Courseiva

CCNA Security Questions

11 questions · Security · All types, answers revealed

1
MCQmedium

A user reports that when visiting a banking website, the browser displays a warning that the site's certificate is not trusted, even though the site worked yesterday. The technician verifies the system clock is correct and the network is functioning. Which of the following is the MOST likely cause?

A.The user's account password has expired.
B.The root certificate for the issuing CA was removed from the Trusted Root Certification Authorities store.
C.The website's TLS certificate has expired.
D.The DNS server is resolving the banking site to an incorrect IP address.
AnswerB

If the root CA certificate is missing from the Trusted Root Certification Authorities store, the browser cannot build a chain of trust to the site's certificate, producing an untrusted warning. Since the clock and network are fine, removal of the root certificate is the most likely cause. Reinstalling the root CA or using a trusted root update resolves the issue.

Why this answer

A browser trusts a TLS certificate only if it can chain it to a root CA in the Trusted Root Certification Authorities store. If that root was removed, the chain breaks and the browser warns that the certificate is not trusted. An expired certificate or DNS problem could also cause warnings, but the sudden failure with a correct clock points to a missing root certificate.

Exam trap

The trap here is assuming any certificate warning means the site's certificate expired, without considering that a missing root CA also breaks the trust chain.

2
MCQmedium

A technician is asked to dispose of several old company laptops that contain sensitive customer data. The company wants to ensure the data cannot be recovered while still allowing the laptops to be donated. Which of the following should the technician perform?

A.Run a standard format on the drives.
B.Delete all partitions and create a new one.
C.Perform a secure erase or overwrite the drives.
D.Physically destroy the hard drives.
AnswerC

Secure erase or overwriting writes patterns across the entire drive, making the original data unrecoverable while leaving the drive functional for donation. This satisfies both the security and reuse requirements. It is the appropriate sanitization method when the hardware will remain in service elsewhere.

Why this answer

Secure erase or overwriting renders the original data unrecoverable while keeping the drive usable, so the laptops can be donated. Physical destruction prevents donation, and formatting or repartitioning leaves recoverable data. The technician should choose a sanitization method that meets both the security and reuse goals.

Exam trap

The trap here is treating formatting or deleting partitions as sufficient data destruction, when those methods leave the original data recoverable.

3
MCQmedium

A user reports that when they connect to the corporate Wi-Fi at a coffee shop, a browser warning appears stating the site's certificate is not trusted. The user is able to browse the internet but sees the warning on every HTTPS site. A technician suspects an on-path attack. Which of the following should the technician check FIRST to confirm the presence of an on-path attack?

A.The DNS server settings on the user's device and compare them to the corporate DNS servers.
B.The certificate chain presented by the browser to see if it is issued by an unknown or self-signed certificate authority.
C.The ARP cache on the user's device to look for duplicate MAC addresses.
D.The Wi-Fi encryption type configured on the user's device to ensure it is using WPA3.
AnswerB

An on-path attack often involves a self-signed or rogue CA certificate to intercept TLS traffic. Inspecting the certificate chain will reveal if the certificate is not issued by a trusted CA, confirming interception. This is the most direct evidence of an on-path attack, as the attacker must present a certificate to decrypt traffic, and it will not be trusted by the user's device.

Why this answer

The certificate chain is the most direct evidence of an on-path attack because the attacker must present a certificate to intercept TLS traffic. If the certificate is self-signed or issued by an untrusted CA, the browser will warn the user. DNS or ARP checks might reveal other attack vectors, but the certificate warning specifically indicates TLS interception, so examining the certificate chain confirms the attack.

Exam trap

The trap here is assuming that a certificate warning always means the website's certificate is expired or misconfigured, rather than considering an on-path attacker presenting a fraudulent certificate.

4
MCQeasy

A user at a small office reports that whenever they connect to the corporate Wi-Fi in the break room, their laptop warns that the network is unsecured and other devices on the same network can see their traffic. The access point in the break room broadcasts an open SSID with no password. Which of the following should a technician configure on the access point to protect wireless traffic while keeping the SSID available to employees?

A.Enable WPA3-Personal with SAE
B.Change the access point to operate on the 5 GHz band only
C.Disable SSID broadcast on the access point
D.Enable MAC address filtering for known employee devices
AnswerA

WPA3-Personal with Simultaneous Authentication of Equals replaces the WPA2 pre-shared key handshake with a password-authenticated key exchange, protecting the wireless traffic and preventing offline dictionary attacks. It keeps a single shared passphrase for employees while encrypting each session, directly addressing the open, unencrypted break-room network described.

