Courseiva

CCNA Network Security Devices Questions

16 questions · Network Security Devices · All types, answers revealed

1
Multi-Selecthard

A security team is deploying an inline intrusion prevention system (IPS) on a critical 10 Gbps link and must minimize the risk of the IPS becoming a single point of failure while still blocking malicious traffic. Which TWO design characteristics should the team ensure are in place? (Choose two.)

Select 2 answers
A.The IPS inspection engine is sized and tuned so that it can process the full 10 Gbps line rate with expected burst traffic.
B.The IPS is configured to drop all traffic that it cannot inspect, including encrypted sessions it cannot decrypt.
C.The IPS is managed out-of-band on a separate management VLAN with restricted access.
D.The IPS supports a hardware bypass or fail-open mechanism that forwards traffic if the device loses power or fails.
E.The IPS is deployed in passive mode with a span port so that it can alert without affecting traffic flow.
AnswersA, D

An inline IPS must keep up with line rate; otherwise it will drop legitimate packets or introduce unacceptable latency. Sizing and tuning the inspection engine for the full 10 Gbps plus expected bursts ensures the device does not become a performance bottleneck or a de facto denial of service. This directly supports the goal of maintaining availability while enforcing prevention. It is a fundamental capacity planning requirement for inline IPS on critical high-speed links.

Why this answer

Inline IPS on a critical 10 Gbps link must both survive failure and keep up with traffic. A hardware bypass or fail-open mechanism ensures traffic continues if the device fails, and proper sizing and tuning ensure the inspection engine can process line rate and bursts without dropping legitimate packets. Passive deployment cannot block, dropping uninspectable traffic harms availability, and out-of-band management, while good practice, does not address the data-plane requirements.

Exam trap

The trap here is treating passive monitoring or strict fail-closed inspection as equivalent to a resilient inline prevention design.

2
MCQeasy

A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?

A.Enable private VLANs on the switch so that guest ports can communicate only with the router port.
B.Configure port security on all switch ports to limit the number of MAC addresses, and enable DHCP snooping on the guest VLAN.
C.Place guest users on the same VLAN as internal users but assign them static IP addresses in a different subnet range.
D.Create separate VLANs for guest and internal users, and apply an ACL on the router interface that blocks traffic from the guest VLAN to the internal VLAN.
AnswerD

VLANs logically separate the guest and internal broadcast domains, and an ACL on the router interface enforces policy between them. Because inter-VLAN traffic must be routed, the router is the correct enforcement point. This combination directly prevents guest users from reaching internal file servers while still allowing both groups to reach the internet through controlled paths. It is the standard and effective way to segment a flat network with existing Layer 2 and Layer 3 equipment.

Why this answer

Segmenting guest and internal users into separate VLANs creates distinct Layer 2 domains, and because traffic between them must be routed, an ACL on the router interface can block guest-to-internal access. This is the most direct and reliable way to enforce the requirement with the described equipment. Same-VLAN addressing, Layer 2 hardening features, and private VLANs either do not enforce the policy or are more complex and less certain for this specific goal.

Exam trap

The trap here is thinking that different IP subnets on the same VLAN provide security separation, when Layer 2 adjacency still allows direct host-to-host traffic.

3
MCQeasy

A security analyst needs to capture raw packet data from a high-speed core switch to analyze suspicious east-west traffic movements without interrupting production data flows. Which device feature should be configured on the switch?

A.Network Address Translation (NAT) overloading
B.Switched Port Analyzer (SPAN) or port mirroring
C.Virtual Router Redundancy Protocol (VRRP) failover
D.Dynamic Host Configuration Protocol (DHCP) snooping
AnswerB

SPAN copies frames from selected switch ports or VLANs to a monitoring port, giving passive visibility of east-west traffic without inline interception. This satisfies the constraint of capturing raw packets while production flows continue uninterrupted.

Why this answer

A Switched Port Analyzer (SPAN), also known as port mirroring, duplicates ingress and egress traffic from specified source ports or VLANs and forwards the copied frames to a dedicated monitoring port connected to a packet analyzer or intrusion detection sensor without disrupting production flows.

Exam trap

Candidates often select 'port forwarding' or 'VLAN trunking'. These are network connectivity configurations that do not provide the packet duplication functionality required for security monitoring.

