Courseiva

CC · domain

Network Security

Practise ISC2 Certified in Cybersecurity CC Network Security practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

120 questions31 easy57 medium32 hard

Focused practice

Practice Network Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Network Security

Network Security questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Network Security exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Network Security questions (120)

Click any question to see the full explanation, or start a practice session above.

1

A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?

Hard
2

A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)

Medium
3

A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?

Hard
4

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

Hard
5

A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?

Medium
6

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Hard
7

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
8

A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)

Medium
9

A security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?

Hard
10

A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?

Hard
11

A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?

Easy
12

Which of the following ports is used by HTTPS for secure web traffic?

Medium
13

A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)

Medium
14

Which OSI layer is responsible for logical addressing and routing?

Easy
15

Which three of the following are benefits of using VLANs in a network? (Choose three.)

Medium
16

What is the primary difference between an IDS and an IPS?

Easy
17

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

Medium
18

A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:

Hard
19

An organization wants to protect its internal network from unsolicited inbound traffic while allowing responses to outbound connections. Which TWO firewall features or types are best suited for this? (Select TWO)

Medium
20

Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?

Easy
21

A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?

Medium
22

Which of the following is a benefit of using VLANs in a network?

Easy
23

A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:

Easy
24

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

Medium
25

An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?

Hard
26

Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?

Medium
27

Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?

Easy
28

Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?

Medium
29

A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?

Medium
30

Which of the following is a common mitigation technique for a SYN flood attack?

Hard
31

Which protocol is considered insecure because it transmits data in cleartext, including passwords?

Easy
32

A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?

Medium
33

Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?

Easy
34

A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?

Medium
35

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

Hard
36

A security analyst is investigating a potential man-in-the-middle attack. Which two techniques are commonly used by attackers to perform MITM attacks? (Choose two.)

Medium
37

An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?

Medium
38

A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?

Easy
39

An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?

Medium
40

A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)

Medium
41

In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?

Medium
42

A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?

Medium
43

A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?

Hard
44

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

Medium
45

A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?

Medium
46

A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?

Medium
47

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

Easy
48

A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?

Easy
49

Which three ports are commonly used by secure protocols? (Choose THREE.)

Medium
50

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

Easy
51

A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?

Medium
52

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

Hard
53

A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)

Hard
54

During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?

Hard
55

A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?

Medium
56

An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?

Medium
57

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Hard
58

Which of the following is a connectionless, unreliable transport protocol?

Easy
59

Which layer of the OSI model is responsible for routing packets based on IP addresses?

Easy
60

A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?

Hard
61

Which OSI layer is responsible for routing packets across networks using IP addresses?

Easy
62

Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?

Easy
63

A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?

Medium
64

An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)

Hard
65

An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?

Medium
66

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

Medium
67

An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?

Hard
68

A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?

Medium
69

An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?

Medium
70

An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?

Hard
71

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Medium
72

Which OSI layer is responsible for routing packets based on IP addresses?

Easy
73

A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?

Medium
74

Which protocol is considered insecure because it transmits data, including credentials, in cleartext?

Medium
75

A company wants to mitigate the risk of a man-in-the-middle (MITM) attack. Which three measures are effective? (Choose THREE.)

Hard
76

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

Hard
77

An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?

Medium
78

A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?

Easy
79

Which of the following ports is used by HTTPS?

Easy
80

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Hard
81

Which of the following ports is commonly used for secure web traffic (HTTPS)?

Easy
82

An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?

Easy
83

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

Medium
84

During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?

Hard
85

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

Medium
86

A company wants to protect its internal web server from common web application attacks. Which two security measures are most appropriate? (Choose TWO.)

Medium
87

Which TCP segment is sent to initiate the three-way handshake?

Easy
88

Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?

Easy
89

A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?

Medium
90

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

Medium
91

An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?

Hard
92

A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)

Medium
93

Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)

Medium
94

A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?

Hard
95

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Medium
96

An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?

Hard
97

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

Easy
98

Which of the following is a security concern associated with the Telnet protocol?

Medium
99

An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?

Medium
100

Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?

Medium
101

Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?

Medium
102

Which common port is used by DNS and which transport layer protocol does it primarily use?

Medium
103

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Medium
104

Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?

Medium
105

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
106

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

Hard
107

A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:

Hard
108

An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?

Medium
109

A company's network has multiple VLANs. An attacker on VLAN 10 sends a frame with a forged source MAC address to a switch, hoping to intercept traffic intended for the default gateway. Which attack is being executed?

Hard
110

Which port number is associated with HTTPS, and what protocol encrypts the communication?

Easy
111

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Easy
112

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Easy
113

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Hard
114

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

Medium
115

An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?

Hard
116

A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)

Medium
117

An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?

Medium
118

A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?

Hard
119

Which layer of the OSI model is responsible for routing packets across networks?

Easy
120

Which security control would best mitigate the risk of network sniffing on a wired LAN segment?

Medium

Frequently asked questions

What does the Network Security domain cover on the CC exam?
Network Security questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 120 Network Security questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISC2 Certified in Cybersecurity CC Network Security Practice Questions