Courseiva

GSEC · domain

Network Security Devices

This domain covers the network security devices a GSEC candidate must recognize and reason about: stateful firewalls, proxies, IDS/IPS, and the placement of each at the internet edge and internal boundaries. Questions present short scenarios or exhibits and ask you to predict traffic behavior, device function, or the effect of a given rule set.

16 questions3 easy7 medium6 hard

Focused practice

Practice Network Security Devices questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Network Security Devices

Be able to read a topology or ACL and predict whether traffic is permitted, dropped, or translated, and identify which device performs which function. The single most important thing is knowing stateful versus stateless behavior and how inline placement affects availability.

How stateful firewalls track sessions and handle idle or long-lived TCP flows

Placement and fail-open versus fail-closed behavior of inline inspection appliances

Distinguishing NAT, stateful inspection, and proxy functions on a network diagram

Reading and predicting the result of an applied ACL on router interface traffic

Watch out for

Common Network Security Devices exam traps

  • ▸Assuming a firewall idle timeout is the only cause of dropped sessions, ignoring TCP keepalive and state table aging
  • ▸Confusing an inline IPS with a passive IDS when the scenario requires continued forwarding during power loss
  • ▸Mixing up NAT and stateful inspection roles when identifying a device from a network diagram description

Question index

All Network Security Devices questions (16)

Click any question to see the full explanation, or start a practice session above.

1

A security team is deploying an inline intrusion prevention system (IPS) on a critical 10 Gbps link and must minimize the risk of the IPS becoming a single point of failure while still blocking malicious traffic. Which TWO design characteristics should the team ensure are in place? (Choose two.)

Hard
2

A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?

Easy
3

A security analyst needs to capture raw packet data from a high-speed core switch to analyze suspicious east-west traffic movements without interrupting production data flows. Which device feature should be configured on the switch?

Easy
4

A security engineer is deploying a next-generation firewall (NGFW) at the perimeter of a company's network. The NGFW must enforce security policies based on application identity and user identity, not just IP addresses and ports. The engineer needs to ensure that the firewall can identify applications even when they use non-standard ports or attempt to evade detection by tunneling over HTTP. Which NGFW feature should the engineer configure to meet these requirements?

Medium
5

A security analyst is reviewing a network diagram and sees a device placed between the internet edge router and the internal firewall. The device is described as providing network address translation and stateful connection tracking but not deep application inspection. Which device type is most consistent with this description?

Medium
6

A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?

Hard
7

A utility company must protect a SCADA network that uses proprietary Modbus/TCP communications on a segmented OT VLAN. The security team wants to block unauthorized function codes while allowing a small set of approved read operations, and it cannot tolerate latency or protocol-breaking behavior. Which control is MOST appropriate?

Hard
8

A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?

Medium
9

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

Hard
10

An organization deploys a network-based Intrusion Detection System (IDS) in passive monitoring mode on a core switch trunk link. If the IDS detects an active external command-and-control connection to an infected internal workstation, what action does the IDS take?

Medium
11

A financial services firm is selecting a web application firewall (WAF) to protect an internet-facing banking portal that uses TLS 1.3 exclusively. The security architect must ensure the WAF can inspect encrypted sessions and detect attacks that unfold across many requests from the same client. Which TWO capabilities are MOST relevant to these requirements? (Choose two.)

Hard
12

A security engineer is configuring an inline intrusion prevention system (IPS) on a 10 Gbps internal segment. During a pilot, the IPS begins dropping legitimate business traffic because its inspection engine cannot keep pace with bursts. Which deployment adjustment best preserves inline prevention while reducing false drops?

Medium
13

A network security team is deploying a web application firewall (WAF) in front of an e-commerce site. The security architect wants the WAF to learn normal application behavior and block deviations without manually writing signatures for every new attack. Which WAF deployment and configuration approach best matches this requirement?

Hard
14

A retail company runs a stateful firewall at its internet edge. Users complain that long-lived SSH sessions to a partner are being dropped roughly every hour even though no idle timeout is configured on the client. Which firewall behavior is the MOST likely cause?

Medium
15

A small business replaces its aging router with a unified threat management (UTM) appliance. The owner wants one device to provide antivirus scanning, content filtering, and intrusion prevention for all outbound traffic. Which statement BEST describes how the UTM appliance delivers these functions?

Easy
16

A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?

Medium

Frequently asked questions

What does the Network Security Devices domain cover on the GSEC exam?
Be able to read a topology or ACL and predict whether traffic is permitted, dropped, or translated, and identify which device performs which function. The single most important thing is knowing stateful versus stateless behavior and how inline placement affects availability.
How many questions are in this domain?
This page lists all 16 Network Security Devices questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Security Devices questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC network security devices Practice Questions