Courseiva

CCNA Cc Network Security Questions

75 of 159 questions · Page 2/3 · Cc Network Security topic · Answers revealed

76
MCQeasy

Which of the following is a connectionless, unreliable transport protocol?

A.IP
B.TCP
C.UDP
AnswerC

UDP sends datagrams without establishing a session, handshake or delivery acknowledgement, so packets may arrive out of order or not at all. This absence of connection state and retransmission makes it the connectionless, unreliable transport protocol.

Why this answer

UDP is connectionless and does not guarantee delivery.

77
MCQeasy

Which layer of the OSI model is responsible for routing packets based on IP addresses?

A.Data Link layer
B.Transport layer
C.Network layer
D.Physical layer
AnswerC

The network layer handles logical addressing and path selection, forwarding packets between networks based on destination IP addresses. Data link addresses frames by MAC, transport segments by port, so routing decisions belong exclusively to layer 3.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing packets based on IP addresses. It determines the best path for data to travel across multiple networks, using routers to forward packets hop-by-hop. This layer encapsulates data into packets and handles fragmentation and reassembly when necessary.

Exam trap

The trap here is confusing the roles of Layer 2 and Layer 3: candidates often associate 'packets' with the Data Link layer because both deal with addressing, but only Layer 3 uses IP addresses for routing across networks.

How to eliminate wrong answers

Option A is wrong because the Data Link layer (Layer 2) handles physical addressing (MAC addresses) and framing for communication within a single network segment, not routing between networks. Option B is wrong because the Transport layer (Layer 4) provides end-to-end communication, segmentation, flow control, and error recovery (e.g., TCP/UDP), but does not route packets based on IP addresses. Option D is wrong because the Physical layer (Layer 1) deals with the transmission of raw bits over a physical medium, defining electrical, mechanical, and procedural specifications, and has no concept of IP addresses or routing.

78
MCQeasy

A network administrator is configuring a new wireless network for a small office. The office has sensitive data and wants to ensure that all wireless traffic is encrypted and that users authenticate with unique credentials. Which security protocol should the administrator implement?

A.WPA2-Enterprise
B.Open authentication
C.WEP
D.WPA2-Personal
AnswerA

WPA2-Enterprise uses 802.1X authentication with an authentication server (e.g., RADIUS) to provide unique credentials for each user. It also uses strong encryption (AES-CCMP). This meets the requirements for encrypted traffic and unique user authentication, making it the appropriate choice for a small office with sensitive data.

Why this answer

WPA2-Enterprise provides both strong encryption and unique user authentication via 802.1X and a RADIUS server. This ensures that each user has distinct credentials and that wireless traffic is encrypted. The other options either lack unique authentication (WPA2-Personal, Open) or are insecure (WEP, Open).

Exam trap

The trap here is confusing WPA2-Personal with WPA2-Enterprise; the key differentiator is whether authentication is centralized and unique per user.

79
MCQhard

A company deploys a firewall that inspects packet headers and maintains a state table to track active connections. It drops any incoming packets that do not match an established connection. What type of firewall is this?

A.Application proxy firewall
B.Stateful inspection firewall
C.Next-generation firewall
D.Packet filtering firewall
AnswerB

Stateful inspection builds a state table of active connections and permits only return traffic matching an established entry, dropping unsolicited inbound packets. This matches the described behaviour of tracking sessions rather than evaluating each packet statelessly.

Why this answer

A stateful inspection firewall maintains a state table that tracks active connections and only allows packets that match an established connection. It inspects packet headers and maintains connection state, dropping packets that do not match. This is the definition of a stateful inspection firewall.

It operates at the network and transport layers and provides better security than simple packet filtering.

Exam trap

CC often tests the difference between stateful and stateless firewalls; candidates may confuse stateful inspection with packet filtering because both inspect headers, but stateful maintains connection state.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at the application layer and acts as an intermediary for specific applications, not just inspecting headers and maintaining state. Option C is wrong because a next-generation firewall (NGFW) includes additional features like application awareness, intrusion prevention, and deep packet inspection, but the description only mentions stateful inspection. Option D is wrong because a packet filtering firewall only inspects individual packets based on static rules (e.g., IP addresses, ports) without maintaining connection state.

80
MCQmedium

A hospital's network team notices that a radiology workstation is receiving a duplicate IP address error. The DHCP server logs show the workstation was assigned 10.10.20.45, but the workstation is manually configured with that same address. Which DHCP feature should have been configured to prevent this conflict?

B.DHCP exclusion range
C.DHCP relay agent
D.DHCP reservation
AnswerB

An exclusion range defines IP addresses within the DHCP scope that the server must not assign to clients. By excluding 10.10.20.45, the DHCP server would never lease it, avoiding a conflict with the manually configured radiology workstation. This is the correct administrative control when static addresses exist inside a dynamic scope.

Why this answer

The conflict occurs because the DHCP server dynamically leases an address that is already statically assigned to another device. To prevent this, the address must be removed from the assignable pool using an exclusion range. This ensures the server never offers that address, eliminating the duplicate IP conflict without changing the workstation's static configuration.

Exam trap

The trap here is confusing DHCP reservations with exclusions; a reservation only affects DHCP clients, while an exclusion prevents the server from ever assigning a specific address, which is needed for statically configured hosts.

81
MCQhard

A financial services firm is designing a network that must allow inbound HTTPS from the internet to a public web application while preventing any direct inbound connections to its internal database servers. The security architect proposes placing the web application in a screened subnet and configuring rules so the database can be reached only from the web application. Which design element is the architect primarily relying on?

A.A hub-based network topology
B.A demilitarized zone (DMZ) with controlled access between zones
C.A flat network with a single perimeter firewall
D.Network address translation (NAT) alone
AnswerB

A DMZ hosts public-facing services in a screened subnet separate from internal systems, and firewall rules control traffic between the DMZ, the internet, and the internal network. This allows inbound HTTPS to the web application while preventing direct inbound access to database servers. The controlled inter-zone rules are the core of the design.

Why this answer

The architect needs a screened subnet for the public web application plus enforced rules controlling traffic between the internet, the DMZ, and internal systems. A DMZ with controlled access accomplishes this by allowing inbound HTTPS to the web tier while denying direct inbound access to database servers. A flat network, NAT alone, or a hub topology lacks the required separation and rule enforcement.

Exam trap

The trap here is believing that address translation or a perimeter firewall alone creates an internal security boundary, when zone separation and inter-zone rules are what actually restrict access.

82
MCQeasy

Which OSI layer is responsible for routing packets across networks using IP addresses?

A.Layer 1 - Physical
B.Layer 3 - Network
C.Layer 4 - Transport
D.Layer 2 - Data Link
AnswerB

Layer 3, the Network layer, handles logical addressing and path selection, so routers use IP addresses to forward packets between distinct networks. Layers 2 and 4 lack routable addressing, making Layer 3 the layer that satisfies the routing requirement in the stem.

Why this answer

The Network layer (Layer 3) is responsible for logical addressing and routing. It uses IP addresses to determine the best path for packets to travel from source to destination across different networks. Protocols like IP (IPv4/IPv6), OSPF, and BGP operate at this layer to perform routing decisions.

Exam trap

A common pitfall is confusing the Data Link layer's local delivery role (Layer 2) with the Network layer's internetwork routing function (Layer 3). Remember that routing across networks using IP addresses occurs at Layer 3.

How to eliminate wrong answers

Option A is wrong because Layer 1 (Physical) deals with the physical transmission of raw bits over media (e.g., cables, voltages, frequencies) and has no concept of IP addresses or routing. Option C is wrong because Layer 4 (Transport) provides end-to-end communication, segmentation, and reliability (e.g., TCP/UDP), but it does not perform routing or use IP addresses for path selection. Option D is wrong because Layer 2 (Data Link) handles frame delivery within a single network segment using MAC addresses and protocols like Ethernet, not IP routing across networks.

83
MCQeasy

Which protocol operates at the Transport layer and provides reliable, connection-oriented data delivery?

A.TCP
B.UDP
C.IP
AnswerA

TCP operates at the Transport layer and provides reliable, connection-oriented delivery through handshaking, sequence numbers and acknowledgements. UDP, its Transport-layer counterpart, is connectionless and unreliable, so TCP uniquely satisfies both the layer and reliability constraints stated in the question.

Why this answer

TCP (Transmission Control Protocol) uses a three-way handshake, sequencing, and acknowledgments to ensure reliable delivery.

84
MCQmedium

A network administrator is configuring a switch to logically separate the Accounting and HR departments on the same physical switch. Which technology should be used?

A.Subnetting
B.DMZ
D.Honeypot
AnswerC

A VLAN applies 802.1Q tagging to logically segment switch ports into separate broadcast domains, so Accounting and HR traffic stays isolated despite sharing one physical switch. This directly satisfies the stem's constraint of logical separation on common hardware, without requiring additional switches or physical rewiring.

Why this answer

A VLAN (Virtual LAN, IEEE 802.1Q) logically segments a single physical switch into multiple isolated broadcast domains, allowing the Accounting and HR departments to share hardware while remaining logically separated at Layer 2. This is the standard technology for departmental segmentation on a common switch. Subnetting operates at Layer 3 and does not by itself isolate traffic on the same switch without VLANs or ACLs.

Exam trap

The trap is conflating Layer 3 subnetting with Layer 2 segmentation — CC candidates often pick 'subnetting' because it sounds like separation, but only VLANs isolate traffic on the same physical switch.

How to eliminate wrong answers

Option A is wrong because subnetting is a Layer 3 IP addressing technique; without VLANs or router ACLs, devices on different subnets on the same switch can still communicate at Layer 2. Option B is wrong because a DMZ is a perimeter network segment for externally facing services, not an internal departmental segmentation tool. Option D is wrong because a honeypot is a decoy system designed to attract and detect attackers, not to separate internal departments.

85
Multi-Selecthard

An organization is planning to deploy a DMZ to host web and email servers accessible from the internet. Which three security best practices should be implemented for the DMZ? (Choose three.)

Select 3 answers
A.Use a single firewall to connect internet, DMZ, and internal network
B.Allow all traffic from the DMZ to the internal network for ease of management
C.Use a separate VLAN for DMZ servers to isolate traffic
D.Place a firewall between the internet and the DMZ, and another between the DMZ and the internal network
E.Configure strict access control rules to allow only necessary services
AnswersC, D, E

A dedicated VLAN segments DMZ broadcast domains from internal LAN traffic, so compromise of a public-facing server cannot sniff or directly reach internal hosts at layer 2. This isolation satisfies the requirement to contain any breach originating from internet-accessible servers.

Why this answer

Option C is correct because placing DMZ servers on a dedicated VLAN segments their broadcast domain and Layer 2 traffic from the internal LAN, so a compromised web or email host cannot directly reach internal systems at Layer 2 and lateral movement is constrained. Option D is correct because a dual-firewall (screened subnet) design puts one firewall between the internet and the DMZ and a second between the DMZ and the internal network, enforcing defense in depth so that even if a DMZ host is compromised, the internal firewall still blocks access to internal resources. Option E is correct because strict access control rules implementing least privilege—permitting only the specific ports and protocols required (for example, TCP 80/443 to the web server and TCP 25/587 to the mail server)—minimize the attack surface and prevent unnecessary services from being reachable.

