Courseiva

CCNA Cc Network Security Questions

75 of 159 questions · Page 1/3 · Cc Network Security topic · Answers revealed

1
MCQhard

A company is deploying a security device that inspects HTTP and HTTPS traffic, applies OWASP rules, and can block malicious requests before they reach the web server. Which device best fits this description?

A.Honeypot
B.Intrusion Prevention System (IPS)
C.Web Application Firewall (WAF)
D.Stateful firewall
AnswerC

A WAF operates at the application layer, terminating and inspecting HTTP and HTTPS requests, applying rule sets such as the OWASP Core Rule Set, and blocking malicious traffic before it reaches the web server. This matches the described inline inspection and blocking requirement.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP and HTTPS traffic at Layer 7, apply rule sets such as the OWASP ModSecurity Core Rule Set, and block malicious requests like SQL injection, XSS, and CSRF before they reach the web server. It understands web protocols and can enforce positive/negative security models based on HTTP headers, cookies, and payloads. This matches the described requirement exactly.

Exam trap

The trap here is confusing an IPS with a WAF — both can block malicious traffic, but only a WAF is purpose-built for HTTP/HTTPS application-layer inspection and OWASP rule enforcement.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not to inspect and block production HTTP/HTTPS traffic. Option B is wrong because an IPS inspects network traffic for known attack signatures and anomalies at Layers 3-7 but is not specialized for HTTP/HTTPS application-layer semantics like OWASP rules; it lacks the deep HTTP parsing and session awareness of a WAF. Option D is wrong because a stateful firewall tracks connection state at Layers 3-4 and cannot inspect HTTP payloads or apply OWASP rules — it only permits or denies based on IP, port, and connection state.

2
Multi-Selecthard

A financial services firm is redesigning its internal network after an incident in which malware spread from a compromised workstation to several unrelated departments. The security architect proposes dividing the flat network into smaller zones so that a future compromise stays contained. Which two measures best support this goal? (Choose two.)

Select 2 answers
A.Deploying a signature-based intrusion detection sensor on the core switch
B.Applying the principle of least privilege to internal firewall rule sets and access control lists
C.Increasing the bandwidth of the internal network backbone between departments
D.Implementing virtual LANs with inter-VLAN filtering by a firewall
E.Enabling dynamic host configuration protocol snooping on all access switches
AnswersB, D

Restricting internal rules and ACLs so each zone can reach only the services it genuinely needs shrinks the paths available for lateral movement. Combined with segmentation, least privilege ensures that even permitted connections are narrowly scoped, so a single compromised workstation cannot pivot broadly across departments.

Why this answer

Containment requires both breaking the flat network into isolated zones and restricting what traffic may cross between them. VLANs with firewall-enforced inter-VLAN rules provide the zones, while least-privilege ACLs and rule sets ensure that any permitted crossing is minimal, together limiting how far a single compromised workstation can spread.

Exam trap

The trap here is selecting monitoring or performance improvements, which detect or speed up traffic, instead of the two controls that actually partition the network and restrict permitted paths.

3
Multi-Selectmedium

A financial services company is designing a demilitarized zone (DMZ) for its public web and email relay servers. The security architect wants to reduce the attack surface and limit what an attacker can reach if a DMZ host is compromised. Which two design practices should be implemented? (Choose two.)

Select 2 answers
A.Allow the DMZ hosts to initiate connections to any internal server for management convenience.
B.Place the DMZ servers on the same VLAN as internal user workstations to simplify routing.
C.Permit only the specific inbound ports required for the public services into the DMZ.
D.Configure the internal firewall to allow only required DMZ-to-internal traffic and deny the rest.
E.Use the same firewall rule set for both the external and internal firewalls to reduce administrative effort.
AnswersC, D

Restricting inbound access to only the ports needed for web and email reduces the exposed attack surface and prevents attackers from reaching unnecessary services. This is a core DMZ design principle: the external firewall allows only what the public service requires, such as HTTPS for the web server and the mail relay port. It directly limits what an external attacker can probe or exploit.

Why this answer

A DMZ should expose only the ports required for public services and should enforce strict, default-deny rules on the internal firewall so that a compromised DMZ host cannot freely reach internal systems. These two practices reduce attack surface and contain lateral movement. Opening management paths or sharing VLANs and rule sets with internal networks removes the separation that makes the DMZ valuable.

Exam trap

The trap here is treating the DMZ as a trusted extension of the internal network, which leads to permissive rules that allow a compromised host to pivot inward.

4
Multi-Selectmedium

A security analyst is investigating a potential DDoS attack. Which of the following are common indicators of a DDoS? (Choose TWO)

Select 2 answers
A.Low CPU usage on servers
B.Unusually high traffic volume from multiple IP addresses
C.Single source sending many packets
D.Slow network performance and increased latency
E.Decrease in DNS queries
AnswersB, D

Unusually high traffic volume from multiple IP addresses directly satisfies the distributed-source constraint distinguishing DDoS from single-origin DoS. Attackers coordinate botnets so requests flood from many geographically dispersed hosts, exhausting bandwidth or connection tables. This pattern is a primary detection indicator in Microsoft Entra ID and network monitoring tools.

Why this answer

Option B is correct because a DDoS (Distributed Denial-of-Service) attack by definition originates from many compromised hosts (a botnet), so the analyst would observe an unusually high volume of traffic arriving from numerous, often geographically dispersed IP addresses. Option D is correct because the flood of requests exhausts server, bandwidth, or connection-table resources, which manifests as slow network performance, increased latency, timeouts, and unresponsive services for legitimate users. Option A is wrong because a DDoS typically drives CPU, memory, and bandwidth utilization up, not down.

Option C is wrong because traffic from a single source describes a DoS attack, not a distributed one. Option E is wrong because DNS query volume usually spikes during many DDoS attacks (e.g., DNS amplification/reflection) rather than decreasing.

Exam trap

The trap here is confusing DoS (single source) with DDoS (many sources) and assuming resource usage always drops during an attack, when in fact CPU and bandwidth typically spike.

5
MCQeasy

A security administrator is configuring a wireless network for a small office. The requirement is to use a protocol that provides strong encryption and authentication, and that is resistant to offline dictionary attacks on captured handshakes. Which protocol should be selected?

A.Open authentication with Captive Portal
B.Wi-Fi Protected Access 2 (WPA2) with Pre-Shared Key (PSK)
C.Wi-Fi Protected Access 3 (WPA3) with Simultaneous Authentication of Equals (SAE)
D.Wired Equivalent Privacy (WEP)
AnswerC

WPA3 introduces SAE, a Dragonfly handshake that provides forward secrecy and resists offline dictionary attacks. Even if an attacker captures the handshake, they cannot perform an offline guessing attack; they must interact with the network for each guess, which is detectable and rate-limited. This directly satisfies the requirement for strong encryption and resistance to offline attacks.

Why this answer

WPA3 with SAE is designed to replace WPA2-PSK's vulnerable four-way handshake with a mutually authenticated exchange that resists offline dictionary attacks. It also provides stronger encryption through the use of SAE and, in WPA3-Personal, forward secrecy. The other options either lack strong encryption or remain susceptible to offline attacks.

Exam trap

The trap here is assuming WPA2-PSK is sufficient because it is widely used, when its four-way handshake still permits offline dictionary attacks on weak passphrases.

6
MCQmedium

A university wants to provide guests with internet access through the same physical wireless infrastructure used by staff, but guests must not reach internal research servers. Staff must authenticate with institutional credentials. Which combination of controls best achieves this separation?

A.A single pre-shared key for all users plus a captive portal.
B.MAC address filtering that allows only registered devices on the wireless network.
C.Separate SSIDs mapped to different VLANs, with 802.1X for staff and a guest portal for visitors.
D.WPA3-Personal on a single SSID with a rotating password posted at reception.
AnswerC

Separate SSIDs mapped to distinct VLANs create logical isolation between guest and staff traffic on shared hardware, and 802.1X authenticates staff against institutional credentials while a guest portal handles visitors. Together these controls enforce the requirement that guests reach only the internet and cannot access internal research servers, while staff retain authenticated access.

Why this answer

Separate SSIDs tied to separate VLANs provide the isolation, and using 802.1X for staff plus a guest portal for visitors supplies the differentiated authentication the university needs. Shared keys, MAC filtering, and a single personal-network SSID all fail to distinguish populations or to prevent guests from reaching internal research servers, so they cannot meet the stated requirements.

Exam trap

The trap here is treating wireless encryption, such as WPA3-Personal, as equivalent to user authentication and network segmentation, when it only protects the radio link.

7
MCQhard

A security engineer is configuring a network security device that can block malicious HTTP requests based on application-layer inspection. Which device type is most suitable?

A.Intrusion Prevention System (IPS)
B.Network-based Intrusion Detection System (NIDS)
C.Web Application Firewall (WAF)
D.Stateful firewall
AnswerC

A Web Application Firewall inspects HTTP request contents at the application layer, matching signatures and rules against payloads, URLs and headers. This lets it block malicious HTTP requests, which a packet-filtering firewall or traditional IPS cannot do at that layer.

Why this answer

A Web Application Firewall (WAF) operates at the application layer (Layer 7) and is specifically designed to inspect HTTP/HTTPS traffic, blocking malicious requests such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attacks. It understands HTTP semantics like headers, cookies, methods, and payloads, making it the right tool for application-layer request filtering.

Exam trap

The trap here is confusing an IPS with a WAF: both can block malicious traffic, but only a WAF is purpose-built for HTTP application-layer request inspection, and the question explicitly specifies HTTP requests.

How to eliminate wrong answers

Option A is wrong because an IPS, while capable of deep packet inspection, is a broader network security control focused on detecting and blocking intrusions across many protocols; it is not specialized for HTTP application-layer request filtering. Option B is wrong because a NIDS only detects and alerts on suspicious traffic—it does not block requests. Option D is wrong because a stateful firewall tracks connection state at Layers 3–4 and cannot inspect HTTP payloads or block application-layer attacks.

8
MCQhard

During a DDoS attack, a company's web server is overwhelmed with a high volume of SYN packets from spoofed IP addresses, never completing the TCP handshake. Which type of attack is this?

A.ICMP flood
B.UDP flood
C.Amplification attack
D.SYN flood
AnswerD

A SYN flood exploits the TCP three-way handshake: spoofed source addresses generate numerous half-open connections, exhausting the server's backlog queue so legitimate clients cannot connect. The never-completed handshake described in the stem is the defining characteristic of this volumetric attack.

Why this answer

A SYN flood sends many SYN packets to exhaust server resources by leaving half-open connections.

9
MCQmedium

A network administrator is troubleshooting connectivity issues and notices that frames are being dropped due to excessive collisions. Which OSI layer is most directly associated with this issue?

A.Physical
B.Data Link
C.Network
D.Transport
AnswerB

Collisions occur when devices on a shared medium transmit simultaneously; Ethernet's CSMA/CD and frame delivery operate at the Data Link layer, so excessive collisions and dropped frames are diagnosed there. Layer 1 handles raw signalling, not collision handling.

Why this answer

Excessive collisions are a Layer 2 (Data Link) phenomenon because CSMA/CD and collision detection operate at the MAC sublayer of the Data Link layer. When two stations transmit simultaneously on a shared Ethernet segment, their frames collide, and the Data Link layer handles retransmission and backoff. The Physical layer deals with the electrical/optical signalling itself, not collision semantics.

Exam trap

The trap here is that candidates may associate 'dropped frames' with the Physical layer because collisions sound like a cabling/signal problem, but the exam expects recognition that collision handling is defined at the Data Link (MAC) sublayer.

