switch, router, firewall) to a scenario, and select the control that mitigates the stated risk. The single most important thing: read what the attacker or administrator actually observes before choosing an answer.
Start practicing
Network Security — choose a session length
Free · No account required
Domain overview
Domain 4 of the ISC2 CC exam covers network architecture, protocols, and defensive controls. Expect scenario questions on TCP/IP layers, addressing, segmentation, and attack signatures. You must map protocols and ports to their functions, choose the right control for a given risk, and identify attacks from observed traffic or log symptoms rather than definitions alone.
Exam objectives
ARP resolving IPv4 addresses to MAC addresses within a local broadcast domain
VLANs logically segmenting departments on one physical switch
TLS/HTTPS and SSH encrypting traffic to defeat sniffing on wired LANs
SYN flood attacks identified by many half-open TCP connection requests
Confusing ARP with DNS or DHCP; ARP maps IP to MAC locally, while DNS resolves names and DHCP assigns addresses.
Assuming encryption stops sniffing; it protects payload confidentiality, but sniffing still captures metadata and unencrypted protocols.
Picking a router or firewall when VLANs are needed to separate departments on the same physical switch.
Click any question to see the full explanation and answer options, or start a focused practice session above.
Which OSI layer is responsible for routing packets across networks using IP addresses?
2A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
3In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
4An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
5A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?
6Which TCP segment is sent to initiate the three-way handshake?
7An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?
8Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?
9A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?
10Which protocol is considered insecure because it transmits data in cleartext, including passwords?
11During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?
12Which security control would best mitigate the risk of network sniffing on a wired LAN segment?
13A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)
14An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)
15A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)
16A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?
17A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?
18An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?
19Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?
20A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:
21An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?
22Which of the following is a common mitigation technique for a SYN flood attack?
23A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?
24Which layer of the OSI model is responsible for routing packets across networks?
25An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?
26Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?
27Which protocol is used to resolve IP addresses to MAC addresses on a local network?
28A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)
29An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)
30Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)
31Which OSI layer is responsible for routing packets based on IP addresses?
32An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?
33A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?
34A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?
35An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?
36Which of the following is a connectionless, unreliable transport protocol?
37Which of the following ports is used by HTTPS for secure web traffic?
38What is the primary difference between an IDS and an IPS?
39A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?
40A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)
41Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)
42A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)
43A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?
44An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
45During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?
46Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?
47A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?
48A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?
49An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?
50Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?
51A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?
52An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?
53A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?
54Which OSI layer is responsible for logical addressing and routing?
55A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?
56Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?
57A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?
58A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?
59Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?
60An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?
61A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?
62A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?
63An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?
64Which of the following ports is commonly used for secure web traffic (HTTPS)?
65A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?
66During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?
67A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:
68Which of the following is a benefit of using VLANs in a network?
69An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?
70A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?
71A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?
72A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?
73Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?
74An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?
75Which of the following is a security concern associated with the Telnet protocol?
76An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?
77An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?
78Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?
79A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?
80An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?
81Which of the following ports is used by HTTPS?
82A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)
83A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)
84A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?
85Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?
86A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?
87An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?
88A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?
89An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?
90A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?
91An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?
92Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?
93Which common port is used by DNS and which transport layer protocol does it primarily use?
94Which port number is associated with HTTPS, and what protocol encrypts the communication?
95Which three of the following are benefits of using VLANs in a network? (Choose three.)
96An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)
97Which layer of the OSI model is responsible for routing packets based on IP addresses?
98A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?
99An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?
100A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?
101Which protocol is considered insecure because it transmits data, including credentials, in cleartext?
102A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:
103Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)
104A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)
105An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)
106Which two of the following are characteristics of a stateful firewall? (Choose TWO.)
107A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)
108Which three ports are commonly used by secure protocols? (Choose THREE.)
109A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)
110A hospital's network team needs to provide secure remote access for clinicians who work from home. The clinicians must be able to reach internal medical records systems as if they were on the hospital LAN, but the hospital's security policy requires that all remote traffic be encrypted and that remote devices be prevented from directly accessing the public internet through the hospital network. Which technology best meets these requirements?
111A small business wants to prevent employees from visiting known malicious websites. The owner asks a technician to implement a control that blocks requests to a maintained list of bad domains before any connection is made to those sites. Which solution should the technician deploy?
112A security analyst at a mid-sized company is reviewing network traffic logs and notices that an internal host is repeatedly sending TCP SYN packets to many different external IP addresses on port 443, but never completing the three-way handshake. The analyst suspects a malware infection. Which type of attack is most likely occurring?
113A hospital's network team must allow external vendors to reach a specific internal patient-monitoring system without exposing the rest of the clinical VLAN. The solution must enforce least privilege and terminate vendor sessions at a hardened appliance before any internal resource is contacted. Which technology best meets these requirements?
114A small accounting firm wants to let guests connect to the internet in its lobby without exposing the internal file server or the payroll system. The network administrator is told to add a separate wireless network that uses different IP addressing and cannot route to internal resources. Which security principle is the administrator primarily applying?
115A network administrator is configuring a new wireless network for a small office. The office has sensitive data and wants to ensure that all wireless traffic is encrypted and that users authenticate with unique credentials. Which security protocol should the administrator implement?
116A hospital's network team notices that a radiology workstation is receiving a duplicate IP address error. The DHCP server logs show the workstation was assigned 10.10.20.45, but the workstation is manually configured with that same address. Which DHCP feature should have been configured to prevent this conflict?
117A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?
