Courseiva

GSEC · topic practice

Network Security Devices practice questions

This domain covers the network security devices a GSEC candidate must recognize and reason about: stateful firewalls, proxies, IDS/IPS, and the placement of each at the internet edge and internal boundaries. Questions present short scenarios or exhibits and ask you to predict traffic behavior, device function, or the effect of a given rule set.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network Security Devices

What the exam tests

What to know about Network Security Devices

Be able to read a topology or ACL and predict whether traffic is permitted, dropped, or translated, and identify which device performs which function. The single most important thing is knowing stateful versus stateless behavior and how inline placement affects availability.

How stateful firewalls track sessions and handle idle or long-lived TCP flows

Placement and fail-open versus fail-closed behavior of inline inspection appliances

Distinguishing NAT, stateful inspection, and proxy functions on a network diagram

Reading and predicting the result of an applied ACL on router interface traffic

Watch out for

Common Network Security Devices exam traps

  • ▸Assuming a firewall idle timeout is the only cause of dropped sessions, ignoring TCP keepalive and state table aging
  • ▸Confusing an inline IPS with a passive IDS when the scenario requires continued forwarding during power loss
  • ▸Mixing up NAT and stateful inspection roles when identifying a device from a network diagram description

Practice set

Network Security Devices questions

20 questions · select your answer, then reveal the explanation

An enterprise network administrator is deploying a next-generation firewall (NGFW) to inspect encrypted traffic. Which architecture allows the NGFW to decrypt and inspect inbound HTTPS traffic destined for internal web servers without compromising private keys on every server?

A security analyst is hardening an enterprise perimeter firewall and evaluating different deployment modes. Which TWO characteristics accurately describe a firewall operating in transparent (virtual wire or layer 2) mode?

Question 3hardmultiple choice
Review the full routing breakdown →

Refer to the exhibit. An administrator implemented the above configuration on a router acting as the network perimeter security device. Based on the configuration snippet, what specific security function is being applied to incoming traffic?

Exhibit

interface GigabitEthernet0/1
 description External-ISP-Connection
 ip address 203.0.113.2 255.255.255.252
 crypto map VPN-MAP
zone-member security EXTERNAL
!
class-map match-any ATTACK-TRAFFIC
 match protocol http
 match length 1400 1500
!
policy-map EDGE-POLICY
 class ATTACK-TRAFFIC
  drop

An organization is planning to deploy an inline Intrusion Prevention System (IPS) on a high-speed 10Gbps backbone link. Which TWO factors must the engineering team evaluate to prevent the IPS from becoming a network bottleneck?

An organization deploys a stateful inspection firewall between the internal network and the internet. A critical database server needs to receive incoming traffic on a specific high-numbered port for a legacy application. Which action ensures the firewall permits the return traffic for this connection while maintaining security?

A security analyst needs to capture raw packet data from a high-speed core switch to analyze suspicious east-west traffic movements without interrupting production data flows. Which device feature should be configured on the switch?

Question 7mediummultiple choice
Open the full VLAN trunking answer →

An organization deploys a network-based Intrusion Detection System (IDS) in passive monitoring mode on a core switch trunk link. If the IDS detects an active external command-and-control connection to an infected internal workstation, what action does the IDS take?

Question 8hardmultiple choice
Study the full ACL explanation →

Refer to the exhibit. A network administrator applies this ACL to a router interface. A user from the 192.168.1.0/24 subnet attempts to access the web server at 10.0.5.5 on port 80. What is the result of this traffic flow?

Exhibit

DENY ip any host 10.0.5.5 eq 80
PERMIT tcp 192.168.1.0 0.0.0.255 host 10.0.5.5 eq 80
PERMIT ip any any
Question 9mediummultiple choice
Open the full VLAN trunking answer →

A security engineer at a hospital is deploying an inline network Intrusion Prevention System (IPS) on a 10 Gbps link between the clinical VLAN and the data center. The IPS must block exploits without introducing latency that would disrupt real-time patient monitoring. Which deployment consideration is MOST critical to meet this requirement?

A financial institution uses a stateful firewall between its internal network and the internet. An administrator notices that return traffic for outbound connections is being blocked even though the outbound rules are correct. The firewall logs show that the return packets are being dropped because they do not match any existing session. Which feature should the administrator verify is enabled to allow return traffic for legitimate outbound sessions?

Question 11mediummultiple choice
Open the full VLAN trunking answer →

A hospital's security team wants to inspect traffic between its clinical VLAN and its guest Wi-Fi VLAN, but the network must keep forwarding packets even if the inspection appliance loses power. The appliance will be inserted transparently without changing IP addressing on either VLAN. Which deployment approach BEST satisfies these requirements?

A financial services firm is selecting a web application firewall (WAF) to protect an internet-facing banking portal that uses TLS 1.3 exclusively. The security architect must ensure the WAF can inspect encrypted sessions and detect attacks that unfold across many requests from the same client. Which TWO capabilities are MOST relevant to these requirements? (Choose two.)

A retail company runs a stateful firewall at its internet edge. Users complain that long-lived SSH sessions to a partner are being dropped roughly every hour even though no idle timeout is configured on the client. Which firewall behavior is the MOST likely cause?

A security engineer is configuring an inline intrusion prevention system (IPS) on a 10 Gbps internal segment. During a pilot, the IPS begins dropping legitimate business traffic because its inspection engine cannot keep pace with bursts. Which deployment adjustment best preserves inline prevention while reducing false drops?

A network security team is deploying a web application firewall (WAF) in front of an e-commerce site. The security architect wants the WAF to learn normal application behavior and block deviations without manually writing signatures for every new attack. Which WAF deployment and configuration approach best matches this requirement?

Question 16hardmultiple choice
Open the full VLAN trunking answer →

A utility company must protect a SCADA network that uses proprietary Modbus/TCP communications on a segmented OT VLAN. The security team wants to block unauthorized function codes while allowing a small set of approved read operations, and it cannot tolerate latency or protocol-breaking behavior. Which control is MOST appropriate?

Question 17easymultiple choice
Review the full routing breakdown →

A small business replaces its aging router with a unified threat management (UTM) appliance. The owner wants one device to provide antivirus scanning, content filtering, and intrusion prevention for all outbound traffic. Which statement BEST describes how the UTM appliance delivers these functions?

Question 18easymultiple choice
Open the full VLAN trunking answer →

A small business wants to segment its flat network so that guest Wi-Fi users cannot reach internal file servers. The administrator has a Layer 2 switch that supports VLANs and a router that supports access control lists. Which combination best enforces the segmentation requirement?

Question 19mediummultiple choice
Review the full routing breakdown →

A security analyst is reviewing a network diagram and sees a device placed between the internet edge router and the internal firewall. The device is described as providing network address translation and stateful connection tracking but not deep application inspection. Which device type is most consistent with this description?

A security team is deploying an inline intrusion prevention system (IPS) on a critical 10 Gbps link and must minimize the risk of the IPS becoming a single point of failure while still blocking malicious traffic. Which TWO design characteristics should the team ensure are in place? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Security Devices sessions

Start a Network Security Devices only practice session

Every question in these sessions is drawn from the Network Security Devices domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Network Security Devices?
Be able to read a topology or ACL and predict whether traffic is permitted, dropped, or translated, and identify which device performs which function. The single most important thing is knowing stateful versus stateless behavior and how inline placement affects availability.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Security Devices questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Security Devices domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.