Courseiva

GSEC · topic practice

Networking and Protocols practice questions

This domain covers TCP/IP fundamentals, protocol behavior, and network service risks. Candidates must identify secure protocols for data in transit, assess ICMP and UDP exposure, and detect DNS tunneling. Questions present analyst scenarios requiring protocol selection, service risk analysis, and traffic characteristic interpretation.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Networking and Protocols

What the exam tests

What to know about Networking and Protocols

A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.

Selecting TLS, IPsec, or SSH for confidentiality and authentication between internal servers.

Identifying risks of ICMP Timestamp replies on perimeter routers, including reconnaissance and fingerprinting.

Comparing UDP and TCP: connectionless vs connection-oriented, reliability, ordering, and header fields.

Analyzing DNS query length, frequency, and record types to detect DNS tunneling to command-and-control.

Watch out for

Common Networking and Protocols exam traps

  • ▸Assuming TLS alone authenticates both endpoints; without mutual authentication, only the server is verified.
  • ▸Believing ICMP Timestamp is harmless; it reveals system time and uptime for reconnaissance and fingerprinting.
  • ▸Confusing UDP and TCP reliability; UDP does not guarantee delivery, ordering, or congestion control.

Practice set

Networking and Protocols questions

20 questions · select your answer, then reveal the explanation

Question 1hardmulti select
Read the full DNS explanation →

An incident responder is analyzing a compromised corporate workstation and finds evidence of DNS poisoning in the local cache. Which THREE indicators or mitigation strategies are most relevant to identifying and preventing this specific threat? (Choose three)

An analyst reviewing packet captures notices that a client completed a TCP handshake with a server, sent a request, and then the server sent a packet with the RST flag set immediately after receiving the request. The client had no prior connection to that port. What is the most likely explanation for the RST?

Question 3mediummultiple choice
Read the full DNS explanation →

A security analyst suspects an internal host is communicating with a command-and-control server using DNS tunneling. Which network protocol characteristic should the analyst examine to best identify this malicious behavior?

Question 4hardmultiple choice
Read the full DHCP explanation →

An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?

Question 5easymultiple choice
Review the full routing breakdown →

During a routine vulnerability assessment, an analyst discovers that a network router is responding to ICMP Timestamp requests. What is the primary security risk associated with enabling this service on perimeter networking equipment?

During a forensic investigation of a compromised web application server, a security analyst discovers that outbound administrative traffic is flowing over unexpected ports and non-standard protocols. Which security architecture control should have been implemented at the network perimeter to restrict this unauthorized outbound communication?

An administrator observes a series of SYN packets originating from an internal workstation targeting random ports on various external IP addresses. The traffic is not resulting in established TCP connections. What is the most likely purpose of this network behavior?

A security analyst needs to ensure that sensitive data in transit between two internal servers remains confidential and authenticated. Which protocol provides the most robust security for this requirement?

Which TWO of the following statements accurately describe the characteristics of UDP compared to TCP?

Question 10hardmultiple choice
Review the full subnetting walkthrough →

An analyst reviewing packet captures from a corporate network sees a workstation send an ARP request for the default gateway's IP address. Within milliseconds, two different ARP replies arrive from two different MAC addresses, and the workstation begins forwarding all off-subnet traffic to the second MAC. The analyst suspects an on-path attack. Which security control would most directly prevent this specific behavior on the local segment?

Question 11mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is deploying a new IDS sensor on a switched segment and needs it to see all unicast traffic between two hosts on the same VLAN, including traffic not addressed to the sensor. The switch supports port mirroring. Which configuration should the engineer implement?

A security analyst is reviewing a packet capture of traffic between a user workstation and a public web server. The analyst observes the workstation completing a three-way handshake on TCP port 443, then negotiating encryption parameters, and finally requesting a specific resource path. The analyst wants to confirm that the client verified the identity of the server before any application data was sent. Which protocol mechanism in this exchange provides that server identity verification?

A network engineer is documenting how a workstation obtains an IPv4 address on a corporate LAN. The engineer observes the workstation broadcasting a request, receiving a unicast offer from a server, broadcasting a formal request for that address, and finally receiving an acknowledgment. The engineer must record which transport protocol and ports this address-assignment exchange uses. Which combination correctly describes the exchange?

A security team is designing a network segmentation scheme for a new data center. They want to restrict lateral movement between workloads and enforce policy based on workload identity rather than IP address. Which TWO technologies best support this goal? (Choose two.)

Question 15hardmulti select
Read the full VPN explanation →

A security engineer is analyzing why a remote user's VPN session intermittently fails to reach internal resources even though the tunnel itself stays up. Packet captures show large packets are dropped while small ones succeed, and the engineer suspects a path MTU discovery problem. Which TWO conditions would cause this behavior on the path between the client and the internal server? (Choose two.)

Question 16easymultiple choice
Read the full DNS explanation →

A help desk technician is troubleshooting a user's inability to reach an internal web application by its hostname, although the application is reachable by IP address. The user's workstation is configured with a DNS server address that is reachable. Which command should the technician run first to verify name resolution from the workstation?

A security analyst is investigating a suspected man-in-the-middle attack on a switched corporate network. The analyst reviews switch logs and notices that a single physical port has learned an unusually large number of distinct MAC addresses within a short period. The analyst wants to determine which attack technique this behavior most directly indicates and what impact it produces on the switch's forwarding behavior. Which statement best describes this scenario?

A security architect is designing a remote access solution and wants to protect against credential theft and man-in-the-middle attacks while allowing employees to use personal devices. The solution must not require installing a client certificate on the personal device. Which approach best meets these requirements?

Question 19hardmultiple choice
Read the full DNS explanation →

A network security team is reviewing how name resolution traffic can be abused. An analyst notes that a compromised host is generating a high volume of DNS queries for long, random-looking subdomains under a single external domain, and responses contain similarly encoded data. The team wants to classify this activity and describe the underlying mechanism. Which statement best characterizes what is occurring?

A security analyst is reviewing packet captures from a corporate network and notices that several internal hosts are receiving unsolicited ARP replies claiming that the default gateway's IP address maps to a MAC address belonging to an unknown device. The analyst confirms the legitimate gateway MAC is different. Which type of attack is most likely occurring?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Networking and Protocols sessions

Start a Networking and Protocols only practice session

Every question in these sessions is drawn from the Networking and Protocols domain — nothing else.

Related practice questions

Related GSEC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the GSEC exam test about Networking and Protocols?
A candidate must select appropriate secure protocols, evaluate network service risks, and interpret protocol characteristics. The most important thing is to match the protocol to the security requirement: use TLS or IPsec for authenticated confidentiality, and recognize that UDP lacks reliability and ordering.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Networking and Protocols questions in a focused session?
Yes — the session launcher on this page draws every question from the Networking and Protocols domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other GSEC topics?
Use the topic links above to move to related areas, or go back to the GSEC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the GSEC exam covers. They are not copied from any real exam or dump site.