Courseiva

CC · topic practice

Network Security practice questions

Domain 4 of the ISC2 CC exam covers network architecture, protocols, and defensive controls. Expect scenario questions on TCP/IP layers, addressing, segmentation, and attack signatures. You must map protocols and ports to their functions, choose the right control for a given risk, and identify attacks from observed traffic or log symptoms rather than definitions alone.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network Security

What the exam tests

What to know about Network Security

Be able to match protocols (ARP, TCP, TLS, SSH) and devices (switch, router, firewall) to a scenario, and select the control that mitigates the stated risk. The single most important thing: read what the attacker or administrator actually observes before choosing an answer.

ARP resolving IPv4 addresses to MAC addresses within a local broadcast domain

VLANs logically segmenting departments on one physical switch

TLS/HTTPS and SSH encrypting traffic to defeat sniffing on wired LANs

SYN flood attacks identified by many half-open TCP connection requests

Watch out for

Common Network Security exam traps

  • ▸Confusing ARP with DNS or DHCP; ARP maps IP to MAC locally, while DNS resolves names and DHCP assigns addresses.
  • ▸Assuming encryption stops sniffing; it protects payload confidentiality, but sniffing still captures metadata and unencrypted protocols.
  • ▸Picking a router or firewall when VLANs are needed to separate departments on the same physical switch.

Practice set

Network Security questions

20 questions · select your answer, then reveal the explanation

A security analyst notices a high volume of ICMP Echo Reply packets from an external server to an internal host that never sent Echo Requests. Which type of attack is likely occurring?

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

Question 3mediummultiple choice
Read the full Network Security explanation →

An attacker intercepts communication between two parties by sending forged ARP messages. This is an example of which type of attack?

Question 4mediummultiple choice
Read the full Network Security explanation →

Which firewall type is capable of inspecting the contents of application-layer traffic, such as HTTP requests, to detect malicious patterns?

A security analyst is reviewing network traffic and needs to identify which of the following protocols are inherently insecure because they transmit data in cleartext. (Select TWO.)

Which protocol is used to resolve IP addresses to MAC addresses on a local network?

An organization wants to protect its internal network from unsolicited inbound traffic while allowing responses to outbound connections. Which TWO firewall features or types are best suited for this? (Select TWO)

Question 8hardmultiple choice
Open the full VLAN trunking answer →

A company's network has multiple VLANs. An attacker on VLAN 10 sends a frame with a forged source MAC address to a switch, hoping to intercept traffic intended for the default gateway. Which attack is being executed?

A security analyst is investigating a potential man-in-the-middle attack. Which two techniques are commonly used by attackers to perform MITM attacks? (Choose two.)

A company wants to protect its internal web server from common web application attacks. Which two security measures are most appropriate? (Choose TWO.)

A company wants to mitigate the risk of a man-in-the-middle (MITM) attack. Which three measures are effective? (Choose THREE.)

Question 12mediummulti select
Study the full AAA explanation →

A financial services firm is designing a defense-in-depth strategy for its internal network. The security architect wants to reduce the risk of lateral movement after an endpoint is compromised and to limit the blast radius of any single compromised host. Which two controls best address these goals? (Choose two.)

Question 13mediummultiple choice
Read the full wireless explanation →

A security analyst at a small e-commerce company notices that customer login credentials are being intercepted when users connect from public Wi-Fi. The company's web application uses HTTPS, but the login page itself is served over HTTP before redirecting to HTTPS. Which mitigation should the analyst implement to prevent credential exposure during the initial login request?

Question 14hardmultiple choice
Read the full wireless explanation →

A security analyst reviewing wireless logs notices that an attacker is capturing authentication frames from a WPA2-Enterprise network and replaying them to a rogue access point to obtain a valid session key. The organization wants to prevent this specific attack without replacing all client devices. Which control should be implemented?

Question 15mediummultiple choice
Read the full Network Security explanation →

A hospital's radiology department transmits patient imaging studies to an external specialist clinic over the internet. The security officer requires that the data be protected so that even if intercepted, the contents cannot be read and any modification is detectable. Which technology should be implemented?

Question 16easymultiple choice
Read the full DNS explanation →

A user reports that they can access websites by typing domain names like www.example.com into their browser, but they cannot access the same sites by typing the IP address directly. The network administrator suspects a DNS issue. Which protocol is primarily responsible for translating domain names to IP addresses?

Question 17hardmulti select
Read the full DHCP explanation →

A security analyst is reviewing network logs and notices that an attacker is attempting to exhaust the DHCP address pool by sending numerous DHCPDISCOVER messages with spoofed MAC addresses. Which two countermeasures should the analyst recommend to mitigate this attack? (Choose two.)

A hospital network uses 802.1X for wired port authentication. An attacker connects a rogue switch to an authenticated port and then attaches multiple unauthorized devices, which gain network access using the authenticated port's credentials. Which feature should be enabled to prevent this?

A security engineer is implementing network access control (NAC) in a corporate environment. The goal is to ensure that only compliant and authenticated devices can access the network, and that non-compliant devices are remediated or quarantined. Which two components are essential for a NAC solution to achieve these goals? (Choose two.)

Question 20easymultiple choice
Review the full routing breakdown →

Which OSI layer is responsible for routing packets across networks using IP addresses?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network Security sessions

Start a Network Security only practice session

Every question in these sessions is drawn from the Network Security domain — nothing else.

Related practice questions

Related CC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CC exam test about Network Security?
Be able to match protocols (ARP, TCP, TLS, SSH) and devices (switch, router, firewall) to a scenario, and select the control that mitigates the stated risk. The single most important thing: read what the attacker or administrator actually observes before choosing an answer.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Network Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CC topics?
Use the topic links above to move to related areas, or go back to the CC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CC exam covers. They are not copied from any real exam or dump site.