4
MCQmedium

A security engineer is deploying a next-generation firewall (NGFW) at the perimeter of a company's network. The NGFW must enforce security policies based on application identity and user identity, not just IP addresses and ports. The engineer needs to ensure that the firewall can identify applications even when they use non-standard ports or attempt to evade detection by tunneling over HTTP. Which NGFW feature should the engineer configure to meet these requirements?

A.User identity awareness via LDAP integration
B.Application-aware filtering with deep packet inspection (DPI)
C.SSL/TLS decryption with certificate pinning
D.Stateful packet inspection (SPI) with port-based rules
AnswerB

Application-aware filtering with DPI examines packet payloads beyond headers to identify applications regardless of port or protocol. It can detect tunneling and evasive techniques by analyzing behavioral patterns and signatures. This directly addresses the requirement to enforce policies based on application identity and to handle non-standard ports and HTTP tunneling.

Why this answer

Application-aware filtering with deep packet inspection is designed to identify applications by analyzing payload content and behavior, not just ports. This enables enforcement of policies based on application identity and detects tunneling or evasion. The other options address different aspects like state tracking, user mapping, or decryption, but none provide the required application identification.

Exam trap

The trap here is assuming that stateful inspection or port-based rules can identify applications, when in fact they cannot see beyond headers.

5
MCQmedium

A security analyst is reviewing a network diagram and sees a device placed between the internet edge router and the internal firewall. The device is described as providing network address translation and stateful connection tracking but not deep application inspection. Which device type is most consistent with this description?

A.A stateless packet-filtering router that evaluates each packet independently against ACLs.
B.A stateful firewall that tracks TCP sessions and allows return traffic for established connections.
C.A next-generation firewall that performs full application-layer inspection and user identity mapping.
D.A web proxy that terminates HTTP and HTTPS connections and enforces content policies.
AnswerB

A stateful firewall maintains a connection table and permits return traffic for sessions that were initiated according to policy. Many stateful firewalls also perform network address translation at the edge. The scenario describes stateful connection tracking and NAT but not deep application inspection, which is exactly the core behavior of a traditional stateful firewall. This device type fits the placement and described functions precisely.

Why this answer

Stateful connection tracking and network address translation are core functions of a traditional stateful firewall, which maintains a session table and allows return traffic for established flows. The scenario explicitly excludes deep application inspection, ruling out a next-generation firewall. Stateless filtering lacks connection state, and a web proxy is application-specific rather than a general stateful gateway, so the stateful firewall is the correct device type.

Exam trap

The trap here is assuming that any device performing NAT and stateful tracking must be a next-generation firewall, when deep application inspection is explicitly absent.

6
MCQhard

A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?

A.Stateful inspection with session tracking
B.Access control lists (ACLs) applied to the inbound interface
C.Deep packet inspection (DPI) with application signatures
D.Network address translation (NAT) with port forwarding
AnswerA

Stateful inspection maintains a session table that tracks the state of each connection. When an outbound connection is initiated, the firewall creates an entry, and return traffic matching that session is automatically allowed. If session tracking is disabled or the table is full, return packets may be dropped. This feature is essential for allowing return traffic without explicit inbound rules.

Why this answer

Stateful inspection with session tracking allows the firewall to dynamically permit return traffic for outbound connections by maintaining a session table. Without it, return packets are treated as new inbound traffic and may be blocked by default. The administrator should verify that stateful inspection is enabled and that the session table is not exhausted, which can cause drops.

Exam trap

The trap here is confusing stateful session tracking with other firewall features like DPI or NAT, or assuming that an ACL must be added to allow return traffic, when the real issue is that stateful inspection is not functioning correctly.

7
MCQhard

A utility company must protect a SCADA network that uses proprietary Modbus/TCP communications on a segmented OT VLAN. The security team wants to block unauthorized function codes while allowing a small set of approved read operations, and it cannot tolerate latency or protocol-breaking behavior. Which control is MOST appropriate?