How to eliminate wrong answers

Option A is wrong because the Physical layer concerns voltage levels, cabling, connectors, and bit transmission — it does not define collision handling, which is a MAC-layer function. Option C is wrong because the Network layer handles logical addressing and routing (IP), and collisions are not a routing concern. Option D is wrong because the Transport layer handles end-to-end reliability and flow control (TCP/UDP), which is above the collision domain and unrelated to frame collisions.

10
Multi-Selecthard

A security team is analyzing network segmentation strategies. Which THREE of the following are benefits of using VLANs for network segmentation?

Select 3 answers
A.They allow logical grouping of users regardless of physical location
B.They eliminate the need for IP addressing
C.They increase the collision domain size
D.They reduce broadcast traffic by dividing broadcast domains
E.They can isolate sensitive systems from the rest of the network
AnswersA, D, E

VLANs decouple broadcast domains from physical switch ports, so membership follows configuration rather than cabling. This satisfies the stem's benefit of grouping users logically irrespective of physical location, letting a department span floors or buildings while remaining one isolated Layer 2 segment.

Why this answer

Option A is correct because VLANs are Layer 2 logical constructs that let you group users by function, department, or role rather than by their physical switch port or building location, so a user in one office can belong to the same VLAN as a colleague elsewhere. Option D is correct because each VLAN forms its own broadcast domain, so broadcasts are confined to the VLAN's member ports instead of flooding the entire switched network, thereby reducing broadcast traffic. Option E is correct because placing sensitive systems (for example, servers holding regulated data) in a dedicated VLAN lets you control inter-VLAN traffic with Layer 3 filtering, ACLs, or a firewall, isolating them from general user traffic.

Option B is not correct because VLANs operate at Layer 2 and still require Layer 3 addressing (IP subnets) for inter-VLAN routing and end-to-end communication. Option C is not correct because VLANs actually shrink collision domains (each switch port is its own collision domain) and divide broadcast domains; they do not increase the collision domain size.

Exam trap

CC often tests the misconception that VLANs eliminate IP addressing or increase collision domains, so candidates who confuse collision and broadcast domains pick the wrong options.

11
MCQeasy

A small business wants to provide secure remote access to its internal file server for employees working from home. The company requires that all traffic between the employee's device and the file server be encrypted and that the internal network topology remain hidden. Which technology best meets these requirements?

A.VPN
C.SSH
D.SFTP
AnswerA

A virtual private network (VPN) creates an encrypted tunnel between the remote user and the corporate network, protecting data in transit and hiding internal IP addresses. It allows employees to access internal resources as if they were on-site. This directly satisfies the requirement for encrypted communication and concealment of the internal network topology.

Why this answer

A VPN is designed to provide encrypted, tunneled access to an entire network, making it ideal for remote employees who need to reach internal resources securely. It encapsulates traffic, encrypts it, and masks internal addresses, fulfilling both the encryption and topology-hiding requirements. Other options are protocol-specific and cannot deliver equivalent network-level access.

Exam trap

The trap here is assuming any encrypted protocol (like SSH or HTTPS) provides equivalent remote access; only a VPN creates a network-level tunnel that hides internal topology and supports multiple services.

12
MCQeasy

A small accounting firm has a single flat network. During a risk review, the consultant recommends placing all wireless guest users on a separate logical network so they cannot reach the internal file server, even though both networks share the same physical switches and access points. Which technology best accomplishes this?

AnswerD

A VLAN creates logically separate broadcast domains on shared physical infrastructure, so guest wireless traffic can be confined to its own segment and blocked from reaching the internal file server through Layer 3 rules. This directly satisfies the requirement to isolate guest users without running new cabling or buying separate switches, and it is the foundational segmentation technology for this scenario.

Why this answer

VLANs let one physical switch infrastructure carry multiple isolated logical networks, which is exactly what is needed to separate guest wireless users from internal resources. Access control lists or firewall rules between the VLANs enforce the policy. NAT, DHCP, and DNS are addressing or naming services and do not by themselves prevent one group of users from reaching another group's systems.

Exam trap

The trap here is assuming that giving guests a different IP subnet through DHCP automatically isolates them, when segmentation actually requires a VLAN or equivalent Layer 2 separation plus enforcement.

13
MCQhard

A retail chain wants to prevent customers on its guest wireless from reaching point-of-sale terminals on the corporate wired network, while still allowing guests to browse the internet. The chain already separates the two networks with a firewall. Which additional configuration most directly enforces this restriction?

A.Configure the firewall to deny traffic from the guest wireless subnet to the point-of-sale subnet while permitting outbound internet access
B.Enable WPA3 encryption on the guest wireless network
C.Change the guest wireless pre-shared key on a monthly schedule
D.Deploy a wireless intrusion prevention system to detect rogue access points
AnswerA

An explicit deny from the guest subnet to the point-of-sale subnet, paired with a permit for internet-bound traffic, enforces the exact requirement at the boundary between the two networks. Because the firewall already separates them, this rule is the direct and auditable control that prevents guests from initiating sessions to the terminals.

Why this answer

Because the networks are already separated by a firewall, the restriction is enforced by a rule that denies guest-subnet traffic destined for the point-of-sale subnet while still allowing internet access. This places the control at the routing boundary where it can be logged and audited, rather than relying on wireless-layer measures that only affect the radio link.

Exam trap

The trap here is assuming that stronger wireless encryption or key rotation isolates guests from internal systems, when the restriction must be enforced by filtering routed traffic between the subnets.

14
MCQeasy

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

AnswerA

ARP broadcasts a request asking which device holds a given IPv4 address, and the owner replies with its MAC address, which the sender caches. This address-resolution function on the local segment is exactly what the stem asks for.

Why this answer

ARP (Address Resolution Protocol) resolves a known IPv4 address to its corresponding MAC address on a local network segment by broadcasting an ARP request and receiving a unicast ARP reply. It is the standard Layer 2/Layer 3 glue protocol for Ethernet and IPv4 communication.

Exam trap

The trap is conflating DNS (name-to-IP) with ARP (IP-to-MAC); candidates who skim may pick DNS because both are 'resolution' protocols, but the question specifies IP-to-MAC on a local network.

How to eliminate wrong answers

Option B is wrong because DHCP dynamically assigns IP addresses and other network configuration to hosts, not MAC resolution. Option C is wrong because DNS resolves human-readable domain names to IP addresses, not IP addresses to MAC addresses. Option D is wrong because ICMP is used for diagnostic and error messaging (e.g., ping, traceroute), not address resolution.

15
Multi-Selectmedium

A network administrator needs to segment traffic and isolate sensitive systems. Which two technologies can achieve this? (Choose TWO.)

Select 2 answers
B.VLANs
C.Stateful firewall
D.DMZ
E.Subnetting
AnswersB, E

VLANs logically partition a single physical network into isolated broadcast domains at Layer 2, so sensitive systems exchange traffic only with permitted members. This directly satisfies the stem's segmentation and isolation requirement, restricting lateral movement without additional hardware.

Why this answer

VLANs (B) are correct because they logically segment a switched network at Layer 2, allowing the administrator to isolate sensitive systems into separate broadcast domains and control traffic between them via inter-VLAN routing or ACLs. Subnetting (E) is correct because dividing a network into smaller IP subnets at Layer 3 separates traffic into distinct address ranges, enabling isolation and controlled routing between sensitive systems and the rest of the network. An IDS (A) only monitors and alerts on malicious activity; it does not segment or isolate traffic.

A stateful firewall (C) filters traffic based on connection state but is a control mechanism rather than a segmentation technology itself. A DMZ (D) is a perimeter network design that exposes public-facing services, not a general-purpose segmentation method for isolating internal sensitive systems.

Exam trap

The CC exam often tests the difference between segmentation technologies (VLANs, subnetting) and security controls (IDS, firewalls) or design patterns (DMZ), tricking candidates into selecting tools that monitor or filter rather than segment.

16
MCQhard

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and a public DNS server. The requirement is to ensure that if either public server is compromised, it cannot initiate connections to the internal network. Which design approach best meets this requirement?

A.Use a single firewall with three interfaces: internet, DMZ, and internal, with rules that allow any traffic from the DMZ to the internal network.
B.Create a DMZ on a separate subnet with firewall rules that allow inbound traffic to the servers but deny all outbound traffic from the DMZ to the internal network.
C.Place both servers on the internal network and use host-based firewalls to restrict outbound traffic.
D.Place the servers on the internal network and use a reverse proxy to handle all incoming requests.
AnswerB

A DMZ on a separate subnet with a firewall that blocks outbound traffic from the DMZ to the internal network prevents a compromised server from pivoting into the internal network. Inbound access from the internet is permitted to the public services, while internal access is strictly controlled. This segmentation enforces the requirement effectively.

Why this answer

The most effective way to prevent a compromised DMZ host from reaching the internal network is to segment the DMZ on its own subnet and enforce firewall rules that deny outbound traffic from the DMZ to the internal network. This limits lateral movement and contains potential breaches. Other options either place servers on the internal network or allow unrestricted DMZ-to-internal traffic, failing the requirement.

Exam trap

The trap here is thinking that a DMZ alone provides security, when without strict outbound filtering a compromised server can still initiate connections into the internal network.

17
MCQhard

A security analyst detects a large volume of small ICMP echo request packets from multiple external sources targeting a single internal server, causing the server to become unresponsive. Which type of attack is this?

A.ICMP flood (DDoS)
B.ARP spoofing
C.Man-in-the-middle
D.SYN flood
AnswerA

Many external hosts simultaneously sending small ICMP echo requests to one internal server is a distributed denial-of-service flood. The volume of echo requests exhausts the target's resources, making it unresponsive, which distinguishes it from a single-source ping flood.

Why this answer

A DDoS attack using ICMP flood overwhelms the target with echo requests, consuming bandwidth and resources.

18
MCQmedium

A hospital's network team must allow external vendors to reach a specific internal patient-monitoring system without exposing the rest of the clinical VLAN. The solution must enforce least privilege and terminate vendor sessions at a hardened appliance before any internal resource is contacted. Which technology best meets these requirements?

A.A jump host placed directly on the clinical VLAN with local firewall rules.
B.A site-to-site IPsec tunnel built directly between each vendor and the monitoring system.
C.A secure remote access gateway that brokers and inspects vendor sessions before forwarding them.
D.A remote access VPN that places vendors on the clinical VLAN after authentication.
AnswerC

A secure remote access gateway authenticates vendors, terminates their sessions on a hardened appliance, and then proxies only approved connections to the specific monitoring system. This enforces least privilege because vendors never obtain direct network reachability to the clinical VLAN, and the appliance can log, inspect, and restrict each session, satisfying both the isolation and session-termination requirements.

Why this answer

Brokering vendor access through a hardened gateway enforces least privilege because each session is authenticated, terminated, and inspected before any internal system is contacted. Direct VLAN placement, VPN-to-VLAN access, and site-to-site tunnels all create broader network reachability than necessary, allowing lateral movement if a vendor endpoint is compromised. Only the access gateway keeps the clinical VLAN hidden while permitting tightly scoped, auditable sessions.

Exam trap

The trap here is assuming that any encrypted or authenticated remote connection automatically enforces least privilege, when reachability to the target VLAN is what actually determines exposure.

19
MCQeasy

A security analyst notices unusual traffic on the network and wants to capture packets for analysis without altering traffic. Which device should they use?

B.Intrusion Prevention System (IPS)
C.Proxy server
D.Network tap
AnswerD

A network tap passively copies frames at the physical layer, delivering a duplicate stream to the capture device without introducing latency, dropping packets or altering traffic. This satisfies the requirement to capture packets for analysis while leaving the original traffic untouched.

