Courseiva

N10-009 · topic practice

Network Security practice questions

Network Security is 14% of the CompTIA Network+ N10-009 exam. It covers hardening wired and wireless networks, implementing segmentation and access control, and applying defense-in-depth. Expect scenario questions where you select the correct security control, protocol, or placement for a given threat, and identify misconfigurations in ACLs, VLANs, or wireless authentication settings.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network Security

What the exam tests

What to know about Network Security

Configure ACLs, 802.1X, and WPA3 on switches and APs, then place firewalls, IDS/IPS, and VPNs correctly to enforce least privilege. Get segmentation right: VLANs plus ACLs must actually block lateral movement, not just exist.

Differentiate WPA2-Personal, WPA2-Enterprise, WPA3, and 802.1X with RADIUS authentication

Place firewalls, IDS/IPS, and honeypots correctly in a network topology

Configure ACL rules, VLAN segmentation, and screened subnets for least privilege

Identify common attacks and apply mitigations like DHCP snooping, DAI, and port security

Watch out for

Common Network Security exam traps

  • ▸Confusing IDS (detects and alerts) with IPS (detects and blocks inline), leading to wrong placement or action in scenarios.
  • ▸Assuming WPA2-Personal uses a RADIUS server; it uses a pre-shared key, while Enterprise requires 802.1X authentication.
  • ▸Placing a honeypot inside the trusted network instead of a screened subnet, which increases risk rather than diverting attackers.

Practice set

Network Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Read the full DHCP explanation →

A security analyst notices that the DHCP server is responding to a large number of DHCP Discover messages from a single MAC address, but that client never sends a DHCP Request to complete the lease. This pattern repeats continuously. Which type of attack is most likely occurring?

A company is implementing 802.1X port-based authentication on its wired network to control access. The network uses Active Directory for user accounts. Which type of server must be deployed to authenticate clients connecting to the switch ports?

Question 3mediummultiple choice
Read the full wireless explanation →

A company is deploying a wireless network that requires the highest level of security for client authentication. The network must use a RADIUS server. Which wireless security standard should be implemented?

Question 4hardmultiple choice
Read the full DHCP explanation →

A security analyst is reviewing logs and finds that a single MAC address is rapidly requesting IP addresses from a DHCP server, each time with a different client ID. The DHCP server is exhausting its address pool. Which type of attack is occurring?

A company wants to allow external users to access a web server located in the DMZ. The firewall has three interfaces: inside, outside, and DMZ. Which firewall rule is necessary?

Question 6mediummultiple choice
Read the full NAT/PAT explanation →

A security analyst is configuring a firewall to allow HTTPS traffic from the internet to an internal web server with a private IP address. The firewall must translate the destination IP address of incoming packets to the private server IP. Which type of NAT should be configured?

Question 7mediummultiple choice
Read the full Network Security explanation →

A network administrator wants to ensure that only authorized devices can access the network on a switch port. The administrator has a list of allowed MAC addresses. Which security feature should be enabled on the switch port?

Match each network topology to its characteristic. Select all that apply.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

All devices connect to a central hub or switch

Every device connects to every other device

All devices share a single communication line

Each device connects to two others, forming a closed loop

A security analyst notices that an attacker is sending crafted packets with overlapping IP fragments to a target server, causing the server to crash. Which type of attack is described?

A company wants to implement network access control that requires users to authenticate before gaining access to the network. The NAC solution uses a policy that checks for antivirus updates and OS patches. Which component enforces the policy?

A security auditor is reviewing firewall logs and notices repeated login attempts from a single external IP address to the company's SSH server. Which type of attack is likely occurring?

Question 12mediummultiple choice
Read the full Network Security explanation →

A network administrator wants to prevent unauthorized devices from connecting to the company's Ethernet ports. The company uses a centralized authentication server. Which IEEE standard should be implemented?

Question 13mediummultiple choice
Read the full Network Security explanation →

A security analyst notices that a web server is receiving a large number of ICMP echo reply packets from many different external hosts. The server did not send any echo requests. Which type of attack is most likely occurring?

A company wants to ensure that only authorized employee computers can connect to the wired network. Each computer must be authenticated before it is granted access to the network. Which technology is designed to provide this port-based authentication?

A security analyst notices that the company's web server is receiving a high volume of TCP SYN packets from a single source IP address, but the server is not completing the three-way handshake. Which type of attack is most likely occurring?

A security administrator is configuring a firewall to allow remote employees to access the company's internal web server (port 443) from the internet. The web server has an internal IP address of 10.0.0.5. The firewall has a public IP of 203.0.113.10. Which type of firewall rule should be created?

A security analyst is reviewing firewall logs and sees many incoming packets with a source IP address that matches the internal IP range of the company (10.0.0.0/8) arriving on the external interface. Which type of attack is likely being attempted?

Question 18hardmultiple choice
Read the full wireless explanation →

A security administrator is configuring a wireless network to use WPA3-Enterprise. Which authentication server protocol is required for WPA3-Enterprise?

Question 19hardmultiple choice
Read the full DHCP explanation →

A security analyst is reviewing DHCP server logs and notices that a single MAC address is sending an extremely high number of DHCP discover packets. The DHCP server is responding, but the client never sends a DHCP request. Which type of attack is most likely occurring?

Question 20mediummultiple choice
Read the full Network Security explanation →

A company is implementing 802.1X port-based authentication on its wired network to ensure only authorized devices can connect. Which of the following servers is required to authenticate users and devices?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Security sessions

Start a Network Security only practice session

Every question in these sessions is drawn from the Network Security domain — nothing else.

Related practice questions

Related N10-009 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the N10-009 exam test about Network Security?
Configure ACLs, 802.1X, and WPA3 on switches and APs, then place firewalls, IDS/IPS, and VPNs correctly to enforce least privilege. Get segmentation right: VLANs plus ACLs must actually block lateral movement, not just exist.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other N10-009 topics?
Use the topic links above to move to related areas, or go back to the N10-009 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the N10-009 exam covers. They are not copied from any real exam or dump site.