ISC2 CC Network Security Practice Question
Which of the following are effective defenses against man-in-the-middle attacks? (Choose THREE)
⚠ Common exam trap
The trap here is that candidates might think disabling ARP (Option C) is a valid defense against ARP-based MITM attacks, but it's not a practical solution; also, they might overlook user education as a defense, focusing only on technical controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Educating users to verify certificates
Option B is correct because user education to verify certificates helps detect MITM attacks where an attacker presents a forged or self-signed certificate, prompting users to check the certificate's issuer, validity, and hostname match before trusting a connection. Option D is correct because HTTPS with proper certificate validation uses TLS to authenticate the server and encrypt traffic, and validating the certificate chain against trusted CAs prevents an attacker from impersonating the server with a fraudulent certificate. Option E is correct because a VPN encrypts all traffic between the client and the VPN gateway using protocols such as IPsec or TLS, which prevents an on-path attacker from reading or modifying the traffic and can authenticate the tunnel endpoints. Option A is not correct because HTTP is unencrypted and provides no authentication, making MITM attacks easier, not harder. Option C is not correct because disabling ARP is not a practical or effective defense; ARP is required for normal IPv4 LAN communication, and the proper mitigation for ARP spoofing is dynamic ARP inspection or static ARP entries, not disabling ARP entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Using HTTP instead of HTTPS
Why it's wrong here
HTTP transmits data in cleartext, so an attacker positioned on the path can read and alter traffic undetected; HTTPS with certificate validation is the defence. Plain HTTP is tempting when diagnosing with packet captures or hosting non-sensitive internal content, where confidentiality is not required.
- ✓
Educating users to verify certificates
Why this is correct
User education to verify certificates counters MitM interception by prompting rejection of forged or unexpected certificates before credentials are submitted. This satisfies the scenario's need for a defence against credential interception, complementing technical controls. However, it relies on human vigilance, so pairing with certificate pinning or Microsoft Entra ID token protections strengthens the overall posture.
- ✗
Disabling ARP
Why it's wrong here
Disabling ARP removes address resolution entirely, breaking normal network communication rather than defending against interception. It is tempting because ARP spoofing underpins many man-in-the-middle attacks, and disabling it would be considered only in isolated, statically configured environments using permanent ARP entries.
- ✓
Implementing HTTPS with proper certificate validation
Why this is correct
HTTPS encrypts traffic between client and server using TLS, while certificate validation confirms the server's identity against a trusted certificate authority. This prevents an attacker from silently intercepting or altering communications, directly satisfying the scenario's requirement for an effective man-in-the-middle defence.
- ✓
Using a VPN to encrypt all traffic
Why this is correct
A VPN tunnels traffic through an encrypted channel, so an attacker positioned on the path cannot read or alter the payload without detection. This directly defeats interception and tampering, satisfying the requirement for a defence that protects data confidentiality and integrity in transit.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
Authentication and Authorization Methods
Key term
Internet Protocol Security
Internet Protocol Security (IPsec) is a suite of protocols that encrypts and authenticates data packets sent over IP networks to ensure private and secure communication.
Key term
Dynamic ARP Inspection
Dynamic ARP Inspection is a security feature that validates ARP packets on a network to prevent man-in-the-middle attacks by ensuring that only legitimate ARP messages are forwarded.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.