Why this answer

A network tap is a passive hardware device inserted inline (or via a mirror port) that copies traffic to a monitoring port without altering or delaying the original traffic. This makes it ideal for packet capture and analysis because it provides a true copy of the wire traffic and does not introduce a point of failure or modify packets. Firewalls, IPS, and proxies are all inline devices that can alter or block traffic.

Exam trap

The trap is confusing inline security devices (firewall, IPS, proxy) with passive monitoring devices; the exam tests that only a tap provides a non-intrusive copy of traffic without altering it.

How to eliminate wrong answers

Option A is wrong because a firewall is an inline security device that inspects and can block or modify traffic, so it is not passive and may not provide a full copy of all packets. Option B is wrong because an IPS is inline and can drop or alter malicious traffic, which changes the traffic and is not suitable for passive capture. Option C is wrong because a proxy server terminates and re-initiates connections, altering traffic and not providing a transparent copy of the original packets.

20
MCQmedium

Which of the following ports is used by HTTPS for secure web traffic?

A.443
B.80
C.22
D.53
AnswerA

Port 443 carries HTTP over TLS, encrypting web traffic between client and server. This directly satisfies the stem's requirement for HTTPS, the secure variant of HTTP. Port 80 serves unencrypted HTTP, while 22 and 21 belong to SSH and FTP respectively, so 443 is the sole match.

Why this answer

HTTPS uses port 443 by default.

21
Multi-Selectmedium

A network administrator is designing a DMZ to host a web server, an email server, and a DNS server. Which TWO of the following principles should be applied to secure the DMZ? (Select TWO.)

Select 2 answers
A.Use a firewall to control traffic between the DMZ and internal network.
B.Place all DMZ servers on the same VLAN to simplify management.
C.Implement separate VLANs for each type of server to limit lateral movement.
D.Allow all outbound traffic from the DMZ to the internet for ease of use.
E.Disable logging on DMZ devices to conserve resources.
AnswersA, C

A firewall between the DMZ and internal network enforces traffic control, satisfying the requirement to contain compromised DMZ hosts. It restricts inbound access so internet-facing servers cannot freely reach internal resources, applying least privilege and limiting lateral movement if the web, email, or DNS server is breached.

Why this answer

Option A is correct because a firewall must mediate traffic between the DMZ and the internal network, enforcing rules that prevent a compromised DMZ host from directly reaching internal resources; this segmentation is a core DMZ security control. Option C is correct because placing each server type (web, email, DNS) on its own VLAN segments the DMZ and limits lateral movement if one server is compromised, so an attacker cannot easily pivot to the other servers. Option B is incorrect because putting all DMZ servers on one flat VLAN increases the attack surface and enables lateral movement between them.

Option D is incorrect because unrestricted outbound traffic from the DMZ enables data exfiltration, command-and-control callbacks, and abuse of the servers; outbound traffic should be restricted to required destinations and ports. Option E is incorrect because disabling logging removes the audit trail needed for detecting and investigating intrusions, and logging is a required security control, not an optional resource saving.

Exam trap

The trap is choosing 'simplify management' options (like same VLAN or allow all outbound) because they sound operationally convenient, but the CC exam tests security-first principles: segmentation, least privilege, and logging are always preferred over convenience.

22
MCQeasy

Which OSI layer is responsible for logical addressing and routing?

A.Data Link layer
B.Network layer
C.Transport layer
D.Physical layer
AnswerB

The Network layer (Layer 3) handles logical addressing and path selection between networks, satisfying the stem's routing requirement. IP addresses operate here, letting routers forward packets across disparate networks using routing tables. This distinguishes it from the Data Link layer, which uses physical MAC addressing for local delivery only.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing (e.g., IP addresses) and routing, which determines the best path for data across interconnected networks. It uses protocols like IP, ICMP, and routing protocols (OSPF, BGP) to forward packets based on logical addresses, enabling communication between different networks.

Exam trap

The trap here is confusing the Data Link layer's MAC addressing with the Network layer's logical addressing, or assuming the Transport layer handles routing because it deals with end-to-end delivery.

How to eliminate wrong answers

Option A is wrong because the Data Link layer (Layer 2) handles physical addressing (MAC addresses) and framing, not logical addressing or routing. Option C is wrong because the Transport layer (Layer 4) provides end-to-end communication, segmentation, and reliability (TCP/UDP), but does not perform logical addressing or routing. Option D is wrong because the Physical layer (Layer 1) deals with raw bit transmission over physical media, with no addressing or routing functions.

23
Multi-Selectmedium

Which three of the following are benefits of using VLANs in a network? (Choose three.)

Select 3 answers
A.Enhanced security through network segmentation
B.Eliminates the need for routing
C.Increased collision domains
D.Reduction of broadcast traffic
E.Simplified network administration when users move
AnswersA, D, E

VLANs logically partition one physical switch fabric into isolated broadcast domains, so hosts in different VLANs cannot reach each other without a Layer 3 device. This segmentation satisfies the stem's security benefit by containing reconnaissance and limiting lateral movement between departments.

Why this answer

Option A is correct because VLANs logically segment a physical switch into isolated broadcast domains, so traffic from one VLAN cannot reach another without a Layer 3 device (router or multilayer switch), which enforces policy and limits unauthorized access. Option D is correct because each VLAN is its own broadcast domain, so broadcasts are confined to the ports assigned to that VLAN rather than flooding the entire switched network, reducing overall broadcast traffic. Option E is correct because VLAN membership is a logical configuration, so when a user relocates, an administrator can reassign the port or use dynamic VLAN assignment (e.g., via 802.1Q or VMPS) instead of physically rewiring or moving the user to a different switch.

Option B is not correct because inter-VLAN communication still requires Layer 3 routing (router-on-a-stick, SVIs, or a Layer 3 switch), so routing is not eliminated. Option C is not correct because VLANs actually reduce the size of broadcast domains and do not increase collision domains; collision domains are determined by switch ports and full-duplex links, not by VLAN creation.

Exam trap

The trap is selecting 'eliminates the need for routing' or 'increases collision domains' as benefits; the exam tests that VLANs require routing for inter-VLAN traffic and actually reduce collision domains.

24
MCQeasy

What is the primary difference between an IDS and an IPS?

A.IDS is faster than IPS
B.IDS is hardware, IPS is software
C.IDS monitors only hosts, IPS monitors network
D.IDS only alerts, IPS can block traffic
AnswerD

An IDS passively monitors copies of traffic and raises alerts, leaving response to administrators. An IPS sits inline on the traffic path, so it can drop malicious packets or reset connections in real time. That inline blocking capability, absent from an alert-only IDS, is the defining difference the question asks for.

Why this answer

The primary difference is that an IDS (Intrusion Detection System) is passive and only alerts on suspicious activity, while an IPS (Intrusion Prevention System) is inline and can actively block or drop malicious traffic. Both can monitor network or host activity, but the key distinction is the response capability: detect vs. detect and prevent.

Exam trap

The trap is confusing the deployment mode (inline vs. out-of-band) with the response capability; the exam tests that the key difference is alert-only vs. block, not speed, form factor, or scope.

How to eliminate wrong answers

Option A is wrong because speed is not the defining difference; both can operate at similar speeds, and an IPS may introduce latency due to inline processing. Option B is wrong because both IDS and IPS can be hardware or software; the deployment form factor is not the primary difference. Option C is wrong because both IDS and IPS can monitor hosts or networks (HIDS/NIDS, HIPS/NIPS); the scope is not the defining difference.

25
Multi-Selectmedium

A security analyst is investigating a potential DDoS attack on the company's web server. Which two symptoms are indicative of a SYN flood attack? (Select TWO.)

Select 2 answers
A.Increased DNS query responses
B.High number of ICMP echo replies
C.Unusual outbound traffic on port 80
D.Large number of half-open connections
E.High number of SYN packets with no ACK
AnswersD, E

Each spoofed SYN packet forces the server to allocate a connection table entry and reply with SYN-ACK, then wait for a response that never arrives. These half-open connections accumulate until the backlog queue is exhausted, which is the defining resource-exhaustion symptom of a SYN flood.

Why this answer

Options D and E are both correct indicators of a SYN flood attack. Option D is correct because a SYN flood sends many SYN packets to initiate TCP connections but never completes the three-way handshake, leaving numerous half-open connections in the SYN_RECEIVED state on the server, which exhausts resources. Option E is correct because the attack generates a high number of SYN packets from the attacker, and since the handshake is never completed, the corresponding ACK packets are absent.

Both symptoms—half-open connections and SYN packets without ACK—are characteristic of a SYN flood.

Exam trap

A common pitfall in the ISC2 CC exam is distinguishing between the symptom of 'half-open connections' (server-side resource exhaustion) and the traffic pattern of 'SYN packets with no ACK' (attacker behavior). Both are correct indicators of a SYN flood.

26
MCQhard

A company deploys a device that inspects HTTP and HTTPS traffic to block SQL injection and cross-site scripting attacks. This device is best described as a:

A.Stateful firewall
B.Web application firewall (WAF)
C.Honeypot
D.Network-based IPS
AnswerB

A web application firewall inspects HTTP and HTTPS requests, applying signatures and rules to block SQL injection and cross-site scripting. It operates at the application layer, distinguishing it from network firewalls that filter by IP, port, or protocol.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block application-layer attacks like SQL injection and cross-site scripting (XSS). It operates at Layer 7 and understands web protocols, making it the correct choice for protecting web applications from these threats.

Exam trap

The trap is confusing a WAF with a network IPS or stateful firewall; the exam tests that only a WAF is purpose-built for HTTP/HTTPS application-layer attack prevention like SQLi and XSS.

How to eliminate wrong answers

Option A is wrong because a stateful firewall operates at Layers 3-4 and tracks connection state but does not inspect HTTP payloads for SQL injection or XSS. Option C is wrong because a honeypot is a decoy system designed to attract attackers, not to inspect and block web traffic. Option D is wrong because a network-based IPS can detect some web attacks via signatures, but it is not specialized for HTTP/HTTPS application-layer inspection and may not decode web traffic as deeply as a WAF.

27
MCQeasy

Which firewall type operates at Layer 3 and Layer 4, making decisions based solely on source/destination IP and port numbers?

A.Stateful inspection firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Application proxy firewall
AnswerB

Packet filtering firewalls inspect only Layer 3 and Layer 4 headers, permitting or denying traffic by source and destination IP addresses and port numbers. They perform no application-layer inspection, which matches the stated decision criteria exactly.

Why this answer

A packet filtering firewall operates at Layer 3 (Network) and Layer 4 (Transport) of the OSI model, examining source and destination IP addresses and port numbers to allow or deny traffic. It is stateless and makes decisions per packet based on configured ACLs.

Exam trap

The trap is confusing stateless packet filtering with stateful inspection; the key phrase 'solely based on source/destination IP and port numbers' signals a stateless Layer 3/4 filter.

How to eliminate wrong answers

Option A is wrong because a stateful inspection firewall tracks connection state (e.g., TCP handshake) and makes decisions based on the state table, not solely on IP and port. Option C is wrong because an NGFW adds application-layer inspection, intrusion prevention, and user identity awareness, going well beyond Layer 3/4 headers. Option D is wrong because an application proxy firewall operates at Layer 7, terminating and inspecting application protocols, not just IP and port.

28
MCQmedium

A network administrator needs to segment traffic between departments without additional hardware. Which technology allows this logical separation on a Layer 2 switch?

A.Subnetting
C.VPN
D.DMZ
AnswerB

VLANs create logically separate broadcast domains on a single Layer 2 switch, satisfying the no-additional-hardware constraint. Each department's traffic stays isolated at Layer 2 through distinct VLAN IDs and 802.1Q tagging, without requiring routers or extra switches.

