Courseiva

CCNA Networking and Protocols Questions

18 questions · Networking and Protocols · All types, answers revealed

1
MCQhard

An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?

A.Implementing Port Security along with Static ARP entries on all critical endpoints.
B.Enabling BPDU Guard and Root Guard on all designated edge access ports.
C.Deploying Dynamic ARP Inspection paired with an active DHCP Snooping binding table.
D.Configuring VLAN Access Control Lists alongside private VLAN isolated port modes.
AnswerC

DHCP Snooping tracks legitimate IP-to-MAC address assignments by monitoring untrusted switch ports. Dynamic ARP Inspection references this verified database to intercept and drop malicious ARP packets, successfully preventing both DHCP spoofing and man-in-the-middle ARP cache poisoning attempts.क्क

Why this answer

DHCP Snooping builds a trusted binding database by intercepting DHCP messages on untrusted ports, while Dynamic ARP Inspection utilizes this database to drop forged ARP replies. Implementing both mitigates rogue DHCP servers and prevents ARP cache poisoning attacks, securing Layer 2 communications from interception and spoofing without relying solely on static configurations.

Exam trap

Candidates often select Port Security alone. While Port Security limits MAC addresses, it does not validate the content of ARP packets or DHCP traffic, leaving the network vulnerable to spoofing and poisoning.

2
MCQmedium

A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?

A.VLAN hopping, where the attacker injects double-tagged frames to reach a different VLAN.
B.MAC flooding, where the attacker fills the content-addressable memory table so the switch floods frames out all ports.
C.ARP spoofing, where the attacker sends forged ARP replies to associate their MAC with a victim's IP address.
D.STP root bridge takeover, where the attacker sends superior BPDUs to become the root of the spanning tree.
AnswerB

MAC flooding sends frames with many spoofed source MAC addresses, exhausting the switch's CAM table. Once the table is full, the switch cannot map destinations to ports and falls back to flooding unknown unicast frames out every port, allowing the attacker to capture traffic intended for other hosts. The log pattern of many MACs learned on one port is the direct signature of this technique.

Why this answer

A switch port learning an excessive number of distinct MAC addresses indicates MAC flooding, in which spoofed source addresses exhaust the CAM table. Once the table overflows, the switch floods unknown unicast frames to all ports, enabling the attacker to capture traffic. This differs from ARP spoofing and STP attacks, whose signatures involve forged mappings or BPDUs rather than a MAC learning spike.

Exam trap

The trap here is conflating any Layer 2 man-in-the-middle technique with the specific CAM table exhaustion signature that only MAC flooding produces.

3
Multi-Selecthard

A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)

Select 2 answers
A.The internal server uses a smaller TCP receive window than the client advertises during the handshake.
B.The client's DNS resolver returns a stale record pointing to a decommissioned server address.
C.The client and server negotiated a weak cipher suite during the VPN handshake.
D.An intermediate firewall blocks all ICMP Destination Unreachable messages, including the fragmentation-needed type.
E.The VPN concentrator sets the Don't Fragment bit on encapsulated packets but the underlying path supports a smaller MTU than the tunnel interface.
AnswersD, E

Path MTU discovery depends on ICMP Destination Unreachable with the fragmentation-needed code to tell the sender to reduce packet size. If that ICMP is filtered, the sender never learns the smaller MTU and keeps emitting oversized packets that are silently dropped. This exactly produces the pattern where small packets pass and large ones fail, making it a genuine cause in this scenario.

Why this answer

Path MTU discovery relies on ICMP fragmentation-needed messages to signal senders to shrink packets. Filtering those ICMP messages, or setting the Don't Fragment bit on encapsulated packets larger than the real path MTU, leaves the sender unaware and causes silent drops of large packets while small ones pass. Both conditions match the observed size-dependent failure.

Exam trap

The trap here is blaming performance-tuning settings like window size or cipher strength for a symptom that is fundamentally about packet size and ICMP signaling.

4
MCQmedium

A network engineer is deploying a new IDS sensor on a switched segment and needs it to see all unicast traffic between two hosts on the same VLAN, including traffic not addressed to the sensor. The switch supports port mirroring. Which configuration should the engineer implement?

