Courseiva

CCNA Network and Communications Security Questions

75 of 100 questions · Page 1/2 · Network and Communications Security · Answers revealed

1
MCQhard

A security engineer is configuring a site-to-site VPN between two branch offices using IPsec in tunnel mode. Which protocol provides both authentication and encryption of the entire original IP packet?

A.IKEv2 in transport mode
B.ESP (Encapsulating Security Payload) in tunnel mode
C.L2TP in tunnel mode
D.AH (Authentication Header) in tunnel mode
AnswerB

ESP in tunnel mode encapsulates the entire original IP packet and applies both encryption and authentication, satisfying the stem's dual requirement. AH provides authentication only, without confidentiality, so it cannot encrypt payloads. ESP's tunnel encapsulation also hides original source and destination addresses, which transport mode does not.

Why this answer

ESP (Encapsulating Security Payload) in tunnel mode encrypts and authenticates the entire original IP packet, then encapsulates it inside a new IP packet with new headers. This provides confidentiality, integrity, and origin authentication for the payload, making it the standard choice for site-to-site VPNs.

Exam trap

SSCP often tests the AH vs. ESP distinction — the trap is selecting AH for 'authentication' when the question also requires encryption, which only ESP provides.

How to eliminate wrong answers

Option A is wrong because IKEv2 is a key-exchange protocol (used to negotiate SAs), not a data-encryption protocol, and transport mode does not encapsulate the original IP header. Option C is wrong because L2TP provides no encryption on its own — it is typically paired with IPsec for confidentiality. Option D is wrong because AH provides authentication and integrity but no encryption, so it cannot satisfy the 'encryption' requirement.

2
Multi-Selecthard

A security analyst is reviewing a TLS 1.3 deployment. Which THREE of the following are features of TLS 1.3?

Select 3 answers
A.Use of static RSA key exchange
B.Mandatory forward secrecy
C.Support for 0-RTT handshake
D.Removal of cipher suites like RC4 and DES
E.Support for SSL 3.0 compatibility
AnswersB, C, D

TLS 1.3 removes static RSA and plain Diffie-Hellman key exchange, leaving only ephemeral (EC)DHE and PSK modes. Every session therefore derives unique keys, so forward secrecy is mandatory rather than optional as in TLS 1.2.

Why this answer

Option B is correct because TLS 1.3 mandates forward secrecy by eliminating static RSA and static Diffie-Hellman key exchange, requiring ephemeral key exchanges (ECDHE or DHE) so that compromise of long-term keys cannot decrypt past sessions. Option C is correct because TLS 1.3 introduces a 0-RTT (early data) mode using PSK resumption, allowing the client to send application data in the first flight, though it carries replay risk. Option D is correct because TLS 1.3 removes all legacy cipher suites based on RC4, DES/3DES, CBC-mode, and MD5/SHA-1, restricting the protocol to AEAD ciphers such as AES-GCM, ChaCha20-Poly1305, and AES-CCM.

Option A is not correct because static RSA key exchange was explicitly removed in TLS 1.3, since it lacks forward secrecy. Option E is not correct because TLS 1.3 does not support SSL 3.0 compatibility; SSL 3.0 was already deprecated and TLS 1.3 removed backward compatibility with such legacy protocols.

Exam trap

SSCP often tests the misconception that TLS 1.3 is backward compatible with SSL 3.0 or that static RSA remains an option — candidates who confuse TLS 1.2 features with TLS 1.3 pick A or E.

3
MCQmedium

An attacker sends a forged ARP reply associating the attacker's MAC address with the IP address of the default gateway. What type of attack is this?

A.ARP spoofing
B.MAC flooding
C.DHCP starvation
D.DNS poisoning
AnswerA

ARP spoofing fits because the attacker forges an ARP reply, binding their MAC address to the gateway's IP. This poisons the victim's ARP cache, redirecting traffic through the attacker for interception. The stem's defining constraint — a falsified ARP reply impersonating the default gateway — is precisely ARP spoofing, not DNS or IP spoofing.

Why this answer

ARP spoofing (also called ARP cache poisoning) is the attack in which a malicious host sends forged ARP replies to bind its own MAC address to the IP address of a legitimate host — here, the default gateway. Because ARP has no authentication mechanism, victims update their ARP caches with the attacker's MAC, causing traffic destined for the gateway to flow through the attacker, enabling man-in-the-middle interception.

Exam trap

The trap here is confusing layer-2 attacks: candidates may pick MAC flooding because it also involves MAC addresses, but only ARP spoofing forges the IP-to-MAC binding of the gateway.

How to eliminate wrong answers

Option B is wrong because MAC flooding overwhelms a switch's CAM table with bogus source MAC addresses, forcing the switch to flood frames out all ports — it does not forge ARP replies or impersonate a gateway. Option C is wrong because DHCP starvation exhausts a DHCP server's address pool by requesting all available leases with spoofed MACs, causing denial of service rather than gateway impersonation. Option D is wrong because DNS poisoning corrupts DNS resolver caches to redirect name resolution to attacker-controlled IPs, which operates at the DNS layer, not the ARP/L2 layer.

4
MCQeasy

Which TCP port is commonly used for secure web traffic (HTTPS) and is often allowed through firewalls for web browsing?

A.22
B.443
C.80
D.3389
AnswerB

TCP 443 carries HTTPS, using TLS to encrypt web traffic. Firewalls commonly permit it outbound so users can browse securely, satisfying the stem's requirement. Port 80 is unencrypted HTTP, while 22 and 25 serve SSH and SMTP respectively.

Why this answer

HTTPS uses TCP port 443 by default, as defined in RFC 2818. Firewalls commonly allow outbound TCP 443 to permit secure web browsing, and it is the standard port for TLS-encrypted HTTP traffic.

Exam trap

The trap is confusing port 80 (HTTP) with port 443 (HTTPS); candidates may pick 80 because it is the well-known web port, but the question specifically asks for secure web traffic.

How to eliminate wrong answers

Option A is wrong because port 22 is used for SSH (Secure Shell), not HTTPS. Option C is wrong because port 80 is used for plain HTTP, which is unencrypted and not considered secure web traffic. Option D is wrong because port 3389 is used for RDP (Remote Desktop Protocol), not web traffic.

5
MCQmedium

An organization wants to ensure that only authorized devices can connect to the corporate wired network. Which technology should they implement to enforce this?

A.Network Access Control (NAC) with 802.1X
B.VLAN segmentation
C.MAC address filtering
D.Firewall rules
AnswerA

802.1X port-based authentication requires a supplicant to authenticate against a RADIUS server before the switch port grants access, and NAC enforces the resulting policy. Together they ensure only authorised, compliant devices can connect to the wired network.

Why this answer

Network Access Control (NAC) with 802.1X authenticates devices before granting network access, enforcing compliance and authorization.

6
MCQmedium

A network administrator is tasked with segmenting the network to isolate a DMZ containing public-facing web servers from the internal corporate network. Which device should be placed between the DMZ and internal network, and what type of traffic should it allow?

A.Router; allow all traffic but use NAT.
B.IDS; monitor traffic but do not block.
C.Firewall; allow only specific traffic from internal to DMZ and block DMZ-initiated connections to internal.
D.Switch; allow all traffic between DMZ and internal network.
AnswerC

A firewall between the DMZ and internal network enforces stateful rules permitting only specific internal-to-DMZ traffic while blocking DMZ-initiated connections inward. This satisfies the segmentation requirement, containing a compromised public-facing web server so it cannot pivot into the corporate network.

Why this answer

A firewall is the correct segmentation control between a DMZ and the internal network because it enforces stateful policy that permits only specific, necessary flows (typically internal-initiated sessions to DMZ services) while blocking DMZ-initiated connections inbound to the internal network. This prevents a compromised public-facing web server from pivoting into the corporate LAN. The directional rule set is the key security property being tested.

Exam trap

SSCP often tests the misconception that NAT or an IDS provides segmentation — only a firewall (or equivalent policy-enforcing device) can block DMZ-initiated traffic into the internal network.

How to eliminate wrong answers

Option A is wrong because a router with NAT provides address translation, not security policy — NAT is not a security control and 'allow all traffic' defeats segmentation. Option B is wrong because an IDS is passive and only detects/alerts; it cannot block DMZ-to-internal traffic, so it fails the isolation requirement. Option D is wrong because a switch forwards frames within a broadcast domain and provides no policy enforcement between the DMZ and internal network, allowing unrestricted lateral movement.

7
MCQeasy

A network administrator is configuring a switch to prevent unauthorized devices from connecting to a specific switch port. The administrator wants to restrict access based on the device's MAC address. Which feature should be implemented?

A.Dynamic ARP Inspection (DAI)
B.Port security
C.VLAN pruning
D.Spanning Tree Protocol (STP)
AnswerB

Port security allows the administrator to specify which MAC addresses are allowed on a switch port. It can restrict access to a single MAC address or a limited number, and can take actions like shutting down the port if a violation occurs. This directly meets the requirement to prevent unauthorized devices based on MAC address.

Why this answer

Port security is the switch feature that restricts access to a port based on MAC addresses. It can be configured to allow only specific MAC addresses or a maximum number of addresses. When a violation occurs, the switch can drop packets, send an alert, or shut down the port.

This effectively prevents unauthorized devices from connecting.

Exam trap

The trap here is confusing port security with other switch security features like DAI, which protect against specific attacks but do not control port access based on MAC addresses.

8
Multi-Selectmedium

A network administrator is troubleshooting a DNS poisoning attack. Which TWO countermeasures can help prevent such attacks? (Select two)

Select 2 answers
A.Implement DNSSEC to validate DNS responses
B.Configure firewall rules to block UDP port 53
C.Disable DNS recursion on authoritative servers
D.Use secure DNS resolvers that enforce DNSSEC validation
E.Enable DHCP snooping on switches
AnswersA, D

DNSSEC cryptographically signs DNS records, letting resolvers verify responses originated from the authoritative zone and were not altered in transit. This directly defeats cache poisoning, where forged replies redirect users to attacker-controlled addresses, satisfying the stem's requirement to prevent spoofed DNS data from being trusted.

Why this answer

Option A (Implement DNSSEC to validate DNS responses) is correct because DNSSEC adds cryptographic signatures (RRSIG) to DNS records so a resolver can verify authenticity and integrity, preventing forged or spoofed records from being accepted during a poisoning attack. Option D (Use secure DNS resolvers that enforce DNSSEC validation) is correct because even with DNSSEC deployed, the resolver must actually perform validation of the chain of trust (via DS/DNSKEY records) to reject bogus answers; resolvers that enforce validation stop poisoned data from reaching clients. Option B is wrong because blocking UDP port 53 would break legitimate DNS resolution entirely rather than prevent poisoning.

Option C is wrong because disabling recursion on authoritative servers is a general hardening practice but does not by itself prevent cache poisoning of recursive resolvers. Option E is wrong because DHCP snooping protects against rogue DHCP servers and Layer 2 attacks, not DNS cache poisoning.

Exam trap

SSCP often tests the confusion between DNSSEC (integrity/authenticity) and encryption (DoH/DoT), and candidates may pick 'block port 53' as a quick fix, not realizing it breaks DNS entirely.

9
Multi-Selectmedium

A security analyst is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of a SYN flood attack. The analyst wants to generate alerts when the number of half-open connections exceeds a threshold. Which TWO of the following metrics are MOST relevant for detecting a SYN flood? (Choose two.)

Select 2 answers
A.Number of SYN packets received per second
B.Number of established connections
C.Number of half-open connections
D.Number of ICMP echo requests
E.Number of RST packets sent
AnswersA, C

A high rate of SYN packets is a primary indicator of a SYN flood, as the attacker sends many SYN requests to exhaust the target's connection table. Monitoring the rate of SYN packets helps detect the initial phase of the attack. However, it must be correlated with other metrics to avoid false positives from legitimate traffic spikes.

Why this answer

A SYN flood is characterized by a high volume of SYN packets and a corresponding increase in half-open connections. Monitoring these two metrics allows the NIDS to detect the attack by recognizing the abnormal rate of SYNs and the accumulation of incomplete handshakes. The other metrics do not directly reflect the mechanics of a SYN flood and would not provide reliable detection.

Exam trap

The trap here is confusing SYN floods with other types of floods (e.g., ICMP or UDP) and focusing on metrics that are not specific to TCP half-open connections.

10
MCQmedium

Which security control can prevent a rogue DHCP server from assigning incorrect gateway addresses to clients?

A.IP source guard
B.Dynamic ARP inspection
C.Port security
D.DHCP snooping
AnswerD

DHCP snooping designates trusted ports and filters server replies on untrusted ones, so a rogue DHCP server cannot hand out a falsified default gateway. This directly satisfies the stem's constraint of preventing incorrect gateway assignment.