Why this answer

VLANs (Virtual LANs) allow a single Layer 2 switch to be logically partitioned into multiple broadcast domains, separating traffic between departments without buying additional hardware. Each VLAN behaves like a separate physical switch, and inter-VLAN traffic must be routed.

Exam trap

The trap is confusing logical separation at Layer 2 (VLAN) with Layer 3 segmentation (subnetting) or with security zones like DMZ/VPN; the key phrase 'on a Layer 2 switch' points to VLAN.

How to eliminate wrong answers

Option A is wrong because subnetting is a Layer 3 IP addressing technique that divides an IP network; by itself it does not logically separate traffic on a Layer 2 switch without VLANs or routing. Option C is wrong because a VPN creates an encrypted tunnel over an untrusted network (e.g., the internet) and is not a Layer 2 switch segmentation technology. Option D is wrong because a DMZ is a network segment for exposing public-facing services, typically implemented with firewalls and separate subnets, not a Layer 2 logical separation feature on a switch.

29
MCQeasy

Which of the following is a benefit of using VLANs in a network?

A.Logical segmentation without additional hardware
B.Elimination of all broadcast traffic
C.Faster data transfer speeds
D.Increased physical security
AnswerA

VLANs deliver logical segmentation by partitioning a single physical switch into isolated broadcast domains, satisfying the stem's benefit requirement without buying extra switches or routers. This reduces hardware cost and administrative overhead, while containing broadcast traffic and enabling policy separation between departments on shared infrastructure.

Why this answer

VLANs allow logical segmentation of a network at Layer 2, improving security and reducing broadcast traffic without requiring additional physical switches.

30
MCQeasy

A firewall that filters traffic based solely on source and destination IP addresses and ports without considering the state of connections is known as a:

A.Application proxy
B.Stateless firewall
C.Stateful firewall
D.Next-generation firewall
AnswerB

A stateless firewall inspects each packet in isolation against static rules for source and destination IP addresses and ports, maintaining no connection table. This directly satisfies the stem's constraint of filtering without considering connection state, unlike stateful firewalls that track sessions via a state table.

Why this answer

A stateless firewall inspects each packet in isolation, matching only on source/destination IP addresses and ports (Layer 3/4 headers) without maintaining any connection state table. Because it does not track TCP handshakes or session context, it cannot distinguish a legitimate return packet from a spoofed one. This is the defining characteristic described in the question.

Exam trap

The trap here is confusing 'stateless' with 'stateful' — candidates see 'filters traffic' and default to the more familiar stateful firewall, missing the key phrase 'without considering the state of connections.'

How to eliminate wrong answers

Option A is wrong because an application proxy operates at Layer 7, terminating and re-originating connections to inspect application payloads, which is the opposite of simple header-only filtering. Option C is wrong because a stateful firewall maintains a connection state table and evaluates packets against established sessions, which the question explicitly excludes. Option D is wrong because a next-generation firewall adds application identification, user awareness, and threat inspection on top of stateful filtering, far beyond simple IP/port matching.

31
MCQmedium

A company's public web server is placed in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this network architecture called?

A.Subnet
B.Honeypot
D.DMZ
AnswerD

A DMZ is a screened subnet placed between the internet and the internal LAN. It hosts internet-facing services such as the public web server while firewall rules restrict traffic from the DMZ into the internal network, providing the required isolation.

Why this answer

A DMZ (demilitarized zone) is a network segment that sits between the internet and the internal LAN, hosting public-facing services while isolating them from internal resources. It is accessible from the internet but separated from the internal network by firewalls, exactly as described. This architecture limits the blast radius if a public server is compromised.

Exam trap

The trap is selecting 'subnet' or 'VLAN' because they describe network segmentation — candidates must recognize that the question describes a security architecture (DMZ), not just a logical grouping.

How to eliminate wrong answers

Option A is wrong because a subnet is simply a logical subdivision of an IP network for addressing and routing — it does not imply any security isolation or internet-facing role. Option B is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not a segment hosting legitimate public services. Option C is wrong because a VLAN is a Layer 2 broadcast domain segmentation technique; while VLANs may be used within a DMZ, a VLAN alone does not provide the internet-facing isolation described.

32
MCQeasy

A hospital's biomedical team connects a new MRI workstation to the clinical VLAN. The workstation must reach a PACS archive on a different subnet, but the team reports that no traffic leaves the workstation. A technician confirms the workstation has an IP address of 10.20.30.44/24 and the PACS archive is 10.20.40.10/24. Which device should the workstation be configured to use as its default gateway?

A.A router interface on the 10.20.30.0/24 subnet
B.The PACS archive server itself at 10.20.40.10
C.The DNS server address assigned by DHCP
D.A Layer 2 switch's management IP address on the 10.20.30.0/24 subnet
AnswerA

A default gateway must be an address on the same local subnet as the sending host, so the workstation can ARP for it and hand off off-subnet traffic. A router interface in 10.20.30.0/24 satisfies this, and the router then forwards the packet to the 10.20.40.0/24 network. Pointing to any device outside the local subnet would leave the workstation unable to deliver the frame.

Why this answer

The workstation needs a next-hop address inside its own subnet so it can ARP for that device and hand off traffic destined for 10.20.40.0/24. Only a router interface on 10.20.30.0/24 provides a reachable Layer 2 next hop that can also route to the PACS subnet. The other candidates either sit outside the local subnet or cannot perform IP routing.

Exam trap

The trap here is assuming any reachable IP address can serve as a default gateway, when the gateway must be on the same local subnet as the sending host.

33
MCQhard

An organization uses a network segmentation strategy that creates separate broadcast domains on a single switch. Which technology is being used?

A.DMZ
B.Honeypot
C.Subnetting
AnswerD

VLANs logically partition one physical switch into isolated Layer 2 broadcast domains, so broadcasts stay within each segment rather than flooding every port. This directly satisfies the stem's requirement for separate broadcast domains on a single switch, unlike subnetting (Layer 3) or physical segmentation, which would need additional hardware.

Why this answer

A VLAN (Virtual Local Area Network) logically partitions a single physical switch into multiple separate broadcast domains. Each VLAN operates as its own Layer 2 network, and broadcast traffic from one VLAN is not forwarded to another without a Layer 3 device. This is the standard technology for network segmentation at Layer 2.

Exam trap

The trap here is confusing Layer 2 segmentation (VLAN) with Layer 3 segmentation (subnetting) — candidates often pick 'Subnetting' because both provide logical separation, but only VLANs create separate broadcast domains on a single switch.

How to eliminate wrong answers

Option A is wrong because a DMZ (Demilitarized Zone) is a perimeter network segment that exposes external-facing services to an untrusted network — it is a security architecture concept, not a Layer 2 segmentation technology on a single switch. Option B is wrong because a honeypot is a decoy system designed to attract and analyze attackers, not a broadcast domain segmentation mechanism. Option C is wrong because subnetting is a Layer 3 (IP) concept that divides an IP network into smaller subnets — while it can align with VLANs, it does not create separate broadcast domains on a switch by itself.

34
MCQmedium

Which OSI layer is responsible for logical addressing, routing, and forwarding of packets, and where does an IP address operate?

A.Layer 2 – Data Link
B.Layer 1 – Physical
C.Layer 3 – Network
D.Layer 4 – Transport
AnswerC

Layer 3, the Network layer, handles logical addressing and path determination, with IP addresses operating here to identify hosts across networks. Routers forward packets between subnets using these addresses, satisfying the stem's requirement for routing and forwarding, unlike Layer 2's MAC-based switching or Layer 4's port-based delivery.

Why this answer

Layer 3 (Network) handles IP addresses, routing, and packet forwarding.

35
MCQeasy

Which protocol is considered insecure because it transmits data, including passwords, in cleartext, and its use should be avoided in favor of more secure alternatives?

A.SSH
B.SFTP
AnswerD

Telnet sends all session traffic, including login credentials, as unencrypted cleartext across the network, so anyone capturing packets reads them directly. SSH replaces it by encrypting the same terminal access, which is why Telnet should be disabled on managed devices.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext over the network, making it trivial to intercept with packet capture. It lacks encryption and integrity protection, so it is considered insecure and should be replaced by SSH for remote administration. This is why Telnet is the correct answer.

Exam trap

The trap is picking a protocol that sounds old or file-related (like SFTP) instead of recognizing that Telnet is the classic cleartext remote-access protocol.

How to eliminate wrong answers

Option A is wrong because SSH encrypts the entire session, including authentication, using strong ciphers and is the recommended replacement for Telnet. Option B is wrong because SFTP runs over SSH and provides encrypted file transfer, not cleartext. Option C is wrong because HTTPS uses TLS to encrypt HTTP traffic, protecting credentials and data in transit.

36
MCQmedium

Which firewall type inspects the entire packet, including application data, and can enforce rules based on user identity?

A.Application proxy firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Stateful inspection firewall
AnswerC

A next-generation firewall performs deep packet inspection, examining payload and application-layer data rather than only headers and ports. It also integrates with directory services to enforce rules based on user identity, satisfying both constraints in the stem, unlike packet-filtering or stateful inspection firewalls.

Why this answer

A Next-Generation Firewall (NGFW) goes beyond traditional port/protocol inspection by performing deep packet inspection (DPI) up to Layer 7, identifying applications regardless of port, and integrating user identity awareness (via LDAP, Active Directory, or captive portal) to enforce policies based on who the user is. It combines stateful inspection, application control, IPS, and identity-based rules in a single platform. This matches the question's requirement of inspecting application data and enforcing rules based on user identity.

Exam trap

The trap is assuming 'application proxy firewall' equals 'NGFW' because both inspect application data — but the CC exam distinguishes that only NGFW adds user-identity-based enforcement and integrated Layer 7 inspection across all applications.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall inspects application-layer data but typically operates as a proxy per application and does not natively enforce rules based on user identity across all traffic types. Option B is wrong because a packet filtering firewall only examines headers (source/destination IP, port, protocol) at Layers 3–4 and cannot inspect application data or identify users. Option D is wrong because a stateful inspection firewall tracks connection state (Layer 4) but does not perform deep application-layer inspection or user-identity-based enforcement — those are NGFW capabilities.

37
MCQmedium

A company deploys a network security device that can block malicious traffic in real-time by inspecting packet payloads and application data. However, the device occasionally blocks legitimate traffic. Which device is described?

A.IPS
C.WAF
D.IDS
AnswerA

An IPS inspects packet payloads and application-layer data inline, blocking malicious traffic in real time. Its signature-based detection can flag benign activity as malicious, producing false positives that block legitimate traffic — exactly the occasional over-blocking described. A firewall filtering only headers could not inspect payloads, so it fails the stem's inspection constraint.

Why this answer

An IPS (Intrusion Prevention System) inspects packet payloads and application data in real time and can actively block malicious traffic. The fact that it occasionally blocks legitimate traffic is a classic false-positive behavior of IPS devices, which is why tuning is required.

Exam trap

The trap is confusing IDS and IPS — the key differentiator is that IPS blocks in real time (and can cause false positives), while IDS only detects and alerts.

How to eliminate wrong answers

Option B is wrong because a traditional firewall filters based on IP addresses, ports, and protocols — it does not inspect payloads or application data for malicious content. Option C is wrong because a WAF specifically protects web applications at the HTTP/HTTPS layer and would not be described as inspecting general packet payloads across all traffic. Option D is wrong because an IDS only detects and alerts; it does not block traffic in real time.

38
MCQeasy

A small business wants to give employees secure access to internal file shares while they work from home. The company has no dedicated security operations staff and wants a solution that authenticates users and encrypts traffic without deploying agents on every personal device. Which technology is the most appropriate?

