Courseiva

SSCP · domain

Network and Communications Security

Domain 4 of the SSCP exam covers network architecture, secure transmission, and attack mitigation across OSI layers. Questions present short scenarios—spoofed DHCP requests, forged ARP replies, TLS version differences, VPN protocol selection—and ask you to identify the attack, protocol, or control. Expect protocol-level recognition rather than configuration depth.

100 questions24 easy47 medium29 hard

Focused practice

Practice Network and Communications Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Network and Communications Security

Map each scenario to its exact protocol and OSI layer, then name the attack or control precisely. The critical skill is distinguishing Layer 2 attacks (ARP, DHCP, MAC) from higher-layer ones and knowing which VPN or TLS feature the question describes.

Identifying secure remote access VPN protocols such as TLS-based Cisco AnyConnect versus IPsec alternatives

Recognizing TLS 1.3 improvements including removal of legacy ciphers and simplified handshake

Naming Layer 2 attacks like ARP spoofing, DHCP starvation, and MAC flooding from scenario descriptions

Selecting network segmentation, NAC, and 802.1X controls that limit lateral movement and rogue devices

Watch out for

Common Network and Communications Security exam traps

  • ▸Confusing ARP spoofing with DNS poisoning or DHCP starvation; each targets a different protocol and layer, so read the scenario's mechanism carefully.
  • ▸Assuming TLS 1.3 still supports RSA key exchange or renegotiation; it removed those, so answers referencing them are wrong.
  • ▸Mixing up VPN types—treating IPsec IKEv2 and TLS/SSL VPNs as interchangeable when the question names a specific client or protocol.

Question index

All Network and Communications Security questions (100)

Click any question to see the full explanation, or start a practice session above.

1

A security engineer is configuring a site-to-site VPN between two branch offices using IPsec in tunnel mode. Which protocol provides both authentication and encryption of the entire original IP packet?

Hard
2

A security analyst is reviewing a TLS 1.3 deployment. Which THREE of the following are features of TLS 1.3?

Hard
3

An attacker sends a forged ARP reply associating the attacker's MAC address with the IP address of the default gateway. What type of attack is this?

Medium
4

Which TCP port is commonly used for secure web traffic (HTTPS) and is often allowed through firewalls for web browsing?

Easy
5

An organization wants to ensure that only authorized devices can connect to the corporate wired network. Which technology should they implement to enforce this?

Medium
6

A network administrator is tasked with segmenting the network to isolate a DMZ containing public-facing web servers from the internal corporate network. Which device should be placed between the DMZ and internal network, and what type of traffic should it allow?

Medium
7

A network administrator is configuring a switch to prevent unauthorized devices from connecting to a specific switch port. The administrator wants to restrict access based on the device's MAC address. Which feature should be implemented?

Easy
8

A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)

Medium
9

A security analyst is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of a SYN flood attack. The analyst wants to generate alerts when the number of half-open connections exceeds a threshold. Which TWO of the following metrics are MOST relevant for detecting a SYN flood? (Choose two.)

Medium
10

Which security control can prevent a rogue DHCP server from assigning incorrect gateway addresses to clients?

Medium
11

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and an internal database. The architect must ensure that if the web server is compromised, the attacker cannot directly access the internal database. Which DMZ design principle should be applied?

Medium
12

Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?

Hard
13

Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?

Easy
14

A security analyst notices that an attacker on the same VLAN is able to capture traffic from other hosts, including sensitive data. The attacker has not compromised any switch or router. Which network attack is most likely being used?

Hard
15

Which THREE of the following are valid considerations when deploying a remote access VPN using SSL/TLS? (Select THREE)

Hard
16

Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?

Medium
17

Which of the following is a connectionless transport layer protocol primarily used for services like DNS and DHCP?

Easy
18

A security administrator is configuring a VPN between two branch offices. The requirement is to encrypt the entire original IP packet and add a new IP header for routing over the internet. Which IPsec mode should be used?

Medium
19

Which UDP port is used by the Domain Name System (DNS) for name resolution queries?

Easy
20

Which protocol and port combination is commonly used for secure remote administration of a server?

Easy
21

A company wants to deploy a network IDS that can analyze traffic patterns and detect anomalies. Where should the IDS sensor be placed to monitor all traffic on a network segment without introducing latency?

