Courseiva

GSEC · domain

Networking and Protocols

This domain covers TCP/IP fundamentals, protocol behavior, and network service risks. Candidates must identify secure protocols for data in transit, assess ICMP and UDP exposure, and detect DNS tunneling. Questions present analyst scenarios requiring protocol selection, service risk analysis, and traffic characteristic interpretation.

18 questions3 easy8 medium7 hard

Focused practice

Practice Networking and Protocols questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Networking and Protocols

A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.

Selecting TLS, IPsec, or SSH for confidentiality and authentication between internal servers.

Identifying risks of ICMP Timestamp replies on perimeter routers, including reconnaissance and fingerprinting.

Comparing UDP and TCP: connectionless vs connection-oriented, reliability, ordering, and header fields.

Analyzing DNS query length, frequency, and record types to detect DNS tunneling to command-and-control.

Watch out for

Common Networking and Protocols exam traps

  • ▸Assuming TLS alone authenticates both endpoints; without mutual authentication, only the server is verified.
  • ▸Believing ICMP Timestamp is harmless; it reveals system time and uptime for reconnaissance and fingerprinting.
  • ▸Confusing UDP and TCP reliability; UDP does not guarantee delivery, ordering, or congestion control.

Question index

All Networking and Protocols questions (18)

Click any question to see the full explanation, or start a practice session above.

1

An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?

Hard
2

A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?

Medium
3

A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)

Hard
4

A network engineer is deploying a new IDS sensor on a switched segment and needs it to see all unicast traffic between two hosts on the same VLAN, including traffic not addressed to the sensor. The switch supports port mirroring. Which configuration should the engineer implement?

Medium
5

A security team is designing a network segmentation scheme for a new data center. They want to restrict lateral movement between workloads and enforce policy based on workload identity rather than IP address. Which TWO technologies best support this goal? (Choose two.)

Medium
6

An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?

Hard
7

A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?

Easy
8

A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?

Medium
9

A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?

Hard
10

A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?

Hard
11

A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?

Medium
12

A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?

Medium
13

During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?

Easy
14

An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?

Medium
15

Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?

Hard
16

A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?

Medium
17

A network engineer is documenting how a workstation obtains an IPv4 address on a corporate LAN. The engineer observes the workstation broadcasting a request, receiving a unicast offer from a server, broadcasting a formal request for that address, and finally receiving an acknowledgment. The engineer must record which transport protocol and ports this address-assignment exchange uses. Which combination correctly describes the exchange?

Easy
18

During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?

Hard

Frequently asked questions

What does the Networking and Protocols domain cover on the GSEC exam?
A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.
How many questions are in this domain?
This page lists all 18 Networking and Protocols questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Networking and Protocols questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
giac-gsec GIAC-GSEC networking and protocols Practice Questions