A.A web application firewall protecting the file server.
B.A remote access VPN using TLS or IPsec.
C.A host-based intrusion prevention system on each laptop.
D.A network access control solution enforcing 802.1X on the office switches.
AnswerB

A remote access VPN authenticates the user and encrypts the entire session between the remote device and the corporate gateway, so file-share traffic is protected in transit without requiring per-application agents. It is well suited to a small business because it uses standard client software or a browser-based portal and centralizes access control at the VPN concentrator, meeting the authentication and encryption goals.

Why this answer

A remote access VPN is designed exactly for this need: it authenticates the user at a central gateway and encrypts traffic between the remote device and the corporate network. The other choices address endpoint protection, local network admission control, or web application defense, none of which establish an authenticated, encrypted path to internal file shares for off-site workers.

Exam trap

The trap here is confusing endpoint security controls, such as host intrusion prevention, with the transport security and authentication that a remote access VPN actually provides.

39
MCQhard

Which of the following is a common mitigation technique for a SYN flood attack?

A.SYN cookies
B.Use UDP instead of TCP
C.Disable TCP timestamps
D.Increase the TCP backlog queue
AnswerA

SYN cookies let the server avoid allocating state for half-open connections: it encodes connection details in the sequence number of the SYN-ACK, so the backlog cannot be exhausted by spoofed SYNs. This directly mitigates the resource-exhaustion constraint of a SYN flood.

Why this answer

SYN cookies are the canonical mitigation for SYN flood attacks. When the SYN backlog is exhausted or under stress, the server encodes connection state into the initial sequence number (ISN) of the SYN-ACK rather than allocating a half-open socket, so no state is consumed until the client returns the final ACK. This defeats the attacker's ability to exhaust the backlog with spoofed SYNs.

Exam trap

The trap here is confusing 'increase the backlog' with an actual mitigation — candidates reason that a bigger queue absorbs the flood, but it only raises the resource ceiling the attacker must exhaust.

How to eliminate wrong answers

Option B is wrong because switching to UDP is not a mitigation — it abandons TCP's reliability and handshake entirely, and UDP itself is trivially spoofable and floodable (e.g., UDP amplification). Option C is wrong because disabling TCP timestamps has no bearing on SYN flood handling; timestamps are an RFC 1323/7323 performance and PAWS mechanism, not a defense against half-open connection exhaustion. Option D is wrong because increasing the TCP backlog queue only raises the ceiling of half-open connections an attacker must fill — it delays but does not prevent exhaustion, and can worsen memory pressure.

40
MCQeasy

A small business wants to prevent employees from visiting known malicious websites. The owner asks for a solution that can block requests based on a constantly updated list of harmful domains without requiring software on each employee device. Which technology should be recommended?

A.Stateful packet inspection firewall
B.DNS filtering
C.Network access control (NAC)
D.Host-based antivirus
AnswerB

DNS filtering intercepts domain name resolution requests and blocks those matching a threat intelligence list of malicious domains. It requires no endpoint software, works network-wide, and is easy to update centrally. This directly prevents users from reaching harmful sites by returning a block response before any connection to the malicious IP is made.

Why this answer

DNS filtering blocks malicious domains by intercepting DNS queries and checking them against a threat intelligence feed. It requires no endpoint agent, applies network-wide, and updates centrally. Host-based antivirus needs per-device installation, stateful firewalls lack domain awareness, and NAC governs device admission rather than web content, so none satisfy the stated constraints.

Exam trap

The trap here is confusing network admission control or firewall filtering with DNS-layer security, which specifically blocks domains before a connection is established.

41
MCQeasy

Which protocol is considered insecure because it transmits data in cleartext, including passwords?

A.SFTP
B.SSH
AnswerD

Telnet transmits all session data, including login credentials, as unencrypted cleartext across the network, so anyone capturing traffic can read passwords directly. This satisfies the stem's constraint of a protocol deemed insecure precisely because it lacks encryption, unlike SSH, which tunnels the same terminal access within an encrypted channel.

Why this answer

Telnet is considered insecure because it transmits all data — including usernames and passwords — in cleartext over the network, with no encryption whatsoever. Anyone with access to the traffic path (via packet capture or MITM) can read credentials directly. This is why Telnet has been replaced by SSH for remote administration.

Exam trap

The trap here is confusing 'file transfer' protocols with 'remote login' protocols — candidates may pick SFTP thinking it is insecure because it sounds like FTP, when in fact SFTP is encrypted and FTP is the cleartext one.

How to eliminate wrong answers

Option A is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts all data in transit, so it is not a cleartext protocol. Option B is wrong because SSH provides strong encryption and authentication for remote sessions, making it the secure replacement for Telnet. Option C is wrong because HTTPS wraps HTTP inside TLS, encrypting credentials and session data, so it is not cleartext.

42
MCQmedium

A security analyst at a mid-sized company is reviewing network traffic logs and notices that an internal host is repeatedly sending TCP SYN packets to many different external IP addresses on port 443, but never completing the three-way handshake. The analyst suspects a malware infection. Which type of attack is most likely occurring?

A.MAC flooding
B.SYN flood
C.Smurf attack
D.Ping flood
AnswerB

A SYN flood is a type of denial-of-service attack where the attacker sends a large number of TCP SYN packets to a target but does not complete the handshake, exhausting the target's connection resources. In this scenario, the internal host is sending SYN packets to many external IPs on port 443 without completing the handshake, which is characteristic of a SYN flood. The host is likely compromised and participating in a botnet.

Why this answer

The host is sending numerous TCP SYN packets to various external IP addresses on port 443 without completing the three-way handshake. This pattern indicates a SYN flood attack, where the attacker attempts to exhaust connection resources on targets. The host is likely part of a botnet.

The other options describe different attack types that do not match the observed traffic pattern.

Exam trap

The trap here is assuming that any flood of packets is a ping flood or Smurf attack, but the key differentiator is the protocol and handshake behavior.

43
MCQmedium

A company wants to host a public-facing web server and an email server while protecting the internal network. Which network architecture is best suited for this purpose?

A.Subnetting
B.Full mesh topology
C.Virtual LAN (VLAN)
D.DMZ
AnswerD

A DMZ sits between the internet-facing firewall and the internal network, so public web and email servers are reachable externally while internal hosts stay shielded. This satisfies the stem's requirement to host public services and protect the internal network, since inbound traffic terminates in the DMZ rather than crossing into the trusted zone.

Why this answer

A DMZ (demilitarized zone) is a segmented network that sits between the internet and the internal network, hosting public-facing servers while allowing controlled access from both sides.

44
MCQeasy

Which of the following protocols operates at the Transport layer and provides reliable, connection-oriented communication?

B.TCP
C.IP
D.UDP
AnswerB

TCP establishes a connection via a three-way handshake and uses sequence numbers, acknowledgements and retransmissions to guarantee ordered, error-free delivery. This connection-oriented reliability at the Transport layer satisfies the stem's requirement, unlike connectionless UDP, which offers no delivery guarantees.

Why this answer

TCP provides reliable delivery via acknowledgments and retransmissions, and uses a three-way handshake to establish a connection. UDP is connectionless and unreliable.

45
MCQmedium

A company places a web server and an email server in a separate network segment that is accessible from the internet but isolated from the internal LAN. What is this segment called?

B.DMZ
C.Honeypot
D.Subnet
AnswerB

A DMZ is a perimeter subnetwork exposing public-facing services such as web and email servers to the internet while firewall rules block direct access to the internal LAN, limiting exposure if those hosts are compromised.

Why this answer

A DMZ (demilitarized zone) is a perimeter network segment that hosts internet-facing services such as web and email servers while keeping them isolated from the trusted internal LAN. It creates a buffer zone so that if a public-facing server is compromised, the attacker cannot directly pivot into internal systems. This matches the scenario exactly: internet-accessible but separated from the internal network.

Exam trap

The trap here is confusing a DMZ with a generic subnet or VLAN — candidates pick 'subnet' because a DMZ is technically implemented as one, but the question is testing the security concept of an isolated internet-facing buffer zone, not the addressing construct.

How to eliminate wrong answers

Option A is wrong because a VLAN is a Layer 2 logical segmentation mechanism for grouping devices within a switched network — it does not by itself define an internet-facing isolated zone with firewall-enforced separation from the LAN. Option C is wrong because a honeypot is a decoy system designed to lure and observe attackers, not to host production web and email services. Option D is wrong because a subnet is simply an IP addressing subdivision (a Layer 3 range); while a DMZ is often implemented as a subnet, 'subnet' alone does not convey the security isolation and internet-facing purpose described.

46
MCQhard

An organization wants to prevent malicious HTTP requests targeting a web application. Which security device is specifically designed for this purpose?

A.NIDS
B.HIDS
C.WAF
D.IPS
AnswerC

A Web Application Firewall inspects HTTP and HTTPS request content, applying signatures and rules to detect and block injection, cross-site scripting and similar attacks. Network firewalls filter by port and address only, so they cannot inspect application-layer payloads.

Why this answer

A Web Application Firewall (WAF) operates at Layer 7 and inspects HTTP/HTTPS requests specifically to detect and block web application attacks such as SQL injection, XSS, and malicious payloads. It is purpose-built to understand HTTP semantics (headers, cookies, parameters, body) and apply rules like OWASP ModSecurity Core Rule Set. This directly matches the requirement to prevent malicious HTTP requests targeting a web application.

Exam trap

The trap is conflating a general-purpose IPS with a WAF — candidates pick IPS because it 'prevents' attacks, but the question specifically targets HTTP application-layer protection, which is the WAF's specialized domain.

How to eliminate wrong answers

Option A is wrong because a NIDS (Network Intrusion Detection System) monitors network traffic for suspicious patterns but is passive/detection-oriented and does not specifically parse HTTP to block web application attacks — and it's an IDS, not a prevention device. Option B is wrong because a HIDS (Host Intrusion Detection System) monitors host-level activity (file integrity, logs, processes) on a server, not HTTP request content at the application layer. Option D is wrong because an IPS (Intrusion Prevention System) is a broader network-layer prevention device; while some IPS products include web attack signatures, a WAF is the device specifically designed for HTTP application-layer protection, and the question asks for the device 'specifically designed' for this purpose.

47
MCQmedium

An attacker captures network traffic and forges the source IP address to impersonate a trusted host. Which type of network threat is this?

A.Sniffing
B.Spoofing
C.Man-in-the-middle
D.Denial of Service
AnswerB

Forging the source IP address to impersonate a trusted host is IP address spoofing. The attacker manipulates the packet header's source field so the receiver believes traffic originates from a legitimate system, enabling masquerade and bypassing trust-based access controls.

Why this answer

Spoofing is the act of forging a source IP address (or other identity field) to impersonate a trusted host. In this scenario, the attacker captures traffic and crafts packets with a falsified source IP to make them appear to originate from a trusted system. This is the definition of IP spoofing, a foundational network threat.

Exam trap

The trap is confusing spoofing with MITM — candidates pick MITM because both involve impersonation, but the scenario describes only forging a source IP, not intercepting an existing session between two parties.

How to eliminate wrong answers

Option A is wrong because sniffing is passive capture of network traffic (e.g., with Wireshark or tcpdump) — it does not involve forging source addresses. Option C is wrong because a man-in-the-middle attack involves an attacker positioning themselves between two communicating parties to intercept or alter traffic; while spoofing is often a component of MITM, the scenario describes only the forging of a source IP, not interception of an ongoing session. Option D is wrong because a Denial of Service attack aims to exhaust resources and disrupt availability; spoofing may be used to hide the attacker's identity in a DoS, but the scenario describes impersonation, not resource exhaustion.