A.A web application firewall placed in front of the SCADA historian's HTTP interface.
B.An industrial protocol-aware firewall or IPS module that performs deep packet inspection of Modbus/TCP function codes.
C.An email and web gateway performing TLS interception on the OT VLAN.
D.A stateless packet filter permitting only TCP port 502 between the engineering workstation and the PLC.
AnswerB

Deep packet inspection that understands Modbus/TCP can parse the function code field and enforce an allowlist of approved read operations while dropping others, which matches the requirement to block unauthorized function codes. Because it is purpose-built for OT protocols, it can do this without the latency and compatibility problems a general-purpose proxy would introduce.

Why this answer

Enforcing an allowlist of Modbus/TCP function codes requires inspecting the protocol payload, which only a control-system-aware firewall or IPS can do reliably. Port-based filtering cannot separate reads from writes because all Modbus/TCP operations share the same transport port.

Exam trap

The trap here is assuming that restricting traffic to TCP port 502 secures Modbus, when that port carries both benign reads and dangerous write or diagnostic function codes.

8
MCQmedium

A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?

A.Verify the IPS can perform inspection at line rate with low latency and has a hardware bypass mechanism to maintain availability if it fails.
B.Configure the IPS in tap mode with a fail-open bypass so it can inspect traffic without being in the forwarding path.
C.Enable full packet capture on the IPS to record all traffic for forensic analysis, accepting the performance overhead.
D.Deploy the IPS in promiscuous mode and rely on span ports to mirror traffic from the core switch.
AnswerA

For an inline IPS on a high-speed clinical link, the device must handle 10 Gbps of traffic without adding latency that affects real-time monitoring. A hardware bypass or fail-to-wire capability ensures that if the IPS fails or loses power, traffic continues to flow, preserving patient safety. This combination of performance and availability is the primary deployment consideration for this scenario.

Why this answer

An inline IPS on a critical 10 Gbps link must inspect and block at line rate while not introducing latency that disrupts real-time applications. A hardware bypass or fail-to-wire mechanism is essential to maintain network availability if the IPS fails, which is especially important in a hospital setting. Performance and availability are the key considerations for this deployment.

Exam trap

The trap here is assuming that any inline IPS can handle 10 Gbps without verifying its throughput and latency specifications, or overlooking the need for a hardware bypass to prevent a single point of failure.

9
MCQhard

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

A.The traffic is permitted because the second rule matches the source subnet.
B.The traffic is denied because the first rule matches and terminates evaluation.
C.The traffic is permitted because permit rules take precedence over deny rules.
D.The router generates an error because the ACL rules are contradictory.
AnswerB

The router processes the ACL in a top-down fashion. The first rule denies all traffic to 10.0.5.5 on port 80. Since the packet matches this criteria, the evaluation stops, and the router silently discards the packet. The permit rule located on the second line is never reached.

Why this answer

Cisco standard and extended ACLs process rules sequentially from top to bottom. The first rule explicitly denies any IP traffic to the host 10.0.5.5 on port 80. Because this deny rule is matched first, the router immediately drops the packet before evaluating subsequent lines.

Even though the second rule would have permitted the traffic, it is unreachable due to the specificity and position of the initial deny statement.

Exam trap

Candidates often assume that because a permit rule exists for the subnet, the traffic will be allowed, forgetting that ACLs are processed top-down and the first match wins.

10
MCQmedium

An organization deploys a network-based Intrusion Detection System (IDS) in passive monitoring mode on a core switch trunk link. If the IDS detects an active external command-and-control connection to an infected internal workstation, what action does the IDS take?

A.It automatically injects TCP reset (RST) packets into the stream to terminate the active session.
B.It drops the malicious packets at the interface level to protect the internal workstation from further compromise.
C.It generates an alert log entry and notifies security analysts via SIEM integration or SNMP traps.
D.It dynamically updates the core switch routing table to quarantine the infected workstation into an isolated VLAN.
AnswerC

Passive IDS sensors monitor mirrored traffic without interfering with packet delivery. Upon detecting malicious indicators, they record the event to local logs and transmit alerts to centralized management systems and SIEM platforms for analyst review.

Why this answer

A network-based IDS operates in passive monitoring mode, receiving mirrored traffic copies via a SPAN port or network tap. Because it is deployed out-of-band, it cannot inline drop packets; instead, it generates security alerts, logs events, and can trigger external response mechanisms like SNMP traps or API calls.

Exam trap

Candidates often assume an IDS can automatically block traffic, confusing it with an IPS (Intrusion Prevention System), which sits inline and has the capability to drop malicious packets.