A.Create an EtherChannel bundle between the sensor and the switch, and enable trunking on the link.
B.Configure a SPAN session on the switch, designating the sensor port as the destination and the VLAN or relevant ports as the source.
C.Configure a SPAN session on the switch, designating the sensor port as the source and the monitored host ports as the destination.
D.Enable promiscuous mode on the sensor NIC and connect it to an access port in the same VLAN as the two hosts.
AnswerB

A Switched Port Analyzer (SPAN) session copies frames from selected source ports or VLANs to a destination port, allowing the sensor to passively observe unicast traffic it would otherwise never receive. This is the standard, vendor-supported way to gain visibility on a switched segment without disrupting forwarding, and it satisfies the requirement that the sensor see traffic not addressed to it.

Why this answer

On a switch, unicast frames are forwarded only out the port leading to the destination MAC, so a sensor on an ordinary access port cannot see other hosts' conversations. A SPAN session with the sensor as the destination port and the monitored ports or VLAN as the source copies those frames to the sensor. This preserves normal forwarding while giving the IDS the full traffic view it needs.

Exam trap

The trap here is assuming that enabling promiscuous mode on a NIC is sufficient to capture all traffic on a switched network, when port mirroring or a network tap is actually required.

5
Multi-Selectmedium

A security team is designing a network segmentation scheme for a new data center. They want to restrict lateral movement between workloads and enforce policy based on workload identity rather than IP address. Which TWO technologies best support this goal? (Choose two.)

Select 2 answers
A.Microsegmentation using a software-defined overlay with workload-level policy enforcement.
B.A next-generation firewall with identity-based rules applied to workload-to-workload flows.
C.VLANs assigned by physical switch port with inter-VLAN routing disabled.
D.A perimeter firewall with rules based on source and destination IP addresses.
E.802.1X port-based network access control on all switch ports.
AnswersA, B

Microsegmentation applies granular security policy to individual workloads or groups, often using an overlay that decouples policy from physical topology. Because enforcement is tied to workload identity and tags rather than subnet boundaries, an attacker who compromises one workload cannot freely reach others. This directly satisfies the requirement to restrict lateral movement and enforce identity-based policy, making it a correct choice for the scenario.

Why this answer

Restricting lateral movement and enforcing workload-identity policy requires controls that operate on east-west traffic and understand workload context. Microsegmentation with a software-defined overlay enforces per-workload policy regardless of IP, and a next-generation firewall with identity-based rules can inspect and permit only authorized workload flows. Together they address both the segmentation and identity-policy requirements.

Exam trap

The trap here is choosing perimeter or admission-control technologies that govern initial access or north-south traffic, when the requirement is specifically about east-west workload-to-workload policy based on identity.

6
MCQhard

An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?

A.Enabling private VLAN edge isolation between access ports
B.Deploying 802.1X port-based network access control on access ports
C.Configuring Dynamic ARP Inspection with a DHCP snooping binding table
D.Enabling Spanning Tree Protocol on all access switches
AnswerC

Dynamic ARP Inspection intercepts ARP packets on untrusted ports and compares the sender IP and MAC against the DHCP snooping binding database. A forged reply from a MAC that does not own the gateway address is dropped before it reaches the workstation, so the victim never updates its ARP cache with the attacker's address. This directly targets the gratuitous or unsolicited ARP reply used in the on-path attack.

Why this answer

Dynamic ARP Inspection is the control specifically designed to stop forged ARP replies. By relying on the DHCP snooping binding table as its source of truth for which MAC legitimately owns which IP, the switch can drop any ARP packet whose sender information does not match an authorized binding. This blocks the attacker's spoofed reply before the workstation can poison its cache and redirect off-subnet traffic.

Exam trap

The trap here is assuming that any Layer 2 hardening feature, such as 802.1X or private VLANs, will stop ARP spoofing, when only Dynamic ARP Inspection validates ARP payloads against a trusted binding table.

7
MCQeasy

A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?

A.netstat -an
B.ipconfig /all
C.nslookup app.internal.example.com
D.tracert app.internal.example.com
AnswerC

nslookup queries DNS servers directly and reports the resolved address or an error, which quickly confirms whether the configured resolver can resolve the internal hostname. Because the application works by IP, the failure is isolated to name resolution, and this command tests exactly that path. It is available on Windows, Linux, and macOS and is the appropriate first diagnostic step in this scenario.