48
MCQeasy

A network administrator is configuring a new wireless network for a small office. The office manager wants to ensure that only authorized employees can connect and that traffic between wireless clients is encrypted. Which security protocol should the administrator implement?

A.Media Access Control (MAC) address filtering with a whitelist
B.Open authentication with a captive portal for user login
C.Wi-Fi Protected Access 2 (WPA2) with Advanced Encryption Standard (AES) and a pre-shared key
D.Wired Equivalent Privacy (WEP) with a 128-bit key
AnswerC

WPA2 with AES (also known as WPA2-PSK) provides strong encryption and requires a pre-shared key for authentication. It ensures that only users with the correct key can connect and that traffic between clients is encrypted. AES is a robust encryption standard, making it suitable for a small office environment.

Why this answer

WPA2 with AES and a pre-shared key provides both authentication (via the key) and strong encryption for wireless traffic. It is the standard for securing small office wireless networks. Other options either lack encryption or use weak, outdated methods that do not meet the security requirements.

Exam trap

The trap here is confusing authentication mechanisms like MAC filtering or captive portals with encryption, which are separate concerns.

49
MCQeasy

A network administrator is troubleshooting connectivity issues and suspects a problem at the Data Link layer. Which of the following addresses would be most relevant to examine?

A.IP address
C.Port number
D.Domain name
AnswerB

MAC addresses operate at the Data Link layer, uniquely identifying network interfaces within a local segment. Examining them reveals framing, switching and ARP-related faults, directly satisfying the stem's constraint of isolating a Layer 2 connectivity problem.

Why this answer

The Data Link layer (Layer 2) of the OSI model deals with MAC addresses for node-to-node delivery within a local network segment. When troubleshooting connectivity issues at Layer 2, the MAC address is the most relevant address to examine because it identifies the physical network interface and is used by switches to forward frames. IP addresses operate at Layer 3, port numbers at Layer 4, and domain names at Layer 7, so they are not relevant to a Data Link layer problem.

Exam trap

The trap is confusing OSI layer responsibilities — candidates may pick IP address because it is commonly used in troubleshooting, but the CC exam specifically tests that MAC addresses belong to Layer 2 while IP addresses belong to Layer 3.

How to eliminate wrong answers

Option A is wrong because IP addresses operate at the Network layer (Layer 3), which is above the Data Link layer; while IP issues can cause connectivity problems, they are not the focus when the suspected problem is at Layer 2. Option C is wrong because port numbers operate at the Transport layer (Layer 4), which is higher than the Data Link layer and relates to application/service identification, not frame delivery. Option D is wrong because domain names are resolved at the Application layer (Layer 7) via DNS and have no role in Data Link layer operations.

50
MCQmedium

A company's web server is experiencing a high volume of traffic from thousands of different IP addresses, causing service degradation. The security team determines it is a distributed denial-of-service (DDoS) attack. Which mitigation strategy is most effective for this scenario?

A.Configure an intrusion prevention system (IPS) to block the attack.
B.Use a cloud-based DDoS mitigation service.
C.Increase the web server's bandwidth and CPU resources.
D.Install a host-based firewall on the web server.
AnswerB

Cloud-based DDoS mitigation services divert traffic to scrubbing centers that filter malicious packets and forward only clean traffic to the origin server. They have massive bandwidth and can absorb volumetric attacks, making them ideal for distributed attacks. This preserves server availability and scales beyond on-premises capabilities.

Why this answer

A cloud-based DDoS mitigation service is specifically designed to absorb and filter large volumetric attacks by leveraging distributed scrubbing centers and high bandwidth. It can handle thousands of source IPs and protect the origin server without requiring on-premises hardware upgrades. This is the most effective and scalable solution for the described scenario.

Exam trap

The trap here is assuming that any security device (like an IPS or host firewall) can stop a DDoS; volumetric attacks require specialized, high-capacity mitigation that only cloud or ISP-based scrubbing services typically provide.

51
MCQhard

A financial services firm must protect a legacy trading application that uses a proprietary protocol on TCP port 7000. The security team wants to block all traffic to this port except from a small set of approved internal subnets, and they must ensure that fragmented packets cannot bypass the rule. Which control most directly achieves this?

A.A stateful inspection firewall that tracks established TCP sessions.
B.A network intrusion prevention system tuned to the trading protocol.
C.A packet-filtering firewall that reassembles fragments before applying rules.
D.An application-layer gateway that decodes the proprietary protocol.
AnswerC

A packet-filtering firewall evaluates source and destination addresses and ports, and by reassembling fragments before rule evaluation it prevents attackers from splitting a prohibited packet across fragments to evade the filter. This directly implements the requirement to allow only approved subnets to reach TCP port 7000 while closing the fragmentation bypass, making it the most targeted control.

Why this answer

The requirement is deterministic network-layer access control on a specific port combined with protection against fragmentation evasion. A packet-filtering firewall that reassembles fragments before applying rules does exactly that, whereas application gateways, stateful inspection, and intrusion prevention systems address different concerns and do not guarantee both the source restriction and the anti-fragmentation behavior in this scenario.

Exam trap

The trap here is assuming that any firewall or IPS automatically defeats fragmentation evasion, when reassembly before rule evaluation is a specific capability that must be confirmed.

52
MCQmedium

A hospital's security team wants to detect when an attacker is probing its internal network for open ports, but the team must not block legitimate clinical traffic because doing so could interrupt patient care. The team decides to deploy a solution that only alerts on suspicious activity. Which type of solution best matches this requirement?

A.A network-based intrusion prevention system (NIPS)
B.A stateful packet-filtering firewall
C.A network-based intrusion detection system (NIDS)
D.A web application firewall (WAF)
AnswerC

A NIDS monitors network traffic and generates alerts for suspicious patterns such as port scans without actively blocking traffic. Because it is passive, it will not interrupt clinical communications even if it flags legitimate activity. This matches the requirement to detect probing while avoiding any disruption to patient care.

Why this answer

The requirement is detection without disruption, which points to a passive monitoring technology. A network-based intrusion detection system observes copies of traffic and raises alerts on suspicious activity such as port scanning, but it does not sit inline to block. Prevention systems, web application firewalls, and stateful firewalls either block traffic or focus on the wrong layer for this internal reconnaissance scenario.

Exam trap

The trap here is assuming that any intrusion detection tool will also block attacks, when detection-only monitoring is specifically required to avoid disrupting clinical traffic.

53
MCQmedium

An attacker sends an email to an employee that appears to come from the CEO, asking for sensitive data. This is an example of which type of threat?

A.Spoofing
B.Phishing
C.Man-in-the-middle
D.Sniffing
AnswerB

Phishing is a social engineering attack where an attacker sends a fraudulent communication (often email) that appears to come from a trusted source to trick the recipient into providing sensitive information. This scenario perfectly matches phishing.

Why this answer

Phishing is a social engineering attack where an attacker impersonates a trusted entity (like the CEO) to trick the recipient into revealing sensitive information. The scenario describes an email that appears to come from the CEO, which is a classic phishing attempt. Spoofing (A) refers to falsifying the sender address, but the broader threat here is phishing because it involves deception to extract data.

Man-in-the-middle (C) and sniffing (D) are network-level attacks, not email-based social engineering.

Exam trap

The trap here is confusing spoofing (a technique) with phishing (the overall attack), as spoofing is often a component of phishing but not the primary threat type.

How to eliminate wrong answers

Option A is wrong because spoofing specifically refers to falsifying the sender address (e.g., email header), but the question emphasizes the deceptive request for sensitive data, which is phishing. Option C is wrong because man-in-the-middle involves intercepting and possibly altering communications between two parties, not sending a deceptive email. Option D is wrong because sniffing is passive capture of network traffic, not an email-based social engineering attack.

54
Multi-Selectmedium

A security analyst is reviewing network traffic and notices that some devices are using a protocol that does not guarantee delivery and has no error recovery. Which ONE transport layer protocol fits this description? (Select ONE)

Select 1 answer
AnswersD

UDP is connectionless and provides no acknowledgement, retransmission or sequencing, so delivery is never guaranteed and lost datagrams are not recovered. This directly satisfies the stem's constraint of a transport protocol lacking both guaranteed delivery and error recovery, unlike TCP, which retransmits unacknowledged segments.

Why this answer

UDP (User Datagram Protocol) is a connectionless transport layer protocol that does not guarantee delivery, ordering, or error recovery. It is designed for speed and low overhead, making it suitable for applications like streaming, DNS, and VoIP where occasional packet loss is acceptable. The question explicitly asks for a protocol that does not guarantee delivery and has no error recovery, which matches UDP's characteristics.

Exam trap

The trap is confusing transport layer protocols with application or network layer protocols. Candidates might choose HTTP because it is common, but HTTP is application layer and relies on TCP. Also, some might think ICMP is transport layer because it is connectionless, but it is network layer.

The key is to remember that UDP is the only transport layer protocol among the options that lacks reliability guarantees.

55
MCQmedium

In the OSI model, which layer uses MAC addresses to forward frames and supports VLANs?

A.Layer 2 - Data Link
B.Layer 4 - Transport
C.Layer 3 - Network
D.Layer 1 - Physical
AnswerA

Layer 2, the Data Link layer, forwards frames using MAC addresses and supports VLANs through 802.1Q tagging, which inserts a VLAN identifier into the Ethernet frame header. This satisfies the stem's requirement for the layer that both addresses frames by MAC and provides VLAN segmentation.

Why this answer

The Data Link layer (Layer 2) is responsible for framing, MAC addressing, and forwarding frames within a local network segment. VLANs (802.1Q) are a Layer 2 construct that logically segments a switch into multiple broadcast domains, and VLAN tags are inserted into Ethernet frames — making Layer 2 the correct answer. Switches use MAC address tables to forward frames and enforce VLAN membership.

Exam trap

The trap here is confusing Layer 2 and Layer 3 responsibilities — candidates see 'VLANs' and think routing (Layer 3), but VLAN tagging and MAC-based forwarding are strictly Layer 2 functions.

How to eliminate wrong answers

Option B is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and protocols like TCP and UDP — it deals with port numbers, not MAC addresses or VLANs. Option C is wrong because Layer 3 (Network) handles logical addressing (IP) and routing between networks; while inter-VLAN routing occurs at Layer 3, VLANs themselves are defined and tagged at Layer 2. Option D is wrong because Layer 1 (Physical) deals with bits, cables, connectors, and signaling — it has no concept of addressing or VLANs.

56
Multi-Selectmedium

A security analyst is deploying network security devices. Which TWO of the following are characteristics of an Intrusion Detection System (IDS)?

Select 2 answers
A.Can be placed inline to block malicious traffic
B.Operates in passive mode by monitoring a copy of traffic
C.Can automatically reconfigure firewall rules
D.Ensures zero false positives
E.Generates alerts when suspicious activity is detected
AnswersB, E

An IDS receives mirrored traffic via a SPAN port or TAP and analyses it without sitting inline, so it cannot block packets. This passive monitoring is the defining architectural characteristic distinguishing it from an IPS.

Why this answer

Option B is correct because an IDS is fundamentally a passive monitoring technology: it receives a copy of the traffic (typically via a SPAN/mirror port or a network TAP) and analyzes it without sitting in the forwarding path, so it cannot drop packets. Option E is correct because the core function of an IDS is to detect suspicious or malicious activity and generate alerts (e.g., via signatures or anomaly detection) for analysts to investigate. Option A is wrong because inline blocking is characteristic of an IPS, not an IDS.

Option C is wrong because an IDS does not automatically modify firewall rules; that would require integration with a firewall or an IPS/automated response system. Option D is wrong because no detection system guarantees zero false positives; IDS products inherently produce some false positives and false negatives.

