Courseiva

CCNA Cc Network Security Questions

9 of 159 questions · Page 3/3 · Cc Network Security topic · Answers revealed

151
MCQmedium

An attacker captures network traffic using Wireshark and reads unencrypted emails. Which security goal is most directly compromised?

A.Integrity
B.Availability
C.Non-repudiation
D.Confidentiality
AnswerD

Unencrypted email content is readable by anyone capturing the traffic, so unauthorised parties gain access to information they should not see. Confidentiality is the goal protecting data from disclosure, making it the property directly breached; integrity and availability remain intact.

Why this answer

Confidentiality ensures that data is only readable by authorized parties. When an attacker captures unencrypted email traffic in Wireshark and reads the contents, the confidentiality of the email is directly compromised because the data was exposed in plaintext to an unauthorized party.

Exam trap

CC often tests whether candidates can distinguish confidentiality (secrecy/reading) from integrity (modification) and non-repudiation (proof of origin) — eavesdropping is always a confidentiality violation, not integrity.

How to eliminate wrong answers

Option A is wrong because integrity refers to data being unaltered — the attacker read the email but did not necessarily modify it, so integrity is not the primary goal compromised. Option B is wrong because availability refers to data/services being accessible — reading traffic does not deny access. Option C is wrong because non-repudiation ensures a sender cannot deny sending a message — it is about proof of origin, not secrecy, and is not directly violated by passive eavesdropping.

152
MCQhard

An organization deploys a network security device that inspects application-layer payloads, can block malicious HTTP requests, and uses OWASP rules. Which type of device is this?

A.Intrusion Detection System (IDS)
B.Next-Generation Firewall (NGFW)
C.Web Application Firewall (WAF)
D.Intrusion Prevention System (IPS)
AnswerC

A Web Application Firewall operates at Layer 7, inspecting HTTP request payloads against rule sets such as the OWASP Core Rule Set to block SQL injection, cross-site scripting and similar attacks. This directly satisfies the stem's requirement for application-layer inspection and malicious HTTP request blocking, unlike packet-filtering or stateful firewalls.

Why this answer

A Web Application Firewall (WAF) operates at Layer 7, inspects HTTP/HTTPS payloads, blocks malicious requests such as SQL injection and XSS, and commonly uses rule sets like the OWASP ModSecurity Core Rule Set. The question's emphasis on application-layer payload inspection, HTTP request blocking, and OWASP rules maps directly to WAF capabilities. WAFs are typically deployed in front of web servers or via cloud services (AWS WAF, Cloud Armor, Azure WAF).

Exam trap

CC often tests the distinction between detection (IDS) and prevention (IPS/WAF) and between network-layer firewalls (NGFW) and application-layer firewalls (WAF), tempting candidates to pick NGFW because it sounds 'next-gen' and comprehensive.

How to eliminate wrong answers

Option A is wrong because an IDS is passive — it detects and alerts on suspicious traffic but does not block it, and it is not specifically focused on HTTP/OWASP rules. Option B is wrong because an NGFW adds application awareness, IPS, and user identity to a traditional firewall, but it is not defined by OWASP rule sets or HTTP payload inspection as its primary function; NGFWs operate across many protocols, not just web. Option D is wrong because an IPS blocks intrusions at the network/transport layer based on signatures or anomalies, but it is not specifically an HTTP/OWASP-focused device and does not typically parse web application payloads with OWASP rules.

153
MCQhard

A security engineer is reviewing firewall logs and notices that an internal host is making repeated outbound connections to a known malicious IP address on port 443. The firewall is configured to allow all outbound traffic to port 443. The engineer wants to block this specific traffic without disrupting other legitimate HTTPS traffic. Which action should the engineer take?

A.Implement a URL filtering rule to block the domain name associated with the malicious IP.
B.Enable intrusion prevention system (IPS) signatures to detect and block the malicious traffic.
C.Create an outbound rule to block all traffic to the malicious IP address on any port.
D.Configure a quality of service (QoS) policy to throttle traffic to the malicious IP address.
AnswerC

Blocking all traffic to the specific malicious IP address effectively stops the communication while allowing other HTTPS traffic to proceed. Since the malicious IP is known, a targeted block rule is precise and does not disrupt legitimate traffic to other destinations. This is the most direct and least disruptive mitigation.