Why this answer

The reported problem is an open wireless network where traffic is visible to other devices. The fix must add authentication and encryption to the wireless link. WPA3-Personal with SAE provides strong per-session encryption using a shared passphrase, which fits a small office that wants employees to connect with one password while keeping the SSID broadcast for easy discovery.

Exam trap

The trap here is assuming that hiding the SSID or filtering MAC addresses secures a wireless network, when neither provides encryption for the traffic.

5
MCQmedium

A technician is asked to dispose of several old company laptops that contain customer records on their internal drives. The drives are traditional spinning magnetic disks, and the company wants to reuse the laptops internally after the data is removed. Which of the following is the BEST method to ensure the customer data cannot be recovered?

A.Run a standard format of the drive from the operating system installer
B.Degauss the drive and then reinstall the operating system
C.Delete all partitions and leave the drive unallocated
D.Perform a low-level wipe by overwriting the entire drive with multiple passes of random data
AnswerD

Overwriting every sector of a magnetic hard disk with random data destroys the original bit patterns, and multiple passes add assurance. This sanitizes the drive while leaving it functional for internal reuse, which matches the requirement to remove customer records and keep the laptops in service. It is the appropriate method for spinning magnetic media.

Why this answer

The laptops will be reused internally, so the storage must remain functional while the customer data becomes unrecoverable. Overwriting every sector of a magnetic hard disk with random data removes the original bit patterns and defeats forensic recovery. Partition deletion and quick formatting leave recoverable remnants, and degaussing renders the drive unusable.

Exam trap

The trap here is treating deletion or quick formatting as sufficient sanitization, when only overwriting the full media removes the data while preserving the drive for reuse.

6
MCQhard

A security analyst notices that an employee's account is logging in successfully from two different countries within a five-minute window. The account uses a complex password, and the employee confirms they did not travel. The organization already requires multifactor authentication for all users. Which of the following is the MOST likely cause of the suspicious logins?

A.The employee is using a corporate VPN that assigns an exit node in another country
B.The employee's password was guessed by a brute-force attack
C.The employee's session cookie was stolen and reused by an attacker
D.The multifactor authentication provider is synchronizing time zones incorrectly
AnswerC

When MFA is enforced, an attacker who cannot replay the password may steal an authenticated session cookie and present it from another location, bypassing the need to re-authenticate. Two successful logins from distant countries within minutes, with a valid complex password and no travel, match session hijacking rather than password compromise or normal behavior.

Why this answer

MFA blocks credential replay, so an attacker who obtains a valid session token can continue using the already-authenticated session without triggering another challenge. Two successful logins from distant countries within minutes, with a complex password and no travel, point to stolen session cookies rather than password guessing, time-zone display issues, or a single VPN exit node.

Exam trap

The trap here is assuming MFA prevents all account takeover, when stolen session cookies let an attacker ride an already-authenticated session from a different location.

7
MCQeasy

A technician is configuring a Windows 11 workstation for a small business that handles credit card payments. The owner wants to ensure that stored cardholder data cannot be read if the drive is removed and attached to another computer. Which Windows feature should the technician enable?

A.BitLocker
B.Encrypting File System (EFS)
C.Windows Defender Firewall
D.User Account Control (UAC)
AnswerA

BitLocker provides full volume encryption for Windows 11, protecting data at rest so a removed drive cannot be read on another system. Enabling it on the OS drive with a TPM satisfies the requirement to render cardholder data unreadable if the disk is physically stolen. It is the built-in Windows feature that directly addresses this scenario.

Why this answer

BitLocker encrypts the entire volume, so if the drive is removed and connected to another computer, the data remains unreadable without the recovery key or the original TPM. EFS, firewall rules, and UAC do not provide full-volume encryption, so they fail the physical-theft requirement. BitLocker is the correct built-in Windows feature for protecting data at rest.

Exam trap

The trap here is confusing file-level encryption such as EFS with full-disk encryption such as BitLocker, which leads to choosing a partial solution that leaves most data exposed.

8
Multi-Selecthard

A security administrator is reviewing authentication methods for a company that wants to reduce the risk of credential theft while allowing employees to log in from personal mobile devices. Which two of the following should the administrator implement? (Choose two.)