Medium
22

An attacker sends a gratuitous ARP reply associating the attacker's MAC address with the default gateway's IP address. Which attack is being performed, and what is the primary risk?

Medium
23

A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?

Medium
24

A company needs to provide secure remote access for employees working from home. The security team wants to ensure the solution provides strong authentication and encryption, and supports a wide range of client devices without requiring proprietary software. Which technology should they implement?

Medium
25

A security engineer is reviewing a network architecture that uses IPsec in tunnel mode between two site gateways. The engineer must verify that the design provides confidentiality for the entire original IP packet. Which component of the IPsec architecture is responsible for encrypting the payload and providing confidentiality?

Medium
26

An attacker sends a flood of DHCP request packets with spoofed MAC addresses to exhaust the DHCP server's IP address pool, preventing legitimate clients from obtaining IP addresses. This attack is known as:

Medium
27

Which wireless security standard introduced the Simultaneous Authentication of Equals (SAE) handshake to replace the pre-shared key (PSK) method?

Medium
28

A network engineer is implementing a secure network design that requires separating the network into multiple segments to limit the scope of a potential breach. The engineer wants to ensure that even if one segment is compromised, the attacker cannot easily move laterally to other segments. Which of the following technologies should be implemented to achieve this?

Medium
29

A company is designing a network with multiple security zones. Which TWO of the following are best practices for network segmentation? (Select TWO)

Medium
30

A system administrator notices a high number of half-open TCP connections to the company's web server. The server is becoming unresponsive. Which attack is likely occurring, and which mitigation is effective?

Medium
31

Which protocol is used for secure web browsing and operates on TCP port 443?

Easy
32

A security analyst discovers that an attacker has set up a fake wireless access point with the same SSID as the corporate network. Users are unknowingly connecting to it. What is this attack called?

Medium
33

A security analyst is investigating a potential attack on a web application. The analyst observes that an attacker is sending specially crafted requests that cause the application to execute unintended commands on the underlying operating system. Which type of attack is this?

Medium
34

A security administrator is reviewing network traffic logs and notices a large number of TCP SYN packets from various source IP addresses to a single destination IP address on port 443. The destination server is unresponsive. Which type of attack is most likely occurring?

Hard
35

An organization is setting up a site-to-site VPN between two branch offices. They require encryption of the entire IP packet, including the original IP header, and plan to use IPsec. Which mode should they configure?

Hard
36

A security administrator is configuring a network tap to monitor traffic between two switches. The tap is placed inline and must not disrupt network connectivity if it loses power. Which type of tap should be used?

Medium
37

An organization is deploying a network-based intrusion detection system (NIDS). The security team must decide on placement and configuration. Which THREE considerations are critical for effective NIDS deployment?

Hard
38

Which UDP port is used by the Dynamic Host Configuration Protocol (DHCP) for server communication?

Easy
39

A network architect is designing a solution to protect against ARP spoofing attacks on a flat Layer 2 network. The architect wants to ensure that only valid IP-to-MAC address mappings are used by hosts. Which feature should be enabled on the switches?

Hard
40

A security engineer is configuring an IPsec VPN between two offices to protect data in transit. The requirement is to ensure that packets cannot be modified or replayed by an attacker. Which security service should be enabled in the IPsec configuration?

Medium
41

A company is migrating from WPA2-PSK to WPA3 for its wireless network. Which THREE benefits does WPA3 provide compared to WPA2?

Medium
42

Which of the following wireless security protocols uses AES-CCMP and is based on the 802.11i standard?

Easy
43

A security engineer is designing a network segmentation strategy to isolate a DMZ containing public-facing web servers from the internal corporate network. Which TWO controls should be implemented? (Select two)

Hard
44

Which wireless security standard replaces WPA2 and mandates Protected Management Frames (PMF) to prevent certain types of attacks?

Easy
45

A network administrator wants to block all inbound traffic except for web and email services. Which firewall rule configuration would achieve this?

Medium
46

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of attacks. The administrator wants to ensure the NIDS can detect attacks that involve fragmented packets. Which of the following should be enabled on the NIDS to reassemble fragmented packets before analysis?