Option A is not correct because a single firewall with three interfaces, while workable, does not provide the layered separation and defense in depth that a dual-firewall DMZ design offers. Option B is not correct because allowing all traffic from the DMZ to the internal network violates least privilege and would let a compromised DMZ host pivot freely into the internal network.

Exam trap

The trap here is that candidates pick 'single firewall' because it sounds simpler and cheaper, but CompTIA and security exams consistently reward defense-in-depth with separate firewall boundaries between trust zones.

86
MCQmedium

An attacker intercepts communications between a client and server by establishing independent connections with each. The client believes it is talking to the server, but the attacker relays messages. What is this attack?

A.Phishing
B.Man-in-the-middle
C.Replay attack
D.DoS
AnswerB

The attacker terminates two separate TCP sessions — one with the client, one with the server — and relays traffic between them, so each endpoint authenticates against the attacker rather than the genuine peer. This active relay, not passive eavesdropping, defines the man-in-the-middle scenario described.

Why this answer

A man-in-the-middle (MITM) attack occurs when an adversary positions themselves between two communicating parties, establishing separate connections with each and relaying (or altering) traffic while both sides believe they are communicating directly. The scenario describes exactly this relay behavior. The attacker can eavesdrop, modify, or inject data because neither endpoint detects the intermediary.

Exam trap

The trap here is conflating MITM with sniffing or replay — candidates must recognize that MITM specifically requires the attacker to sit inline and relay traffic between two parties, not merely observe or retransmit it.

How to eliminate wrong answers

Option A is wrong because phishing is a social-engineering attack that tricks users into revealing credentials or clicking malicious links; it does not involve transparently relaying traffic between two hosts. Option C is wrong because a replay attack captures and retransmits previously valid data (such as an authentication token) to impersonate a legitimate party, rather than maintaining a live relay between client and server. Option D is wrong because a DoS attack aims to exhaust resources and deny availability, not to intercept and relay communications covertly.

87
MCQmedium

A company wants to isolate its public web server from internal networks to reduce risk. The server must be accessible from the internet. Which network architecture should be used?

A.Implement a DMZ
B.Place the server on the internal LAN with a strong firewall rule
C.Use a VLAN to logically separate the server
D.Connect the server directly to the internet without firewall
AnswerA

A DMZ is specifically designed to host public-facing services with controlled access.

Why this answer

A DMZ (demilitarized zone) is a segmented network that sits between the untrusted internet and the trusted internal LAN, hosting public-facing services like web servers. It allows inbound internet access to the server while firewalls restrict traffic from the DMZ into the internal network, minimizing risk if the server is compromised. This directly satisfies the requirement to isolate the public server from internal networks.

Exam trap

The trap is assuming a VLAN alone provides security isolation — candidates must recognize that a DMZ requires firewall-enforced segmentation between internet, DMZ, and internal networks, not just logical separation.

How to eliminate wrong answers

Option B is wrong because placing a public-facing server on the internal LAN exposes the internal network to lateral movement if the server is compromised, even with strong firewall rules — a single misconfiguration can breach the whole LAN. Option C is wrong because a VLAN provides logical Layer 2 segmentation but does not by itself create a security boundary between the internet and internal resources; without firewall enforcement between VLANs, it is insufficient isolation. Option D is wrong because connecting the server directly to the internet with no firewall removes all filtering and exposes the server and any reachable internal resources to unrestricted attacks.

88
MCQhard

An organization experiences intermittent network outages. The security team notices that the ARP cache on several switches has entries pointing to an unknown MAC address for the default gateway. Which attack is most likely occurring?

A.ARP spoofing
B.DNS poisoning
C.IP spoofing
D.MAC flooding
AnswerA

ARP spoofing floods the network with forged ARP replies that map the gateway's IP address to the attacker's MAC address, poisoning switch ARP caches so traffic destined for the default gateway is redirected to the attacker.

Why this answer

ARP spoofing (ARP poisoning) occurs when an attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway. Switches then populate their ARP caches with the attacker's MAC for the gateway IP, causing traffic to be redirected to the attacker. This matches the symptom of ARP cache entries pointing to an unknown MAC for the gateway.

Exam trap

The trap is confusing ARP spoofing with MAC flooding or IP spoofing — candidates see 'MAC address' and pick MAC flooding, but the key clue is the ARP cache being poisoned with a false gateway mapping.

How to eliminate wrong answers

Option B is wrong because DNS poisoning corrupts DNS resolver caches to redirect domain names, not ARP caches or MAC-to-IP mappings. Option C is wrong because IP spoofing forges source IP addresses in packets but does not alter ARP cache entries on switches. Option D is wrong because MAC flooding overwhelms the switch CAM table to force flooding, but it does not create ARP entries pointing to an unknown MAC for the gateway.

89
MCQmedium

A security analyst notices an unusually high number of incomplete TCP connection requests. Which type of attack is most likely occurring?

A.SYN flood
B.Smurf attack
C.ARP spoofing
D.DNS amplification
AnswerA

A SYN flood overwhelms a target by sending numerous TCP SYN packets without completing the three-way handshake, leaving connections half-open. This precisely matches the stem's observation of abnormally high incomplete TCP connection requests, exhausting the backlog queue and preventing legitimate connections from being established.

Why this answer

SYN flood attacks exploit the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting server resources.

90
MCQeasy

A small business wants to prevent employees from visiting known malicious websites. The owner asks a technician to implement a control that blocks requests to a maintained list of bad domains before any connection is made to those sites. Which solution should the technician deploy?

A.A host-based antivirus scanner that quarantines downloaded files
B.An intrusion prevention system placed inline at the network edge
C.A next-generation firewall configured with application signatures
D.A DNS filtering service that refuses to resolve known malicious domains
AnswerD

DNS filtering intercepts name resolution requests and returns a block or sinkhole response for domains on a threat feed. Because the malicious domain is never resolved to an IP address, the client cannot initiate a connection to the site, which directly meets the owner's requirement to block requests before any connection is made.

Why this answer

DNS filtering is the only listed control that stops a malicious website visit at the name-resolution stage. By refusing to resolve the domain, it prevents the client from learning the destination IP address, so no connection can be initiated. Endpoint antivirus, application-aware firewalls, and intrusion prevention systems all operate later in the connection lifecycle.

Exam trap

The trap here is equating any security control that can eventually detect malicious traffic with one that prevents the initial connection from being made.

91
MCQhard

An attacker sends a forged ARP response to a switch, associating the attacker's MAC address with the IP address of the default gateway. The switch updates its ARP cache accordingly. This is an example of which attack?

A.MAC flooding
B.DNS spoofing
C.IP spoofing
D.ARP spoofing
AnswerD

ARP spoofing sends forged ARP replies that map the attacker's MAC address to another host's IP, here the default gateway. The switch caches this false binding, redirecting traffic through the attacker. This satisfies the scenario's constraint of a forged ARP response poisoning the cache.

Why this answer

ARP spoofing (or ARP poisoning) involves sending fake ARP messages to associate the attacker's MAC with a legitimate IP, enabling man-in-the-middle attacks.

92
Multi-Selectmedium

A network engineer is designing a DMZ. Which three servers should typically be placed in the DMZ? (Choose THREE.)

Select 3 answers
A.Web server
B.DHCP server
C.Mail server
D.Database server
E.DNS server
AnswersA, C, E

A web server must accept HTTP and HTTPS requests from untrusted internet clients, so it belongs in the DMZ. Hosting it there prevents direct external access to the internal network, satisfying the design constraint of segregating publicly reachable services.

Why this answer

Public-facing servers like web, mail, and DNS servers are typically placed in a DMZ to isolate them from the internal network. DHCP servers are usually internal, and database servers are kept internal for security.

93
MCQmedium

A hospital's security team wants to give remote clinicians access to internal patient systems without exposing those systems directly to the internet. The team requires strong encryption, per-user authentication, and the ability to log every session. Which solution best fits these requirements?

A.A remote desktop gateway that publishes the internal applications over HTTPS
B.A site-to-site IPsec tunnel between the hospital and each clinician's home router
C.A remote access VPN terminating on a VPN concentrator with user authentication and session logging
D.Publishing the patient systems through a reverse proxy with TLS
AnswerC

A remote access VPN encrypts traffic from the clinician's device to the concentrator, authenticates each user, and can log session start, stop, and assigned addresses. It keeps internal patient systems off the public internet while granting authenticated users access, matching every requirement in the scenario.

Why this answer

A remote access VPN provides the encrypted tunnel, individual user authentication, and auditable session records that the hospital requires, while keeping internal systems unreachable from the public internet. It scales to a distributed clinical workforce far better than fixed site-to-site links and gives the security team the visibility it needs.

Exam trap

The trap here is treating any TLS-protected path to an internal application as equivalent to a per-user encrypted tunnel, when only the VPN delivers authenticated, loggable network access for roaming users.

94
MCQeasy

Which OSI layer is responsible for routing packets based on IP addresses?

A.Layer 3 – Network
B.Layer 1 – Physical
C.Layer 4 – Transport
D.Layer 2 – Data Link
AnswerA

Layer 3, the network layer, handles logical addressing and path selection, forwarding packets between networks according to IP addresses. This satisfies the stem's requirement by naming the layer whose protocol data unit is the packet and whose function is routing.

Why this answer

Layer 3, the Network layer, is responsible for logical addressing and routing packets based on IP addresses. It determines the best path across interconnected networks using routing protocols and forwarding tables.

Exam trap

The trap is confusing Layer 2 MAC-based switching with Layer 3 IP-based routing; the mention of IP addresses specifically points to Layer 3.

How to eliminate wrong answers

Option B is wrong because Layer 1 (Physical) deals with transmission of raw bits over media, not IP addressing. Option C is wrong because Layer 4 (Transport) handles end-to-end communication, segmentation, and reliability (TCP/UDP), not routing based on IP. Option D is wrong because Layer 2 (Data Link) uses MAC addresses for node-to-node delivery within a local network, not IP-based routing.

95
MCQmedium

A security analyst detects a large number of incomplete TCP connection requests (SYN segments) directed at a server. This is indicative of which type of attack?

A.ICMP flood
B.UDP flood
C.Smurf attack
D.SYN flood
AnswerD

A SYN flood exploits the TCP three-way handshake by sending numerous SYN segments without completing the final ACK, exhausting the server's half-open connection table. This matches the stem's observation of many incomplete TCP connection requests.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending numerous SYN packets with spoofed source addresses, leaving the server with half-open connections that exhaust its backlog queue. The server responds with SYN-ACK to unreachable hosts and waits for the final ACK that never arrives, consuming resources until legitimate connections are refused. This matches the scenario of many incomplete TCP connection requests.

Exam trap

The trap here is confusing volumetric floods (ICMP/UDP) with protocol-level exhaustion attacks; candidates may pick 'ICMP flood' simply because it is a flood, missing that the question specifies incomplete TCP connection requests (SYN segments).