Why this answer

DHCP snooping is a switch feature that filters DHCP messages based on trusted ports, blocking rogue DHCP servers.

11
MCQmedium

A network architect is designing a demilitarized zone (DMZ) for a company that hosts a public web server and an internal database. The architect must ensure that if the web server is compromised, the attacker cannot directly access the internal database. Which DMZ design principle should be applied?

A.Implement a single firewall with three interfaces: internet, DMZ, and internal network, with rules allowing any traffic between DMZ and internal.
B.Allow all traffic from the DMZ to the internal network to ensure the web server can retrieve data from the database.
C.Use a screened subnet with two firewalls: an external firewall between the internet and DMZ, and an internal firewall between DMZ and internal network.
D.Place the database in the same DMZ as the web server to simplify firewall rules.
AnswerC

A screened subnet with dual firewalls creates two distinct security boundaries. The external firewall controls internet-to-DMZ traffic, while the internal firewall restricts DMZ-to-internal traffic. Even if the web server is compromised, the attacker must bypass the internal firewall to reach the database. This layered defense enforces segmentation and is a best practice for DMZ design.

Why this answer

Using a screened subnet with two firewalls provides defense in depth: the external firewall protects the DMZ from the internet, and the internal firewall protects the internal network from the DMZ. If the web server is compromised, the attacker still faces the internal firewall, which should only allow specific traffic to the database. Placing the database in the DMZ or allowing unrestricted DMZ-to-internal traffic would eliminate this protection.

Exam trap

The trap here is thinking that a single firewall with multiple interfaces is inherently insecure, but the real issue is the rule set; however, the dual-firewall design provides a clearer separation of duties and is a stronger recommendation.

12
MCQhard

Which of the following best describes the function of SYN cookies in mitigating SYN flood attacks?

A.They block all incoming SYN packets from suspicious sources.
B.They encode connection state in the SYN-ACK sequence number, allowing the server to avoid storing state until the ACK is received.
C.They increase the backlog queue size to accommodate more half-open connections.
D.They require clients to solve a computational puzzle before completing the handshake.
AnswerB

SYN cookies encode connection state within the SYN-ACK sequence number, so the server holds no state until the client's ACK returns. This removes the half-open connection table exhaustion that defines a SYN flood, satisfying the stem's mitigation requirement.

Why this answer

SYN cookies encode the connection state (such as sequence numbers and timestamps) into the initial sequence number of the SYN-ACK. This allows the server to avoid allocating resources until the final ACK is received, mitigating SYN flood attacks that exhaust the backlog queue.

Exam trap

The trap is confusing SYN cookies with other DoS mitigation techniques like rate limiting or CAPTCHAs, leading candidates to pick options that involve blocking or puzzles.

How to eliminate wrong answers

Option A is wrong because SYN cookies do not block SYN packets; they allow the handshake to proceed without storing state. Option C is wrong because increasing the backlog queue only delays the exhaustion and does not address the root cause. Option D is wrong because computational puzzles are used in proof-of-work systems, not SYN cookies.

13
MCQeasy

Which attack sends a flood of forged ICMP echo requests to a network's broadcast address to overwhelm a target?

A.Ping of death
B.Smurf attack
C.SYN flood
D.DNS amplification
AnswerB

A Smurf attack spoofs the victim's source address and sends ICMP echo requests to a network broadcast address, so every host replies to the victim, amplifying traffic. This matches the stem's forged ICMP flood against a broadcast address.

Why this answer

A Smurf attack sends a flood of forged ICMP echo requests to a network's broadcast address with the source IP spoofed as the target's IP. All hosts on the network respond to the broadcast, overwhelming the target with ICMP echo replies. This is a classic amplification attack.

Therefore, Smurf attack is correct.

Exam trap

SSCP often tests the distinction between various flood attacks, and candidates might confuse Smurf with SYN flood or DNS amplification due to the common element of flooding.

How to eliminate wrong answers

Option A is wrong because Ping of death involves sending malformed or oversized ICMP packets to crash a system, not a flood to a broadcast address. Option C is wrong because a SYN flood sends TCP SYN packets to a target to exhaust its connection table, not ICMP to a broadcast address. Option D is wrong because DNS amplification uses DNS queries with spoofed source IPs to overwhelm a target with DNS responses, not ICMP.

14
MCQhard

A security analyst notices that an attacker on the same VLAN is able to capture traffic from other hosts, including sensitive data. The attacker has not compromised any switch or router. Which network attack is most likely being used?

A.ARP spoofing
B.MAC flooding
C.VLAN hopping
D.DHCP starvation
AnswerA

ARP spoofing sends forged ARP replies to associate the attacker's MAC address with the IP address of another host, such as the default gateway. This causes traffic to be sent to the attacker, who can then forward it to the legitimate destination while capturing it, enabling man-in-the-middle without switch compromise.

Why this answer

ARP spoofing, also called ARP poisoning, allows an attacker on the same subnet to intercept traffic by sending forged ARP messages. The attacker can then forward traffic to the real destination while capturing it, achieving a man-in-the-middle attack without compromising network devices.

Exam trap

The trap here is assuming that capturing traffic requires a compromised switch or router, when ARP spoofing can achieve it at the endpoint level.

15
Multi-Selecthard

Which THREE of the following are valid considerations when deploying a remote access VPN using SSL/TLS? (Select THREE)

Select 3 answers
A.Typically uses UDP port 500
B.Supports endpoint security posture checks
C.Can be configured for split tunneling
D.Can traverse firewalls more easily than IPsec
E.Requires pre-shared keys for authentication
AnswersB, C, D

Many SSL/TLS VPN gateways integrate host checks, verifying patch level, antivirus state and device compliance before granting tunnel access. This satisfies the stem's deployment consideration by enforcing endpoint posture at connection time, a control IPsec remote-access deployments typically require separate tooling to achieve.

Why this answer

Option B is correct because SSL/TLS VPNs (such as Cisco AnyConnect or Fortinet SSL VPN) commonly integrate host-scanning or posture-assessment modules that verify antivirus, patch level, and firewall status on the endpoint before granting access. Option C is correct because SSL/TLS VPN clients can be configured for split tunneling, allowing only traffic destined for corporate subnets to go through the tunnel while other traffic (e.g., internet browsing) goes directly out the local gateway. Option D is correct because SSL/TLS VPNs typically operate over TCP port 443 (HTTPS), which is almost universally permitted through firewalls and proxies, whereas IPsec requires UDP 500/4500 and ESP (protocol 50), which are frequently blocked.

Option A is incorrect because UDP port 500 is used by IKE for IPsec, not by SSL/TLS VPNs. Option E is incorrect because SSL/TLS VPNs authenticate users via certificates, RADIUS, LDAP, or SAML, and pre-shared keys are characteristic of IPsec, not SSL/TLS VPNs.

Exam trap

SSCP often tests whether candidates can distinguish SSL/TLS VPN characteristics from IPsec characteristics — mixing up ports (UDP 500 vs TCP 443) and authentication methods (PSK vs certificates/SAML) is the common error.

16
MCQmedium

Which wireless security protocol uses the Simultaneous Authentication of Equals (SAE) handshake to replace the Pre-Shared Key (PSK) method and provides stronger protection against offline dictionary attacks?

A.WPA2
B.WPA
C.WPA3
D.WEP
AnswerC

WPA3 replaces the pre-shared key handshake with Simultaneous Authentication of Equals, a dragonfly-based exchange that resists offline dictionary attacks. This directly satisfies the requirement for a protocol using SAE instead of PSK, unlike WPA2's four-way handshake.

Why this answer

WPA3 introduces Simultaneous Authentication of Equals (SAE), a Dragonfly-based handshake that replaces the WPA2 four-way handshake's PSK exchange. SAE provides forward secrecy and resists offline dictionary attacks because each session derives a unique key, so captured handshakes cannot be brute-forced offline.

Exam trap

SSCP often tests the difference between WPA2's 4-way handshake (vulnerable to offline dictionary attacks) and WPA3's SAE (resistant) — candidates pick WPA2 thinking it already includes SAE.

How to eliminate wrong answers

Option A is wrong because WPA2 uses the 4-way handshake with PSK (or 802.1X), which is vulnerable to offline dictionary attacks against captured handshakes (e.g., via hashcat against the PMKID or 4-way handshake). Option B is wrong because WPA (original) uses TKIP and a weaker PSK-based handshake, also vulnerable to offline attacks. Option D is wrong because WEP uses RC4 with static keys and is trivially broken — it has no SAE or modern handshake at all.

17
MCQeasy

Which of the following is a connectionless transport layer protocol primarily used for services like DNS and DHCP?

A.UDP
B.IP
C.TCP
D.ICMP
AnswerA

UDP operates without establishing a session, sending datagrams independently with no handshake, acknowledgement, or retransmission. This connectionless design satisfies the stem's requirement, and its low overhead suits DNS and DHCP, which favour speed over guaranteed delivery. TCP, by contrast, is connection-oriented and would add unnecessary latency.

Why this answer

UDP (User Datagram Protocol) is a connectionless transport layer protocol that does not establish a session before sending data. It is used for services like DNS and DHCP because they require fast, lightweight communication without the overhead of TCP's three-way handshake. UDP operates at Layer 4 of the OSI model.

Exam trap

SSCP often tests the distinction between transport layer protocols (TCP/UDP) and network layer protocols (IP/ICMP), and candidates may incorrectly select IP or ICMP as transport layer protocols.

How to eliminate wrong answers

Option B is wrong because IP (Internet Protocol) is a network layer protocol, not a transport layer protocol, and it is connectionless but not used for transport-layer services like DNS and DHCP directly. Option C is wrong because TCP (Transmission Control Protocol) is connection-oriented and establishes a session, which adds overhead not suitable for DNS and DHCP. Option D is wrong because ICMP (Internet Control Message Protocol) is a network layer protocol used for diagnostic and error messages, not for transport-layer services.

18
MCQmedium

A security administrator is configuring a VPN between two branch offices. The requirement is to encrypt the entire original IP packet and add a new IP header for routing over the internet. Which IPsec mode should be used?

A.Aggressive mode
B.Transport mode
C.Main mode
D.Tunnel mode
AnswerD

Tunnel mode encapsulates the entire original IP packet, including its header, then prepends a new IP header for routing across the internet. Transport mode encrypts only the payload, so tunnel mode satisfies the stated requirement.

Why this answer

Tunnel mode encapsulates the entire original IP packet — including its original header — inside a new IP packet with a new header, which is exactly what is required for site-to-site VPNs between branch offices. The new header carries the tunnel endpoint addresses so the encrypted payload can be routed across the public internet, and the original packet is restored on decapsulation.

Exam trap

SSCP often tests the confusion between IKE Phase 1 modes (main/aggressive) and IPsec encapsulation modes (transport/tunnel) — candidates pick aggressive or main mode thinking they describe packet wrapping.

How to eliminate wrong answers

Option A is wrong because aggressive mode is an IKE Phase 1 negotiation mode (fewer messages, no identity protection), not an IPsec encapsulation mode — it does not describe how packets are wrapped. Option B is wrong because transport mode encrypts only the payload and leaves the original IP header intact, which is used for host-to-host traffic, not for routing between two private networks over the internet. Option C is wrong because main mode is also an IKE Phase 1 exchange mode providing identity protection, not a packet encapsulation mode.

19
MCQeasy

Which UDP port is used by the Domain Name System (DNS) for name resolution queries?

A.UDP 161
B.UDP 67
C.UDP 53
D.UDP 123
AnswerC

DNS name resolution queries use UDP port 53 for standard lookups, with TCP 53 reserved for zone transfers and responses exceeding 512 bytes. This satisfies the stem's requirement for the specific UDP port used in resolution queries.

Why this answer

DNS uses UDP port 53 for standard name resolution queries because the request and response are small and UDP's low overhead is ideal for the query-response pattern. TCP port 53 is used only for zone transfers (AXFR/IXFR), DNSSEC responses exceeding 512 bytes, or when the TC (truncated) bit forces a TCP retry.

Exam trap

The trap here is confusing DNS with other common UDP services — candidates who memorize port numbers loosely may pick UDP 67 (DHCP) or UDP 123 (NTP) under time pressure.

How to eliminate wrong answers

Option A is wrong because UDP 161 is used by SNMP for polling and management queries, not DNS. Option B is wrong because UDP 67 is used by DHCP servers to assign IP addresses to clients (with UDP 68 on the client side). Option D is wrong because UDP 123 is used by NTP for time synchronization.

20
MCQeasy

Which protocol and port combination is commonly used for secure remote administration of a server?