Exam trap

The trap here is conflating IDS with IPS — candidates see 'block malicious traffic' and assume detection implies prevention, but the CC exam specifically tests that IDS is passive/alerting while IPS is inline/blocking.

57
MCQhard

A security analyst detects an ARP spoofing attack on the local network. What is the primary goal of an ARP spoofing attack?

A.To disable the switch by sending fake VLAN tags
B.To overwhelm the network with broadcast traffic
C.To redirect traffic to the attacker's machine for eavesdropping or modification
D.To corrupt the DNS cache
AnswerC

ARP spoofing forges gratuitous ARP replies that bind the gateway's IP address to the attacker's MAC address, so victims forward their frames to the attacker. The attacker then relays traffic onward while capturing credentials and session data, or alters payloads in transit, satisfying the eavesdropping and modification goal.

Why this answer

ARP spoofing allows an attacker to intercept traffic by associating their MAC address with the IP address of a legitimate host.

58
MCQmedium

An organization wants to place its public web server, email server, and DNS server in a network that is accessible from the internet but isolated from the internal corporate network. Which network design should be used?

A.DMZ
B.VPN
D.Subnet
AnswerA

A DMZ (demilitarised zone) sits between the internet-facing perimeter and the internal network, so public-facing servers are reachable from the internet while firewall rules block direct access to internal corporate systems. This satisfies the isolation requirement without exposing the internal network.

Why this answer

A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the internet. It adds an additional layer of security by isolating these services from the internal corporate network. Public web, email, and DNS servers are typically placed in a DMZ to allow external access while protecting the internal network.

Exam trap

The trap is confusing a DMZ with a VLAN or subnet. While a DMZ can be implemented using VLANs and subnets, the key is its purpose: isolating external-facing services from the internal network.

How to eliminate wrong answers

Option B is wrong because a VPN is used to create a secure connection over an untrusted network, not to isolate public servers. Option C is wrong because a VLAN is a logical segmentation at Layer 2, but it does not inherently provide isolation from the internal network; it can be used within a DMZ. Option D is wrong because a subnet is a logical subdivision of an IP network, but not all subnets are DMZs; a DMZ is a specific type of subnet designed for external-facing services.

59
Multi-Selectmedium

A security team is designing a network segmentation strategy to protect a database server that contains sensitive customer information. The database server should only be accessible by the application server, and no other systems should be able to initiate connections to it. Which two controls should the team implement to achieve this? (Choose two.)

Select 2 answers
A.Place the database server in a separate VLAN and configure firewall rules to allow traffic only from the application server's IP address.
B.Use network address translation (NAT) to hide the database server's IP address from other internal systems.
C.Enable port security on the switch port connected to the database server to restrict MAC addresses.
D.Deploy an intrusion detection system (IDS) to monitor traffic to the database server and alert on suspicious connections.
E.Implement a host-based firewall on the database server that allows connections only from the application server's IP address.
AnswersA, E

Segmenting the database server into its own VLAN isolates it at the network layer, and firewall rules restrict access to only the application server. This combination enforces least privilege and reduces the attack surface. It ensures that even if other systems are compromised, they cannot directly reach the database.

Why this answer

Combining network segmentation with firewall rules and a host-based firewall provides defense in depth. The VLAN and network firewall restrict access at the network perimeter, while the host firewall adds protection directly on the server. Together, they ensure only the application server can connect, aligning with least privilege.

Exam trap

The trap here is relying on detection or obscurity controls like IDS or NAT instead of preventive access controls that actually restrict connections.

60
MCQmedium

A technician is configuring a firewall to allow secure web traffic. Which port and protocol should be permitted?

A.UDP port 443
B.TCP port 80
C.TCP port 443
D.TCP port 22
AnswerC

HTTPS traffic uses TCP port 443, where TLS encapsulates HTTP. Permitting TCP 443 satisfies the secure web traffic requirement; port 80 carries unencrypted HTTP, and UDP 443 is used by HTTP/3 rather than standard secure browsing.

Why this answer

Secure web traffic uses HTTPS, which by default runs over TCP port 443. The question specifies 'secure web traffic,' so the correct protocol/port pairing is TCP 443. HTTPS encrypts HTTP using TLS, protecting confidentiality and integrity of web communications.

Exam trap

The trap is the UDP 443 distractor — candidates who know HTTP/3 uses QUIC may pick it, but the standard, expected answer for 'secure web traffic' is TCP 443.

How to eliminate wrong answers

Option A is wrong because UDP port 443 is used by HTTP/3 (QUIC), but the standard, universally supported secure web protocol is TCP 443 — and the question asks for the standard secure web traffic port, which is TCP-based. Option B is wrong because TCP port 80 is plain HTTP, which is unencrypted and therefore not 'secure' web traffic. Option D is wrong because TCP port 22 is SSH, used for secure remote administration, not web traffic.

61
MCQhard

A security analyst reviewing network logs notices that an internal workstation is resolving a well-known banking domain to an IP address that belongs to an unknown external host. The workstation's configured DNS server is the corporate resolver, and no changes were made to it. Which type of attack is most likely occurring?

A.DNS tunneling
B.Domain hijacking
C.DNS amplification
D.DNS cache poisoning
AnswerD

DNS cache poisoning inserts false records into a resolver's cache so that legitimate domain names resolve to attacker-controlled addresses. Since the workstation uses the corporate resolver and no local configuration changed, a poisoned cache on that resolver would explain the incorrect answer. This enables redirection to malicious sites and is a classic man-in-the-middle enabler.

Why this answer

When a workstation uses the corporate resolver and suddenly receives an attacker-controlled IP for a legitimate banking domain, the most likely cause is that the resolver's cache has been poisoned with a forged record. DNS cache poisoning redirects users to malicious destinations without changing endpoint configuration. Tunneling, domain hijacking, and amplification do not match the observed symptom of a wrong but locally scoped resolution.

Exam trap

The trap here is attributing any DNS anomaly to domain hijacking, when a resolver-scoped wrong answer more strongly indicates cache poisoning.

62
MCQmedium

A security analyst wants to detect malicious traffic on the network without affecting performance. Which type of device should be deployed?

A.IDS
B.Honeypot
C.IPS
AnswerA

An IDS passively copies and analyses network traffic, comparing it against signatures or anomalies to raise alerts. Because it sits out-of-band rather than inline, it detects malicious activity without adding latency or dropping packets, satisfying the no-performance-impact constraint.

Why this answer

An IDS (Intrusion Detection System) monitors network traffic passively, typically via a SPAN port or network TAP, and generates alerts on suspicious activity without blocking traffic. Because it operates out-of-band and does not sit inline, it does not affect network performance or latency — exactly matching the requirement to detect without impacting performance.

Exam trap

The trap is the IDS vs. IPS distinction — candidates who focus only on 'detect' may overlook that IPS is inline and affects performance, while IDS is passive and does not.

How to eliminate wrong answers

Option B is wrong because a honeypot is a decoy system designed to attract and study attackers, not to monitor general network traffic for intrusions — it detects only activity directed at itself. Option C is wrong because an IPS (Intrusion Prevention System) sits inline and can block traffic, which introduces latency and potential throughput bottlenecks, violating the 'without affecting performance' requirement. Option D is wrong because a firewall enforces access control policy based on rules; while it may have some detection capability, its primary role is filtering, and inline enforcement can affect performance.

63
Multi-Selecteasy

Which two protocols operate at the Transport layer of the OSI model? (Choose TWO.)

Select 2 answers
B.TCP
C.IP
D.Ethernet
E.UDP
AnswersB, E

TCP operates at the Transport layer, providing connection-oriented, reliable delivery with sequencing, acknowledgements and flow control. Its layer 4 port addressing and segmentation satisfy the question's requirement for protocols operating at the Transport layer of the OSI model.

Why this answer

TCP and UDP are the primary Transport layer protocols. IP is Network layer, Ethernet is Data Link, and HTTP is Application layer.

64
MCQhard

A software company allows developers to work from home and connect to internal code repositories over the internet. The security team wants to verify the identity of each developer and the health of their device before granting access, without exposing the repositories directly to the internet. Which solution should the team implement?

A.Expose the repositories through a jump host with SSH key authentication and no device checks.
B.Use a site-to-site IPsec tunnel between each developer's home router and the corporate gateway.
C.Publish the code repositories through a reverse proxy with HTTP basic authentication.
D.Deploy a remote access VPN that authenticates users and then performs a posture check before allowing access to the repository subnet.
AnswerD

A remote access VPN authenticates each developer and can integrate a posture or host-check step that evaluates device health before granting network access. The repositories remain on an internal subnet that is not directly reachable from the internet. This satisfies identity verification, device health assessment, and non-exposure of the repositories in one design.

Why this answer

A remote access VPN authenticates each developer and can enforce a posture check that verifies device health before allowing access to internal repositories. The repositories stay on an internal subnet and are not published to the internet. A reverse proxy with basic authentication, a site-to-site tunnel to home routers, and a jump host without device checks each fail at least one requirement.

Exam trap

The trap here is focusing only on user authentication and overlooking the explicit requirement to verify device health before granting access.

65
MCQeasy

A network administrator needs to allow secure remote management of a router. Which protocol and port should be used?

A.FTP on port 21
B.HTTP on port 80
C.SSH on port 22
D.Telnet on port 23
AnswerC

SSH encrypts the entire management session, including credentials and commands, preventing eavesdropping and man-in-the-middle interception. Port 22 is its assigned transport port. Telnet on port 23 sends everything in cleartext, failing the secure remote management constraint.

Why this answer

SSH on TCP port 22 provides encrypted, authenticated remote management of network devices, protecting credentials and session data from eavesdropping. It is the standard secure replacement for Telnet and is widely supported on routers and switches.

Exam trap

The trap is choosing HTTP because many routers have a web interface, but the question asks for secure remote management, and only SSH provides encrypted CLI access on its well-known port.

How to eliminate wrong answers

Option A is wrong because FTP on port 21 is an unencrypted file transfer protocol and does not provide interactive remote management of a router. Option B is wrong because HTTP on port 80 is unencrypted web traffic; while some devices offer a web GUI, it is not secure without HTTPS and is not the protocol/port pair for secure CLI management. Option D is wrong because Telnet on port 23 sends credentials and commands in cleartext, making it insecure for remote management.

66
Multi-Selectmedium

Which three ports are commonly used by secure protocols? (Choose THREE.)

Select 3 answers
A.80 (HTTP)
B.443 (HTTPS)
C.22 (SSH)
D.23 (Telnet)
E.636 (LDAPS)
AnswersB, C, E

Port 443 carries HTTPS, which wraps HTTP inside TLS, encrypting credentials and session data in transit. This directly satisfies the stem's requirement for a secure protocol port, unlike cleartext alternatives such as port 80. Microsoft Entra ID authentication traffic and most modern web APIs rely on 443 for this reason.

Why this answer

HTTPS uses 443, SSH uses 22, and LDAPS uses 636. HTTP (80), Telnet (23), and FTP (21) are insecure or unencrypted.

67
MCQeasy

An organization wants to separate its internal network from a publicly accessible web server. Which network segmentation technique should be used to isolate the web server while allowing controlled access?

A.Honeypot
B.Subnetting
C.DMZ
AnswerC

A DMZ sits between the internal network and the internet, exposing the web server to public traffic while firewalls restrict inbound connections to that segment alone. This satisfies the stem's requirement to isolate the server yet permit controlled access, preventing direct reach from the public internet into internal systems.

Why this answer

A DMZ (Demilitarized Zone) is a segmented network that sits between the internal trusted network and the untrusted internet, specifically designed to host publicly accessible services like web servers while isolating them from internal systems. Firewall rules control traffic between the internet, the DMZ, and the internal network, so if the web server is compromised, the attacker cannot directly reach internal resources.