How to eliminate wrong answers

Option A is wrong because an ICMP flood sends large volumes of ICMP Echo Request packets (e.g., ping flood) to overwhelm bandwidth, not incomplete TCP handshakes. Option B is wrong because a UDP flood targets connectionless UDP services with high packet volume, and UDP has no handshake or SYN segments. Option C is wrong because a Smurf attack uses ICMP Echo Requests with a spoofed source address sent to a network's broadcast address, amplifying traffic to the victim, not TCP SYN segments.

96
MCQmedium

Which protocol is considered insecure because it transmits data, including credentials, in cleartext?

A.SFTP
B.SSH
AnswerC

Telnet transmits all session data, including usernames and passwords, as unencrypted cleartext, so anyone capturing traffic on the network can read credentials directly. This satisfies the stem's constraint of a protocol insecure specifically because it sends credentials in cleartext, unlike SSH, which encrypts the entire session.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext over the network, making it trivial to intercept with packet sniffing. It lacks encryption and is considered insecure for any authentication or sensitive data. This is why Telnet has been replaced by SSH for remote administration.

Exam trap

The trap here is confusing similarly named protocols — candidates may pick SFTP or SSH assuming they are insecure because they sound like FTP, when in fact Telnet is the only cleartext option listed.

How to eliminate wrong answers

Option A is wrong because SFTP (SSH File Transfer Protocol) runs over SSH and encrypts data and credentials in transit. Option B is wrong because SSH provides strong encryption and is the secure replacement for Telnet. Option D is wrong because HTTPS uses TLS to encrypt HTTP traffic, protecting credentials and data in transit.

97
MCQmedium

A security analyst is investigating a suspected data exfiltration incident. The analyst observes that outbound DNS queries from an internal host contain long, random-looking subdomains and occur at a regular interval. The volume of these queries is unusually high. Which technique is most likely being used?

A.DNS tunneling for command and control or data exfiltration
B.A cache poisoning attack against the internal DNS resolver
C.A distributed denial-of-service attack using DNS amplification
D.A zone transfer attempt from an internal host
AnswerA

DNS tunneling encodes data in DNS queries and responses, often using long, encoded subdomains to carry payloads. The regular interval and high volume of random-looking subdomains are characteristic of malware using DNS to exfiltrate data or receive commands, since DNS is often allowed through firewalls. This matches the observed pattern.

Why this answer

The high volume of DNS queries with long, random subdomains sent at regular intervals is a classic indicator of DNS tunneling, where data is encoded in DNS queries to bypass network controls. This technique is commonly used for command and control and data exfiltration. Other DNS-based attacks like amplification or cache poisoning do not produce this pattern.

Exam trap

The trap here is assuming that because DNS is a legitimate protocol, any DNS traffic is benign, when the pattern of encoded subdomains and regular timing reveals malicious tunneling.

98
MCQmedium

A company's security policy requires that all outbound web traffic be inspected for malware and that users be prevented from accessing known malicious domains. The security team wants a single appliance that can decrypt TLS sessions, apply content filters, and block threats inline. Which solution best meets these requirements?

A.A stateful packet-filtering firewall
B.A next-generation firewall with TLS inspection and threat prevention
C.A web application firewall (WAF) protecting internal servers
D.A standalone intrusion detection system (IDS)
AnswerB

A next-generation firewall combines stateful filtering with application awareness, TLS decryption, intrusion prevention, and reputation-based URL filtering. It can decrypt outbound TLS, inspect the plaintext for malware, and block known malicious domains inline. This matches the requirement for a single appliance that performs content inspection and threat blocking rather than just port-based filtering.

Why this answer

The policy requires inline inspection of encrypted outbound traffic, content filtering, and malware blocking in one appliance. A next-generation firewall with TLS inspection and threat prevention provides all of these capabilities. Stateful firewalls lack content inspection, IDS is passive, and WAFs focus on inbound application attacks rather than outbound browsing.

Exam trap

The trap here is assuming a traditional firewall or IDS can inspect encrypted traffic, when TLS decryption and inline content filtering require additional capabilities found in a next-generation firewall.

99
Multi-Selecthard

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

Select 3 answers
A.Using HTTP instead of HTTPS
B.Educating users to verify certificates
C.Disabling ARP
D.Implementing HTTPS with proper certificate validation
E.Using a VPN to encrypt all traffic
AnswersB, D, E

User education to verify certificates counters MitM interception by prompting rejection of forged or unexpected certificates before credentials are submitted. This satisfies the scenario's need for a defence against credential interception, complementing technical controls. However, it relies on human vigilance, so pairing with certificate pinning or Microsoft Entra ID token protections strengthens the overall posture.

Why this answer

Option B is correct because user education to verify certificates helps detect MITM attacks where an attacker presents a forged or self-signed certificate, prompting users to check the certificate's issuer, validity, and hostname match before trusting a connection. Option D is correct because HTTPS with proper certificate validation uses TLS to authenticate the server and encrypt traffic, and validating the certificate chain against trusted CAs prevents an attacker from impersonating the server with a fraudulent certificate. Option E is correct because a VPN encrypts all traffic between the client and the VPN gateway using protocols such as IPsec or TLS, which prevents an on-path attacker from reading or modifying the traffic and can authenticate the tunnel endpoints.

Option A is not correct because HTTP is unencrypted and provides no authentication, making MITM attacks easier, not harder. Option C is not correct because disabling ARP is not a practical or effective defense; ARP is required for normal IPv4 LAN communication, and the proper mitigation for ARP spoofing is dynamic ARP inspection or static ARP entries, not disabling ARP entirely.

Exam trap

The trap here is that candidates might think disabling ARP (Option C) is a valid defense against ARP-based MITM attacks, but it's not a practical solution; also, they might overlook user education as a defense, focusing only on technical controls.

100
MCQmedium

An IT administrator wants to inspect HTTP traffic for malicious payloads such as SQL injection. Which network security device is most appropriate?

A.IDS
B.WAF
C.Honeypot
D.IPS
AnswerB

A web application firewall inspects HTTP/HTTPS request payloads at layer 7, matching signatures for SQL injection, cross-site scripting and similar attacks. It satisfies the stem's requirement to inspect HTTP traffic for malicious payloads, which a network firewall cannot decode.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block malicious payloads such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 attacks. It operates at the application layer (Layer 7) and can enforce custom rules based on HTTP request contents. An IDS or IPS may detect or block some attacks but is not purpose-built for web application protection.

Exam trap

The trap is choosing IDS or IPS because they sound like security devices that inspect traffic; candidates must remember that a WAF is the specialized tool for HTTP application-layer attacks like SQL injection.

How to eliminate wrong answers

Option A is wrong because an IDS (Intrusion Detection System) monitors network traffic for suspicious activity and alerts, but it does not actively inspect and block HTTP payloads like SQL injection; it is passive. Option C is wrong because a honeypot is a decoy system designed to attract attackers and study their behavior, not to protect production web traffic. Option D is wrong because an IPS (Intrusion Prevention System) can block attacks but is typically signature-based at the network layer and less effective at parsing HTTP for application-specific attacks like SQL injection compared to a WAF.

101
MCQeasy

A security analyst notices unusual traffic on the network. Using Wireshark, they capture packets and see that an attacker is reading all unencrypted data from the network segment. Which type of attack is most likely being performed?

A.Spoofing
B.DoS
C.Sniffing / Eavesdropping
D.Man-in-the-middle
AnswerC

Sniffing passively captures frames traversing a shared segment, letting the attacker read unencrypted payloads without altering traffic. This matches the stem's evidence: Wireshark shows data being read, not modified or blocked. Eavesdropping requires no injection or spoofing, only promiscuous-mode capture on the segment.

Why this answer

Sniffing or eavesdropping involves capturing network traffic to read data. In this scenario, unencrypted data is being read, which is characteristic of sniffing.

102
MCQeasy

Which of the following ports is used by HTTPS?

A.80
B.21
C.25
D.443
AnswerD

HTTPS uses TCP port 443 by default, carrying HTTP traffic encrypted with TLS. Port 80 serves plain HTTP, while 22 and 3389 handle SSH and RDP respectively. Browsers and servers therefore negotiate secure web sessions on 443 unless an administrator configures a non-standard port.

Why this answer

HTTPS (Hypertext Transfer Protocol Secure) operates over TCP port 443 by default, using TLS to encrypt HTTP traffic between client and server. This is the IANA-assigned well-known port for HTTPS, so any browser request to https:// implicitly targets port 443 unless overridden. Port 80 is the counterpart for unencrypted HTTP, which is why the two are so often confused.

Exam trap

The trap here is confusing port 80 (HTTP) with port 443 (HTTPS); candidates who memorize only 'web = 80' pick A without noticing the 'S' in HTTPS.

How to eliminate wrong answers

Option A is wrong because port 80 is the default for plain HTTP, which transmits data in cleartext and is not the secure variant. Option B is wrong because port 21 is assigned to FTP control commands, not web traffic. Option C is wrong because port 25 is used for SMTP mail relay, unrelated to HTTPS.

103
Multi-Selecthard

An organization wants to implement network segmentation to improve security. Which three methods are commonly used for network segmentation? (Select THREE.)

Select 3 answers
A.Subnetting
B.DMZs
C.Firewalls
D.VLANs
E.Intrusion Detection Systems
AnswersA, B, D

Subnetting divides an IP network into smaller logical ranges at Layer 3, using the subnet mask to separate address blocks. Each subnet forms its own broadcast domain, and inter-subnet traffic must route through a gateway, enabling policy enforcement and limiting breach propagation.

Why this answer

Subnetting (A) is correct because dividing a larger IP network into smaller logical subnets using CIDR and subnet masks creates distinct broadcast domains and limits lateral movement between segments. DMZs (B) are correct because a demilitarized zone places internet-facing services such as web, mail, or DNS servers in a separate screened segment, isolating them from the internal trusted network. VLANs (D) are correct because IEEE 802.1Q VLANs logically segment a switched network at Layer 2, allowing departments or device groups to be separated without physical rewiring and enforcing traffic isolation via trunk and access port configuration.

Firewalls (C) are not a segmentation method themselves; they are policy enforcement devices that control traffic between segments, so they are typically deployed to secure segmentation rather than create it. Intrusion Detection Systems (E) are monitoring tools that detect malicious activity and generate alerts, but they do not divide or isolate network segments.

Exam trap

The trap here is confusing security controls (firewalls, IDS) with segmentation techniques — candidates often select firewalls because they 'segment' traffic, but the question asks for methods that create the segments themselves.

104
MCQeasy

Which of the following ports is commonly used for secure web traffic (HTTPS)?

A.53
B.80
C.22
D.443
AnswerD

Port 443 is the IANA-assigned default for HTTPS, carrying HTTP over TLS to encrypt web traffic. Port 80 handles unencrypted HTTP, while 22 and 3389 serve SSH and RDP respectively, so 443 satisfies the secure web traffic requirement.

Why this answer

HTTPS uses TCP port 443 by default, wrapping HTTP inside a TLS tunnel so credentials, cookies, and page content are encrypted in transit. Port 443 is the IANA-registered well-known port for HTTPS and is what browsers assume when no port is specified in an https:// URL. This is why secure web traffic is universally associated with 443.