A.HTTPS on TCP 443
B.Telnet on TCP 23
C.RDP on TCP 3389
D.SSH on TCP 22
AnswerD

SSH on TCP 22 encrypts the entire remote administration session, including credentials and commands, satisfying the requirement for secure remote server management. Unlike Telnet on port 23, which transmits data in cleartext, SSH provides confidentiality and integrity through cryptographic tunnelling, making it the standard choice for hardened administrative access.

Why this answer

SSH on TCP port 22 is the standard protocol for secure remote administration of Linux/Unix servers, providing encrypted authentication and session traffic. It replaces insecure protocols like Telnet and rlogin by encrypting the entire session, including credentials, using strong ciphers and key exchange.

Exam trap

SSCP often tests the confusion between secure web management (HTTPS) and secure command-line administration (SSH) — candidates pick HTTPS because it is 'secure' but it is not the remote shell protocol.

How to eliminate wrong answers

Option A is wrong because HTTPS on TCP 443 is used for secure web traffic and web-based management consoles, not for command-line remote administration of a server. Option B is wrong because Telnet on TCP 23 transmits credentials and data in cleartext and is considered insecure — it is not a secure remote administration protocol. Option C is wrong because RDP on TCP 3389 is a graphical remote desktop protocol for Windows systems; while it can be secured with TLS, it is not the commonly cited secure remote administration protocol in the SSCP context, and SSH is the canonical answer.

21
MCQmedium

A company wants to deploy a network IDS that can analyze traffic patterns and detect anomalies. Where should the IDS sensor be placed to monitor all traffic on a network segment without introducing latency?

A.Inline between the router and the switch
B.At the core switch as a transparent bridge
C.On the same segment as the router
D.Connected to a switch SPAN port
AnswerD

A SPAN port mirrors copies of frames from the monitored segment to the sensor, so the IDS analyses traffic passively without sitting inline in the forwarding path. This satisfies the requirement to monitor all segment traffic without introducing latency.

Why this answer

A SPAN (Switched Port Analyzer) port mirrors traffic from one or more switch ports or VLANs to a dedicated monitoring port, allowing the IDS sensor to receive a copy of the traffic passively. Because the sensor is not in the forwarding path, it introduces zero latency to production traffic while still seeing all frames on the monitored segment. This is the canonical out-of-band IDS deployment.

Exam trap

SSCP often tests the confusion between inline (IPS, adds latency) and out-of-band (IDS, passive) deployments — candidates pick 'inline' thinking it guarantees visibility, but it violates the no-latency requirement.

How to eliminate wrong answers

Option A is wrong because placing the IDS inline between router and switch puts it in the traffic path, adding latency and creating a single point of failure — that is an IPS deployment pattern, not a passive IDS. Option B is wrong because a transparent bridge at the core switch still forwards traffic through the device, introducing latency and risking outages. Option C is wrong because simply being on the same segment as the router does not guarantee visibility into all traffic — modern switched networks isolate unicast frames, so the sensor would only see broadcast/multicast.

22
MCQmedium

An attacker sends a gratuitous ARP reply associating the attacker's MAC address with the default gateway's IP address. Which attack is being performed, and what is the primary risk?

A.DNS poisoning; risk is traffic redirection to malicious sites.
B.DHCP starvation; risk is denial of service.
C.SYN flood; risk is resource exhaustion.
D.ARP spoofing; risk is man-in-the-middle traffic interception.
AnswerD

Gratuitous ARP replies let the attacker poison victims' ARP caches, binding the gateway's IP to the attacker's MAC. Traffic destined for the gateway is then redirected through the attacker, enabling man-in-the-middle interception and potential modification of communications.

Why this answer

A gratuitous ARP reply that binds the attacker's MAC to the gateway's IP is the classic ARP spoofing (ARP poisoning) attack. The victim's ARP cache is poisoned so traffic destined for the gateway is sent to the attacker, enabling man-in-the-middle interception, modification, or denial of service.

Exam trap

The trap is that gratuitous ARP sounds like a DNS or DHCP concept to candidates unfamiliar with layer 2 attacks — the key discriminator is that the attack manipulates MAC-to-IP bindings in the ARP cache, which points to ARP spoofing, not DNS or DHCP attacks.

How to eliminate wrong answers

Option A is wrong because DNS poisoning corrupts DNS resolver caches to redirect domain name resolution, not ARP caches, and it does not involve MAC-to-IP binding at layer 2. Option B is wrong because DHCP starvation exhausts the DHCP pool by flooding DISCOVER requests with spoofed MACs, causing denial of service for legitimate clients — it does not involve gratuitous ARP or gateway impersonation. Option C is wrong because a SYN flood exhausts TCP connection state on a server by sending many half-open connections, which is a layer 4 DoS attack unrelated to ARP cache manipulation.

23
MCQmedium

A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?

A.Stateless packet filter
B.Stateful firewall
C.Application proxy firewall
D.Next-generation firewall
AnswerB

A stateful firewall maintains a connection state table, tracking each flow's context so return traffic and established sessions are evaluated against recorded states rather than static rules alone. This satisfies the requirement to make decisions based on the context of active traffic flows.

Why this answer

A stateful firewall tracks the state of active connections using a state table, so it can allow return traffic for an established session without an explicit inbound rule. This context-aware decision-making — matching packets to existing flows — is exactly what the requirement describes.

Exam trap

SSCP often tests the distinction between stateful inspection and application proxy inspection — candidates pick NGFW or proxy because they sound more advanced, missing the specific 'connection state' wording.

How to eliminate wrong answers

Option A is wrong because a stateless packet filter evaluates each packet in isolation against static ACLs and has no concept of connection state, so it cannot make context-based decisions. Option C is wrong because an application proxy firewall terminates and inspects traffic at Layer 7, which is more than the requirement asks for and is typically slower; the requirement is about connection state tracking, which is Layer 3/4 stateful inspection. Option D is wrong because a next-generation firewall adds application awareness, IPS, and threat intelligence on top of stateful inspection — it is a superset, not the precise answer to a question about state tracking.

24
MCQmedium

A company needs to provide secure remote access for employees working from home. The security team wants to ensure the solution provides strong authentication and encryption, and supports a wide range of client devices without requiring proprietary software. Which technology should they implement?

A.Secure Shell (SSH) tunneling
B.Remote Desktop Protocol (RDP) with TLS
C.IPsec VPN with IKEv2
D.File Transfer Protocol Secure (FTPS)
AnswerC

IKEv2 is a robust VPN protocol that supports strong encryption and authentication, and is widely supported on many devices including mobile platforms. It can be used with various authentication methods such as certificates, EAP, and pre-shared keys. It does not require proprietary software, as it is built into most modern operating systems. Therefore, it meets the requirements for secure remote access with broad compatibility.

Why this answer

IKEv2 is a modern VPN protocol that offers strong security and is widely supported across devices without proprietary clients. It supports various authentication methods and is efficient in reconnecting after network changes, making it ideal for mobile workers. The other options are either not full VPN solutions or are limited in scope.

Therefore, IKEv2 IPsec VPN is the correct choice.

Exam trap

The trap here is assuming that any encrypted remote access method, such as SSH or RDP, provides the same level of network access and security as a full VPN solution.

25
MCQmedium

A security engineer is reviewing a network architecture that uses IPsec in tunnel mode between two site gateways. The engineer must verify that the design provides confidentiality for the entire original IP packet. Which component of the IPsec architecture is responsible for encrypting the payload and providing confidentiality?

A.Encapsulating Security Payload (ESP)
B.Security Association (SA)
C.Internet Key Exchange (IKE)
D.Authentication Header (AH)
AnswerA

ESP is the IPsec component that provides confidentiality by encrypting the payload. In tunnel mode, ESP encrypts the entire original IP packet and encapsulates it within a new IP packet. Thus, it meets the requirement to protect the original packet's contents from eavesdropping.

Why this answer

In IPsec, ESP is the protocol that provides confidentiality by encrypting the payload. In tunnel mode, it encrypts the entire original IP packet, ensuring that the contents are protected. AH only provides integrity and authentication without encryption, while IKE and SAs are supporting components that establish and define security parameters but do not perform encryption.

Exam trap

The trap here is assuming that AH provides encryption because it is part of IPsec, but AH only offers integrity and authentication, not confidentiality.

26
MCQmedium

An attacker sends a flood of DHCP request packets with spoofed MAC addresses to exhaust the DHCP server's IP address pool, preventing legitimate clients from obtaining IP addresses. This attack is known as:

A.ARP poisoning
B.MAC flooding
C.DHCP starvation
D.DHCP spoofing
AnswerC

DHCP starvation exhausts the server's address pool by flooding it with requests bearing spoofed MAC addresses, so no leases remain for legitimate clients. This matches the stem's constraint exactly: pool exhaustion via forged MAC addresses denying address assignment. Rogue DHCP servers and scope tampering describe different attacks, not pool depletion.

Why this answer

DHCP starvation exhausts the IP pool by sending many fake DHCP requests, leading to denial of service.

27
MCQmedium

Which wireless security standard introduced the Simultaneous Authentication of Equals (SAE) handshake to replace the pre-shared key (PSK) method?

A.802.11i
B.WEP
C.WPA3
D.WPA2
AnswerC

WPA3 introduced SAE, a dragonfly-based handshake providing forward secrecy and resisting offline dictionary attacks that PSK's four-way handshake permitted. SAE replaces the pre-shared key exchange while remaining compatible with password-based authentication, satisfying the requirement for a PSK replacement.

Why this answer

WPA3 replaced WPA2's PSK with SAE, which provides forward secrecy and is resistant to offline dictionary attacks.

28
MCQmedium

A network engineer is implementing a secure network design that requires separating the network into multiple segments to limit the scope of a potential breach. The engineer wants to ensure that even if one segment is compromised, the attacker cannot easily move laterally to other segments. Which of the following technologies should be implemented to achieve this?

A.Network Address Translation (NAT)
B.VLAN segmentation with ACLs
C.Demilitarized zone (DMZ)
D.Virtual Private Network (VPN)
AnswerB

VLANs logically separate network traffic at Layer 2, and ACLs on routers or Layer 3 switches can control traffic between VLANs. This creates distinct security zones and restricts lateral movement. If one VLAN is compromised, the attacker cannot freely access other VLANs without passing through the ACLs. This provides a strong segmentation strategy that meets the requirement. Therefore, VLAN segmentation with ACLs is the correct choice.

Why this answer

VLAN segmentation combined with ACLs allows the network to be divided into isolated logical segments with controlled traffic between them. This limits lateral movement because an attacker in one VLAN cannot access other VLANs without passing through the ACLs, which can be configured to deny unauthorized traffic. Other options like NAT, DMZ, and VPN do not provide the same level of internal segmentation and access control.

Exam trap

The trap here is assuming that any security technology that separates networks, such as a DMZ, provides the same internal segmentation as VLANs with ACLs.

29
Multi-Selectmedium

A company is designing a network with multiple security zones. Which TWO of the following are best practices for network segmentation? (Select TWO)

Select 2 answers
A.Place a firewall between each security zone to enforce traffic filtering.
B.Use a single flat network to reduce complexity.
C.Implement VLANs to logically separate traffic within a switch.
D.Disable logging on inter-zone firewalls to improve performance.
E.Place all servers in the same broadcast domain for easier management.
AnswersA, C

Placing a firewall between each zone enforces traffic filtering at every boundary, satisfying the segmentation requirement by preventing unrestricted lateral movement. Inter-zone traffic is inspected and permitted only per policy, containing breaches within a single zone.

Why this answer

Option A is correct because placing a firewall between each security zone enforces traffic filtering and access control at zone boundaries, which is the core principle of defense-in-depth segmentation — inter-zone traffic should be inspected and permitted only per policy rather than flowing freely. Option C is correct because VLANs (IEEE 802.1Q) logically separate traffic at Layer 2 within a switch, limiting broadcast domains and isolating hosts even when they share physical infrastructure, which is a standard segmentation technique. Option B is wrong because a single flat network removes all segmentation boundaries, allowing unrestricted lateral movement and broadcast propagation.

Option D is wrong because disabling logging on inter-zone firewalls destroys the audit trail and visibility needed to detect and investigate policy violations. Option E is wrong because putting all servers in one broadcast domain increases attack surface and broadcast traffic, directly contradicting segmentation best practices.

Exam trap

The trap here is confusing 'reducing complexity' with security best practice — flat networks are simpler but insecure, and candidates may pick them under time pressure.

30
MCQmedium

A system administrator notices a high number of half-open TCP connections to the company's web server. The server is becoming unresponsive. Which attack is likely occurring, and which mitigation is effective?

A.ARP spoofing; mitigation: static ARP entries.
B.Smurf attack; mitigation: disable IP broadcasts.
C.SYN flood; mitigation: enable SYN cookies.
D.Ping of death; mitigation: block fragmented ICMP packets.
AnswerC

A SYN flood exhausts the connection table with half-open handshakes, matching the observed symptom. SYN cookies remove that state by encoding the handshake in the sequence number, so the server no longer allocates resources before completion.

