CC · domain
Network Security
Practise ISC2 Certified in Cybersecurity CC Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Network Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Network Security
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Network Security exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Network Security questions (120)
Click any question to see the full explanation, or start a practice session above.
A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?
Hard2A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)
Medium3A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?
Hard4During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?
Hard5A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?
Medium6A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?
Hard7Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy8A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)
Medium9A security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?
Hard10A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?
Hard11A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?
Easy12Which of the following ports is used by HTTPS for secure web traffic?
Medium13A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)
Medium14Which OSI layer is responsible for logical addressing and routing?
Easy15Which three of the following are benefits of using VLANs in a network? (Choose three.)
Medium16What is the primary difference between an IDS and an IPS?
Easy17A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)
Medium18A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:
Hard19An organization wants to protect its internal network from unsolicited inbound traffic while allowing responses to outbound connections. Which TWO firewall features or types are best suited for this? (Select TWO)
Medium20Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?
Easy21A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?
Medium22Which of the following is a benefit of using VLANs in a network?
Easy23A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:
Easy24A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?
Medium25An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?
Hard26Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?
Medium27Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?
Easy28Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?
Medium29A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?
Medium30Which of the following is a common mitigation technique for a SYN flood attack?
Hard31Which protocol is considered insecure because it transmits data in cleartext, including passwords?
Easy32A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?
Medium33Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?
Easy34A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?
Medium35An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?
Hard36A security analyst is investigating a potential man-in-the-middle attack. Which two techniques are commonly used by attackers to perform MITM attacks? (Choose two.)
Medium37An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?
Medium38A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?
Easy39An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?
Medium40A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)
Medium41In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?
Medium42A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?
Medium43A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?
Hard44An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?
Medium45A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?
Medium46A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?
Medium47Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)
Easy48A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?
Easy49Which three ports are commonly used by secure protocols? (Choose THREE.)
Medium50An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?
Easy51A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?
Medium52An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)
Hard53A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)
Hard54During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?
Hard55A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?
Medium56An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?
Medium57An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)
Hard58Which of the following is a connectionless, unreliable transport protocol?
Easy59Which layer of the OSI model is responsible for routing packets based on IP addresses?
Easy60A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?
Hard61Which OSI layer is responsible for routing packets across networks using IP addresses?
Easy62Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?
Easy63A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?
Medium64An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)
Hard65An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?
Medium66A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?
Medium67An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?
Hard68A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?
Medium69An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?
Medium70An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?
Hard71A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)
Medium72Which OSI layer is responsible for routing packets based on IP addresses?
Easy73A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?
Medium74Which protocol is considered insecure because it transmits data, including credentials, in cleartext?
Medium75A company wants to mitigate the risk of a man-in-the-middle (MITM) attack. Which three measures are effective? (Choose THREE.)
Hard76Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)
Hard77An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?
Medium78A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?
Easy79Which of the following ports is used by HTTPS?
Easy80An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)
Hard81Which of the following ports is commonly used for secure web traffic (HTTPS)?
Easy82An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?
Easy83An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?
Medium84During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?
Hard85An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?
Medium86A company wants to protect its internal web server from common web application attacks. Which two security measures are most appropriate? (Choose TWO.)
Medium87Which TCP segment is sent to initiate the three-way handshake?
Easy88Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?
Easy89A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?
Medium90A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)
Medium91An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?
Hard92A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)
Medium93Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)
Medium94A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?
Hard95Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?
Medium96An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?
Hard97A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?
Easy98Which of the following is a security concern associated with the Telnet protocol?
Medium99An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?
Medium100Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?
Medium101Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?
Medium102Which common port is used by DNS and which transport layer protocol does it primarily use?
Medium103A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)
Medium104Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?
Medium105Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy106Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?
Hard107A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:
Hard108An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?
Medium109A company's network has multiple VLANs. An attacker on VLAN 10 sends a frame with a forged source MAC address to a switch, hoping to intercept traffic intended for the default gateway. Which attack is being executed?
Hard110Which port number is associated with HTTPS, and what protocol encrypts the communication?
Easy111Which protocol is used to resolve IP addresses to MAC addresses on a local network?
Easy112Which two of the following are characteristics of a stateful firewall? (Choose TWO.)
Easy113A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?
Hard114An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?
Medium115An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?
Hard116A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)
Medium117An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?
Medium118A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?
Hard119Which layer of the OSI model is responsible for routing packets across networks?
Easy120Which security control would best mitigate the risk of network sniffing on a wired LAN segment?
MediumOther domains
All CC exam domains
Frequently asked questions
- What does the Network Security domain cover on the CC exam?
- Network Security questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 120 Network Security questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Network Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.