Exam trap

The trap here is that both 80 and 443 are 'web' ports; candidates who skim the question and see 'web traffic' pick 80, missing the word 'secure' that points to 443.

How to eliminate wrong answers

Option A is wrong because port 53 is used by DNS for name resolution over UDP and TCP, not for web traffic. Option B is wrong because port 80 carries unencrypted HTTP, which is the insecure counterpart to HTTPS. Option C is wrong because port 22 is assigned to SSH for secure remote shell access, not for serving web content.

105
MCQeasy

An organization wants to segment its network so that public-facing servers are isolated from internal users. Which network design component should be used?

A.Honeypot
B.Subnet
C.DMZ
AnswerC

A DMZ is a screened subnet placed between the internal network and the internet, hosting public-facing servers while enforcing firewall rules that block inbound traffic from reaching internal users. This directly satisfies the requirement to isolate public-facing servers from the internal network.

Why this answer

A DMZ (demilitarized zone) is a perimeter subnetwork that hosts public-facing services such as web, mail, and DNS servers while keeping them separated from the internal trusted network. Traffic from the internet reaches the DMZ, but the DMZ is firewalled off from the internal LAN, so a compromised public server cannot pivot directly into internal systems. This is the standard architecture for isolating externally accessible servers.

Exam trap

The trap is confusing DMZ with VLAN; candidates think any network segmentation equals a DMZ, but a VLAN alone does not create the internet-facing, firewalled isolation a DMZ provides.

How to eliminate wrong answers

Option A is wrong because a honeypot is a decoy system designed to attract and study attackers, not to host production public services. Option B is wrong because a subnet is a generic Layer 3 address range; by itself it does not enforce the security separation between public and internal zones that a DMZ provides. Option D is wrong because a VLAN is a Layer 2 broadcast-domain segmentation tool used mainly for internal traffic separation, not for hosting internet-facing servers behind a perimeter firewall.

106
MCQmedium

An organization wants to allow external users to securely access internal web applications. Which network security device is specifically designed to inspect HTTP/HTTPS traffic and block malicious requests?

A.Stateful firewall
B.Web Application Firewall (WAF)
C.Intrusion Detection System (IDS)
D.Packet filtering firewall
AnswerB

A Web Application Firewall operates at Layer 7, inspecting HTTP/HTTPS request content against rule sets to block SQL injection, cross-site scripting and similar exploits. This directly satisfies the stem's requirement to inspect web traffic and block malicious requests, unlike packet-filtering firewalls that cannot parse application payloads.

Why this answer

A Web Application Firewall (WAF) inspects HTTP/HTTPS traffic at Layer 7 and applies rules to block attacks like SQL injection, cross-site scripting (XSS), and malicious bots. It understands web protocols and can examine request bodies, headers, and cookies, which is exactly what is needed to protect internal web applications exposed to external users. This makes WAF the purpose-built device for the scenario.

Exam trap

The trap is confusing a stateful firewall with a WAF; candidates assume 'firewall' means it inspects everything, but only a WAF understands HTTP/HTTPS application-layer content.

How to eliminate wrong answers

Option A is wrong because a stateful firewall tracks connection state at Layers 3-4 but does not parse HTTP payloads, so it cannot detect application-layer attacks like XSS or SQLi. Option C is wrong because an IDS detects and alerts on suspicious traffic but does not sit inline to block malicious HTTP requests by default. Option D is wrong because a packet-filtering firewall only examines IP addresses, ports, and protocol types with no awareness of HTTP content.

107
MCQhard

During a security assessment, a penetration tester captures network traffic and notices that the source IP address in packets appears to be from a different network. Which technique is the attacker likely using?

A.DNS spoofing
B.ARP spoofing
C.MAC spoofing
D.IP spoofing
AnswerD

IP spoofing forges the source address field in packet headers so traffic appears to originate from a different network, matching the observed foreign source addresses. It is distinct from MAC spoofing, which alters Layer 2 addresses.

Why this answer

IP spoofing involves forging the source IP address field in packet headers so the traffic appears to originate from a different network or host. The scenario explicitly describes source IP addresses appearing to come from a different network, which is the defining symptom of IP spoofing. Attackers use it for reflection/amplification DDoS, evasion, and impersonation.

Exam trap

The trap here is confusing Layer 2 address manipulation (ARP/MAC spoofing) with Layer 3 source-address forgery (IP spoofing) — the question's phrase 'source IP address' is the decisive clue.

How to eliminate wrong answers

Option A is wrong because DNS spoofing corrupts DNS responses to redirect name resolution, not the source IP in packet headers. Option B is wrong because ARP spoofing poisons the ARP cache to associate an attacker's MAC with a legitimate IP on the local subnet, affecting Layer 2 resolution rather than the IP header's source field. Option C is wrong because MAC spoofing alters the Layer 2 source MAC address, not the Layer 3 source IP address observed in captured packets.

108
MCQmedium

An attacker sends a flood of SYN packets to a server, never completing the three-way handshake, exhausting the server's resources and causing it to become unresponsive. What type of attack is this?

A.ICMP flood
B.SYN flood
C.UDP flood
D.ARP spoofing
AnswerB

A SYN flood exploits the TCP three-way handshake: the attacker sends many SYN packets with spoofed source addresses, so the server allocates half-open connection resources awaiting final ACKs that never arrive, exhausting its backlog and rendering it unresponsive.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that are never completed. This exhausts the server's connection table and backlog, making it unresponsive to legitimate traffic. It is a classic denial-of-service attack.

Exam trap

The trap here is confusing SYN flood with other flood attacks — candidates may pick UDP or ICMP flood because they see 'flood,' but only SYN flood specifically abuses the TCP three-way handshake and half-open connections.

How to eliminate wrong answers

Option A is wrong because an ICMP flood sends large volumes of ICMP echo requests (pings) to overwhelm bandwidth, not to exhaust TCP connection state. Option C is wrong because a UDP flood sends UDP packets to random ports, consuming bandwidth and forcing ICMP port-unreachable responses, but it does not involve the TCP handshake. Option D is wrong because ARP spoofing is a man-in-the-middle technique that maps an attacker's MAC to a legitimate IP, not a resource-exhaustion flood.

109
MCQeasy

Which TCP segment is sent to initiate the three-way handshake?

A.ACK
B.SYN-ACK
C.FIN
D.SYN
AnswerD

SYN initiates the three-way handshake by carrying the synchronise flag with an initial sequence number, prompting the server to reply with SYN-ACK before the client's ACK completes connection setup. This directly satisfies the stem's requirement for the segment that starts the handshake, distinguishing it from data or teardown segments.

Why this answer

The TCP three-way handshake begins with the client sending a SYN segment to the server to request a connection and synchronize sequence numbers. The server responds with SYN-ACK, and the client completes with ACK. Therefore, the segment that initiates the handshake is SYN.

Exam trap

The trap is confusing the order of the handshake: candidates may pick SYN-ACK because it contains 'SYN', but the question asks for the segment that initiates the handshake, which is the pure SYN from the client.

How to eliminate wrong answers

Option A is wrong because ACK is the final segment in the handshake (and is used throughout the session for acknowledgment), not the initiator. Option B is wrong because SYN-ACK is the server's response to the initial SYN, not the first segment. Option C is wrong because FIN is used to gracefully terminate an established TCP connection, not to start one.

110
MCQeasy

Which protocol operates at the Transport layer of the OSI model and is connectionless and unreliable?

A.TCP
C.IP
D.UDP
AnswerD

UDP operates at the Transport layer and is connectionless, sending datagrams without handshaking, acknowledgement, or retransmission, so delivery is unreliable. TCP, the alternative Transport protocol, establishes connections and guarantees ordered, reliable delivery, which contradicts both stated constraints.

Why this answer

UDP (User Datagram Protocol) is a Transport layer (Layer 4) protocol that is connectionless and unreliable. It does not establish a connection before sending data, and it does not guarantee delivery, ordering, or error recovery. This makes it suitable for applications that prioritize speed over reliability, such as streaming or DNS.

Exam trap

The trap here is confusing the OSI layers: candidates might think IP is Transport layer because it's connectionless, or assume TCP is unreliable because it's often compared to UDP. Remember: UDP is the connectionless, unreliable Transport layer protocol.

How to eliminate wrong answers

Option A is wrong because TCP is connection-oriented and reliable, using handshakes and acknowledgments to ensure data delivery. Option B is wrong because HTTP is an Application layer protocol, not a Transport layer protocol, and it typically relies on TCP for reliable transport. Option C is wrong because IP operates at the Network layer (Layer 3) and is connectionless but not a Transport layer protocol; it handles addressing and routing, not end-to-end transport.

111
MCQmedium

A security analyst detects a large number of half-open TCP connections targeting a web server. This is most likely indicative of what type of attack?

A.Smurf attack
B.SYN flood
C.ARP spoofing
D.DNS amplification
AnswerB

Half-open connections arise when a host receives SYN packets but never completes the three-way handshake, exhausting the backlog queue. A SYN flood deliberately sends spoofed SYNs at volume, matching the observed pattern and denying legitimate clients access to the web server.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending numerous SYN packets with spoofed source addresses, causing the server to allocate resources for half-open connections that never complete. The server's connection table fills up, exhausting resources and preventing legitimate connections. This matches the symptom of many half-open TCP connections observed by the analyst.

Exam trap

The trap here is confusing volumetric network attacks (Smurf, DNS amplification) with TCP state exhaustion attacks; candidates may pick Smurf because it also causes many connections, but Smurf uses ICMP, not TCP.

How to eliminate wrong answers

Option A is wrong because a Smurf attack is an ICMP-based amplification attack using broadcast addresses to flood a victim with echo replies, not TCP half-open connections. Option C is wrong because ARP spoofing is a layer 2 attack that poisons ARP caches to intercept traffic, not a flood of TCP connections. Option D is wrong because DNS amplification uses open DNS resolvers and spoofed queries to amplify traffic via large DNS responses, unrelated to TCP handshake states.

112
MCQeasy

A small accounting firm wants to let guests connect to the internet in its lobby without exposing the internal file server or the payroll system. The network administrator is told to add a separate wireless network that uses different IP addressing and cannot route to internal resources. Which security principle is the administrator primarily applying?

A.Data remanence
B.Network segmentation
C.Non-repudiation
D.Least privilege
AnswerB

Segmenting the guest wireless onto separate IP addressing and blocking routes to internal systems isolates untrusted traffic from sensitive resources. This is a core network security control that limits the blast radius if a guest device is compromised. It directly implements the requirement that guests reach only the internet, not the file server or payroll system.

Why this answer

Separating guest wireless onto distinct IP addressing and preventing routes to internal systems is a segmentation control. Segmentation confines untrusted devices to a limited network zone, so a compromised guest endpoint cannot directly reach the payroll system or file server. The other concepts address data remnants, proof of actions, or user permissions, none of which create the required network boundary.

Exam trap

The trap here is confusing an access-control principle like least privilege with the network design control that actually isolates guest traffic from internal subnets.

113
Multi-Selectmedium

A security team is investigating a potential man-in-the-middle attack. Which TWO of the following are common techniques used in MITM attacks? (Select TWO.)