Why this answer

Because the application is reachable by IP but not by hostname, the fault lies in name resolution rather than connectivity or routing. Querying DNS directly with nslookup tests whether the configured resolver returns the correct address or an error, which isolates the problem. Other commands either require successful resolution first or inspect unrelated local state.

Exam trap

The trap here is reaching for a connectivity tool such as tracert or a configuration display like ipconfig /all, when the symptom specifically points to a name-resolution failure that only a DNS query can confirm.

8
MCQmedium

A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?

A.ARP cache poisoning
B.VLAN hopping
C.DHCP starvation
D.MAC flooding
AnswerA

ARP cache poisoning involves sending forged ARP replies to associate an attacker's MAC address with a legitimate IP, such as the default gateway. This allows the attacker to intercept or redirect traffic. In this scenario, the unsolicited replies with a mismatched MAC for the gateway IP are a classic indicator of ARP spoofing, enabling man-in-the-middle or denial-of-service conditions on the LAN.

Why this answer

Unsolicited ARP replies that incorrectly map the default gateway's IP to an attacker-controlled MAC address are the hallmark of ARP cache poisoning. This attack poisons the ARP cache of hosts, redirecting their traffic through the attacker for interception or disruption. The mismatch between the legitimate gateway MAC and the claimed MAC confirms the malicious manipulation.

Exam trap

The trap here is confusing ARP cache poisoning with MAC flooding, but MAC flooding targets switch CAM tables, not host ARP caches, and does not produce forged gateway mappings.

9
MCQhard

A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?

A.A DNS amplification attack, where spoofed queries generate large responses aimed at a victim.
B.DNS cache poisoning, where forged responses insert malicious records into a resolver's cache.
C.DNS tunneling, where data and commands are encoded into DNS queries and responses to create a covert channel.
D.A zone transfer abuse, where the attacker pulls the entire DNS zone from an authoritative server.
AnswerC

DNS tunneling encodes arbitrary payloads into query names and response records, using the resolver as a transport to an attacker-controlled authoritative server. Long, high-entropy subdomain labels and a high volume of queries to one domain are classic indicators. Because DNS is rarely blocked, this technique lets a compromised host exfiltrate data and receive commands while blending into normal resolution traffic.

Why this answer

Encoding data into DNS query names and response records creates a covert channel known as DNS tunneling. High-entropy subdomain labels and a sustained query volume toward one external domain are the hallmarks. The resolver forwards queries to the attacker's authoritative server, which returns encoded responses.

This differs from zone transfers, cache poisoning, and amplification, which have distinct traffic signatures and objectives.

Exam trap

The trap here is labeling any abusive DNS traffic as cache poisoning or amplification when the bidirectional, encoded query pattern uniquely indicates tunneling.

10
MCQhard

A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?

A.Deploy a TLS-based VPN portal with multi-factor authentication, server certificates, and HSTS enforced.
B.Publish the internal application through a reverse proxy that uses basic authentication over HTTPS.
C.Deploy an IPsec VPN that requires a client certificate issued to each device.
D.Deploy an IPsec VPN with pre-shared keys distributed to each employee's device.
AnswerA

A TLS-based portal authenticates the server with a certificate the client validates, and multi-factor authentication protects against stolen passwords. HSTS forces browsers to use HTTPS and prevents downgrade or SSL-stripping attacks. Because the client only needs to trust the server certificate and complete MFA, no client certificate is required on the personal device, satisfying all stated constraints.

Why this answer

The design must authenticate the server, resist credential theft, resist man-in-the-middle, and avoid client certificates on personal devices. A TLS-based VPN portal with MFA and server certificates meets all of these: the client validates the server certificate, MFA blocks stolen-password reuse, and HSTS prevents downgrade attacks. The other options either require client certificates, rely on weak shared secrets, or use reusable basic credentials.

Exam trap

The trap here is equating strong authentication with client certificates, when server-certificate validation plus multi-factor authentication can meet the requirement without provisioning anything on the personal device.

11
MCQmedium

A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?

A.The server's TCP initial sequence number, which is randomized to prevent session hijacking.
B.The HTTP Host header, which tells the server which virtual host the client intends to reach.
C.The TCP SYN, SYN-ACK, ACK sequence confirms the server's identity before data transfer.
D.The TLS handshake, where the server presents a certificate and the client validates it against trusted certificate authorities.
AnswerD

During the TLS handshake the server transmits its X.509 certificate, and the client verifies the signature chain up to a trusted root, checks the subject name against the requested host, and confirms validity dates. Only after this validation does the client derive session keys and send the HTTP request. This is precisely the mechanism that authenticates the server's identity before application data flows on port 443.