Why this answer

A SYN flood attack exploits the TCP three-way handshake by sending many SYN packets with spoofed source addresses, leaving the server with numerous half-open connections that exhaust the backlog queue. Enabling SYN cookies allows the server to avoid allocating state until the handshake completes, mitigating the flood. This matches the symptom of high half-open TCP connections and an unresponsive web server.

Exam trap

SSCP often tests the mapping between attack symptoms and mitigations — candidates see 'half-open connections' and may incorrectly associate it with ICMP-based attacks like Smurf or Ping of Death instead of TCP SYN flooding.

How to eliminate wrong answers

Option A is wrong because ARP spoofing is a Layer 2 man-in-the-middle attack that does not produce half-open TCP connections; static ARP entries mitigate spoofing, not SYN floods. Option B is wrong because a Smurf attack uses ICMP echo requests to a broadcast address with a spoofed source, amplifying traffic — it does not create half-open TCP connections. Option D is wrong because a Ping of Death relies on oversized or malformed ICMP fragments to crash a host, not on TCP handshake exhaustion.

31
MCQeasy

Which protocol is used for secure web browsing and operates on TCP port 443?

A.HTTPS
B.HTTP
C.SSH
D.FTP
AnswerA

HTTPS wraps HTTP inside TLS, encrypting web traffic and authenticating the server, and by convention listens on TCP port 443. That combination delivers the confidentiality and integrity required for secure browsing over the specified port.

Why this answer

HTTPS (HTTP over TLS) uses TCP port 443 and provides encrypted communication for websites.

32
MCQmedium

A security analyst discovers that an attacker has set up a fake wireless access point with the same SSID as the corporate network. Users are unknowingly connecting to it. What is this attack called?

A.KRACK
B.Rogue AP
C.Evil twin
D.PMKID attack
AnswerC

An evil twin is a rogue access point broadcasting the same SSID as the legitimate corporate network, often with a stronger signal, luring users into connecting so the attacker can intercept their traffic. This matches the stem's fake access point scenario exactly.

Why this answer

An evil twin is a rogue access point that impersonates a legitimate AP by broadcasting the same SSID (and often cloning the BSSID and security settings) to trick users into associating with it. Because clients auto-connect to known SSIDs, the attacker can harvest credentials, perform on-path (MITM) interception, or serve captive-portal phishing pages. The distinguishing feature is the deliberate imitation of a trusted network, which is exactly what the scenario describes.

Exam trap

The trap here is confusing the broad category 'rogue AP' with the specific impersonation attack 'evil twin' — the exam expects you to recognize that the matching SSID and user deception are the differentiators.

How to eliminate wrong answers

Option A is wrong because KRACK (Key Reinstallation Attack, CVE-2017-13077 and related) exploits the WPA2 4-way handshake to force nonce reuse and decrypt traffic — it does not involve standing up a fake AP with a matching SSID. Option B is wrong because 'rogue AP' is the broader umbrella term for any unauthorized AP on the network (e.g., an employee's personal hotspot); it does not specifically require spoofing a legitimate SSID to lure victims, which is the defining trait of the evil twin. Option D is wrong because a PMKID attack captures the PMKID from the RSN IE of the first EAPOL message to crack WPA2/WPA3 passphrases offline — it is a credential-cracking technique, not an AP impersonation attack.

33
MCQmedium

A security analyst is investigating a potential attack on a web application. The analyst observes that an attacker is sending specially crafted requests that cause the application to execute unintended commands on the underlying operating system. Which type of attack is this?

A.SQL injection
B.Cross-site scripting (XSS)
C.Command injection
D.Cross-site request forgery (CSRF)
AnswerC

Command injection occurs when an application passes unsafe user input to a system shell, allowing an attacker to execute arbitrary commands on the host operating system. The scenario describes crafted requests causing unintended OS command execution, which is the definition of command injection. This vulnerability often arises when applications use functions like system() or exec() without proper input sanitization.

Why this answer

Command injection is the correct answer because the scenario describes an attacker causing the application to execute unintended operating system commands. This occurs when user input is passed to a system shell without proper sanitization. XSS targets the browser, SQL injection targets the database, and CSRF tricks the user's browser into making requests.

None of these directly result in OS command execution as described.

Exam trap

The trap here is confusing command injection with SQL injection, as both involve injecting malicious input, but only command injection leads to OS command execution.

34
MCQhard

A security administrator is reviewing network traffic logs and notices a large number of TCP SYN packets from various source IP addresses to a single destination IP address on port 443. The destination server is unresponsive. Which type of attack is most likely occurring?

A.Teardrop attack
B.SYN flood
C.Ping flood
D.Smurf attack
AnswerB

A SYN flood is a type of denial-of-service attack where an attacker sends a succession of SYN requests to a target's system in an attempt to consume enough server resources to make the system unresponsive. The server allocates resources for each half-open connection, and when the attacker never completes the handshake, those resources are exhausted. The scenario describes many SYN packets from spoofed sources to one destination, which is characteristic of a SYN flood.

Why this answer

The scenario describes a large volume of TCP SYN packets from various sources to a single destination, resulting in an unresponsive server. This is indicative of a SYN flood attack, where the attacker sends numerous SYN requests but does not complete the TCP handshake, causing the server to exhaust its resources on half-open connections. Other attacks like Smurf, ping flood, or Teardrop involve different protocols or mechanisms and do not match the described traffic pattern.

Exam trap

The trap here is confusing a SYN flood with other volumetric attacks that also cause unresponsiveness but use different protocols, such as ICMP-based floods.

35
MCQhard

An organization is setting up a site-to-site VPN between two branch offices. They require encryption of the entire IP packet, including the original IP header, and plan to use IPsec. Which mode should they configure?

A.Transport mode
B.Tunnel mode
C.ESP mode
D.AH mode
AnswerB

Tunnel mode encapsulates the entire original IP packet inside a new IPsec packet, encrypting the original header as required. This satisfies the stem's whole-packet encryption constraint, whereas transport mode encrypts only the payload and leaves the original IP header intact.

Why this answer

Tunnel mode in IPsec encapsulates the entire original IP packet, including the original IP header, within a new IP packet with a new IP header. This provides confidentiality and integrity for the entire packet and is typically used for site-to-site VPNs between gateways. Transport mode only encrypts the payload, leaving the original IP header intact, which does not meet the requirement.

Exam trap

The trap is confusing IPsec modes (transport vs. tunnel) with protocols (ESP vs. AH). Candidates may select ESP or AH thinking they are modes, but the question specifically asks for the mode that encrypts the entire IP packet, which is tunnel mode.

How to eliminate wrong answers

Option A is wrong because Transport mode only protects the payload (e.g., TCP/UDP) and not the original IP header, so it does not encrypt the entire IP packet. Option C is wrong because ESP (Encapsulating Security Payload) is a protocol that can be used in either transport or tunnel mode; it is not a mode itself. Option D is wrong because AH (Authentication Header) provides authentication and integrity but not encryption, and it also can be used in transport or tunnel mode.

36
MCQmedium

A security administrator is configuring a network tap to monitor traffic between two switches. The tap is placed inline and must not disrupt network connectivity if it loses power. Which type of tap should be used?

A.Fail-to-wire tap
B.Span port
C.Aggregating tap
D.Network hub
AnswerA

A fail-to-wire tap, also known as a bypass tap, has a relay that closes and directly connects the two network segments if the tap loses power. This ensures that network traffic continues to flow uninterrupted, maintaining connectivity. This directly meets the requirement that the tap must not disrupt network connectivity if it loses power, making it the correct choice.

Why this answer

A fail-to-wire tap ensures that if the tap loses power, the connection between the two network segments is physically closed, allowing traffic to continue flowing. This maintains network availability. Other options like aggregating taps, SPAN ports, or hubs do not provide this fail-safe inline capability.

The requirement for non-disruption on power loss is specifically addressed by fail-to-wire functionality.

Exam trap

The trap here is confusing a SPAN port with an inline tap; SPAN ports are not inline and rely on switch resources, while fail-to-wire taps are inline and provide physical bypass.

37
Multi-Selecthard

An organization is deploying a network-based intrusion detection system (NIDS). The security team must decide on placement and configuration. Which THREE considerations are critical for effective NIDS deployment?

Select 3 answers
A.Using a network tap or SPAN port to monitor traffic without introducing latency
B.Placing the NIDS inline to block malicious traffic immediately
C.Configuring the NIDS to drop packets that match attack signatures
D.Placing the NIDS on the internal network behind the firewall to detect insider threats
E.Tuning signatures to reduce false positives relevant to the environment
AnswersA, D, E

A tap or SPAN port copies traffic to the NIDS passively, so monitoring introduces no inline latency or single point of failure. This satisfies the deployment constraint of inspecting traffic without disrupting production forwarding paths.

Why this answer

Option A is correct because a NIDS is a passive monitoring technology, so it must receive a copy of traffic via a network TAP or a switch SPAN/mirror port; this preserves the monitored link's performance and avoids introducing latency or a failure point. Option D is correct because placing the NIDS behind the firewall on internal segments lets it inspect east-west traffic and detect insider threats or compromised hosts that perimeter filtering would miss. Option E is correct because signature tuning is essential: enabling only signatures relevant to the environment's OS, applications, and protocols reduces false positives and alert fatigue, keeping the IDS effective.

Option B is not correct because inline placement is characteristic of an intrusion prevention system (IPS), not a NIDS, and it adds a potential latency and availability risk. Option C is not correct because dropping packets is an IPS blocking action; a NIDS only detects and alerts and cannot drop traffic.

Exam trap

SSCP often tests whether candidates confuse NIDS (detect and alert) with IPS (detect and block), leading them to select inline placement or packet-dropping options that are IPS characteristics.

38
MCQeasy

Which UDP port is used by the Dynamic Host Configuration Protocol (DHCP) for server communication?

A.161
B.69
C.53
D.67
AnswerD

DHCP servers listen on UDP port 67 for client requests, while clients use port 68 to receive replies. This satisfies the stem's requirement for the server-side communication port, distinguishing the server's listening socket from the client's response socket.

Why this answer

DHCP servers listen on UDP port 67 for client requests, while clients use UDP port 68. When a client broadcasts a DHCPDISCOVER message, it is sent from source port 68 to destination port 67. The server responds with a DHCPOFFER from port 67 to port 68.

Therefore, port 67 is the correct answer for server communication.

Exam trap

SSCP often tests the specific UDP port numbers for common protocols, and candidates frequently confuse DHCP server port 67 with client port 68 or with other well-known ports like 53 (DNS) or 69 (TFTP).

How to eliminate wrong answers

Option A is wrong because UDP port 161 is used by SNMP (Simple Network Management Protocol) for agent queries, not DHCP. Option B is wrong because UDP port 69 is used by TFTP (Trivial File Transfer Protocol) for file transfers, not DHCP. Option C is wrong because UDP port 53 is used by DNS (Domain Name System) for name resolution, not DHCP.

39
MCQhard

A network architect is designing a solution to protect against ARP spoofing attacks on a flat Layer 2 network. The architect wants to ensure that only valid IP-to-MAC address mappings are used by hosts. Which feature should be enabled on the switches?

A.802.1X authentication
B.DHCP snooping
C.Dynamic ARP Inspection (DAI)
D.Port security
AnswerC

Dynamic ARP Inspection (DAI) validates ARP packets on untrusted ports by comparing the IP-to-MAC binding against a trusted database, typically built by DHCP snooping. It drops ARP packets with invalid mappings, preventing ARP spoofing attacks. DAI is the specific feature designed to protect against ARP spoofing on Layer 2 switches, making it the correct choice for this scenario.

Why this answer

Dynamic ARP Inspection (DAI) is the switch feature specifically designed to prevent ARP spoofing by validating ARP packets against a trusted binding table. It drops packets with invalid IP-to-MAC mappings, ensuring that hosts only receive legitimate ARP information. The other options do not provide this capability, although DHCP snooping is often used to build the binding table that DAI relies on.

Exam trap

The trap here is confusing ARP spoofing mitigation with general Layer 2 security features like port security or DHCP snooping, which address different threats.

40
MCQmedium

A security engineer is configuring an IPsec VPN between two offices to protect data in transit. The requirement is to ensure that packets cannot be modified or replayed by an attacker. Which security service should be enabled in the IPsec configuration?

A.Secure Hash Algorithm 2 (SHA-2) in tunnel mode
B.Authentication Header (AH)
C.Internet Key Exchange (IKE) version 2
D.Encapsulating Security Payload (ESP) with confidentiality only
AnswerB

AH provides data integrity and authentication for IP packets, including protection against replay attacks by using a sequence number. It ensures that packets cannot be modified without detection. In this scenario, the requirement is specifically to prevent modification and replay, making AH the appropriate choice. However, AH does not provide confidentiality, so if encryption were also required, ESP would be needed.