Select 2 answers
A.ARP poisoning
B.SYN flood
C.DNS amplification
D.Setting up a rogue Wi-Fi access point
E.ICMP flood
AnswersA, D

ARP poisoning sends forged ARP replies that bind the attacker's MAC address to a legitimate IP, so traffic between victim and gateway flows through the attacker. This enables interception and modification on the local subnet, a classic MITM technique.

Why this answer

ARP poisoning (A) is a classic MITM technique: the attacker sends forged ARP replies to associate their MAC address with the IP of the default gateway (or another host), causing victim traffic to flow through the attacker, who can then intercept or modify it. Setting up a rogue Wi-Fi access point (D) is also a common MITM method, often called an evil twin attack, where victims connect to the attacker-controlled AP and all their traffic is relayed or captured by the attacker. The other options are denial-of-service or amplification attacks rather than interception techniques: a SYN flood (B) exhausts TCP connection state to deny service, DNS amplification (C) abuses open DNS resolvers to flood a target with large responses, and an ICMP flood (E) overwhelms a target with ping traffic — none of these position the attacker to intercept and relay traffic between two parties.

Exam trap

The trap here is confusing DoS attacks (SYN flood, DNS amplification, ICMP flood) with MITM attacks; candidates may select any flooding technique thinking it involves interception, but only ARP poisoning and rogue APs directly enable man-in-the-middle positioning.

114
MCQhard

An attacker sends forged ARP messages to associate their MAC address with the IP address of a legitimate server. This allows the attacker to intercept traffic intended for that server. What is this attack?

A.DNS poisoning
B.MAC flooding
C.ARP spoofing
D.IP spoofing
AnswerC

ARP spoofing works by sending forged ARP replies that bind the attacker's MAC address to a legitimate server's IP, poisoning victims' ARP caches so traffic is redirected through the attacker for interception. This directly satisfies the stem's constraint of impersonating the server's IP-to-MAC mapping.

Why this answer

ARP spoofing (or ARP poisoning) involves sending fake ARP replies to associate the attacker's MAC with a victim's IP, enabling man-in-the-middle attacks.

115
Multi-Selectmedium

A network administrator is planning to segment the network. Which of the following are valid segmentation methods? (Choose TWO)

Select 2 answers
A.Subnetting
B.Firewalls
C.VLANs
D.IDS
E.Honeypots
AnswersA, C

Subnetting divides a larger IP network into smaller logical subnets using the subnet mask, separating traffic at Layer 3. Each subnet forms its own broadcast domain, giving the administrator a valid method to segment the network.

Why this answer

Subnetting (A) is a valid segmentation method because it divides a single IP address space into smaller logical networks using subnet masks, creating separate broadcast domains and controlling traffic flow between subnets via routing. VLANs (C) are also valid segmentation methods because they logically partition a physical switch into multiple isolated Layer 2 broadcast domains, typically defined by 802.1Q tagging, allowing separation of devices regardless of physical location. Firewalls (B) enforce security policy between zones but are access-control devices rather than a segmentation technique themselves.

IDS (D) monitors and alerts on malicious traffic but does not segment the network, and honeypots (E) are decoy systems used for detection and research, not segmentation.

Exam trap

The trap here is confusing security tools (firewalls, IDS, honeypots) with actual segmentation mechanisms; candidates often pick firewalls because they are associated with network separation, but firewalls enforce policy between segments rather than create them.

116
Multi-Selectmedium

A retail chain is redesigning its network security and wants to reduce the attack surface on its point-of-sale (POS) systems. The company asks a security architect to identify two controls that directly limit what a compromised POS system can reach on the corporate network. (Choose two.)

Select 2 answers
A.Require a complex password on the local administrator account of each POS system.
B.Deploy a host-based firewall on each POS system with rules that allow only the payment application and management agent.
C.Enable full-disk encryption on the POS system drives to protect data at rest.
D.Install an antivirus agent on each POS system and schedule a full scan every night.
E.Place POS systems on a dedicated VLAN with an ACL that allows only traffic to the payment processor and a management server.
AnswersB, E

A host-based firewall on the POS system enforces least privilege at the endpoint by permitting only required outbound and inbound flows for the payment application and management agent. Even if the terminal is compromised, other network paths are blocked. This directly limits what the system can reach, complementing network segmentation.

Why this answer

A dedicated POS VLAN with a restrictive ACL and a host-based firewall on each terminal both enforce least privilege on network reachability. The VLAN and ACL stop lateral movement at the network layer, while the host firewall restricts the endpoint's own traffic to only necessary services. Antivirus, password complexity, and full-disk encryption improve other areas but do not limit what a compromised POS system can reach.

Exam trap

The trap here is equating endpoint hardening or data-at-rest protection with network reach limitation, when only segmentation and host-based filtering actually restrict where a compromised system can connect.

117
MCQhard

A financial services company wants to allow employees to use personal laptops on the corporate wireless network without installing company-managed certificates on those devices. The company still needs to authenticate each user and apply role-based access to internal applications. Which approach best meets these requirements?

A.WPA2-Personal with a strong pre-shared key and MAC address filtering for known laptops.
B.An open wireless network with a captive portal that asks users to type their employee ID.
C.WPA2-Enterprise with PEAP-MSCHAPv2 using corporate directory credentials, plus a NAC or RADIUS authorization policy for role mapping.
D.WPA2-Enterprise with EAP-TLS using a client certificate issued by the corporate PKI.
AnswerC

PEAP-MSCHAPv2 lets users authenticate with directory credentials without a client certificate on the personal laptop, satisfying the no-certificate constraint. The RADIUS or NAC layer can then apply authorization policies that map each user or group to a role, which controls access to internal applications. This combination meets both user authentication and role-based access.

Why this answer

PEAP-MSCHAPv2 authenticates users against the corporate directory using usernames and passwords, so no client certificate is needed on personal laptops. A RADIUS or NAC authorization policy then maps the authenticated identity to a role that governs access to internal applications. EAP-TLS requires certificates, WPA2-Personal has no per-user identity, and a captive portal lacks strong authentication and authorization.

Exam trap

The trap here is treating the choice between EAP-TLS and PEAP-MSCHAPv2 as only a security-strength decision while overlooking the constraint that personal devices cannot receive corporate certificates.

118
Multi-Selectmedium

Which two of the following are best practices to mitigate man-in-the-middle attacks? (Select TWO.)

Select 2 answers
A.Disable SSL/TLS on web servers
B.Use HTTPS with proper certificate validation
C.Use ARP spoofing detection tools
D.Implement a VPN for remote connections
E.Use Telnet for remote administration
AnswersB, D

HTTPS with proper certificate validation encrypts traffic and authenticates the server via a trusted certificate chain, preventing an attacker from silently intercepting or altering communications. This directly satisfies the stem's man-in-the-middle mitigation requirement by ensuring clients reject forged or untrusted certificates rather than trusting an impostor endpoint.

Why this answer

Option B is correct because HTTPS with proper certificate validation encrypts traffic with TLS and verifies the server's identity against a trusted CA chain, preventing an attacker from silently intercepting or impersonating the endpoint in a man-in-the-middle attack. Option D is correct because a VPN (e.g., IPsec or TLS-based) establishes an authenticated, encrypted tunnel between the remote client and the corporate network, so an attacker on the local network or internet path cannot read or alter the traffic. Option A is wrong because disabling SSL/TLS removes encryption and authentication, making MITM attacks easier, not harder.

Option C, while useful for detecting ARP poisoning on a LAN, is a detection/monitoring measure rather than a primary mitigation best practice for MITM, and it does not protect traffic on its own. Option E is wrong because Telnet transmits credentials and data in cleartext, which is exactly what enables MITM interception; SSH should be used instead.

Exam trap

The trap is selecting ARP spoofing detection as a general MITM mitigation; it only addresses LAN-based ARP spoofing, not the broader category of MITM attacks that HTTPS and VPNs address.

119
MCQhard

A network engineer wants to mitigate ARP spoofing attacks. Which of the following is the most effective technique?

B.Enable STP
C.Use static ARP entries
D.Disable ICMP
AnswerA

Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table, dropping packets with spoofed IP-to-MAC mappings. This directly neutralises ARP spoofing on the switched segment, unlike encryption or static entries, satisfying the stem's mitigation requirement.

Why this answer

Dynamic ARP Inspection (DAI) is a security feature on switches that validates ARP packets in a network. It intercepts ARP requests and replies on untrusted ports, compares them against a trusted binding table (often built via DHCP snooping), and drops invalid or malicious ARP packets. This directly prevents ARP spoofing by ensuring only legitimate ARP mappings are allowed.

Exam trap

The trap is confusing ARP spoofing mitigation with general Layer 2 security features like STP or with host-based static entries; candidates must recognize that DAI is the specific switch-based defense against ARP spoofing.

How to eliminate wrong answers

Option B is wrong because Spanning Tree Protocol (STP) prevents Layer 2 loops, not ARP spoofing. Option C is wrong because static ARP entries can prevent spoofing for specific hosts but are not scalable or practical in most networks, and they do not dynamically protect all hosts. Option D is wrong because disabling ICMP (e.g., ping) does not affect ARP spoofing, which operates at Layer 2 using ARP, not ICMP.

120
Multi-Selectmedium

Which THREE of the following are common mitigation techniques against Denial of Service (DoS) attacks?

Select 3 answers
A.Implementing rate limiting on servers
B.Disabling all firewall rules
C.Allowing all inbound traffic to avoid blocking legitimate users
D.Filtering traffic based on IP reputation
E.Using a Content Delivery Network (CDN) to absorb traffic
AnswersA, D, E

Rate limiting caps the number of requests a server accepts per client within a time window, throttling floods before they exhaust connection or processing capacity. This directly satisfies the DoS mitigation requirement by preserving availability for legitimate users during volumetric or application-layer attacks.

Why this answer

DoS mitigation includes using DDoS protection services, rate limiting, and filtering traffic based on IP reputation.

121
MCQmedium

A hospital's radiology department transmits large medical images to a remote clinic over a public network. The security team must ensure that the images cannot be read or modified in transit, and that the remote clinic can verify the images came from the hospital. Which combination of controls should the team use?

A.SFTP with a shared username and password for the radiology and clinic staff.
B.IPsec in tunnel mode with confidentiality and data origin authentication enabled.
C.A site-to-site VPN using GRE without encryption or authentication.
D.TLS 1.3 with a server certificate issued to the remote clinic.
AnswerB

IPsec tunnel mode encapsulates the entire original IP packet and can apply ESP encryption for confidentiality plus an authentication mechanism that provides data origin authentication and integrity. This protects the images from being read or altered in transit and lets the remote clinic verify the hospital as the source. It matches both requirements in a single, standard site-to-site design.

Why this answer

IPsec in tunnel mode with ESP confidentiality and authentication provides encryption for the images and cryptographically verifies the hospital as the origin. The remote clinic can validate the sender and detect any modification in transit. TLS with a certificate issued to the wrong party, shared SFTP credentials, and unencrypted GRE do not meet both requirements.

