20+ practice questions focused on Network Security — one of the most tested topics on the ISC2 Certified in Cybersecurity CC exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Network Security PracticeA security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?
Explanation: A Smurf attack involves sending ICMP Echo Requests to a broadcast address with a spoofed source IP (the victim's IP). All hosts on the network reply with ICMP Echo Replies to the victim, flooding it. The victim never sent Echo Requests, which matches the scenario of unsolicited Echo Replies from an external server.
Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Explanation: ARP (Address Resolution Protocol) is used to resolve an IP address to a MAC address on a local network. When a host wants to send data to another host on the same subnet, it broadcasts an ARP request asking 'Who has this IP?' and the owner replies with its MAC address.
An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?
Explanation: Sending forged ARP messages to associate the attacker's MAC address with another host's IP address is ARP spoofing (also called ARP poisoning), which enables the attacker to intercept and relay traffic between two parties — a man-in-the-middle attack. The scenario explicitly describes interception via forged ARP messages, so MITM is the resulting attack type. The attacker positions themselves inline by poisoning ARP caches on both sides.
Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?
Explanation: An application proxy firewall terminates the client connection and re-establishes a separate connection to the server, fully reconstructing and inspecting application-layer payloads such as HTTP requests, URLs, headers, and form data. This deep inspection at Layer 7 allows it to detect malicious patterns like SQL injection strings or known attack signatures embedded in application traffic.
A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)
Explanation: FTP (Option C) is correct because it transmits both authentication credentials and data in cleartext over TCP ports 20 and 21, with no built-in encryption, making it inherently insecure. Telnet (Option D) is also correct because it sends all session data, including usernames and passwords, as unencrypted plaintext over TCP port 23. HTTPS (Option B) is not correct because it wraps HTTP in TLS encryption, and SSH (Option E) is not correct because it provides strong encrypted channels for remote sessions. DNS (Option A) is not marked correct because, although traditional DNS queries over UDP/TCP port 53 are cleartext, the protocol itself can be secured via DoH or DoT, so it is not inherently insecure in the same definitive sense as FTP and Telnet.
+15 more Network Security questions available
Practice all Network Security questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Network Security. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Network Security questions on the CC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Network Security is tested as part of the ISC2 Certified in Cybersecurity CC blueprint. Practicing with targeted Network Security questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Network Security is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Network Security practice session with instant scoring and detailed explanations.
Start Network Security Practice →