Why this answer

Server identity in HTTPS is established during the TLS handshake, where the server proves possession of a private key matching a certificate that the client validates against trusted roots and the requested hostname. The TCP handshake merely creates the connection, and application headers such as Host are client-supplied and unauthenticated. Confirming the certificate chain is what binds the session to a verified server identity.

Exam trap

The trap here is assuming the TCP three-way handshake or an application header authenticates the server, when only the TLS certificate validation does.

12
MCQmedium

A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?

A.Telnet
B.IPsec
C.HTTP
D.SNMPv1
AnswerB

IPsec offers a suite of protocols that provide encryption, integrity, and authentication at the network layer. By securing packets between two hosts, it ensures that even if internal traffic is intercepted, the payload remains unreadable and protected from tampering, which is necessary for sensitive data transmission.

Why this answer

IPsec provides end-to-end security at the network layer, ensuring that all data between the two endpoints is encrypted and authenticated regardless of the underlying application. This is essential for protecting sensitive traffic within a private network from sniffing or spoofing. Implementing IPsec allows for granular control over traffic security policies, making it a standard requirement for high-security environments where network-level protection is prioritized over application-specific encryption.

Exam trap

Candidates often choose application-layer protocols like HTTPS or SSH, overlooking that IPsec provides transparent, robust security directly at the network layer for all traffic.

13
MCQeasy

During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?

A.Enabling remote attackers to execute arbitrary shell commands via buffer overflows in the ICMP daemon.
B.Allowing unauthorized entities to gather precise system uptime and clock synchronization data.
C.Exposing internal private IP address ranges through embedded DNS zone transfer responses.
D.Facilitating high-bandwidth distributed denial-of-service reflection attacks using small spoofed packets.
AnswerB

ICMP Timestamp replies expose a device's current clock and uptime, letting an attacker fingerprint the OS, infer patch cycles, and correlate hosts across the estate. On perimeter routers this reconnaissance data aids targeted exploitation, which is the specific risk the question asks about.

Why this answer

Responding to ICMP Timestamp requests leaks the exact system uptime and local clock settings to unauthenticated external entities. Attackers use this timing information to fingerprint operating systems, map network latency anomalies, and design precise timing attacks against time-dependent cryptographic protocols and authentication tokens.

Exam trap

Candidates frequently select generic denial-of-service impacts, overlooking that ICMP timestamps specifically leak precise system uptime and clock data for reconnaissance.

14
MCQmedium

An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?

A.The workstation is performing a standard DNS resolution process.
B.The system is initiating a legitimate peer-to-peer file transfer.
C.The host is performing TCP half-open reconnaissance.
D.The network interface is experiencing a broadcast storm.
AnswerC

TCP half-open scanning, often called SYN scanning, involves sending SYN packets to probe ports. The attacker analyzes the responses to determine if ports are open, closed, or filtered. Because the full handshake is never completed, the scanning activity is harder to log on the target system.

Why this answer

The behavior described is characteristic of a TCP port scan. By sending SYN packets without completing the three-way handshake, the attacker identifies open services while attempting to minimize detection. Understanding reconnaissance techniques is vital for network defense, as these scans often precede targeted exploitation attempts.

Security analysts must identify such patterns early to implement egress filtering or isolate the compromised host before it initiates a more severe attack.

Exam trap

Candidates often mistake half-open SYN packets for a full Denial of Service flood, missing that scanning random ports without completing handshakes indicates reconnaissance.

15
MCQhard

Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?

A.UDP provides guaranteed delivery of packets.
B.UDP is faster due to the lack of a handshake.
C.UDP uses flow control to manage data transmission rates.
D.UDP is connectionless and does not maintain state.
E.UDP is the primary protocol for HTTP web traffic.
AnswerB, D

UDP eliminates the overhead of the three-way handshake required by TCP. By sending data immediately without establishing a stateful connection, UDP significantly reduces latency, which is essential for time-sensitive applications like DNS queries, streaming media, and VoIP, where retransmission delays would degrade the user experience.