Why this answer

The Authentication Header (AH) provides data integrity and authentication, and includes a sequence number to prevent replay attacks. In an IPsec VPN, AH ensures that packets cannot be altered in transit without detection. While ESP can also provide integrity and replay protection when configured with authentication, the scenario specifically asks for a service to prevent modification and replay, and AH is the dedicated protocol for that purpose.

ESP is more commonly used because it also offers confidentiality, but AH alone meets the stated requirement.

Exam trap

The trap here is assuming that ESP always provides integrity and replay protection, but ESP can be configured with confidentiality only, which lacks those services.

41
Multi-Selectmedium

A company is migrating from WPA2-PSK to WPA3 for its wireless network. Which THREE benefits does WPA3 provide compared to WPA2?

Select 3 answers
A.Mandatory use of Protected Management Frames (PMF)
B.Use of TKIP as the mandatory encryption protocol
C.Support for 192-bit security suite in Enterprise mode
D.Resistance to offline dictionary attacks through SAE
E.Backward compatibility with WEP devices
AnswersA, C, D

Protected Management Frames become mandatory in WPA3, whereas WPA2 left them optional. This closes the deauthentication and disassociation forgery attacks that WPA2 networks remained exposed to, directly satisfying the scenario's requirement for a security improvement over WPA2-PSK.

Why this answer

Option A is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protects management frames such as deauthentication and disassociation, preventing spoofing and denial-of-service attacks that remain possible under WPA2 where PMF is optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security mode based on CNSA Suite algorithms (GCMP-256, HMAC-SHA-384, ECDHE and ECDSA with 384-bit curves), providing stronger cryptographic protection than the standard WPA2-Enterprise 128-bit suite. Option D is correct because WPA3 replaces the WPA2-PSK 4-way handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that resists offline dictionary attacks by requiring live interaction with the AP for each guess.

Option B is incorrect because TKIP is a deprecated, legacy encryption protocol; WPA3 requires CCMP-128 at minimum and does not mandate TKIP. Option E is incorrect because WPA3 does not provide backward compatibility with WEP devices, which use the obsolete RC4-based WEP cipher and cannot negotiate WPA3 security.

Exam trap

SSCP often tests wireless security features. The trap is confusing WPA3 benefits with those of WPA2 or assuming backward compatibility with older protocols like WEP. Candidates must remember that WPA3 does not support WEP and that TKIP is not used in WPA3.

42
MCQeasy

Which of the following wireless security protocols uses AES-CCMP and is based on the 802.11i standard?

A.WEP
B.WPA
C.WPA2
D.WPA3
AnswerC

WPA2 implements the 802.11i amendment, mandating AES-CCMP for confidentiality and integrity, replacing WPA's weaker TKIP. This satisfies the stem's requirement for a protocol using AES-CCMP and based on 802.11i, unlike WEP's RC4 or WPA's TKIP.

Why this answer

WPA2 is the Wi-Fi Alliance certification that implements the IEEE 802.11i standard and mandates AES-CCMP for encryption and integrity. It replaced WPA's TKIP/RC4-based Temporal Key Integrity Protocol with the stronger AES block cipher in Counter Mode with CBC-MAC Protocol. This is why WPA2 is the correct answer for AES-CCMP plus 802.11i.

Exam trap

SSCP often tests the WPA vs. WPA2 distinction — candidates remember 'WPA2 is better' but forget that only WPA2 mandates AES-CCMP, while WPA is stuck on TKIP/RC4.

How to eliminate wrong answers

Option A is wrong because WEP uses RC4 with a static 40- or 104-bit key and a 24-bit IV, offering no real protection and predating 802.11i entirely. Option B is wrong because WPA was an interim fix that uses TKIP with RC4 and was designed to run on legacy hardware before 802.11i was ratified; it does not use AES-CCMP. Option D is wrong because WPA3, while newer and stronger, uses SAE (Simultaneous Authentication of Equals) for the handshake and GCMP-256 in WPA3-Enterprise, and it is based on the later 802.11-2016 amendments rather than the original 802.11i standard.

43
Multi-Selecthard

A security engineer is designing a network segmentation strategy to isolate a DMZ containing public-facing web servers from the internal corporate network. Which TWO controls should be implemented? (Select two)

Select 2 answers
A.Separate VLANs for DMZ and internal networks
B.A firewall that only permits necessary inbound traffic to the DMZ and restricts outbound traffic from the DMZ to internal
C.Network Access Control (NAC) on all endpoints
D.A separate IP subnet for the DMZ
E.An intrusion detection system (IDS) monitoring traffic between segments
AnswersA, B

Separate VLANs provide Layer 2 isolation, ensuring broadcast traffic and direct frame-level communication cannot pass between the DMZ web servers and internal hosts. This satisfies the segmentation requirement by enforcing distinct logical network boundaries, with inter-VLAN routing then controlled by a firewall applying least-privilege rules.

Why this answer

Option A is correct because placing the DMZ and internal network in separate VLANs provides Layer 2 segmentation, preventing broadcast traffic and direct frame-level communication between the two zones unless explicitly routed through a Layer 3 device. Option B is correct because a firewall enforcing least privilege between zones is the core segmentation control: it allows only required inbound traffic (e.g., TCP 443 to the web servers) into the DMZ and restricts outbound DMZ-to-internal traffic, blocking lateral movement if a public-facing server is compromised. Option D is not sufficient on its own because a separate IP subnet alone does not enforce traffic filtering; routing between subnets can still occur without a firewall policy.

Option C does not belong because NAC controls endpoint admission to the network and does not segment an existing DMZ from the internal network. Option E does not belong because an IDS only monitors and alerts on traffic; it does not enforce segmentation or block unauthorized flows.

Exam trap

SSCP often tests the difference between preventive and detective controls, and candidates may select IDS or NAC as segmentation controls when they are not.

44
MCQeasy

Which wireless security standard replaces WPA2 and mandates Protected Management Frames (PMF) to prevent certain types of attacks?

A.802.1X
B.WPA3
C.WEP
D.WPA2
AnswerB

WPA3 mandates Protected Management Frames, which authenticate and encrypt management frames so attackers cannot forge deauthentication or disassociation frames. WPA2 left these frames unprotected, enabling those denial-of-service and handshake-capture attacks. This mandatory PMF requirement is precisely the constraint the stem specifies.

Why this answer

WPA3 is the wireless security standard that replaces WPA2 and mandates Protected Management Frames (PMF) to prevent attacks such as deauthentication and disassociation. PMF provides integrity protection for management frames, which WPA2 did not require.

Exam trap

SSCP often tests the specific features that distinguish WPA3 from WPA2, and candidates may incorrectly associate PMF with WPA2 or confuse 802.1X with a wireless security standard.

How to eliminate wrong answers

Option A is wrong because 802.1X is an authentication framework for port-based network access control, not a wireless security standard that replaces WPA2. Option C is wrong because WEP is an outdated and insecure encryption protocol, not a replacement for WPA2. Option D is wrong because WPA2 is the predecessor to WPA3 and does not mandate PMF; PMF is optional in WPA2.

45
MCQmedium

A network administrator wants to block all inbound traffic except for web and email services. Which firewall rule configuration would achieve this?

A.Default-deny with allow rules for HTTP, HTTPS, and SMTP
B.Stateful inspection without default policy
C.Stateless packet filtering with a rule per service
D.Default-allow with deny rules for unwanted services
AnswerA

Default-deny drops all inbound packets unless a rule explicitly permits them, so only HTTP, HTTPS and SMTP traffic reaches the internal network. This satisfies the requirement to block everything else, since any protocol without a matching allow rule is discarded at the perimeter.

Why this answer

A default-deny with allow rules for HTTP, HTTPS, and SMTP is the correct approach because it blocks all inbound traffic except the specified services. This follows the principle of least privilege and ensures only necessary traffic is permitted.

Exam trap

SSCP often tests the concept of default-deny versus default-allow, and candidates may incorrectly believe that stateful inspection alone provides sufficient security without a default policy.

How to eliminate wrong answers

Option B is wrong because stateful inspection without a default policy leaves the firewall without a clear deny-all rule, potentially allowing unwanted traffic. Option C is wrong because stateless packet filtering with a rule per service may not explicitly deny all other traffic unless a default-deny rule is also present; the option does not mention a default-deny. Option D is wrong because default-allow with deny rules for unwanted services is less secure and more error-prone, as it allows all traffic except what is explicitly denied.

46
MCQhard

A security administrator is configuring a network intrusion detection system (NIDS) to monitor traffic for signs of attacks. The administrator wants to ensure the NIDS can detect attacks that involve fragmented packets. Which of the following should be enabled on the NIDS to reassemble fragmented packets before analysis?

A.TCP segmentation offload
B.IP defragmentation
C.Application layer gateway
D.Stream reassembly
AnswerB

IP defragmentation is the process of reassembling fragmented IP packets into complete packets before analysis. Attackers often use fragmentation to evade detection by splitting malicious payloads across multiple fragments. Enabling IP defragmentation on the NIDS allows it to reconstruct the original packet and inspect it for malicious content. This is essential for detecting fragmentation-based attacks, making it the correct choice.

Why this answer

IP defragmentation is necessary for a NIDS to reassemble fragmented IP packets before inspecting them. Fragmentation is a common evasion technique where attackers split malicious payloads across multiple packets to avoid detection. By enabling IP defragmentation, the NIDS can reconstruct the original packet and analyze it for threats.

Stream reassembly and other options do not address IP-layer fragmentation.

Exam trap

The trap here is confusing stream reassembly, which rebuilds TCP sessions, with IP defragmentation, which rebuilds fragmented IP packets.

47
MCQeasy

A small business wants to prevent employees from accessing known malicious websites without deploying a full next-generation firewall. The IT consultant recommends a service that filters DNS queries before they reach the public internet. Which technology is being described?

A.A web application firewall (WAF) placed in front of the company's public website.
B.A DNS filtering service that blocks resolution of known malicious domains.
C.An intrusion prevention system (IPS) deployed inline at the network perimeter.
D.A forward proxy that caches frequently visited web content.
AnswerB

DNS filtering intercepts name resolution requests and refuses to return addresses for domains on a threat intelligence blocklist. Because it operates at the resolution stage, it can prevent connections to malicious sites across all applications without installing a full firewall. This matches the consultant's recommendation and the small business constraint.

Why this answer

DNS filtering works by checking each name resolution request against a threat intelligence feed and returning a block response for known malicious domains. It requires no inline firewall, covers all applications that use DNS, and is simple to deploy for a small business. The other options address different layers or purposes and would not deliver the same lightweight outbound protection.

Exam trap

The trap here is assuming that any perimeter security device, such as an IPS or WAF, automatically performs DNS reputation filtering, when those controls inspect different traffic.

48
MCQmedium

A network administrator wants to prevent unauthorized devices from connecting to the wired network. Which technology can be used to enforce authentication at the switch port level before granting network access?

A.MAC address filtering
B.WPA2-Enterprise
C.VLAN segmentation
D.802.1X
AnswerD

802.1X enforces port-based network access control, requiring a supplicant to authenticate via EAP through the switch to a RADIUS server before any traffic passes. Unauthorised devices fail authentication, so the port stays blocked, satisfying the switch-port-level requirement.

Why this answer

802.1X is an IEEE standard for port-based network access control that authenticates devices before granting access to the wired network. It uses EAP over LAN to communicate with a RADIUS server, ensuring only authorized devices can connect. This directly enforces authentication at the switch port level.

Exam trap

SSCP often tests the confusion between wireless security (WPA2-Enterprise) and wired port security (802.1X), or the misconception that MAC filtering is sufficient for authentication.

How to eliminate wrong answers

Option A is wrong because MAC address filtering can be spoofed and does not provide strong authentication; it merely checks a hardware address. Option B is wrong because WPA2-Enterprise is for wireless networks, not wired switch ports. Option C is wrong because VLAN segmentation isolates traffic but does not authenticate devices before granting network access.

49
MCQmedium

A company is deploying a VPN for remote employees. They require strong encryption and authentication, and the solution must be compatible with native OS clients without additional software. Which VPN protocol is most appropriate?

A.PPTP
B.SSL VPN with proprietary client
C.IPsec with IKEv2
D.L2TP/IPsec with pre-shared keys
AnswerC

IPsec with IKEv2 provides strong encryption and authentication while being natively supported by Windows, macOS, iOS and Android VPN clients, so no third-party software is required. IKEv2 also reconnects quickly after network changes, suiting remote employees on unstable connections.

