Courseiva

SSCP · topic practice

Network and Communications Security practice questions

Domain 4 of the SSCP exam covers network architecture, secure transmission, and attack mitigation across OSI layers. Questions present short scenarios—spoofed DHCP requests, forged ARP replies, TLS version differences, VPN protocol selection—and ask you to identify the attack, protocol, or control. Expect protocol-level recognition rather than configuration depth.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Network and Communications Security

What the exam tests

What to know about Network and Communications Security

Map each scenario to its exact protocol and OSI layer, then name the attack or control precisely. The critical skill is distinguishing Layer 2 attacks (ARP, DHCP, MAC) from higher-layer ones and knowing which VPN or TLS feature the question describes.

Identifying secure remote access VPN protocols such as TLS-based Cisco AnyConnect versus IPsec alternatives

Recognizing TLS 1.3 improvements including removal of legacy ciphers and simplified handshake

Naming Layer 2 attacks like ARP spoofing, DHCP starvation, and MAC flooding from scenario descriptions

Selecting network segmentation, NAC, and 802.1X controls that limit lateral movement and rogue devices

Watch out for

Common Network and Communications Security exam traps

  • ▸Confusing ARP spoofing with DNS poisoning or DHCP starvation; each targets a different protocol and layer, so read the scenario's mechanism carefully.
  • ▸Assuming TLS 1.3 still supports RSA key exchange or renegotiation; it removed those, so answers referencing them are wrong.
  • ▸Mixing up VPN types—treating IPsec IKEv2 and TLS/SSL VPNs as interchangeable when the question names a specific client or protocol.

Practice set

Network and Communications Security questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full wireless explanation →

During a wireless penetration test, an attacker captures the four-way handshake of a WPA2-PSK network and attempts to crack the passphrase offline. Which attack is the attacker likely using?

An organization wants to deploy a firewall that can inspect the payload of application-layer protocols such as HTTP and FTP, and make access decisions based on application data. Which type of firewall best meets this requirement?

Which protocol is used to securely transfer files over a network and operates on TCP port 22?

An organization deploys a firewall that examines the entire packet, including application-layer data, and can block specific commands or content. Which type of firewall is this?

Question 5hardmultiple choice
Read the full VPN explanation →

In IPsec VPNs, which protocol provides authentication and encryption of the entire IP packet, including the IP header, in tunnel mode?

Which of the following is a primary advantage of using TLS 1.3 over earlier versions?

Question 7mediummultiple choice
Read the full wireless explanation →

During a security assessment, a penetration tester discovers that the network uses WPA2-PSK. Which attack could be used to recover the pre-shared key without interacting with the access point after capturing a single handshake?

Question 8mediummulti select
Read the full wireless explanation →

A security administrator is hardening a wireless network. Which TWO of the following should be avoided due to known vulnerabilities?

A security analyst is investigating a potential ARP spoofing attack on a local network segment. Which TWO network security controls would be most effective in preventing or detecting such an attack at Layer 2?

Question 10easymulti select
Read the full DHCP explanation →

During a security assessment, a penetration tester successfully performs a DHCP starvation attack followed by a DHCP spoofing attack. Which TWO outcomes are the most likely consequences of this combined attack?

Question 11hardmulti select
Read the full VPN explanation →

A security engineer is configuring a site-to-site VPN between two data centers using IPsec in tunnel mode. The engineer must ensure that the VPN provides data origin authentication and integrity for each packet without relying solely on the encryption algorithm. Which two components of the IPsec suite should be used together to meet these requirements? (Choose two.)

Question 12mediummultiple choice
Read the full VPN explanation →

A security administrator is configuring a new IPsec VPN tunnel between two branch offices. The requirement is to ensure that each packet's payload is encrypted but the original IP header is preserved so that routing across the public internet works without additional encapsulation. Which IPsec mode should be used?

A security administrator is reviewing a network diagram and notices that a legacy application server communicates with a database server over an unencrypted connection. To protect this traffic without modifying the application, the administrator decides to implement a solution that operates at the transport layer and can provide confidentiality and integrity for the data in transit. Which technology should be used?

A security engineer is evaluating a network protocol that uses a 32-bit sequence number and a 16-bit checksum. The engineer is concerned about an attacker injecting spoofed packets into an established TCP session. Which of the following is the MOST effective mitigation to prevent this type of attack?

Question 15hardmultiple choice
Review the full subnetting walkthrough →

A security engineer is reviewing a packet capture and sees that an internal host is sending TCP segments with the SYN flag set, a spoofed source address of a server on the same subnet, and a destination of another internal host. The two internal hosts then exchange no further traffic. Which type of activity does this pattern most likely represent?

An organization must protect the integrity and confidentiality of email in transit between two sites, and it also wants to ensure that the sending server's identity is validated by the receiving server before mail is accepted. Which combination of controls best meets these goals?

Which protocol and port combination is commonly used for secure remote administration of a server?

A security analyst notices an unusual number of ARP replies on the network where one MAC address is claiming to be multiple IP addresses. Which type of attack is most likely occurring?

A company wants to deploy a firewall that can track the state of active connections and make decisions based on the context of traffic flows. Which firewall type should they choose?

Which protocol is used for secure web browsing and operates on TCP port 443?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Network and Communications Security sessions

Start a Network and Communications Security only practice session

Every question in these sessions is drawn from the Network and Communications Security domain — nothing else.

Related practice questions

Related SSCP topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the SSCP exam test about Network and Communications Security?
Map each scenario to its exact protocol and OSI layer, then name the attack or control precisely. The critical skill is distinguishing Layer 2 attacks (ARP, DHCP, MAC) from higher-layer ones and knowing which VPN or TLS feature the question describes.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Network and Communications Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Network and Communications Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other SSCP topics?
Use the topic links above to move to related areas, or go back to the SSCP question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the SSCP exam covers. They are not copied from any real exam or dump site.