Why this answer

A targeted outbound block rule for the specific malicious IP address stops the communication without affecting legitimate HTTPS traffic. This approach is precise, does not require deep packet inspection, and is effective regardless of the port used. Other methods either do not guarantee a block or require additional capabilities like SSL decryption.

Exam trap

The trap here is overcomplicating the solution with application-layer inspection when a simple network-layer block is sufficient and less disruptive.

154
MCQmedium

An organization wants to implement a network security device that can block malicious traffic in real-time and must be placed inline. Which device should be chosen?

A.Vulnerability scanner
B.Packet sniffer
C.Intrusion Detection System (IDS)
D.Intrusion Prevention System (IPS)
AnswerD

An IPS is inline and can block traffic.

Why this answer

An Intrusion Prevention System (IPS) is deployed inline in the traffic path and can actively block malicious traffic in real time by dropping or resetting malicious packets. Because it sits inline, it can make blocking decisions on live traffic, which is exactly what the requirement specifies. This distinguishes it from detection-only or passive tools.

Exam trap

CC often tests the IDS vs IPS distinction — candidates see 'block malicious traffic' and pick IDS, forgetting that only an inline IPS can actually block; IDS is detect-and-alert only.

How to eliminate wrong answers

Option A is wrong because a vulnerability scanner is an assessment tool that probes systems for known weaknesses on a schedule — it does not sit inline or block live traffic. Option B is wrong because a packet sniffer is a passive capture tool that copies and analyzes traffic but cannot block anything. Option C is wrong because an Intrusion Detection System (IDS) is typically deployed out-of-band (via a SPAN port or TAP) and can only detect and alert — it cannot block traffic because it is not in the traffic path.

155
MCQhard

A security engineer is evaluating different firewall architectures. Which firewall type can decrypt SSL/TLS traffic, inspect the contents, and then re-encrypt it?

A.Application proxy firewall
B.Packet filtering firewall
C.Next-generation firewall (NGFW)
D.Stateful inspection firewall
AnswerC

A next-generation firewall performs SSL/TLS inspection by acting as a man-in-the-middle proxy: it decrypts traffic using a trusted certificate, examines payloads for threats and policy violations, then re-encrypts before forwarding. This satisfies the stem's requirement for content inspection of encrypted sessions, which traditional packet-filtering or stateful firewalls cannot achieve.

Why this answer

A Next-Generation Firewall (NGFW) includes SSL/TLS decryption and inspection capabilities, allowing it to decrypt encrypted traffic, inspect the plaintext for threats or policy violations, and then re-encrypt it before forwarding. This is a defining feature that separates NGFWs from traditional firewalls. The other firewall types lack the deep packet inspection and decryption engine required.

Exam trap

CC often tests whether candidates know that only NGFWs (and dedicated TLS inspection appliances) can decrypt and re-encrypt SSL/TLS — candidates may incorrectly attribute this to application proxy or stateful inspection firewalls because those sound more 'advanced.'

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at the application layer but traditionally does not perform SSL/TLS decryption and re-encryption of arbitrary traffic — it proxies specific application protocols and lacks the integrated TLS inspection engine. Option B is wrong because a packet filtering firewall only examines packet headers (source/destination IP, port, protocol) and cannot see inside encrypted payloads at all. Option D is wrong because a stateful inspection firewall tracks connection state but still only inspects headers and cannot decrypt TLS to examine content.

156
MCQmedium

A financial services firm wants to allow employees to securely access internal applications from home without exposing those applications directly to the internet. The security team proposes using a VPN that encrypts traffic at the network layer and can carry non-web protocols. Which VPN technology best meets this requirement?

A.TLS-based web VPN portal
B.RADIUS authentication with 802.1X
C.IPsec in tunnel mode
D.SSH port forwarding
AnswerC

IPsec in tunnel mode encapsulates entire IP packets, encrypting the payload and original headers, so remote clients can reach internal applications over any IP-based protocol. It operates at the network layer, providing confidentiality and integrity for non-web traffic, which matches the firm's need to avoid exposing applications directly while supporting diverse internal services.