Why this answer

UDP is a connectionless, datagram-oriented protocol that prioritizes speed and efficiency over reliability. It does not perform handshakes, flow control, or error correction, making it ideal for real-time applications like VoIP. TCP, conversely, provides a reliable stream by managing connections and acknowledging packet delivery.

Understanding these differences is crucial for firewall configuration, as security policies must account for the stateless nature of UDP versus the stateful requirements of TCP.

Exam trap

Candidates often confuse UDP with TCP characteristics, specifically claiming that UDP performs flow control or error recovery, which are exclusive to TCP's stateful, reliable delivery mechanism.

16
MCQmedium

A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?

A.TCP connection state tables showing persistent half-open sessions on port 53.
B.Unusually high frequency and elevated entropy levels within TXT or subdomain record queries.
C.Frequent receipt of ICMP Destination Unreachable messages indicating blocked UDP traffic.
D.Elevated round-trip time latency on standard HTTP GET requests traversing proxy servers.
AnswerB

Malicious actors encode stolen data or remote commands within the subdomains of DNS requests or inside TXT records. Inspecting query frequency, length, and entropy reveals the high-density encoded payloads characteristic of modern tunneling tools like Iodine.क्क

Why this answer

DNS tunneling embeds arbitrary data inside standard DNS queries and responses, primarily utilizing TXT, NULL, or subdomains of A records. Analysing query length and entropy helps security professionals detect abnormal payload sizes that deviate from legitimate domain name resolution patterns, protecting enterprise networks from stealthy data exfiltration and C2 channels.

Exam trap

Candidates often look for 'high bandwidth usage'. DNS tunneling is often slow and stealthy; it relies on the content (entropy/record type) rather than large volumes of data.

17
MCQeasy

A network engineer is documenting how a workstation obtains an IPv4 address on a corporate LAN. The engineer observes the workstation broadcasting a request, receiving a unicast offer from a server, broadcasting a formal request for that address, and finally receiving an acknowledgment. The engineer must record which transport protocol and ports this address-assignment exchange uses. Which combination correctly describes the exchange?

A.UDP ports 53 and 54, because the address server acts as a directory service.
B.ICMP type 4 and type 5 messages, because routers advertise addresses to local hosts.
C.TCP ports 67 and 68, because address assignment requires a reliable connection.
D.UDP ports 67 and 68, with the server listening on 67 and the client on 68.
AnswerD

DHCP uses UDP because the client initially has no IP address and must broadcast. The server listens on UDP port 67 and the client uses UDP port 68. The four-step DORA exchange (Discover, Offer, Request, Acknowledge) fits this model. This combination correctly matches both the transport protocol and the port assignments observed in the scenario.

Why this answer

DHCP performs address assignment over UDP, with the server on port 67 and the client on port 68, because the client must broadcast before it possesses an address. The DORA sequence (Discover, Offer, Request, Acknowledge) matches the observed broadcast request, unicast offer, broadcast request, and acknowledgment. TCP and the other listed protocols cannot provide this broadcast-based assignment.

Exam trap

The trap here is matching the well-known DHCP port numbers to TCP instead of UDP, or confusing DHCP with DNS based on similar client-server roles.

18
MCQhard

During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?

A.Deploying a traditional static packet-filtering firewall with inbound rule sets.
B.Enforcing strict Egress Filtering policies on internal router and firewall interfaces.
C.Configuring port security on all access layer switch ports to limit MAC addresses.
D.Implementing WPA3 Enterprise wireless security across all corporate access points.
AnswerB

Egress filtering inspects and blocks outbound traffic at router and firewall interfaces, permitting only approved ports and protocols. This directly prevents the unexpected outbound administrative channels observed, satisfying the requirement to restrict unauthorised outbound communication at the network perimeter.

Why this answer

Egress filtering inspects and restricts outbound traffic leaving the internal network to ensure only authorized business protocols and ports can traverse the perimeter. Implementing strict egress filtering prevents compromised hosts from communicating with external command-and-control servers or exfiltrating data via unauthorized ports.

Exam trap

Candidates often select internal host-based firewalls or ingress filtering, forgetting that outbound traffic requires egress filtering at the perimeter to stop exfiltration.

Ready to test yourself?

Try a timed practice session using only Networking and Protocols questions.