GSEC · domain
Networking and Protocols
This domain covers TCP/IP fundamentals, protocol behavior, and network service risks. Candidates must identify secure protocols for data in transit, assess ICMP and UDP exposure, and detect DNS tunneling. Questions present analyst scenarios requiring protocol selection, service risk analysis, and traffic characteristic interpretation.
Focused practice
Practice Networking and Protocols questions
Scored sessions drawing only from this domain — pick a length below.
What this domain covers
What to know about Networking and Protocols
A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.
Identifying risks of ICMP Timestamp replies on perimeter routers, including reconnaissance and fingerprinting.
Comparing UDP and TCP: connectionless vs connection-oriented, reliability, ordering, and header fields.
Analyzing DNS query length, frequency, and record types to detect DNS tunneling to command-and-control.
Watch out for
Common Networking and Protocols exam traps
- ▸Assuming TLS alone authenticates both endpoints; without mutual authentication, only the server is verified.
- ▸Believing ICMP Timestamp is harmless; it reveals system time and uptime for reconnaissance and fingerprinting.
- ▸Confusing UDP and TCP reliability; UDP does not guarantee delivery, ordering, or congestion control.
Question index
All Networking and Protocols questions (18)
Click any question to see the full explanation, or start a practice session above.
An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?
Hard2A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?
Medium3A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)
Hard4A network engineer is deploying a new IDS sensor on a switched segment and needs it to see all unicast traffic between two hosts on the same VLAN, including traffic not addressed to the sensor. The switch supports port mirroring. Which configuration should the engineer implement?
Medium5A security team is designing a network segmentation scheme for a new data center. They want to restrict lateral movement between workloads and enforce policy based on workload identity rather than IP address. Which TWO technologies best support this goal? (Choose two.)
Medium6An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?
Hard7A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?
Easy8A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?
Medium9A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?
Hard10A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?
Hard11A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?
Medium12A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?
Medium13During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?
Easy14An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?
Medium15Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?
Hard16A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?
Medium17A network engineer is documenting how a workstation obtains an IPv4 address on a corporate LAN. The engineer observes the workstation broadcasting a request, receiving a unicast offer from a server, broadcasting a formal request for that address, and finally receiving an acknowledgment. The engineer must record which transport protocol and ports this address-assignment exchange uses. Which combination correctly describes the exchange?
Easy18During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?
HardOther domains
All GSEC exam domains
Frequently asked questions
- What does the Networking and Protocols domain cover on the GSEC exam?
- A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.
- How many questions are in this domain?
- This page lists all 18 Networking and Protocols questions in the GSEC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Networking and Protocols questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.