Why this answer

IPsec in tunnel mode encrypts and encapsulates entire IP packets, enabling remote users to securely reach internal applications over any IP-based protocol. Unlike browser-based TLS VPNs or SSH port forwarding, it provides transparent network-layer connectivity without exposing applications to the internet. RADIUS with 802.1X handles LAN access control, not remote traffic encryption, so it cannot meet the stated requirement.

Exam trap

The trap here is assuming any encrypted remote access method, such as a TLS web portal or SSH tunnel, provides the same broad network-layer VPN coverage as IPsec tunnel mode.

157
MCQeasy

Which layer of the OSI model is responsible for routing packets across networks?

A.Network layer
B.Physical layer
C.Transport layer
D.Data Link layer
AnswerA

The network layer handles logical addressing and path selection, forwarding packets between networks via routers using layer 3 addresses. This satisfies the stem's routing requirement, distinguishing it from the data link layer, which forwards frames within a single network segment.

Why this answer

The Network layer (Layer 3) of the OSI model is responsible for logical addressing and routing packets across networks. Protocols like IP, ICMP, and routing protocols (OSPF, BGP) operate at this layer, using IP addresses to determine the best path between networks. Routers are the classic Layer 3 devices that forward packets based on routing tables.

Exam trap

CC often tests OSI layer responsibilities, and the trap is confusing the Transport layer (end-to-end delivery, TCP/UDP) with the Network layer (routing, IP addressing) — candidates may pick Transport because it 'delivers' data, but routing specifically belongs to Layer 3.

How to eliminate wrong answers

Option B is wrong because the Physical layer (Layer 1) deals with the transmission of raw bits over physical media — cables, connectors, voltages, and signaling — not routing. Option C is wrong because the Transport layer (Layer 4) handles end-to-end communication, segmentation, flow control, and reliability via TCP/UDP, but it does not route packets between networks. Option D is wrong because the Data Link layer (Layer 2) handles framing, MAC addressing, and error detection on the local link, and switches operate here — it does not perform inter-network routing.

158
MCQmedium

Which security control would best mitigate the risk of network sniffing on a wired LAN segment?

A.Using encryption protocols (e.g., IPsec, TLS)
B.Implementing VLANs
C.Disabling unused ports on the switch
AnswerA

IPsec and TLS encrypt payloads end-to-end, so frames captured by a sniffer on the wired segment appear as ciphertext rather than readable credentials or data. Encryption directly defeats sniffing, whereas segmentation or port security only limit where an attacker can capture traffic.

Why this answer

Encrypting traffic (e.g., using HTTPS, VPN) makes sniffed data unreadable.

159
MCQmedium

A financial services firm wants to give remote employees encrypted access to internal trading applications without exposing those applications directly to the internet. The security team requires that only the remote client's traffic to specific internal resources is tunneled, and that the internal application servers never initiate connections back to the client. Which technology best meets these requirements?

A.A network access control (NAC) solution
B.A remote access VPN terminating on a VPN concentrator
C.A reverse proxy published in the DMZ
D.A site-to-site IPsec tunnel between two data centers
AnswerB

A remote access VPN lets individual clients establish an encrypted tunnel to a VPN concentrator, and split-tunnel or full-tunnel policies can restrict which internal resources are reachable. Because the client initiates the connection, internal application servers never need to initiate connections back to the client, satisfying the requirement. This design keeps internal applications off the public internet while giving employees authenticated access.

Why this answer

Remote employees need an encrypted path into the internal network that they initiate, so internal servers never connect back to them. A remote access VPN terminated on a concentrator provides exactly this client-initiated tunnel and can be scoped to specific internal resources. Site-to-site tunnels, reverse proxies, and NAC address different problems and do not meet both stated constraints.

Exam trap

The trap here is conflating site-to-site VPNs with remote access VPNs, even though only the latter is designed for individual clients initiating connections from outside the network.

← PreviousPage 3 of 3 · 159 questions total

Ready to test yourself?

Try a timed practice session using only Cc Network Security questions.