Exam trap

The trap here is confusing encryption with data origin authentication and assuming that any encrypted tunnel proves who sent the data.

122
MCQmedium

A company uses a SIEM to monitor network security events. The security analyst notices a high volume of alerts about suspicious outbound traffic to a known command-and-control server. The traffic is encrypted and uses non-standard ports. Which security control would best detect this activity if the SIEM relies only on network flow data?

A.Web application firewall (WAF) in reverse proxy mode
B.Host-based antivirus with heuristic scanning
C.Signature-based intrusion detection system (IDS)
D.Network flow analysis with anomaly detection
AnswerD

Network flow analysis examines metadata such as IP addresses, ports, byte counts, and timing without needing payload decryption. Anomaly detection can flag deviations like regular beaconing to a known C2 IP on non-standard ports. This approach works with the SIEM's flow data and can detect encrypted C2 traffic based on behavioral patterns.

Why this answer

Since the SIEM only has network flow data and the traffic is encrypted, payload inspection is impossible. Network flow analysis with anomaly detection uses metadata like IP, port, and timing to identify beaconing patterns to known C2 servers. Signature IDS, host antivirus, and WAFs either need payload visibility or do not monitor outbound flows.

Exam trap

The trap here is assuming that encrypted traffic cannot be detected, when flow-based anomaly detection can identify malicious behavior from metadata alone.

123
MCQhard

An organization decides to implement an Intrusion Prevention System (IPS) to protect its network. Which statement about an IPS compared to an IDS is correct?

A.An IPS is placed inline and can automatically block malicious traffic.
B.An IPS is placed out of band and monitors traffic.
C.An IPS generates alerts but does not block traffic.
D.An IPS operates only at the application layer.
AnswerA

An IPS sits inline in the traffic path, so it can drop or reset malicious packets in real time rather than merely alerting. This satisfies the scenario's requirement to actively protect the network, whereas an IDS only monitors a copy of traffic and cannot block.

Why this answer

An IPS is deployed inline in the traffic path, so it can inspect packets in real time and actively drop or reset malicious sessions, whereas an IDS is passive and only alerts. This inline placement is what enables automatic blocking. The other options describe IDS behavior or overstate the IPS's scope.

Exam trap

The trap here is the common misconception that an IPS only alerts like an IDS, when the key differentiator is inline placement and active blocking.

How to eliminate wrong answers

Option B is wrong because out-of-band monitoring is the defining characteristic of an IDS, not an IPS — an out-of-band device cannot block traffic in real time. Option C is wrong because generating alerts without blocking is exactly what an IDS does; an IPS both detects and prevents. Option D is wrong because an IPS can operate at multiple layers (network, transport, application) depending on whether it is a network-based or host-based IPS, so limiting it to the application layer is incorrect.

124
MCQeasy

A security analyst notices unusual traffic from an internal workstation to an external IP address on port 25. Which protocol is most likely being used?

AnswerA

Port 25 is the standard TCP port for SMTP, used for sending and relaying email. Outbound traffic from an internal workstation to an external address on this port suggests the host is acting as a mail client or, more likely in this scenario, a compromised machine sending spam.

Why this answer

SMTP (Simple Mail Transfer Protocol) operates over TCP port 25 by default for relaying and receiving email. Unusual outbound traffic on port 25 from an internal workstation often indicates a compromised host sending spam or a malware infection attempting to exfiltrate data via email. The other protocols listed use different default ports: FTP uses 20/21, DNS uses 53, and HTTP uses 80.

Exam trap

CC often tests port number memorization; candidates may confuse port 25 with other common ports like 21 (FTP), 53 (DNS), or 80 (HTTP).

How to eliminate wrong answers

Option B is wrong because FTP uses ports 20 and 21 for data and control, not port 25. Option C is wrong because DNS primarily uses port 53 for queries and zone transfers. Option D is wrong because HTTP uses port 80 for unencrypted web traffic, not port 25.

125
MCQeasy

A small accounting firm has a flat network where all employee workstations and a guest Wi-Fi access point connect to the same switch. The owner asks a security consultant to keep guests from reaching the payroll server, which resides on the same subnet as employee devices. Which control should the consultant implement to meet this requirement with the least disruption?

A.Deploy an IPS between the guest access point and the switch to block attacks aimed at the payroll server.
B.Enable a host-based firewall on the payroll server that permits only the payroll application's TCP port.
C.Create a separate VLAN for guests and apply an access control list that denies guest subnet traffic to the payroll server.
D.Change the guest Wi-Fi pre-shared key every 30 days and publish it only to visitors.
AnswerC

Placing guests on a dedicated VLAN segments the guest broadcast domain from employee systems, and an ACL on the router or Layer 3 switch can explicitly deny guest-to-payroll traffic. This directly satisfies the requirement to keep guests from reaching the payroll server while preserving the existing flat employee network, resulting in minimal disruption to employee workflows.

Why this answer

Segmenting guest traffic into its own VLAN removes it from the employee broadcast domain, and an ACL on the Layer 3 device enforces the rule that guests cannot reach the payroll server. This addresses the requirement directly without redesigning the employee network. Host firewalls, key rotation, and intrusion prevention do not provide the same deterministic isolation.

Exam trap

The trap here is assuming that a security appliance such as an IPS or a host firewall provides the same deterministic traffic separation as network segmentation with an ACL.

126
MCQmedium

Which of the following is a security concern associated with the Telnet protocol?

A.It transmits data in cleartext.
B.It requires certificate management.
C.It is vulnerable to DNS poisoning.
D.It uses encryption that is too weak.
AnswerA

Telnet sends all session data, including credentials and commands, as unencrypted cleartext across the network. Anyone capturing traffic on the path can read or alter it, which is the fundamental security weakness distinguishing Telnet from SSH.

Why this answer

Telnet transmits all data, including usernames and passwords, in cleartext, making it vulnerable to eavesdropping and credential theft. This lack of encryption is the primary security concern associated with Telnet. Other options do not accurately describe Telnet's security weaknesses.

Exam trap

CC often tests protocol security; candidates might confuse Telnet with protocols that use weak encryption, but Telnet uses no encryption at all, making 'cleartext' the correct concern.

How to eliminate wrong answers

Option B is wrong because Telnet does not use certificates; it has no built-in encryption or certificate management. Option C is wrong because while Telnet can be affected by DNS poisoning like any network protocol, it is not a specific security concern unique to Telnet; the core issue is cleartext transmission. Option D is wrong because Telnet does not use encryption at all, so it cannot be said to use weak encryption; it uses no encryption.

127
MCQmedium

An organization wants to securely manage network devices from remote locations. Which of the following protocols should be used for command-line access?

AnswerB

SSH encrypts the entire session, including credentials and commands, over TCP port 22, satisfying the requirement for secure remote command-line access. Unlike Telnet, which transmits data in plaintext, SSH provides confidentiality and integrity, making it the appropriate protocol for managing network devices from untrusted remote locations.

Why this answer

SSH (Secure Shell) provides encrypted command-line access to network devices, ensuring confidentiality and integrity of the session. It is the standard protocol for secure remote administration. The other protocols either lack encryption or are not designed for command-line access.

Exam trap

CC often tests secure alternatives; candidates might choose Telnet for command-line access due to familiarity, but the question emphasizes secure management, making SSH the correct choice.

How to eliminate wrong answers

Option A is wrong because HTTP is used for web traffic and does not provide command-line access; it is also unencrypted by default. Option C is wrong because Telnet provides command-line access but transmits data in cleartext, making it insecure for remote management. Option D is wrong because FTP is used for file transfer, not command-line access, and it also lacks encryption in its basic form.

128
MCQhard

A security administrator is configuring a network tap to monitor traffic between two switches. The administrator needs to ensure that the monitoring device receives a copy of all traffic, including packets that might be dropped due to errors. Which type of tap should be used?

A.Passive tap
B.Active tap
C.Regenerating tap
D.Aggregating tap
AnswerA

A passive tap, also known as a break-out tap, splits the signal optically or electrically without regenerating it. It forwards all traffic, including errored packets, because it does not interpret or filter the data. This makes it ideal for capturing a complete copy of traffic for analysis, including frames with errors.

Why this answer

A passive tap splits the signal without regeneration, ensuring that all traffic, including errored packets, is copied to the monitoring port. Active and regenerating taps may filter or drop errored frames. For complete traffic capture, a passive tap is the correct choice.

Exam trap

The trap here is confusing active and passive taps; active taps regenerate signals and may drop errors, while passive taps provide a true copy of all traffic, including errors.

129
MCQmedium

Which firewall type reads packet headers and also tracks the state of active connections to make filtering decisions?

A.Stateful inspection
B.Packet filtering
C.Application proxy
AnswerA

Stateful inspection maintains a connection-state table, recording each session's source, destination and port so return traffic is permitted automatically. This satisfies the stem's requirement to track active connections, unlike stateless packet filtering, which evaluates each packet in isolation against static rules alone.

Why this answer

Stateful inspection firewalls maintain a state table to track connections, allowing return traffic for permitted outbound connections.

130
MCQmedium

A hospital's network team needs to provide secure remote access for clinicians who work from home. The clinicians must be able to reach internal medical records systems as if they were on the hospital LAN, but the hospital's security policy requires that all remote traffic be encrypted and that remote devices be prevented from directly accessing the public internet through the hospital network. Which technology best meets these requirements?

A.A full-tunnel VPN
B.Secure Shell (SSH) port forwarding
C.A remote desktop gateway
D.A split-tunnel VPN
AnswerA

A full-tunnel VPN routes all client traffic, including internet-bound traffic, through the encrypted tunnel to the hospital network. This satisfies both the encryption requirement and the policy that remote devices must not directly access the public internet through the hospital network, because the hospital's egress controls apply to the tunneled traffic.

Why this answer

A full-tunnel VPN is the only option that both encrypts remote access and forces all client traffic through the hospital network, satisfying the policy that remote devices must not reach the public internet directly. Split tunneling, SSH port forwarding, and remote desktop gateways each leave internet-bound traffic outside the hospital's control.

Exam trap

The trap here is assuming that any encrypted remote access method, such as a split-tunnel VPN, automatically satisfies a policy requiring all traffic to traverse the corporate network.

131
MCQeasy

A small accounting firm's staff connect to the corporate wireless network using a shared passphrase that every employee knows, and the same passphrase has not been changed in two years. A security consultant recommends moving to a deployment where each user authenticates with their own domain credentials and a RADIUS server validates the logon before network access is granted. Which technology should the consultant recommend?

A.A captive portal that displays an acceptable-use policy before granting access
B.WPA2-Personal with a longer and more complex pre-shared key
C.MAC address filtering on the wireless access points
D.WPA2-Enterprise with 802.1X authentication
AnswerD

WPA2-Enterprise with 802.1X gives each user a unique credential validated by a RADIUS server before the client is granted network access, so a departing employee can be disabled individually. This directly replaces the shared passphrase model described in the scenario and satisfies the consultant's requirement for per-user domain authentication.

Why this answer

Enterprise-mode wireless security couples the 802.1X framework with a RADIUS server so each user presents unique credentials, commonly their domain logon, before access is granted. This eliminates the shared-secret weakness, enables per-user revocation, and produces authentication logs tied to individuals, which is exactly what the consultant was asked to deliver for the accounting firm.