Select 2 answers
A.Biometric authentication
B.Role-based access control (RBAC)
C.Single sign-on (SSO)
D.Password manager
E.Multifactor authentication (MFA)
AnswersA, E

Biometric authentication uses a fingerprint, face, or other physical trait as a factor. When used as part of MFA or as a strong authenticator on mobile devices, it makes stolen passwords insufficient for access. It directly reduces the risk of credential theft because the attacker cannot easily replicate the biometric factor.

Why this answer

MFA and biometric authentication both add factors that a stolen password alone cannot satisfy, directly reducing the risk of credential theft. SSO, password managers, and RBAC are useful but do not prevent an attacker with stolen credentials from logging in. The administrator should implement MFA and biometric authentication to strengthen login security for personal mobile devices.

Exam trap

The trap here is selecting SSO or a password manager because they improve password hygiene, while missing that only additional authentication factors stop a stolen password from being used.

9
MCQeasy

A user reports that their Windows 11 laptop frequently displays a message that the battery is not charging and the system clock keeps resetting to an earlier date. The laptop is plugged into a known-good power outlet. Which of the following should a technician check first?

A.The power adapter
B.The hard drive
C.The RAM
D.The CMOS battery
AnswerD

A failing CMOS battery commonly causes the system clock to reset and can also affect power management, sometimes leading to battery charging issues. Since the laptop is plugged into a good outlet, the CMOS battery is a logical first check. Replacing it often resolves both symptoms. This is the correct answer because the clock reset is a classic indicator of a dead CMOS battery.

Why this answer

The CMOS battery maintains the system clock and BIOS settings when the computer is unplugged. When it fails, the clock resets and sometimes power management settings are lost, which can affect battery charging. The power adapter, hard drive, and RAM do not cause the clock to reset.

Therefore, the CMOS battery is the first component to check.

Exam trap

The trap here is focusing on the battery charging issue and immediately suspecting the power adapter, while overlooking the clock reset as a clear sign of a dead CMOS battery.

10
MCQmedium

An administrator receives an alert that a workstation is repeatedly making DNS queries for random-looking domain names and sending small amounts of data to external IP addresses every few minutes. The endpoint protection agent is installed and up to date, and no user is logged in. Which of the following is the MOST likely explanation for this behavior?

A.The workstation is receiving a legitimate software update from the vendor.
B.The workstation is synchronizing its clock with an external NTP server.
C.The workstation is infected with malware that uses DNS tunneling for command and control.
D.The endpoint protection agent is performing a cloud reputation lookup for each file.
AnswerC

Random-looking domains queried at regular short intervals, combined with small outbound transfers, match DNS tunneling used by malware to reach a command-and-control server. Because DNS is normally allowed through firewalls, attackers encode data in queries and responses. The absence of a logged-in user and the automated cadence point to a compromised host rather than legitimate activity.

Why this answer

Malware that has established a foothold often uses DNS tunneling to evade egress filtering, encoding command-and-control traffic in DNS queries and responses. The combination of randomized domain names, a repeating short interval, small outbound data, and no interactive user strongly indicates a compromised endpoint rather than any normal update, reputation, or time-sync process.

Exam trap

The trap here is dismissing the traffic as routine update or synchronization noise because it is small and periodic, when random domain names plus frequent small transfers are the signature of DNS tunneling.

11
MCQhard

A security analyst notices that several workstations on the same subnet are resolving popular banking domains to an IP address that belongs to an unknown server. The analyst confirms the DHCP server is legitimate and the DNS server settings have not been changed by Group Policy. Which of the following attacks is MOST likely occurring?

A.Evil twin
B.Domain hijacking
C.ARP poisoning
D.DNS poisoning
AnswerD

DNS poisoning corrupts the DNS resolver's cache so that legitimate domain names resolve to attacker-controlled IP addresses. Since DHCP and Group Policy are unchanged, the redirection of banking domains to an unknown server strongly indicates that the DNS cache has been poisoned. This allows the attacker to redirect users to malicious sites without altering client configuration.

Why this answer

DNS poisoning inserts false records into a DNS resolver's cache, so clients receive attacker-controlled IP addresses for legitimate names. Because DHCP and Group Policy are intact, the misdirection must come from the DNS layer. Evil twin, ARP poisoning, and domain hijacking do not match the specific symptom of multiple clients resolving banking domains to an unknown server.

Exam trap

The trap here is confusing DNS poisoning with ARP poisoning, because both can redirect traffic, but only DNS poisoning changes name resolution results.

Ready to test yourself?

Try a timed practice session using only Security questions.