118A small accounting firm has a single flat network. During a risk review, the consultant recommends placing all wireless guest users on a separate logical network so they cannot reach the internal file server, even though both networks share the same physical switches and access points. Which technology best accomplishes this?
119A security engineer is deploying a new VPN solution for remote employees. The company requires that the VPN provide strong encryption, support for multiple users, and the ability to traverse NAT devices. Which VPN protocol should the engineer choose?
120A hospital's security team wants to detect when an attacker is probing its internal network for open ports, but the team must not block legitimate clinical traffic because doing so could interrupt patient care. The team decides to deploy a solution that only alerts on suspicious activity. Which type of solution best matches this requirement?
121A small business wants to provide secure remote access to its internal file server for employees working from home. The company requires that all traffic between the employee's device and the file server be encrypted and that the internal network topology remain hidden. Which technology best meets these requirements?
122A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?
123A financial services firm wants to allow employees to securely access internal applications from home without exposing those applications directly to the internet. The security team proposes using a VPN that encrypts traffic at the network layer and can carry non-web protocols. Which VPN technology best meets this requirement?
124A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?
125A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?
126A university wants to provide guests with internet access through the same physical wireless infrastructure used by staff, but guests must not reach internal research servers. Staff must authenticate with institutional credentials. Which combination of controls best achieves this separation?
127An analyst reviewing traffic captures sees a workstation repeatedly sending TCP packets with the SYN flag set to many different destination ports on a single server, but the workstation never completes the three-way handshake. The server's connection table is becoming exhausted. Which type of activity is most likely occurring?
128A network administrator is configuring a new wireless network for a small office. The office manager wants to ensure that only authorized employees can connect and that traffic between wireless clients is encrypted. Which security protocol should the administrator implement?
129A small business wants to prevent employees from visiting known malicious websites. The owner asks for a solution that can block requests based on a constantly updated list of harmful domains without requiring software on each employee device. Which technology should be recommended?
130A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?
131A financial services firm is designing a network that must allow inbound HTTPS from the internet to a public web application while preventing any direct inbound connections to its internal database servers. The security architect proposes placing the web application in a screened subnet and configuring rules so the database can be reached only from the web application. Which design element is the architect primarily relying on?
132A small accounting firm has a flat network where all employee workstations and a guest Wi-Fi access point connect to the same switch. The owner asks a security consultant to keep guests from reaching the payroll server, which resides on the same subnet as employee devices. Which control should the consultant implement to meet this requirement with the least disruption?
133An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?
134A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)
135A hospital's biomedical team connects a new MRI workstation to the clinical VLAN. The workstation must reach a PACS archive on a different subnet, but the team reports that no traffic leaves the workstation. A technician confirms the workstation has an IP address of 10.20.30.44/24 and the PACS archive is 10.20.40.10/24. Which device should the workstation be configured to use as its default gateway?
136A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?
137A security engineer is reviewing firewall logs and notices that an internal host is making repeated outbound connections to a known malicious IP address on port 443. The firewall is configured to allow all outbound traffic to port 443. The engineer wants to block this specific traffic without disrupting other legitimate HTTPS traffic. Which action should the engineer take?
138A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)
139A hospital's security team wants to give remote clinicians access to internal patient systems without exposing those systems directly to the internet. The team requires strong encryption, per-user authentication, and the ability to log every session. Which solution best fits these requirements?
140A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?
141A financial services company is designing a demilitarized zone (DMZ) for its public web and email relay servers. The security architect wants to reduce the attack surface and limit what an attacker can reach if a DMZ host is compromised. Which two design practices should be implemented? (Choose two.)
142A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and a public DNS server. The requirement is to ensure that if either public server is compromised, it cannot initiate connections to the internal network. Which design approach best meets this requirement?
143A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?
144A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)
145A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)
146A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?
147A company's web server is experiencing a high volume of traffic from thousands of different IP addresses, causing service degradation. The security team determines it is a distributed denial-of-service (DDoS) attack. Which mitigation strategy is most effective for this scenario?
148A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?
149A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?
150A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?
151A retail chain wants to prevent customers on its guest wireless from reaching point-of-sale terminals on the corporate wired network, while still allowing guests to browse the internet. The chain already separates the two networks with a firewall. Which additional configuration most directly enforces this restriction?
152An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password due to a security breach. The link leads to a website that looks identical to the company's login page. Which type of attack is this?
153A company uses a SIEM to monitor network security events. The security analyst notices a high volume of alerts about suspicious outbound traffic to a known command-and-control server. The traffic is encrypted and uses non-standard ports. Which security control would best detect this activity if the SIEM relies only on network flow data?
154A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?
155A company allows employees to connect to the corporate network from home using a VPN. The security team wants to ensure that a remote employee's device meets minimum security requirements, such as current antivirus and patched operating system, before granting access to internal applications. Which control should be implemented?
156A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)
157A company's security policy requires that all outbound web traffic be inspected for malware and that users be prevented from accessing known malicious domains. The security team wants a single appliance that can decrypt TLS sessions, apply content filters, and block threats inline. Which solution best meets these requirements?
158A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?
159A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)
Be able to match protocols (ARP, TCP, TLS, SSH) and devices (switch, router, firewall) to a scenario, and select the control that mitigates the stated risk. The single most important thing: read what the attacker or administrator actually observes before choosing an answer.
The Courseiva CC question bank contains 159 questions in the Network Security domain, covering the 24% of the exam attributed to this domain in the official ISC2 blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Network Security domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included