Exam trap

The trap here is assuming that strengthening the pre-shared key or adding a portal page solves the shared-credential problem, when only per-user authentication through a RADIUS-backed 802.1X exchange actually does.

132
MCQhard

A security analyst notices that users on the corporate wireless network are occasionally redirected to a fraudulent login page when they browse to the company intranet. The analyst confirms the wireless access point is legitimate and that the rogue page presents a certificate issued by an unknown authority. Which attack is most likely occurring?

A.A cross-site scripting flaw in the intranet application
B.A denial-of-service flood against the intranet web server
C.A brute-force attack against the wireless authentication server
D.An on-path attacker intercepting and modifying traffic
AnswerD

An on-path attacker positioned between the wireless clients and the intranet can intercept requests and return a fraudulent login page. The untrusted certificate is consistent with the attacker terminating TLS with a self-signed or otherwise untrusted certificate. Because the access point is legitimate, the attacker is likely using techniques such as ARP spoofing, rogue DHCP, or a malicious proxy to insert themselves into the path.

Why this answer

The untrusted certificate and fraudulent login page indicate that traffic between wireless clients and the intranet is being intercepted and altered. An on-path attacker can redirect requests and present a fake page, especially if users ignore certificate warnings. The legitimate access point rules out a rogue AP, but other interception techniques such as ARP or DHCP manipulation remain plausible.

Exam trap

The trap here is focusing on the wireless access point being legitimate and overlooking that interception can occur at other points on the path, such as through ARP or DHCP manipulation.

133
MCQmedium

Which common port is used by DNS and which transport layer protocol does it primarily use?

A.Port 53, UDP only
B.Port 161, UDP
C.Port 53, both UDP and TCP
D.Port 53, TCP only
AnswerC

DNS queries and responses travel over port 53. UDP carries ordinary lookups for speed, while TCP handles zone transfers and responses exceeding 512 bytes, or when truncation occurs. The protocol choice therefore depends on the query type, not a single transport.

Why this answer

DNS uses port 53 for both UDP and TCP: UDP is used for standard queries and responses because it is fast and low-overhead, while TCP is used for zone transfers, DNSSEC responses, and queries with responses larger than 512 bytes (or EDNS0-negotiated sizes). This dual-protocol design is why the correct answer must include both.

Exam trap

The trap is the assumption that DNS is 'UDP only' because most queries use UDP; the exam tests whether you know TCP/53 is also required for zone transfers and large responses.

How to eliminate wrong answers

Option A is wrong because it claims UDP only, ignoring TCP's role in zone transfers (AXFR/IXFR) and large responses. Option B is wrong because port 161 is used by SNMP, not DNS, and SNMP is a management protocol unrelated to name resolution. Option D is wrong because it claims TCP only, ignoring the fact that the vast majority of DNS queries are UDP for performance reasons.

134
Multi-Selectmedium

A security analyst wants to detect and analyze attacker behavior by deploying a decoy system. Which three characteristics apply to a honeypot? (Choose THREE.)

Select 3 answers
A.It is a decoy system to attract attackers
B.It provides early warning of attacks
C.It contains sensitive production data
D.It is used for legitimate network traffic
E.It allows analysis of attacker tactics
AnswersA, B, E

A honeypot is deliberately deployed as a decoy system to attract attackers, luring them away from production assets while recording their behaviour. This satisfies the analyst's goal of detecting and analysing attacker behaviour through a decoy.

Why this answer

Honeypots are decoy systems designed to attract attackers, provide early warning, and allow analysis of attacker techniques. They do not contain real production data and are not used for legitimate traffic.

135
MCQmedium

Which transport layer protocol is used by voice over IP (VoIP) applications that require low latency and can tolerate some packet loss?

B.SCTP
C.TCP
D.UDP
AnswerD

UDP is connectionless and omits retransmission, handshaking and ordering overhead, so it delivers the low latency VoIP requires. Its tolerance of packet loss suits real-time voice, where retransmitting delayed packets would harm call quality more than dropping them.

Why this answer

UDP is connectionless and has no retransmission, ordering, or congestion-control overhead, which minimizes latency—exactly what VoIP needs. It tolerates some packet loss because voice codecs can interpolate or conceal minor gaps, and retransmitting lost voice packets would arrive too late to be useful anyway.

Exam trap

The trap is equating reliability with quality—candidates pick TCP because it is 'reliable,' but for real-time voice, reliability via retransmission is actually harmful, and UDP's speed and loss tolerance win.

How to eliminate wrong answers

Option A is wrong because ICMP is a control and error-reporting protocol (ping, traceroute), not a transport protocol for carrying voice media. Option B is wrong because SCTP, while designed for message-oriented transport with multi-homing and is used in telecom signaling (SS7 over IP, Diameter), is not the standard transport for VoIP media streams and is not widely supported in enterprise VoIP deployments. Option C is wrong because TCP's retransmissions, three-way handshake, and head-of-line blocking introduce jitter and delay that degrade real-time voice quality.

136
MCQmedium

An analyst reviewing traffic captures sees a workstation repeatedly sending TCP packets with the SYN flag set to many different destination ports on a single server, but the workstation never completes the three-way handshake. The server's connection table is becoming exhausted. Which type of activity is most likely occurring?

A.A man-in-the-middle attack intercepting session traffic
B.A smurf amplification attack using ICMP
C.A SYN flood denial-of-service attack
D.A brute-force password attack against the server
AnswerC

The half-open connections with SYN set and no completed handshake are the signature of a SYN flood, where the attacker exhausts the server's backlog of pending connections. Because the source addresses are often spoofed, the final ACK never arrives, leaving resources tied up until timeouts occur. This matches the scenario of many SYNs to varied ports with no handshake completion.

Why this answer

The repeated SYN packets without completed handshakes indicate a SYN flood, a denial-of-service technique that exhausts a server's pending connection queue. The server cannot complete legitimate connections because its backlog is full. Other attacks would involve different protocols or completed sessions, so the half-open TCP pattern is the key differentiator.

Exam trap

The trap here is assuming any flood of packets is a bandwidth exhaustion attack, when the incomplete TCP handshakes specifically point to resource exhaustion of the connection table.

137
MCQhard

Which of the following is a characteristic of a stateful firewall that distinguishes it from a stateless firewall?

A.It can decrypt SSL traffic
B.It examines each packet in isolation
C.It uses a state table to track connections
D.It can filter based on application-layer data
AnswerC

A state table records each flow's source, destination, ports and TCP session state, so return traffic is permitted automatically without a matching inbound rule. Stateless firewalls inspect each packet in isolation against static ACLs, offering no connection awareness. This satisfies the stem's requirement for a distinguishing characteristic.

Why this answer

A stateful firewall maintains a state table that tracks active connections (source/destination IP, ports, sequence numbers, TCP flags), allowing it to make decisions based on the context of a session rather than each packet in isolation. This lets it automatically permit return traffic for established connections without explicit rules.

Exam trap

The trap is conflating 'stateful' with 'next-gen' — candidates pick A or D because they associate advanced inspection with stateful firewalls, but statefulness is specifically about connection tracking.

How to eliminate wrong answers

Option A is wrong because SSL/TLS decryption is a function of next-generation firewalls (NGFW) or SSL inspection proxies, not a defining characteristic of stateful firewalls — a stateful firewall can operate purely at layers 3-4. Option B is wrong because examining each packet in isolation describes a stateless (packet-filtering) firewall, which is the opposite of stateful behavior. Option D is wrong because application-layer filtering is a feature of layer 7 firewalls or NGFWs, not the distinguishing trait of stateful firewalls, which primarily track connection state at layers 3-4.

138
MCQmedium

A company allows employees to connect to the corporate network from home using a VPN. The security team wants to ensure that a remote employee's device meets minimum security requirements, such as current antivirus and patched operating system, before granting access to internal applications. Which control should be implemented?

A.Network access control (NAC) with posture assessment
B.Multi-factor authentication (MFA) for VPN logins
C.Full-disk encryption on employee laptops
D.Role-based access control (RBAC) on internal applications
AnswerA

NAC with posture assessment evaluates a device's security state, such as antivirus status, patch level, and firewall configuration, before or during network access. If the device fails the check, access can be denied or restricted to a remediation network. This directly enforces the minimum security requirements for remote employees connecting through the VPN.

Why this answer

NAC with posture assessment checks the endpoint's security state before granting network access, which is exactly what is needed to enforce antivirus and patch requirements for remote VPN users. RBAC governs user permissions, MFA verifies identity, and disk encryption protects data at rest; none of them validate the device's health at connection time.

Exam trap

The trap here is equating strong authentication with endpoint compliance, when MFA proves who the user is but not whether the device is healthy.

139
MCQhard

A security engineer is deploying a new VPN solution for remote employees. The company requires that the VPN provide strong encryption, support for multiple users, and the ability to traverse NAT devices. Which VPN protocol should the engineer choose?

A.PPTP
B.IPsec in transport mode
C.L2TP/IPsec
D.SSTP
AnswerC

L2TP/IPsec combines L2TP for tunneling with IPsec for strong encryption and authentication. It supports multiple users and can traverse NAT devices when NAT-T (NAT Traversal) is enabled. This makes it a suitable choice for remote access VPNs requiring strong security and NAT compatibility.

Why this answer

L2TP/IPsec provides strong encryption through IPsec, supports multiple users, and can traverse NAT with NAT-T. It is a widely supported standard for remote access VPNs. The other options either lack strong encryption (PPTP), are platform-specific (SSTP), or are not designed for remote access tunneling (IPsec transport mode).

Exam trap

The trap here is assuming that any VPN protocol with encryption is sufficient, but NAT traversal and multi-user support are critical for remote access.

140
MCQhard

A security team deploys a passive device that monitors network traffic and generates alerts when it detects suspicious patterns, but it does not take any action. This device is best described as a:

A.Web Application Firewall (WAF)
B.Intrusion Detection System (IDS)
C.Intrusion Prevention System (IPS)
D.Stateful firewall
AnswerB

Correct. IDS is passive, alerting only.

Why this answer

An Intrusion Detection System (IDS) passively monitors network traffic, analyzes it against signatures or behavioral baselines, and generates alerts on suspicious activity without blocking or modifying traffic. The question explicitly states the device 'does not take any action,' which is the defining characteristic of an IDS versus an IPS. A WAF and stateful firewall both enforce policy and can block traffic, so they do not fit the passive description.

Exam trap

The trap here is confusing IDS with IPS — candidates see 'monitors traffic and generates alerts' and pick IPS because they associate detection with prevention, but the key phrase 'does not take any action' locks in IDS.

How to eliminate wrong answers

Option A is wrong because a WAF actively inspects and blocks HTTP/HTTPS requests based on rules (e.g., OWASP Top 10), so it takes action rather than being passive. Option C is wrong because an IPS sits inline and actively drops or resets malicious traffic — the opposite of the passive behavior described. Option D is wrong because a stateful firewall maintains connection state and enforces allow/deny rules, which is an active enforcement function, not passive monitoring.

