Courseiva
Network Security →hardMultiple Select

ISC2 CC Network Security Practice Question

Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)

⚠ Common exam trap

The trap here is that candidates might think disabling ARP (Option C) is a valid defense against ARP-based MITM attacks, but it's not a practical solution; also, they might overlook user education as a defense, focusing only on technical controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Educating users to verify certificates

Option B is correct because user education to verify certificates helps detect MITM attacks where an attacker presents a forged or self-signed certificate, prompting users to check the certificate's issuer, validity, and hostname match before trusting a connection. Option D is correct because HTTPS with proper certificate validation uses TLS to authenticate the server and encrypt traffic, and validating the certificate chain against trusted CAs prevents an attacker from impersonating the server with a fraudulent certificate. Option E is correct because a VPN encrypts all traffic between the client and the VPN gateway using protocols such as IPsec or TLS, which prevents an on-path attacker from reading or modifying the traffic and can authenticate the tunnel endpoints. Option A is not correct because HTTP is unencrypted and provides no authentication, making MITM attacks easier, not harder. Option C is not correct because disabling ARP is not a practical or effective defense; ARP is required for normal IPv4 LAN communication, and the proper mitigation for ARP spoofing is dynamic ARP inspection or static ARP entries, not disabling ARP entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Using HTTP instead of HTTPS

    Why it's wrong here

    HTTP transmits data in cleartext, so an attacker positioned on the path can read and alter traffic undetected; HTTPS with certificate validation is the defence. Plain HTTP is tempting when diagnosing with packet captures or hosting non-sensitive internal content, where confidentiality is not required.

  • ✓

    Educating users to verify certificates

    Why this is correct

    User education to verify certificates counters MitM interception by prompting rejection of forged or unexpected certificates before credentials are submitted. This satisfies the scenario's need for a defence against credential interception, complementing technical controls. However, it relies on human vigilance, so pairing with certificate pinning or Microsoft Entra ID token protections strengthens the overall posture.

  • ✗

    Disabling ARP

    Why it's wrong here

    Disabling ARP removes address resolution entirely, breaking normal network communication rather than defending against interception. It is tempting because ARP spoofing underpins many man-in-the-middle attacks, and disabling it would be considered only in isolated, statically configured environments using permanent ARP entries.

  • ✓

    Implementing HTTPS with proper certificate validation

    Why this is correct

    HTTPS encrypts traffic between client and server using TLS, while certificate validation confirms the server's identity against a trusted certificate authority. This prevents an attacker from silently intercepting or altering communications, directly satisfying the scenario's requirement for an effective man-in-the-middle defence.

  • ✓

    Using a VPN to encrypt all traffic

    Why this is correct

    A VPN tunnels traffic through an encrypted channel, so an attacker positioned on the path cannot read or alter the payload without detection. This directly defeats interception and tampering, satisfying the requirement for a defence that protects data confidentiality and integrity in transit.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.