Hard
47

A small business wants to prevent employees from accessing known malicious websites without deploying a full next-generation firewall. The IT consultant recommends a service that filters DNS queries before they reach the public internet. Which technology is being described?

Easy
48

A network administrator wants to prevent unauthorized devices from connecting to the wired network. Which technology can be used to enforce authentication at the switch port level before granting network access?

Medium
49

A company is deploying a VPN for remote employees. They require strong encryption and authentication, and the solution must be compatible with native OS clients without additional software. Which VPN protocol is most appropriate?

Medium
50

A security administrator needs to securely transfer files between two servers over an untrusted network. The administrator wants to use a protocol that provides encryption and authentication and operates over TCP port 22. Which protocol should be used?

Easy
51

What is the default port for Microsoft SQL Server?

Easy
52

A network architect is evaluating a remote access design where users must authenticate with a hardware token and the session must be resistant to replay even if an attacker captures the encrypted traffic. Which protocol property should the architect prioritize?

Medium
53

Which attack exploits the lack of IV (Initialization Vector) randomness in the RC4 algorithm to recover the Wi-Fi password, and is considered completely broken?

Hard
54

Which of the following is a characteristic of TLS 1.3 that improves security over previous versions?

Hard
55

A company wants to protect its web servers from common web application attacks such as SQL injection and cross-site scripting. The security team decides to deploy a device that inspects HTTP traffic and blocks malicious requests. Which technology should they implement?

Easy
56

An attacker sends a large number of DHCP request messages with spoofed MAC addresses to a network's DHCP server, causing the server to exhaust its IP address pool and deny service to legitimate clients. This attack is known as:

Medium
57

An organization wants to ensure that only corporate-managed devices can connect to the internal network. Non-compliant devices should be placed in a restricted VLAN with limited access. Which technology should be deployed?

Medium
58

Which of the following protocols operates on TCP port 443 and provides encrypted communication between a web browser and a web server?

Easy
59

Which of the following is a common defense against ARP spoofing attacks on a local area network?

Easy
60

Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?

Easy
61

A network administrator notices that legitimate clients are unable to obtain IP addresses from the DHCP server. The network logs show a high volume of DHCP Discover messages from different MAC addresses. Which attack is most likely occurring?

Medium
62

A small business wants to let visitors use its guest Wi-Fi without exposing internal servers. The visitors must reach the internet only, while employees keep using the corporate SSID. Which design best isolates guest traffic from the internal network?

Easy
63

A company wants to implement a firewall that can track the state of network connections and make decisions based on the context of traffic (e.g., allowing return packets for an established connection). Which type of firewall should they choose?

Medium
64

A security engineer is implementing a Network Access Control (NAC) solution to enforce endpoint compliance before allowing devices onto the corporate network. Which TWO of the following are common NAC enforcement methods? (Choose two.)

Medium
65

A security team is implementing Network Access Control (NAC) to enforce endpoint compliance before granting network access. Which technology allows port-based authentication on wired networks?

Medium
66

A security analyst is hardening a wireless network that uses WPA2-Enterprise with a RADIUS server. The analyst wants to mitigate the risk of an attacker setting up a rogue access point to capture user credentials. Which TWO measures should be implemented? (Choose two.)

Hard
67

During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?

Medium
68

An attacker is performing a man-in-the-middle attack at Layer 2 by sending forged ARP messages to associate their MAC address with the IP address of a legitimate host on the same subnet. This attack is known as:

Medium
69

Which protocol is used to securely transfer files between a client and server, typically over TCP port 22?

Easy
70

A security analyst is reviewing firewall logs and notices a high rate of TCP SYN packets to multiple ports on a server, but no corresponding ACK or RST packets. This is characteristic of which type of attack?

Hard
71

A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?

Hard
72

A security analyst is reviewing network traffic and notices that an attacker is sending forged ARP replies to a host, attempting to associate the attacker's MAC address with the IP address of the default gateway. Which security feature should be implemented on the switch to prevent this attack?

Hard
73

A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?

Medium
74

Which network security control can enforce that only authorized devices with current antivirus and patches can connect to the network?

Hard
75

A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?