Why this answer

IPsec with IKEv2 is a modern VPN protocol that provides strong encryption and authentication, and it is natively supported by most operating systems (Windows, macOS, iOS, Android) without requiring additional client software. It supports flexible authentication methods including certificates and EAP, making it suitable for remote access.

Exam trap

SSCP often tests the trade-off between security and compatibility; candidates may overlook that IKEv2 is natively supported and choose L2TP/IPsec with PSK, which is less secure.

How to eliminate wrong answers

Option A is wrong because PPTP is outdated and has known security vulnerabilities; it does not provide strong encryption. Option B is wrong because an SSL VPN with a proprietary client requires additional software, violating the requirement for native OS compatibility. Option D is wrong because L2TP/IPsec with pre-shared keys is less secure than IKEv2 (PSK is a shared secret that can be compromised) and may require additional configuration, though it is natively supported; however, IKEv2 is more robust and recommended.

50
MCQeasy

A security administrator needs to securely transfer files between two servers over an untrusted network. The administrator wants to use a protocol that provides encryption and authentication and operates over TCP port 22. Which protocol should be used?

A.File Transfer Protocol (FTP)
B.Hypertext Transfer Protocol (HTTP)
C.Secure Shell (SSH) File Transfer Protocol (SFTP)
D.Trivial File Transfer Protocol (TFTP)
AnswerC

SFTP is a subsystem of SSH that operates over TCP port 22. It provides strong encryption and authentication for file transfers, protecting data in transit. It supports public key and password authentication and is widely used for secure file transfer. This matches the requirement to use TCP port 22 and ensures confidentiality and integrity.

Why this answer

SFTP is the correct protocol because it runs over SSH on TCP port 22, providing encryption and authentication for file transfers. FTP, TFTP, and HTTP are insecure and do not meet the requirements. SFTP ensures that data remains confidential and integrity-protected during transit, making it suitable for untrusted networks.

Exam trap

The trap here is confusing SFTP with FTPS or assuming that FTP can be secured with a simple configuration change.

51
MCQeasy

What is the default port for Microsoft SQL Server?

A.443
B.3389
C.1433
D.3306
AnswerC

Microsoft SQL Server listens on TCP port 1433 by default for client connections, satisfying the stem's request for the standard port. Named instances instead use dynamic ports via the SQL Server Browser service on UDP 1434, but a default instance answers on 1433 unless an administrator has reconfigured it.

Why this answer

Microsoft SQL Server's default instance listens on TCP port 1433 for client connections using the Tabular Data Stream (TDS) protocol. This is the well-known port assigned by IANA for SQL Server, and it is what clients use when connecting without specifying a port. Named instances, however, use dynamic ports and rely on the SQL Server Browser service on UDP 1434 to direct clients to the correct port.

Exam trap

SSCP often tests the confusion between default ports of common services, especially database systems like SQL Server (1433) and MySQL (3306), or remote access protocols like RDP (3389).

How to eliminate wrong answers

Option A is wrong because port 443 is the default for HTTPS (HTTP over TLS), not for SQL Server. Option B is wrong because port 3389 is used by Microsoft Remote Desktop Protocol (RDP) for remote desktop connections, not database traffic. Option D is wrong because port 3306 is the default port for MySQL and MariaDB, not Microsoft SQL Server.

52
MCQmedium

A network architect is evaluating a remote access design where users must authenticate with a hardware token and the session must be resistant to replay even if an attacker captures the encrypted traffic. Which protocol property should the architect prioritize?

A.Use of a shared static key for all sessions to simplify key management.
B.Split tunneling so only corporate traffic traverses the encrypted tunnel.
C.Per-session ephemeral keys established through a Diffie-Hellman exchange.
D.Pre-shared key authentication with AES-256 encryption in tunnel mode.
AnswerC

Ephemeral Diffie-Hellman produces a unique session key for each connection, so capturing one session does not reveal past or future keys and replay of old handshake data fails. Combined with the hardware token's one-time values, this provides the forward secrecy and replay resistance the architect needs. This is the property that directly satisfies the requirement.

Why this answer

Replay resistance and forward secrecy depend on fresh, per-session cryptographic material. Ephemeral Diffie-Hellman generates a unique key for each session, so a recorded handshake cannot be replayed against a new session and compromise of one key does not expose others. Static keys and strong bulk encryption alone do not provide these properties, and split tunneling is unrelated to the authentication exchange.

Exam trap

The trap here is equating strong bulk encryption such as AES-256 with replay protection, when replay resistance actually comes from fresh per-session key material and one-time authentication values.

53
MCQhard

Which attack exploits the lack of IV (Initialization Vector) randomness in the RC4 algorithm to recover the Wi-Fi password, and is considered completely broken?

A.WEP IV attack
B.PMKID attack
C.Evil twin attack
D.KRACK attack
AnswerA

WEP's RC4 implementation uses a short, non-random 24-bit IV, and its reuse enables the FMS and PTW statistical attacks to recover the keystream and derive the WEP key. This directly exploits the absent IV randomness named in the stem, making WEP completely broken.

Why this answer

The WEP IV attack exploits WEP's 24-bit IV, which is too short and reused frequently, allowing an attacker to collect enough packets to recover the RC4 keystream and derive the WEP key. WEP is considered completely broken and deprecated, and this attack (often implemented via tools like Aircrack-ng) is the classic demonstration of its weakness.

Exam trap

SSCP often tests the distinction between WEP IV attacks (RC4/IV reuse), PMKID (WPA2 handshake capture), and KRACK (WPA2 key reinstallation) — candidates confuse the underlying cryptographic flaw with the attack name.

How to eliminate wrong answers

Option B is wrong because the PMKID attack targets WPA/WPA2-PSK by capturing the PMKID from the RSN IE during association, not RC4 IV weaknesses in WEP. Option C is wrong because an evil twin attack is a rogue AP impersonating a legitimate one to lure clients, unrelated to RC4 IV randomness. Option D is wrong because KRACK (Key Reinstallation Attack) exploits the WPA2 4-way handshake by replaying message 3 to reinstall an already-in-use key, not RC4 IV reuse.

54
MCQhard

Which of the following is a characteristic of TLS 1.3 that improves security over previous versions?

A.Reduced cipher suite options including CBC mode
B.Use of RC4 cipher
C.Support for static RSA key exchange
D.Mandatory forward secrecy
AnswerD

TLS 1.3 mandates ephemeral key exchange for all cipher suites, so forward secrecy is compulsory rather than optional. This prevents an attacker who later obtains the server's long-term private key from decrypting previously captured session traffic.

Why this answer

TLS 1.3 mandates forward secrecy by removing static RSA and static Diffie-Hellman key exchange, requiring ephemeral key exchange (ECDHE) for every session. This means a compromised long-term private key cannot decrypt previously recorded sessions, which is a major security improvement over TLS 1.2 where static RSA was optional but allowed. This is codified in RFC 8446.

Exam trap

SSCP often tests whether candidates confuse 'reduced cipher suites' with 'removed CBC' — TLS 1.3 reduced suites by eliminating weak ones (CBC, RC4, static RSA), not by keeping them, and forward secrecy is the headline security gain.

How to eliminate wrong answers

Option A is wrong because TLS 1.3 actually removed CBC-mode cipher suites entirely, keeping only AEAD ciphers like AES-GCM and ChaCha20-Poly1305 — CBC was a source of padding-oracle attacks. Option B is wrong because RC4 was deprecated and removed; TLS 1.3 does not support RC4 at all. Option C is wrong because static RSA key exchange was explicitly removed in TLS 1.3 precisely to enforce forward secrecy — it is not supported.

55
MCQeasy

A company wants to protect its web servers from common web application attacks such as SQL injection and cross-site scripting. The security team decides to deploy a device that inspects HTTP traffic and blocks malicious requests. Which technology should they implement?

A.Unified Threat Management (UTM) appliance
B.Stateful firewall
C.Web Application Firewall (WAF)
D.Intrusion Prevention System (IPS)
AnswerC

A WAF is specifically designed to inspect HTTP/HTTPS traffic and block attacks like SQL injection and cross-site scripting. It operates at the application layer and can enforce security policies based on request patterns. Deploying a WAF directly addresses the requirement to protect web servers from these common web application attacks, making it the correct choice.

Why this answer

A Web Application Firewall (WAF) is purpose-built to inspect HTTP/HTTPS traffic and block application-layer attacks such as SQL injection and cross-site scripting. It understands web protocols and can apply rules to detect and mitigate these threats. Other options like IPS, stateful firewalls, or UTM appliances may offer some protection but are not as specialized or effective for web application security.

Exam trap

The trap here is assuming that a network IPS or stateful firewall can fully protect against web application attacks, but they lack the deep HTTP inspection capabilities of a WAF.

56
MCQmedium

An attacker sends a large number of DHCP request messages with spoofed MAC addresses to a network's DHCP server, causing the server to exhaust its IP address pool and deny service to legitimate clients. This attack is known as:

A.ARP spoofing
B.DNS poisoning
C.DHCP spoofing
D.DHCP starvation
AnswerD

DHCP starvation exhausts the server's address pool by flooding it with requests bearing spoofed MAC addresses, so each bogus request consumes a lease until no addresses remain for legitimate clients. This matches the stem's constraint exactly: pool exhaustion causing denial of service to genuine hosts.

Why this answer

DHCP starvation is an attack in which the attacker floods the DHCP server with DISCOVER/REQUEST messages using spoofed MAC addresses, exhausting the available IP address pool so legitimate clients cannot obtain a lease. The scenario described — pool exhaustion and denial of service to legitimate clients — is the textbook definition of DHCP starvation.

Exam trap

SSCP often tests the distinction between DHCP starvation (exhausting the pool) and DHCP spoofing (rogue server) — candidates conflate the two because both involve DHCP and both can be chained together in a real attack.

How to eliminate wrong answers

Option A is wrong because ARP spoofing poisons the ARP cache to redirect traffic (man-in-the-middle), not to exhaust a DHCP pool. Option B is wrong because DNS poisoning corrupts DNS resolver caches to redirect name resolution, which is unrelated to DHCP lease exhaustion. Option C is wrong because DHCP spoofing involves a rogue DHCP server handing out malicious leases (e.g., a fake gateway), not exhausting the legitimate server's pool.

57
MCQmedium

An organization wants to ensure that only corporate-managed devices can connect to the internal network. Non-compliant devices should be placed in a restricted VLAN with limited access. Which technology should be deployed?

A.Virtual Private Network (VPN)
B.Network Access Control (NAC)
C.Stateful firewall
D.Intrusion Prevention System (IPS)
AnswerB

NAC enforces admission control at the network edge, authenticating and assessing device posture before granting access. Non-compliant devices are dynamically assigned to a restricted VLAN, exactly matching the requirement that only corporate-managed devices reach the internal network.

Why this answer

NAC (Network Access Control) is purpose-built to enforce endpoint compliance before granting network access. It authenticates devices via 802.1X, MAC authentication bypass, or agent-based posture checks, and can dynamically assign non-compliant devices to a quarantine/restricted VLAN with limited ACLs. This matches the requirement of allowing only corporate-managed devices on the internal network while isolating others.

Exam trap

The trap here is confusing 'restrict access' with firewall/IPS filtering — candidates pick a stateful firewall or IPS because they think of blocking traffic, but the question is about device identity and posture-based admission, which only NAC provides.

How to eliminate wrong answers

Option A is wrong because a VPN only provides encrypted remote access tunnels; it does not perform endpoint posture assessment or dynamically place non-compliant devices into a restricted VLAN. Option C is wrong because a stateful firewall filters traffic based on sessions and ports but has no visibility into device identity or compliance state, so it cannot distinguish corporate-managed from unmanaged endpoints. Option D is wrong because an IPS detects and blocks malicious traffic patterns (exploits, signatures, anomalies) but does not authenticate endpoints or enforce VLAN assignment based on device compliance.

58
MCQeasy

Which of the following protocols operates on TCP port 443 and provides encrypted communication between a web browser and a web server?

A.HTTPS
B.SMTP
C.SSH
D.HTTP
AnswerA

HTTPS secures HTTP traffic by layering it over TLS, which encrypts the session between browser and web server. It listens on TCP port 443 by default, satisfying both constraints in the stem: the specified port and encrypted communication. Plain HTTP uses port 80 and offers no encryption.

Why this answer

HTTPS (HTTP over TLS) operates on TCP port 443 and provides encrypted communication between a web browser and a web server using TLS. It is the standard secure web protocol and the only option that matches both the port and the encryption requirement.

Exam trap

SSCP often tests port/protocol pairings — the trap is that candidates know HTTPS is secure but may confuse it with SSH (port 22) or forget that HTTP (port 80) is the unencrypted counterpart.