11
Multi-Selecthard

A financial services firm is selecting a web application firewall (WAF) to protect an internet-facing banking portal that uses TLS 1.3 exclusively. The security architect must ensure the WAF can inspect encrypted sessions and detect attacks that unfold across many requests from the same client. Which TWO capabilities are MOST relevant to these requirements? (Choose two.)

Select 2 answers
A.Configuring the WAF to operate only in detection mode with alerts sent to a SIEM.
B.Enabling promiscuous mode on the WAF's management interface.
C.Disabling HTTP keep-alive so every request opens a fresh TCP connection.
D.Terminating TLS at the WAF using a certificate and private key trusted by the portal's clients.
E.Maintaining per-client session state and scoring correlated requests over time.
AnswersD, E

To inspect TLS 1.3 payloads, the WAF must be a TLS endpoint, which means presenting a certificate and possessing the corresponding private key so it can decrypt, examine, and re-encrypt sessions. Without this termination capability the WAF only sees ciphertext and cannot evaluate HTTP request content, making it useless against application-layer attacks on the portal.

Why this answer

Inspecting TLS 1.3 forces the WAF to act as a TLS endpoint with the portal's certificate and key, because encrypted payloads are otherwise opaque. Detecting attacks spread across many requests requires persistent per-client session tracking and behavioral scoring, so those two capabilities together satisfy the architect's requirements.

Exam trap

The trap here is equating passive packet capture features, such as promiscuous mode, with the active decryption and session correlation a WAF needs to inspect modern TLS.

12
MCQmedium

A security engineer is configuring an inline intrusion prevention system (IPS) on a 10 Gbps internal segment. During a pilot, the IPS begins dropping legitimate business traffic because its inspection engine cannot keep pace with bursts. Which deployment adjustment best preserves inline prevention while reducing false drops?

A.Enable fail-open bypass on the IPS so that traffic is forwarded without inspection when the inspection engine is overwhelmed.
B.Move the IPS to a passive TAP and rely on alerts to manually block offending sources at the firewall.
C.Tune the IPS inspection profile to match the segment's actual protocols and disable signatures for services not present on that segment.
D.Increase the IPS fail-closed timeout so that traffic is buffered longer during inspection spikes.
AnswerC

Overload often comes from inspecting irrelevant protocols and signatures, which consumes CPU and causes legitimate packets to be dropped. Profiling the segment and disabling unused signatures reduces processing load without removing inline prevention. This preserves enforcement while lowering false positives and false drops. It is the targeted, operationally sound adjustment because it aligns inspection scope with actual traffic rather than disabling protection.

Why this answer

Inline IPS overload is usually caused by inspecting traffic and signatures that do not apply to the protected segment. Profiling the segment and disabling irrelevant signatures reduces CPU and memory pressure, allowing the engine to keep up with burst traffic while still enforcing inline prevention. The other choices either remove inline enforcement or fail to address the actual capacity bottleneck, so they do not meet the requirement of preserving prevention while reducing false drops.

Exam trap

The trap here is assuming that preserving availability through bypass or passive monitoring is equivalent to preserving inline prevention.

13
MCQhard

A network security team is deploying a web application firewall (WAF) in front of an e-commerce site. The security architect wants the WAF to learn normal application behavior and block deviations without manually writing signatures for every new attack. Which WAF deployment and configuration approach best matches this requirement?

A.Deploy the WAF in reverse proxy mode with anomaly detection and a learning period that builds a baseline of normal application behavior before enforcement.
B.Deploy the WAF as a host-based agent on each web server with a static rule set based on the OWASP Core Rule Set.
C.Deploy the WAF in monitor-only mode with signature-based rules and alert on known attack patterns.
D.Deploy the WAF in transparent bridge mode with a positive security model that only allows explicitly defined methods, parameters, and content types.
AnswerA

Reverse proxy mode places the WAF inline for HTTP/HTTPS traffic, and anomaly detection with a learning period builds a behavioral baseline of legitimate requests. After the baseline is established, deviations from normal parameters, methods, and request patterns can be blocked without hand-written signatures. This directly matches the architect's requirement to learn normal behavior and block deviations, while reverse proxy mode gives the WAF full visibility and control over application traffic.