Hard
76

Which THREE of the following are security features of WPA3 compared to WPA2? (Select THREE)

Hard
77

A company is migrating from WPA2 to WPA3 for wireless security. Which THREE features does WPA3 introduce? (Select three)

Medium
78

A security analyst is investigating a network incident. Which TWO of the following are indicators of a man-in-the-middle attack using ARP spoofing? (Select TWO)

Medium
79

Which UDP port is used by the Simple Network Management Protocol (SNMP) for receiving traps?

Medium
80

A financial services firm needs to detect unauthorized changes to its public DNS records that could redirect customers to a phishing site. The security team wants a control that validates DNS responses cryptographically so that a resolver can verify the data originated from the authoritative zone. Which technology should they implement?

Medium
81

A security team is reviewing how their organization's DNS infrastructure could be abused. They want to reduce the risk of DNS cache poisoning and of data being smuggled out of the network through DNS queries. Which two measures best address these risks? (Choose two.)

Hard
82

A security administrator is hardening a data center switch. Management requires that only the switch's configured management station can initiate a remote CLI session, and that the switch never accept an inbound management connection from any other host. Which control should the administrator implement on the switch to meet this requirement?

Medium
83

A security analyst is investigating a network where an attacker successfully redirected traffic from a legitimate web server to a malicious server by corrupting the target domain's DNS records in a local resolver cache. Which attack technique was used?

Hard
84

Which TWO of the following are methods to defend against SYN flood attacks? (Select TWO)

Medium
85

An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?

Medium
86

A security analyst is reviewing network traffic and notices a large number of ICMP echo requests from a single source to multiple destinations within the organization's network. The analyst suspects a reconnaissance attempt. Which type of attack is most likely being performed?

Easy
87

Which transport layer protocol is used by DNS for its queries and responses, and why is it appropriate?

Easy
88

A company is deploying a new wireless network and wants to ensure that only authorized devices can connect. The security team decides to use a method that requires a supplicant, authenticator, and authentication server. Which technology should be implemented?

Easy
89

A security analyst is investigating a potential attack on a network. The analyst observes a large number of ICMP echo request packets with spoofed source IP addresses being sent to a subnet's broadcast address. Many hosts on the subnet are replying, causing network congestion. Which type of attack is this?

Hard
90

A security auditor is reviewing the configuration of a remote access VPN. Which TWO features are considered best practices for securing the VPN connection?

Medium
91

A security administrator is reviewing a network diagram and identifies several controls intended to reduce the attack surface of a demilitarized zone (DMZ). Which TWO controls best limit the impact of a compromised DMZ host on the internal network? (Choose two.)

Hard
92

An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?

Medium
93

A security engineer is hardening a data center network against VLAN hopping attacks. The core switches currently use 802.1Q trunking on all inter-switch links, and unused access ports are left in the default VLAN. Which configuration change best mitigates VLAN hopping while preserving legitimate trunk operation?

Hard
94

Which TWO of the following are characteristics of a Smurf attack? (Select TWO)

Medium
95

During a penetration test, a security analyst captures a packet containing a gratuitous ARP reply that associates the attacker's MAC address with the default gateway's IP address. This is a classic indicator of which attack?

Hard
96

A security engineer is deploying a Network Intrusion Detection System (NIDS) on a switched network. The engineer needs to ensure the NIDS can monitor all traffic passing through a critical switch port that connects to a server. Which technology should be configured on the switch to copy traffic from the server port to the NIDS monitoring port?

Hard
97

A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?

Hard
98

During a security audit, a penetration tester successfully extracts the PMKID from a wireless beacon. What information can be derived from this attack?

Hard
99

Which of the following network protocols operates on TCP port 22 and provides secure remote administration of network devices?

Easy
100

A network administrator is configuring a demilitarized zone (DMZ) to host a public web server. The server must be accessible from the internet but should be isolated from the internal network. Which of the following is the primary security benefit of placing the web server in a DMZ?

Easy

Frequently asked questions

What does the Network and Communications Security domain cover on the SSCP exam?
Map each scenario to its exact protocol and OSI layer, then name the attack or control precisely. The critical skill is distinguishing Layer 2 attacks (ARP, DHCP, MAC) from higher-layer ones and knowing which VPN or TLS feature the question describes.
How many questions are in this domain?
This page lists all 100 Network and Communications Security questions in the SSCP question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Network and Communications Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-sscp ISC2-SSCP sscp network security Practice Questions