Exam trap

The trap is confusing VLANs or subnetting with a DMZ — candidates pick VLAN because it 'segments,' but only a DMZ provides firewall-enforced isolation for public-facing services.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system meant to lure and observe attackers, not to host production web servers or provide controlled access. Option B is wrong because subnetting divides an IP network into smaller subnets for organization and routing efficiency, but it does not by itself create a security boundary or controlled access between public and internal networks. Option D is wrong because a VLAN segments traffic at Layer 2 within a network, but it does not provide the firewall-enforced isolation between a public-facing server and the internal network that a DMZ does — VLANs alone are not a security boundary.

68
MCQmedium

A security administrator is configuring a network device that monitors traffic and generates alerts when suspicious patterns are detected. The device does not block traffic. Which type of system is being deployed?

A.Web Application Firewall (WAF)
B.Intrusion Detection System (IDS)
C.Intrusion Prevention System (IPS)
D.Next-Generation Firewall (NGFW)
AnswerB

An IDS passively inspects network traffic, matching signatures or anomalies to raise alerts without dropping packets. Because the stem specifies the device monitors and alerts but does not block, an Intrusion Detection System satisfies that non-preventive constraint; an IPS would actively block traffic inline.

Why this answer

An IDS (Intrusion Detection System) is passive and only alerts, while an IPS actively blocks.

69
Multi-Selecthard

An organization is selecting a network security solution to protect against advanced threats. Which THREE features are characteristic of a Next-Generation Firewall (NGFW)? (Select THREE.)

Select 3 answers
A.Static packet filtering based on IP and port
B.Application identification and control
C.User identity awareness
D.Stateful packet inspection
E.Integrated intrusion prevention system (IPS)
AnswersB, C, E

NGFWs inspect traffic to identify applications regardless of port, then allow, block, or shape them by category. This application-layer control directly addresses advanced threats that tunnel over permitted ports, a capability absent from traditional port-based firewalls.

Why this answer

Option B is correct because an NGFW performs deep packet inspection to identify applications (e.g., via App-ID) and enforce granular control based on the application rather than just port, which is essential against advanced threats that tunnel over allowed ports. Option C is correct because NGFWs integrate with directory services (e.g., Active Directory, LDAP) to map traffic to specific users and groups, enabling identity-based policies that traditional firewalls cannot enforce. Option E is correct because NGFWs bundle an integrated IPS that inspects traffic for known exploit signatures and behavioral anomalies, providing inline threat prevention without a separate appliance.

Option A is not correct because static packet filtering based on IP and port is a first-generation firewall capability, not a distinguishing NGFW feature. Option D is not correct because stateful packet inspection is a baseline capability of traditional stateful firewalls and is not unique to NGFWs.

Exam trap

The trap is including legacy firewall features like static packet filtering or stateful inspection as NGFW characteristics — candidates must distinguish first-, second-, and next-generation firewall capabilities.

70
Multi-Selecthard

A network administrator is implementing a DMZ to host a web server and an email server. Which THREE security best practices should be followed? (Select THREE)

Select 3 answers
A.Place only public-facing servers (e.g., web, email) in the DMZ.
B.Use a firewall to control traffic between the internet, DMZ, and internal network.
C.Configure the DMZ to communicate directly with the internal network without restrictions.
D.Allow all inbound traffic to the DMZ from the internet for ease of access.
E.Restrict inbound traffic to only required services (e.g., HTTP, SMTP).
AnswersA, B, E

Segregating public-facing web and email servers into the DMZ keeps them off the internal network, so a compromise cannot directly pivot inward. This satisfies the DMZ design constraint that only externally reachable services reside in that screened subnet.

Why this answer

Option A is correct because a DMZ is specifically designed to host public-facing services such as web and email servers, isolating them from the trusted internal network so that a compromise of these exposed hosts does not directly expose internal assets. Option B is correct because a firewall (or multiple firewalls) must mediate and filter traffic among the internet, the DMZ, and the internal network, enforcing distinct security policies for each zone rather than allowing unrestricted flows. Option E is correct because inbound traffic to the DMZ should be limited to only the ports and protocols required by the hosted services — for example TCP 80/443 for HTTP/HTTPS and TCP 25 for SMTP — following the principle of least privilege to minimize the attack surface.

Option C is incorrect because unrestricted DMZ-to-internal communication defeats the purpose of segmentation and would let a compromised DMZ host pivot directly into the internal network. Option D is incorrect because allowing all inbound internet traffic to the DMZ exposes unnecessary ports and services, greatly increasing the risk of exploitation.

Exam trap

The trap here is the 'convenience' distractor — options that promise easier access (allow all inbound, unrestricted DMZ-to-LAN) sound operationally appealing but violate the core DMZ principle of least privilege and defense in depth.

71
MCQhard

During a penetration test, an analyst uses a tool to intercept and modify traffic between a client and server by exploiting the Address Resolution Protocol (ARP). This attack is an example of which type of threat?

A.Spoofing
B.Denial of Service (DoS)
C.Sniffing
D.Man-in-the-middle (MITM)
AnswerD

ARP spoofing lets the attacker position themselves between client and server, silently relaying and altering frames while both endpoints believe they hold a direct connection. That interception and modification of live traffic is precisely the man-in-the-middle condition the scenario describes, satisfying the requirement that communications pass through the attacker.

Why this answer

ARP poisoning lets an attacker send forged ARP replies so that the victim's traffic is redirected through the attacker's machine. Because the attacker sits between the client and the server, silently relaying and potentially altering packets, this is a classic man-in-the-middle (MITM) attack. The interception and modification of traffic is the defining characteristic that distinguishes MITM from mere spoofing or sniffing.

Exam trap

The trap is that ARP poisoning technically involves spoofing, so candidates pick 'Spoofing' — but the exam wants the attack category that describes the full outcome (interception plus modification), which is MITM.

How to eliminate wrong answers

Option A is wrong because spoofing only describes falsifying an identity (e.g., a MAC or IP address); ARP poisoning does involve spoofing, but the question emphasizes intercepting and modifying traffic, which is the MITM outcome, not spoofing alone. Option B is wrong because a DoS attack aims to disrupt availability, whereas here the attacker maintains the connection to eavesdrop and tamper. Option C is wrong because sniffing is passive capture of traffic; the scenario explicitly involves the attacker positioning themselves in the path and modifying data, which is active MITM behavior.

72
MCQmedium

A network administrator wants to control traffic based on source and destination IP addresses and port numbers, while also tracking the state of connections. Which type of firewall should they choose?

A.Stateless packet filtering
B.Application proxy
C.Stateful inspection
D.Next-generation firewall (NGFW)
AnswerC

Stateful inspection tracks connection state in a session table, so it filters on source and destination IP addresses and ports while recognising established flows. Stateless packet filtering cannot track connection state, which the stem explicitly requires.

Why this answer

Stateful inspection firewalls maintain a state table that tracks the context of each connection (source/destination IP, ports, and TCP flags), allowing return traffic for established sessions without an explicit rule. This satisfies both requirements in the question: filtering by IP and port, and tracking connection state. Stateless filters can match IPs and ports but have no memory of sessions.

Exam trap

The trap is conflating 'stateful inspection' with 'NGFW' — candidates see 'control traffic by IP and port' and jump to NGFW, but the question's second clause ('tracking the state of connections') is the textbook definition of stateful inspection, and NGFW is a superset that isn't required here.

How to eliminate wrong answers

Option A is wrong because stateless packet filtering evaluates each packet in isolation using only header fields — it cannot track connection state, so return traffic must be explicitly permitted with broad rules. Option B is wrong because an application proxy operates at Layer 7, terminating and re-originating connections to inspect application payloads; while it can filter by IP/port, its defining feature is deep application inspection, not state tracking, and it adds latency. Option D is wrong because an NGFW includes stateful inspection plus additional capabilities like IPS, application awareness, and TLS inspection — it is overkill for the stated requirement and the question asks for the type defined by state tracking, which is stateful inspection.

73
Multi-Selectmedium

An organization wants to ensure that only authorized devices can connect to the wired network. Which TWO methods can be used to enforce this?

Select 2 answers
A.802.1X authentication
B.Firewall rules
D.NAT
E.VLAN segmentation
AnswersA, C

802.1X authentication requires a supplicant to authenticate against a RADIUS server via EAP before the switch grants port access, satisfying the authorised-devices-only constraint. Unauthenticated devices remain in an uncontrolled state and cannot pass traffic onto the wired network.

Why this answer

802.1X authentication (A) is correct because it enforces port-based network access control on wired switches, requiring devices to authenticate via EAPOL to a RADIUS server before the port is authorized to pass traffic. Port security (C) is correct because it restricts which MAC addresses may be learned on a switch port, limiting connections to known/authorized devices and taking action (shutdown, restrict, or protect) on violations. Firewall rules (B) filter traffic by IP/port but do not authenticate or identify devices at the access layer, so they cannot ensure only authorized devices connect.

NAT (D) merely translates addresses for routing/Internet access and provides no device authorization. VLAN segmentation (E) isolates traffic into logical groups but does not by itself verify or restrict which devices are permitted to connect.

Exam trap

The trap is choosing 'VLAN segmentation' or 'firewall rules' as access control — both provide logical separation or traffic filtering, but neither authenticates a device at the physical switch port, which is what 'only authorized devices can connect' requires.

74
Multi-Selecthard

An organization is experiencing network attacks where the attacker forges the source IP address. Which two types of attacks commonly use IP spoofing? (Choose TWO.)

Select 2 answers
A.ARP spoofing
B.MAC flooding
C.Ping of death
D.SYN flood
E.DNS amplification
AnswersD, E

SYN floods exploit spoofed source addresses to conceal the attacker's identity while exhausting a server's half-open connection table. Each forged SYN forces the target to allocate resources and await a final ACK that never arrives, directly satisfying the stem's requirement for attacks that commonly employ IP spoofing.

Why this answer

SYN floods often spoof source IPs to hide the attacker, and DNS amplification attacks use spoofed source IPs to direct responses to the victim. ARP spoofing is local and does not involve IP spoofing in the same way, while MAC flooding and ping of death are different.

75
Multi-Selecthard

A security architect is designing defenses against on-path attacks on a corporate wireless network where employees connect to internal applications. Which two controls most directly protect the confidentiality and integrity of employee traffic against an attacker who can observe or modify wireless frames? (Choose two.)

Select 2 answers
A.Deploying a wireless intrusion detection system to alert on rogue access points.
B.Requiring TLS for all internal application traffic between clients and servers.
C.Implementing MAC address filtering to admit only known corporate devices.
D.Enforcing WPA3-Enterprise with protected management frames on the wireless infrastructure.
E.Disabling SSID broadcast to make the corporate network harder to find.
AnswersB, D

TLS encrypts and integrity-protects application data end to end between the client and the server, so even if an attacker captures or manipulates wireless frames, the payload remains confidential and tampering is detected. This complements link-layer protections by securing the traffic above the wireless hop, directly addressing on-path confidentiality and integrity.

Why this answer

Protecting against an on-path attacker requires cryptography at both the wireless link and the application layer. WPA3-Enterprise with protected management frames secures the radio hop and prevents management-frame manipulation, while TLS secures application data end to end. Monitoring, SSID hiding, and MAC filtering may add visibility or friction but do not encrypt or integrity-protect the traffic itself, so they do not directly meet the stated goal.

Exam trap

The trap here is treating visibility or obscurity controls, such as wireless intrusion detection or hidden SSIDs, as if they provided cryptographic protection of traffic.

Page 1 of 3 · 159 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cc Network Security questions.

CCNA Cc Network Security Questions — Page 1 of 3 | Courseiva