How to eliminate wrong answers

Option B is wrong because SMTP (Simple Mail Transfer Protocol) uses TCP port 25 (or 587/465 for submission) and is for email transport, not encrypted web browsing. Option C is wrong because SSH uses TCP port 22 and provides secure remote shell access, not web browsing. Option D is wrong because HTTP uses TCP port 80 and is unencrypted, so it does not meet the encryption requirement.

59
MCQeasy

Which of the following is a common defense against ARP spoofing attacks on a local area network?

A.DHCP snooping
B.Port security
C.MAC filtering
D.Dynamic ARP Inspection
AnswerD

Dynamic ARP Inspection intercepts ARP packets on untrusted switch ports and validates each against the DHCP snooping binding table, discarding forged replies that map an attacker's MAC to another host's IP. This directly satisfies the stem's requirement for a LAN-level defence, preventing the cache poisoning that enables man-in-the-middle interception.

Why this answer

Dynamic ARP Inspection (DAI) validates ARP packets on a per-port basis by comparing IP-to-MAC bindings against a trusted DHCP snooping database, dropping ARP packets with invalid bindings. This directly prevents ARP spoofing/poisoning attacks by ensuring only legitimate ARP replies are accepted on untrusted ports.

Exam trap

SSCP often tests the distinction between DHCP snooping (filters DHCP) and DAI (filters ARP), so candidates who see 'ARP spoofing' and pick DHCP snooping because it builds the binding table miss that DAI is the enforcement mechanism.

How to eliminate wrong answers

Option A is wrong because DHCP snooping builds the trusted binding table used by DAI but does not itself inspect or block malicious ARP packets — it only filters DHCP messages. Option B is wrong because port security limits the number of MAC addresses per port and can mitigate MAC flooding, but it does not validate ARP payloads or IP-to-MAC bindings. Option C is wrong because MAC filtering restricts which MAC addresses can connect to a port or AP, but an attacker can spoof a permitted MAC and still send forged ARP replies.

60
MCQeasy

Which of the following is a secure remote access VPN protocol that uses TLS for encryption and is commonly used with Cisco AnyConnect?

A.IPsec
B.SSL/TLS VPN
C.L2TP/IPsec
D.PPTP
AnswerB

SSL/TLS VPN tunnels traffic over port 443, so it traverses firewalls that block IPsec's ESP and IKE ports. Cisco AnyConnect is Cisco's SSL/TLS VPN client, satisfying the stem's requirement for a TLS-encrypted remote access protocol commonly paired with AnyConnect.

Why this answer

An SSL/TLS VPN uses TLS (typically over TCP port 443) to encrypt traffic and is the protocol underlying Cisco AnyConnect, which is a classic example of a client-based SSL VPN. It provides secure remote access without requiring IPsec's UDP ports, making it firewall-friendly.

Exam trap

SSCP often tests the confusion between IPsec and SSL/TLS VPNs — candidates see 'Cisco AnyConnect' and pick IPsec because AnyConnect supports both, missing that the question specifies TLS.

How to eliminate wrong answers

Option A is wrong because IPsec is a separate VPN protocol suite (using IKE on UDP 500/4500 and ESP) and, while AnyConnect can support IPsec/IKEv2, the question specifically asks for the TLS-based protocol. Option C is wrong because L2TP/IPsec combines L2TP tunneling with IPsec encryption — it does not use TLS and is not the protocol behind AnyConnect's SSL mode. Option D is wrong because PPTP is an obsolete, insecure protocol (broken MS-CHAPv2, no strong encryption) and is not TLS-based.

61
MCQmedium

A network administrator notices that legitimate clients are unable to obtain IP addresses from the DHCP server. The network logs show a high volume of DHCP Discover messages from different MAC addresses. Which attack is most likely occurring?

A.DHCP starvation
B.DHCP spoofing
C.ARP spoofing
D.DNS amplification
AnswerA

DHCP starvation floods the server with Discover messages using spoofed source MAC addresses, exhausting the available address pool. Legitimate clients then receive no offer, matching the observed high volume of Discover traffic from many different MAC addresses.

Why this answer

DHCP starvation occurs when an attacker floods the DHCP server with Discover requests using spoofed MAC addresses, exhausting the DHCP address pool. Legitimate clients then cannot obtain leases because the server has no available IPs to offer. The high volume of Discover messages from many different MAC addresses is the signature of this attack.

Exam trap

The trap is confusing starvation with spoofing — both involve DHCP and an attacker, but starvation exhausts the pool (denial of service) while spoofing redirects clients to a rogue server (MITM); the 'high volume of Discover from different MACs' clue points to starvation.

How to eliminate wrong answers

Option B is wrong because DHCP spoofing involves a rogue DHCP server responding to client requests with malicious gateway/DNS settings — it does not exhaust the pool or prevent legitimate clients from getting addresses from the real server. Option C is wrong because ARP spoofing poisons ARP caches to redirect traffic (MITM), which does not consume DHCP leases or block DHCP allocation. Option D is wrong because DNS amplification is a reflection/amplification DDoS attack using open DNS resolvers to flood a victim with responses — it has nothing to do with DHCP pool exhaustion.

62
MCQeasy

A small business wants to let visitors use its guest Wi-Fi without exposing internal servers. The visitors must reach the internet only, while employees keep using the corporate SSID. Which design best isolates guest traffic from the internal network?

A.Enable MAC filtering on the guest access points so only registered visitor devices may associate
B.Keep guests on the corporate SSID but enable client isolation so wireless clients cannot talk to each other
C.Place guest clients on a separate VLAN whose only permitted path is to the internet gateway, with ACLs blocking access to internal subnets
D.Configure the guest SSID to use WPA3-Personal with a strong passphrase and rotate it monthly
AnswerC

A dedicated guest VLAN creates a distinct Layer 2 broadcast domain, and ACLs on the router or firewall restrict that VLAN to internet-bound traffic only. Because guest frames never share a segment with corporate hosts and routing rules deny internal destinations, a compromised visitor device cannot reach internal servers. This directly matches the requirement while keeping employee traffic untouched.

Why this answer

Guest isolation requires separating traffic at Layer 2 and controlling it at Layer 3. A dedicated VLAN removes guests from the corporate broadcast domain, and ACLs or firewall rules that permit only internet-bound flows prevent lateral movement to internal servers. Encryption, client isolation, and MAC filtering affect who may join or talk to peers, but none of them keeps an associated guest away from internal subnets.

Exam trap

The trap here is equating wireless client isolation with network segmentation, when isolation only blocks station-to-station traffic on the same SSID.

63
MCQmedium

A company wants to implement a firewall that can track the state of network connections and make decisions based on the context of traffic (e.g., allowing return packets for an established connection). Which type of firewall should they choose?

A.Application proxy firewall
B.Stateless packet filter
C.Next-generation firewall
D.Stateful firewall
AnswerD

A stateful firewall maintains a connection state table, tracking each session's source, destination and sequence so return packets for established connections are permitted automatically. This context-aware inspection satisfies the requirement, unlike stateless packet filtering, which evaluates each packet in isolation.

Why this answer

A stateful firewall tracks the state of network connections in a state table, allowing return packets for established sessions without requiring explicit inbound rules. This context-aware behavior is exactly what the question describes.

Exam trap

SSCP often tests the distinction between stateless packet filters (per-packet ACLs) and stateful firewalls (connection tracking) — the trap is picking NGFW because it sounds more advanced, but the question's defining criterion is state tracking, which is the stateful firewall.

How to eliminate wrong answers

Option A is wrong because an application proxy firewall operates at Layer 7 and brokers application-specific traffic, but the question emphasizes connection state tracking, which is the defining feature of a stateful firewall. Option B is wrong because a stateless packet filter evaluates each packet in isolation against ACLs and cannot track connection state. Option C is wrong because a next-generation firewall (NGFW) includes stateful inspection plus additional features (IPS, application awareness), but the question asks for the type defined by state tracking — stateful firewall is the precise answer.

64
Multi-Selectmedium

A security engineer is implementing a Network Access Control (NAC) solution to enforce endpoint compliance before allowing devices onto the corporate network. Which TWO of the following are common NAC enforcement methods? (Choose two.)

Select 2 answers
A.802.1X with RADIUS authentication
B.VLAN hopping prevention
C.MAC address filtering
D.Captive portal with posture assessment
E.DHCP snooping with IP source guard
AnswersA, D

802.1X is a port-based network access control standard that uses RADIUS for authentication. It is a common NAC enforcement method, allowing or denying network access based on credentials and endpoint posture. When a device connects, the switch port remains unauthorized until authentication succeeds. This method is widely used in enterprise NAC deployments to enforce compliance and identity-based access.

Why this answer

Common NAC enforcement methods include 802.1X with RADIUS authentication and captive portals with posture assessment. 802.1X provides port-based access control using authentication, while captive portals redirect users to a web page for authentication and compliance checks. Both methods can enforce endpoint compliance before granting network access. DHCP snooping, VLAN hopping prevention, and MAC filtering are security features but do not provide the identity and posture assessment typical of NAC.

Exam trap

The trap here is assuming that any access control mechanism, such as MAC filtering, qualifies as NAC, but NAC specifically involves authentication and posture assessment.

65
MCQmedium

A security team is implementing Network Access Control (NAC) to enforce endpoint compliance before granting network access. Which technology allows port-based authentication on wired networks?

A.RADIUS
B.WPA2-Enterprise
C.802.1X
D.MAC filtering
AnswerC

802.1X is the IEEE standard for port-based network access control, authenticating a supplicant via EAP before the switch port grants access. It satisfies the requirement for wired port-based authentication, unlike MAC filtering or captive portals.

Why this answer

802.1X is an IEEE standard for port-based network access control that provides authentication to devices trying to connect to a wired or wireless network. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPOL) to encapsulate authentication messages between the supplicant (client) and the authenticator (switch or access point), which then relays them to an authentication server (typically RADIUS). This ensures that no traffic can pass through the port until the device is authenticated and authorized.

Exam trap

The trap here is confusing the authentication protocol (RADIUS) with the port-based access control mechanism (802.1X); candidates often select RADIUS because it is commonly used in NAC, but the question specifically asks for the technology that enables port-based authentication on wired networks.

How to eliminate wrong answers

Option A is wrong because RADIUS is an authentication, authorization, and accounting (AAA) protocol that verifies credentials but does not itself enforce port-based access control; it works in conjunction with 802.1X. Option B is wrong because WPA2-Enterprise is a wireless security standard that uses 802.1X for authentication but is not a wired port-based authentication technology. Option D is wrong because MAC filtering is a weak access control method that allows or denies based on MAC addresses but does not provide port-based authentication or dynamic authorization.

66
Multi-Selecthard

A security analyst is hardening a wireless network that uses WPA2-Enterprise with a RADIUS server. The analyst wants to mitigate the risk of an attacker setting up a rogue access point to capture user credentials. Which TWO measures should be implemented? (Choose two.)

Select 2 answers
A.Deploy a Wireless Intrusion Prevention System (WIPS) to detect and contain rogue access points.
B.Enable Protected Management Frames (PMF) to prevent deauthentication attacks.
C.Use a preshared key (PSK) instead of 802.1X to simplify authentication.
D.Configure 802.1X authentication with EAP-TLS, requiring client certificates.
E.Disable SSID broadcasting to hide the network name.
AnswersA, D

A WIPS monitors the wireless spectrum for unauthorized access points and can automatically contain them by sending deauthentication frames or alerting administrators. This directly mitigates the risk of a rogue AP capturing credentials by identifying and blocking it. It is a proactive measure that addresses the specific threat of rogue access points in the environment.

Why this answer

Deploying a WIPS detects and contains rogue access points, directly addressing the threat. Configuring 802.1X with EAP-TLS ensures mutual authentication, so clients verify the server's certificate and will not connect to a rogue AP. Together, these measures prevent credential harvesting.

PMF, hidden SSIDs, and PSKs do not adequately mitigate the risk of a rogue AP capturing credentials.

Exam trap

The trap here is assuming that hiding the SSID or using PMF is sufficient to prevent rogue access points, when in fact mutual authentication and active monitoring are required.

67
Multi-Selectmedium

During a wireless site survey, a security engineer identifies several security weaknesses. Which TWO measures should be implemented to improve wireless security for a corporate network using WPA2-Enterprise?

Select 2 answers
A.Use 802.1X authentication with EAP-TLS and certificate-based authentication
B.Implement MAC address filtering to allow only known devices
C.Disable SSID broadcast to hide the network
D.Ensure the RADIUS server uses a trusted certificate and validate client certificates
E.Enable WPS for easy client configuration
AnswersA, D

802.1X with EAP-TLS satisfies WPA2-Enterprise's requirement for per-user authentication against a RADIUS server, using mutual certificate validation rather than shared credentials. This defeats rogue access points and credential-capture attacks, since the client verifies the server's certificate and each session derives unique encryption keys.