Why this answer

Behavioral anomaly detection in a reverse proxy WAF builds a baseline of normal application behavior during a learning period, then flags and blocks requests that deviate from that baseline. This reduces reliance on manually written signatures and matches the architect's goal. Transparent bridge with a positive model still needs explicit definitions, monitor-only mode cannot block, and host-based static rules do not learn, so the reverse proxy anomaly approach is the only one that satisfies all stated requirements.

Exam trap

The trap here is confusing a positive security model, which requires explicit allow rules, with anomaly detection, which learns normal behavior and flags deviations.

14
MCQmedium

A retail company runs a stateful firewall at its internet edge. Users complain that long-lived SSH sessions to a partner are being dropped roughly every hour even though no idle timeout is configured on the client. Which firewall behavior is the MOST likely cause?

A.The firewall is applying egress filtering that blocks the partner's return traffic after the first hour.
B.The firewall's TCP session table entry is expiring because the connection has been idle longer than the configured state timeout.
C.The firewall is performing full packet reassembly and rejecting out-of-order TCP segments from the partner.
D.The firewall's ALG for SSH is rewriting the sequence numbers and desynchronizing the endpoints.
AnswerB

Stateful firewalls age out entries in the session table based on idle timers, and the default TCP idle timeout is often around an hour for established connections. If the SSH session carries no keepalive traffic during that window, the entry is purged and subsequent packets are treated as a new, unauthorized flow and dropped, matching the observed hourly disconnects.

Why this answer

Stateful inspection maintains a session table whose entries expire according to protocol idle timers. An SSH connection that sends no data for the duration of the TCP established timeout is silently removed, after which the firewall no longer recognizes return packets as part of an existing flow and drops them.

Exam trap

The trap here is focusing on client-side keepalive settings while overlooking that the firewall's own idle timeout governs how long the session entry survives.

15
MCQeasy

A small business replaces its aging router with a unified threat management (UTM) appliance. The owner wants one device to provide antivirus scanning, content filtering, and intrusion prevention for all outbound traffic. Which statement BEST describes how the UTM appliance delivers these functions?

A.It relies solely on signature updates pushed to endpoint agents installed on each workstation.
B.It combines multiple security functions in a single platform that inspects traffic as it passes through the appliance.
C.It functions only as a stateful firewall and requires separate appliances for each additional security service.
D.It offloads all inspection to a cloud service, requiring no local processing of network traffic.
AnswerB

A UTM appliance integrates several security services, such as antivirus, content filtering, intrusion prevention, and often VPN, into one device that traffic traverses. This consolidation is exactly what the owner wants: a single platform applying multiple inspection technologies to outbound flows without deploying separate dedicated appliances.

Why this answer

Unified threat management consolidates several inspection technologies into one appliance positioned in the traffic path, letting a small business obtain antivirus, content filtering, and intrusion prevention without procuring and managing separate devices.

Exam trap

The trap here is confusing UTM consolidation with cloud-only or endpoint-only security models, which distribute inspection differently than a single inline appliance.

16
MCQmedium

A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?

A.Deploy the appliance as a routed hop between the two VLANs with a static route on each side.
B.Deploy a TAP aggregator that mirrors both VLANs to the appliance and enable fail-open on the NIC.
C.Deploy a Layer 2 bridge running in inline mode with a hardware bypass fail-to-wire segment.
D.Deploy a SPAN port on the core switch and attach the appliance in passive monitor-only mode.
AnswerC

An inline Layer 2 bridge inspects traffic between the two VLANs while remaining transparent to IP addressing, and a hardware bypass fail-to-wire segment physically shunts packets around the appliance if it loses power, preserving connectivity for clinical systems. This directly satisfies both the inspection and the survivability requirements without renumbering hosts or altering routing.

Why this answer

Transparent inline bridging with a hardware bypass segment keeps the appliance invisible at Layer 3 while still allowing it to enforce policy on traffic crossing between VLANs. The fail-to-wire path guarantees that clinical connectivity survives a power loss, which is the decisive requirement distinguishing this from passive monitoring or routed insertion.

Exam trap

The trap here is assuming that any inline device automatically fails open, when in fact fail-to-wire depends on a dedicated hardware bypass segment rather than software configuration alone.

Ready to test yourself?

Try a timed practice session using only Network Security Devices questions.