141
MCQmedium

An organization decides to implement a security control that can detect and block attacks in real-time by sitting inline in the network. Which of the following should be chosen to meet these requirements?

A.Intrusion Detection System (IDS)
B.Intrusion Prevention System (IPS)
C.Packet filtering firewall
D.Honeypot
AnswerB

Correct. IPS is inline and can block.

Why this answer

An IPS is designed to sit inline in the traffic path, inspect packets in real time, and actively block malicious traffic by dropping or resetting connections. This matches the requirement to both detect and block attacks inline. An IDS only detects and alerts; it cannot block because it is not inline.

Exam trap

The trap here is confusing detection with prevention: candidates see 'detect' and pick IDS, ignoring the requirement to 'block' inline, which only an IPS can satisfy.

How to eliminate wrong answers

Option A is wrong because an IDS is typically deployed out-of-band via a SPAN port or TAP and can only detect and alert, not block. Option C is wrong because a packet filtering firewall makes allow/deny decisions based on headers (IP, port, protocol) and lacks deep packet inspection or signature-based attack detection. Option D is wrong because a honeypot is a decoy system used to lure and study attackers, not to block production traffic inline.

142
MCQmedium

A company is deploying a new wireless network for guests and wants to ensure that guest traffic cannot reach internal corporate resources. The network team plans to use a separate SSID for guests. Which additional configuration is most important to enforce the isolation requirement?

A.Map the guest SSID to a dedicated VLAN with firewall rules that deny access to internal subnets
B.Configure the guest SSID to use a captive portal for user registration
C.Enable WPA3-Personal on the guest SSID with a strong pre-shared key
D.Set the guest SSID to broadcast on a different wireless channel than the corporate SSID
AnswerA

Placing guest traffic on a dedicated VLAN and applying firewall rules that deny access to internal subnets enforces isolation at the network layer. Even if a guest device is compromised or misconfigured, it cannot route to corporate resources because the policy explicitly blocks that traffic, satisfying the stated requirement.

Why this answer

Guest isolation requires a logical network boundary, which is achieved by assigning the guest SSID to a dedicated VLAN and enforcing firewall rules that deny access to internal subnets. Wireless encryption, captive portals, and channel selection do not create that boundary. Without the VLAN and firewall policy, guest devices may reach corporate resources.

Exam trap

The trap here is assuming that a separate SSID, or strong wireless encryption on that SSID, automatically isolates guest traffic from the internal network.

143
Multi-Selecthard

A network architect is designing a defense-in-depth strategy for a new data center. The architect wants to reduce the attack surface by separating public-facing services from internal systems and by limiting the impact of a compromised host. Which two design elements best support these goals? (Choose two.)

Select 2 answers
A.Segmenting internal systems into VLANs with inter-VLAN traffic controlled by a firewall
B.Allowing all outbound traffic from the DMZ to the internal network
C.Connecting all servers to a single flat VLAN for simplified management
D.Placing public web servers in a screened subnet (DMZ) with strict firewall rules
E.Disabling host-based firewalls on internal servers to avoid application conflicts
AnswersA, D

Segmenting internal systems into VLANs and enforcing firewall policy between them prevents a compromised host from freely reaching other systems. Even within the internal network, lateral movement is constrained because traffic between segments must pass through a policy enforcement point. This reduces the blast radius of an incident and supports least-privilege access.

Why this answer

Defense in depth relies on segmentation and policy enforcement at multiple points. A screened subnet keeps public services away from internal systems, and internal VLANs with firewall-controlled inter-VLAN traffic limit lateral movement. Flat networks, unrestricted DMZ outbound access, and disabled host firewalls all weaken these protections and increase the impact of a compromise.

Exam trap

The trap here is choosing convenience-oriented options such as a flat network or disabled host firewalls, which simplify management but directly undermine segmentation and least privilege.

144
MCQeasy

Which port number is associated with HTTPS, and what protocol encrypts the communication?

A.Port 80, SSL/TLS
B.Port 8080, SSL/TLS
C.Port 443, SSL/TLS
D.Port 443, SSH
AnswerC

HTTPS is assigned TCP port 443 by IANA, and the transport encryption is provided by SSL/TLS, with TLS being the modern successor to SSL. This pairing satisfies both the port and encryption protocol elements of the question.

Why this answer

HTTPS uses TCP port 443 by default, and the communication is encrypted using SSL/TLS (with TLS 1.2/1.3 being the modern versions). Port 443 is the IANA-assigned port for HTTP over TLS, and SSL/TLS provides the encryption, integrity, and server authentication for the session.

Exam trap

CC often tests the pairing of port number and protocol — candidates sometimes confuse 8080 with 443 or assume SSH encrypts HTTPS, but the correct mapping is 443 + SSL/TLS.

How to eliminate wrong answers

Option A is wrong because port 80 is the default for plain HTTP, which is unencrypted — SSL/TLS is not used on port 80 by default. Option B is wrong because port 8080 is a common alternative HTTP port (often used for proxies or app servers) and is not the standard HTTPS port. Option D is wrong because SSH (port 22) is a secure remote shell protocol, not the encryption protocol used by HTTPS; HTTPS uses SSL/TLS, not SSH.

145
MCQmedium

A company's security policy requires that all remote employees use a technology that creates an encrypted tunnel over the public internet so their traffic appears to originate from the corporate network. The solution must authenticate users before granting access to internal applications. Which technology should the company deploy?

A.A demilitarized zone (DMZ)
B.A proxy server
C.A virtual private network (VPN)
D.A virtual local area network (VLAN)
AnswerC

A VPN establishes an encrypted tunnel between the remote employee and the corporate network, protecting data in transit over the public internet. It also authenticates users before allowing access to internal applications, which matches the policy. This makes it the appropriate technology for secure remote access in this scenario.

Why this answer

The policy requires an encrypted tunnel over the public internet plus user authentication for internal application access. A VPN provides exactly that by encapsulating traffic and terminating at the corporate edge after verifying credentials. DMZs isolate public services, VLANs segment local networks, and proxies forward specific requests, but none deliver the encrypted authenticated remote-access tunnel described.

Exam trap

The trap here is treating any technology that hides or forwards traffic, such as a proxy, as equivalent to an encrypted authenticated remote-access tunnel.

146
MCQmedium

An e-commerce company hosts its public storefront in a screened subnet. During a review, the security team finds that the database server holding customer records sits in the same subnet and accepts connections from any host on the internal corporate LAN. The team wants to allow storefront-to-database traffic while preventing ordinary employee workstations from reaching the database directly. Which control best meets this goal?

A.A firewall rule set that permits database access only from the storefront server's address and denies all other sources
B.A network-based intrusion prevention system placed inline between the LAN and the screened subnet
C.A host-based antivirus agent installed on each employee workstation
D.Full-disk encryption on the database server's storage volumes
AnswerA

An explicit rule that allows only the storefront server's address to reach the database and denies everything else enforces least privilege at the network layer. It directly implements the stated goal: the application can query the database, while employee workstations are blocked regardless of the protocol or port they attempt.

Why this answer

Reachability between network segments is governed by filtering rules on a firewall or router ACL, so the only control listed that actually limits which sources may open sessions to the database is a rule permitting the storefront and denying everything else. This enforces least privilege and shrinks the attack surface without disrupting the application's legitimate path.

Exam trap

The trap here is confusing inspection or endpoint protection with access control, when only a source-restricting filter rule actually removes the unauthorized network path.

147
Multi-Selecteasy

Which two of the following are characteristics of a stateful firewall? (Choose TWO.)

Select 2 answers
A.Inspects application-layer data
B.Tracks connection state
C.Operates only at Layer 3
D.Filters packets based on static rules only
E.Blocks unsolicited inbound traffic by default
AnswersB, E

A stateful firewall maintains a connection table recording each flow's source, destination and port, so return traffic is matched against established sessions rather than inspected in isolation. This per-session tracking is precisely the defining characteristic the stem asks for, distinguishing it from stateless packet filters that evaluate each packet independently.

Why this answer

A stateful firewall tracks the state of active connections and can block unsolicited inbound traffic. Packet filtering is stateless, and application inspection is typical of proxy firewalls.

148
Multi-Selecthard

A company is experiencing a distributed denial-of-service (DDoS) attack that is overwhelming the network bandwidth. Which THREE mitigation techniques are most effective?

Select 3 answers
A.Enable rate limiting on network devices
B.Disable ICMP on all devices
C.Change the public IP address of the server
D.Use a content delivery network (CDN) to absorb traffic
E.Implement traffic filtering at the perimeter
AnswersA, D, E

Rate limiting caps the packet or connection rate accepted per source or interface, preventing a flood from consuming all available bandwidth. This directly satisfies the stem's bandwidth-overwhelm constraint by throttling excessive traffic at network devices.

Why this answer

Traffic filtering, rate limiting, and using a CDN can help absorb DDoS traffic. Changing IP addresses is reactive and not a standard mitigation; disabling ICMP may help against some attacks but is not a primary mitigation.

149
MCQeasy

An employee receives an email that appears to be from the IT department, asking them to click a link and reset their password due to a security breach. The link leads to a website that looks identical to the company's login page. Which type of attack is this?

A.Vishing
B.Whaling
C.Phishing
D.Spear phishing
AnswerC

Phishing is a social engineering attack where an attacker sends fraudulent messages, often via email, to trick recipients into revealing sensitive information or clicking malicious links. In this scenario, the email impersonates the IT department and directs the employee to a fake login page, which is a classic phishing attempt.

Why this answer

The attack uses email to impersonate the IT department and lure the employee to a fake login page, which is the definition of phishing. While spear phishing and whaling are subsets, the scenario does not indicate a targeted or executive-focused attack, and vishing involves voice, not email.

Exam trap

The trap here is overclassifying the attack as spear phishing or whaling when the scenario lacks evidence of targeting or executive involvement.

150
Multi-Selectmedium

A network administrator is hardening a corporate wireless network. Management wants to ensure that only authorized devices can associate and that wireless traffic cannot be easily read by someone nearby with a packet capture tool. Which two controls should the administrator implement? (Choose two.)

Select 2 answers
A.Media Access Control (MAC) address filtering
B.Wired Equivalent Privacy (WEP)
C.WPA3 with strong authentication
D.Service Set Identifier (SSID) broadcasting disabled
E.IEEE 802.1X port-based network access control
AnswersC, E

WPA3 provides strong encryption for wireless traffic and supports authentication methods that verify authorized users or devices. This prevents casual eavesdropping by someone nearby and helps ensure only approved devices associate. It directly addresses both the confidentiality and access-control goals in the scenario.

Why this answer

Strong wireless encryption with robust authentication, such as WPA3, protects traffic from nearby eavesdropping, while 802.1X ensures only authenticated devices or users can associate. Together they address confidentiality and access control. WEP is broken, SSID hiding is easily defeated, and MAC filtering can be bypassed through spoofing, so none of those reliably satisfy the requirements.

Exam trap

The trap here is relying on obscurity controls like hidden SSIDs or spoofable MAC address lists instead of cryptographic authentication and encryption.

← PreviousPage 2 of 3 · 159 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cc Network Security questions.