Why this answer

Option A is correct because WPA2-Enterprise relies on 802.1X for port-based network access control, and EAP-TLS with certificate-based authentication provides strong mutual authentication using digital certificates rather than weaker credential-based methods like PEAP-MSCHAPv2. Option D is correct because the RADIUS server must present a certificate from a trusted CA so supplicants can validate it and prevent rogue-AP/evil-twin attacks, while validating client certificates ensures only authorized devices/users complete the EAP-TLS exchange. Option B is not appropriate because MAC address filtering is trivially bypassed via spoofing and adds no real cryptographic protection.

Option C is not appropriate because hiding the SSID is security through obscurity and the SSID is still discoverable in management frames. Option E is not appropriate because WPS is vulnerable to brute-force PIN attacks and should be disabled on corporate WPA2-Enterprise networks.

Exam trap

SSCP often tests the misconception that hiding the SSID or using MAC filtering adds security, when in fact these are easily bypassed and not part of a robust WPA2-Enterprise implementation.

68
MCQmedium

An attacker is performing a man-in-the-middle attack at Layer 2 by sending forged ARP messages to associate their MAC address with the IP address of a legitimate host on the same subnet. This attack is known as:

A.ARP spoofing
B.DNS poisoning
C.DHCP spoofing
D.MAC flooding
AnswerA

ARP spoofing sends forged ARP replies that bind the attacker's MAC address to a legitimate host's IP, redirecting Layer 2 traffic through the attacker. This precisely matches the stem's man-in-the-middle mechanism, poisoning neighbours' ARP caches on the same subnet.

Why this answer

ARP spoofing (also called ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with the IP address of a legitimate host, causing traffic intended for that host to be sent to the attacker. This enables man-in-the-middle attacks at Layer 2. The scenario described exactly matches ARP spoofing.

Exam trap

The trap is confusing ARP spoofing with other Layer 2 attacks like MAC flooding or DHCP spoofing; candidates must distinguish between attacks that manipulate ARP caches versus those that flood switch tables or provide rogue DHCP services.

How to eliminate wrong answers

Option B is wrong because DNS poisoning involves corrupting DNS cache entries to redirect domain name resolution, not manipulating ARP tables at Layer 2. Option C is wrong because DHCP spoofing involves a rogue DHCP server providing false IP configuration (including gateway), not forging ARP messages to impersonate a host. Option D is wrong because MAC flooding involves overwhelming a switch's CAM table with bogus MAC addresses to force it into hub mode, not sending forged ARP messages to associate a MAC with an IP.

69
MCQeasy

Which protocol is used to securely transfer files between a client and server, typically over TCP port 22?

A.SMTP
B.TFTP
C.SSH
D.FTP
AnswerC

SSH provides an encrypted channel over TCP port 22 and includes SFTP and SCP for secure file transfer. Unlike FTPS, which uses TLS on different ports, SSH natively satisfies the port 22 and encryption requirements stated in the question.

Why this answer

SSH (Secure Shell) operates over TCP port 22 and provides an encrypted channel for secure file transfer (via SFTP or SCP) as well as remote shell access. Its encryption and host authentication replace the cleartext credentials and data of legacy protocols like FTP and Telnet. This makes SSH the correct answer for secure file transfer on port 22.

Exam trap

SSCP often tests the port-to-protocol mapping and the secure-vs-insecure distinction — candidates may pick FTP because it is the 'file transfer' protocol, missing that the question specifies 'securely' and 'port 22'.

How to eliminate wrong answers

Option A is wrong because SMTP is the email transfer protocol, uses TCP port 25 (or 587/465 for submission), and has nothing to do with file transfer. Option B is wrong because TFTP is a trivial, unauthenticated UDP-based file transfer protocol on port 69 — it is neither secure nor TCP-based. Option D is wrong because FTP uses TCP ports 20/21 and transmits credentials and data in cleartext, so it is not secure; FTPS and SFTP are the secure variants, but plain FTP is not.

70
MCQhard

A security analyst is reviewing firewall logs and notices a high rate of TCP SYN packets to multiple ports on a server, but no corresponding ACK or RST packets. This is characteristic of which type of attack?

A.UDP flood
B.SYN flood
C.Smurf attack
D.Ping of death
AnswerB

A SYN flood exploits the TCP three-way handshake: the attacker sends numerous SYN packets, often with spoofed source addresses, so the server allocates resources and replies with SYN-ACK but never receives the final ACK. The absence of ACK or RST packets in the logs matches this half-open connection pattern.

Why this answer

A SYN flood exploits the TCP three-way handshake by sending many SYN packets, often with spoofed source addresses, so the server allocates half-open connection state and replies with SYN-ACK but never receives the final ACK. The absence of ACK or RST responses in the logs is the signature of this half-open connection exhaustion attack.

Exam trap

SSCP often tests the distinction between TCP-based and ICMP/UDP-based floods — candidates see 'high rate of packets' and jump to a generic flood, but the missing ACK/RST and the SYN-specific pattern are what identify a SYN flood.

How to eliminate wrong answers

Option A is wrong because a UDP flood sends connectionless UDP datagrams and would not produce TCP SYN packets or half-open TCP state at all. Option C is wrong because a Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed victim source, amplifying ICMP replies toward the victim — it involves ICMP, not TCP SYN/ACK behavior. Option D is wrong because a Ping of death relies on oversized or malformed ICMP packets that crash or destabilize a host during reassembly, not on incomplete TCP handshakes.

71
MCQhard

A security analyst discovers that an internal DNS server is returning incorrect IP addresses for legitimate domains. The analyst suspects that an attacker has compromised the DNS resolver's cache. Which type of attack has likely occurred?

A.DNS amplification attack
B.SYN flood
C.DNS tunneling
D.DNS poisoning
AnswerD

DNS poisoning corrupts a resolver's cache with forged records, causing legitimate domain names to resolve to attacker-supplied IP addresses, satisfying the stem's symptom of incorrect addresses for valid domains. Spoofing intercepts a single response; poisoning persists in the cache for the record's TTL.

Why this answer

DNS poisoning (also called DNS cache poisoning or spoofing) occurs when an attacker injects forged DNS records into a resolver's cache, causing it to return incorrect IP addresses for legitimate domain names. The symptom described — a compromised resolver cache returning wrong IPs — is the textbook definition of this attack.

Exam trap

SSCP often tests the difference between attacks that corrupt DNS data (poisoning/spoofing) and attacks that abuse DNS as a transport or amplifier (tunneling, amplification) — candidates confuse 'DNS attack' with 'DNS poisoning' without checking whether records were actually altered.

How to eliminate wrong answers

Option A is wrong because a DNS amplification attack abuses open resolvers to send large responses to a spoofed victim for volumetric DDoS, not to corrupt cached records. Option B is wrong because a SYN flood is a TCP-layer resource exhaustion attack and does not alter DNS resolution results. Option C is wrong because DNS tunneling encodes data inside DNS queries/responses to exfiltrate information or establish covert C2 channels; it does not typically cause legitimate domains to resolve to wrong addresses.

72
MCQhard

A security analyst is reviewing network traffic and notices that an attacker is sending forged ARP replies to a host, attempting to associate the attacker's MAC address with the IP address of the default gateway. Which security feature should be implemented on the switch to prevent this attack?

A.Port security
B.DHCP snooping
C.Dynamic ARP Inspection (DAI)
D.802.1X authentication
AnswerC

Dynamic ARP Inspection (DAI) validates ARP packets on untrusted ports by comparing the IP-to-MAC binding against a trusted database, such as the DHCP snooping binding table. It drops ARP packets with invalid bindings, preventing ARP spoofing attacks. This directly addresses the scenario where an attacker is sending forged ARP replies to impersonate the default gateway.

Why this answer

Dynamic ARP Inspection (DAI) is the switch feature designed to prevent ARP spoofing by validating ARP packets against a trusted binding table. It drops ARP packets that contain invalid IP-to-MAC mappings, thereby blocking the attacker's attempt to associate their MAC with the gateway's IP. Other features like port security, DHCP snooping, or 802.1X do not provide this specific ARP validation.

Exam trap

The trap here is confusing DHCP snooping with Dynamic ARP Inspection; DHCP snooping builds the binding table but does not filter ARP packets, while DAI actively validates and drops malicious ARP replies.

73
MCQmedium

A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?

A.ARP spoofing
B.SYN flood
C.DNS poisoning
D.DHCP starvation
AnswerA

ARP spoofing involves an attacker sending forged ARP replies that bind one MAC address to multiple IP addresses, poisoning neighbours' ARP caches so traffic is redirected to the attacker. This matches the observed pattern of conflicting ARP mappings.

Why this answer

ARP spoofing (or ARP poisoning) involves an attacker sending forged ARP replies to associate their MAC address with multiple IP addresses, causing traffic intended for those IPs to be redirected to the attacker. This matches the scenario where one MAC address claims to be multiple IP addresses. The goal is often to intercept, modify, or block network traffic (man-in-the-middle).

Exam trap

SSCP often tests the confusion between ARP spoofing and other network attacks like DNS poisoning or DHCP starvation, where candidates might focus on the 'multiple IP addresses' aspect and incorrectly choose DHCP starvation, which also involves multiple IPs but through a different mechanism.

How to eliminate wrong answers

Option B is wrong because a SYN flood is a denial-of-service attack that exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, not by sending ARP replies. Option C is wrong because DNS poisoning involves corrupting DNS cache records to redirect domain name resolution, not ARP traffic. Option D is wrong because DHCP starvation exhausts the DHCP server's pool of IP addresses by sending numerous DHCP requests with spoofed MAC addresses, not by sending ARP replies claiming multiple IPs.

74
MCQhard

Which network security control can enforce that only authorized devices with current antivirus and patches can connect to the network?

A.Firewall rules
B.Network Access Control
C.Intrusion Prevention System
D.Port security
AnswerB

Network Access Control enforces endpoint compliance at connection time, quarantining or denying devices whose antivirus definitions or patches are missing or outdated. It is the only listed control that gates network admission on the device's current security posture.

Why this answer

Network Access Control (NAC) is designed to enforce endpoint compliance before granting network access. It checks devices for up-to-date antivirus, patches, and other security posture requirements, and can quarantine or deny access if they fail. This matches the requirement of ensuring only authorized devices with current antivirus and patches can connect.

Exam trap

The trap here is confusing network access control with other security controls that also restrict access, such as firewalls or port security, but do not perform endpoint posture checking.

How to eliminate wrong answers

Option A is wrong because firewall rules filter traffic based on IP addresses, ports, and protocols, but they do not assess the security posture of endpoints (e.g., antivirus status or patch level). Option C is wrong because an Intrusion Prevention System monitors network traffic for malicious activity and can block attacks, but it does not enforce endpoint compliance before allowing connection. Option D is wrong because port security on a switch restricts which MAC addresses can use a port, preventing unauthorized devices but not checking antivirus or patch status.

75
Multi-Selecthard

A network administrator is designing a secure remote access solution for employees using company laptops. The solution must support strong authentication, encryption, and be resistant to man-in-the-middle attacks. Which THREE components should be included?

Select 3 answers
A.L2TP tunneling protocol
B.EAP-TLS for authentication
C.IPsec in tunnel mode
D.PPTP with MPPE encryption
E.IKEv2 key exchange protocol
AnswersB, C, E

EAP-TLS authenticates both client and server using X.509 certificates, delivering mutual authentication without shared secrets. This satisfies the stem's strong authentication requirement and, because the server proves its identity, resists man-in-the-middle attacks against the remote access tunnel.

Why this answer

EAP-TLS (B) is correct because it uses digital certificates on both client and server to perform mutual authentication, providing strong identity verification and enabling the certificate-based trust needed to resist impersonation. IPsec in tunnel mode (C) is correct because it encrypts and authenticates the entire original IP packet between endpoints, protecting confidentiality and integrity of the traffic across an untrusted network. IKEv2 (E) is correct because it securely negotiates and rekeys IPsec security associations using strong cryptographic exchanges, and its support for MOBIKE helps maintain secure sessions while resisting man-in-the-middle interception.

L2TP (A) is not correct here because by itself it provides tunneling but no encryption or strong authentication, so it must be paired with IPsec rather than being the security component. PPTP with MPPE (D) is not correct because PPTP is obsolete and its MS-CHAPv2 authentication and MPPE encryption have well-known weaknesses that make it vulnerable to credential cracking and MITM attacks.

Exam trap

The trap is selecting L2TP or PPTP as they are VPN protocols, but they lack strong encryption or have known vulnerabilities. Candidates must recognize that EAP-TLS, IPsec tunnel mode, and IKEv2 are the secure components.

Page 1 of 2 · 100 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Network and Communications Security questions.