Courseiva

CCNA Sscp Network Security Questions

25 of 100 questions · Page 2/2 · Sscp Network Security topic · Answers revealed

76
Multi-Selecthard

Which THREE of the following are security features of WPA3 compared to WPA2? (Select THREE)

Select 3 answers
A.Backward compatibility with WEP
B.Protected Management Frames (PMF) mandatory
C.192-bit security suite for Enterprise mode
D.Simultaneous Authentication of Equals (SAE) replaces PSK
E.Use of TKIP encryption
AnswersB, C, D

WPA3 makes Protected Management Frames mandatory, whereas WPA2 left PMF optional. PMF cryptographically protects management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks. This mandatory enforcement is a specific WPA3 security improvement over WPA2 that the stem asks you to identify.

Why this answer

Option B is correct because WPA3 mandates Protected Management Frames (PMF, defined in 802.11w), which cryptographically protect management frames such as deauthentication and disassociation, preventing forgery and denial-of-service attacks that were possible under WPA2 where PMF was optional. Option C is correct because WPA3-Enterprise offers an optional 192-bit security suite aligned with CNSA guidance, using stronger cryptographic algorithms (GCMP-256, HMAC-SHA-384, ECDHE with a 384-bit curve) that WPA2-Enterprise did not provide. Option D is correct because WPA3 replaces the WPA2 Pre-Shared Key handshake with Simultaneous Authentication of Equals (SAE), a Dragonfly-based password-authenticated key exchange that provides forward secrecy and resists offline dictionary attacks against captured handshakes.

Option A is incorrect because WPA3 does not support backward compatibility with WEP, a deprecated and broken encryption protocol; WPA3 requires modern ciphers such as CCMP-128 or GCMP-256. Option E is incorrect because TKIP is a legacy, deprecated encryption protocol from WPA/WPA2 and is not used by WPA3, which relies on AES-based CCMP and GCMP instead.

Exam trap

SSCP often tests the confusion between WPA2 and WPA3 features; candidates may incorrectly select TKIP or WEP compatibility because they associate older encryption with broader compatibility, but WPA3 explicitly drops these legacy protocols.

77
Multi-Selectmedium

A company is migrating from WPA2 to WPA3 for wireless security. Which THREE features does WPA3 introduce? (Select three)

Select 3 answers
A.192-bit security suite for Enterprise networks
B.Wi-Fi Protected Setup (WPS)
C.Simultaneous Authentication of Equals (SAE)
D.Protected Management Frames (PMF) mandatory
E.CCMP encryption as mandatory
AnswersA, C, D

WPA3-Enterprise adds an optional 192-bit cryptographic suite aligned with CNSA guidance, using stronger AES-GCM-256 and SHA-384 within EAP-TLS negotiations. This satisfies the stem's requirement for a genuinely new WPA3 feature, unlike WPA2's 128-bit-only Enterprise mode. Simultaneous Authentication of Equals and protected management frames are separate additions.

Why this answer

WPA3 introduces the 192-bit security suite for Enterprise networks (option A), which is based on CNSA Suite algorithms and provides stronger cryptographic protection for government, defense, and high-security enterprise environments. Simultaneous Authentication of Equals (SAE) (option C) is the new WPA3-Personal handshake that replaces WPA2's PSK method, providing forward secrecy and resistance to offline dictionary attacks. Protected Management Frames (PMF) mandatory (option D) is correct because WPA3 requires PMF (802.11w) to protect management frames from forging and eavesdropping attacks, whereas it was optional in WPA2.

Wi-Fi Protected Setup (WPS) (option B) is not a WPA3-introduced feature; it predates WPA3 and is actually discouraged due to security weaknesses. CCMP encryption as mandatory (option E) is incorrect because CCMP is the WPA2 mandatory cipher, while WPA3-Personal still uses CCMP-128 but also introduces GCMP-256 in the 192-bit suite, so CCMP being 'mandatory' is not a new WPA3 feature.

Exam trap

SSCP often tests the distinction between features that are new in WPA3 versus those that were already present or optional in WPA2, such as CCMP and WPS, causing candidates to incorrectly select them as WPA3 introductions.

78
Multi-Selectmedium

A security analyst is investigating a network incident. Which TWO of the following are indicators of a man-in-the-middle attack using ARP spoofing? (Select TWO)

Select 2 answers
A.High number of TCP retransmissions from a single host.
B.An ARP entry for the default gateway points to an unknown MAC address.
C.The ARP cache shows two different MAC addresses for the same IP address (e.g., gateway IP).
D.The switch's CAM table has multiple MAC entries on the same port.
E.Multiple IP addresses resolve to the same MAC address in the ARP cache.
AnswersB, C

ARP spoofing poisons the victim's cache so the gateway's IP resolves to the attacker's MAC. A gateway ARP entry mapping to an unknown MAC therefore directly evidences cache poisoning, satisfying the man-in-the-middle indicator requirement in the stem.

Why this answer

Option B is correct because in ARP spoofing the attacker sends forged ARP replies claiming the gateway's IP, so the victim's ARP entry for the default gateway resolves to the attacker's (unknown/unexpected) MAC address instead of the legitimate router MAC. Option C is correct because duplicate/conflicting ARP entries—two different MAC addresses bound to the same IP such as the gateway IP—are a classic sign of ARP cache poisoning, where the attacker's reply overwrites or races with the legitimate mapping. Option A is not specific to ARP spoofing, since TCP retransmissions can result from many causes (congestion, packet loss, duplex mismatch) and are only a generic symptom.

Option D describes MAC flooding against a switch CAM table, not ARP spoofing. Option E (multiple IPs mapping to one MAC) is typical of NAT, proxy ARP, or a router interface, not an ARP spoofing indicator.

Exam trap

The trap is selecting generic network symptoms (retransmissions, CAM table anomalies) as ARP-spoofing indicators instead of the specific ARP cache anomalies — a gateway IP mapped to an unknown MAC or duplicate MACs for one IP — that directly evidence ARP poisoning.

79
MCQmedium

Which UDP port is used by the Simple Network Management Protocol (SNMP) for receiving traps?

A.UDP 161
B.UDP 162
C.UDP 123
D.UDP 514
AnswerB

SNMP traps are asynchronous notifications sent by agents to a manager, and they arrive on UDP port 162 rather than the polling port 161. This separation lets the manager listen for unsolicited alerts on 162 while still issuing requests to agents on 161, satisfying the stem's requirement for the trap-receiving port.

Why this answer

SNMP agents listen for requests on UDP port 161, but SNMP traps (and inform requests) are sent by the agent to the manager on UDP port 162. The manager must listen on UDP 162 to receive unsolicited notifications. This separation of ports lets the manager distinguish inbound trap traffic from its own outbound polling.

Exam trap

The trap is mixing up the agent's polling port (UDP 161) with the manager's trap-receiving port (UDP 162); candidates often assume traps use the same port as requests.

How to eliminate wrong answers

Option A is wrong because UDP 161 is the port on which the SNMP agent listens for GET, GETNEXT, GETBULK, and SET requests from the manager, not the trap-receiving port. Option C is wrong because UDP 123 is used by NTP for time synchronization, unrelated to SNMP. Option D is wrong because UDP 514 is used by syslog (and historically rsh), not SNMP traps.

80
MCQmedium

A financial services firm needs to detect unauthorized changes to its public DNS records that could redirect customers to a phishing site. The security team wants a control that validates DNS responses cryptographically so that a resolver can verify the data originated from the authoritative zone. Which technology should they implement?

A.DNS over HTTPS (DoH)
B.DNSSEC (Domain Name System Security Extensions)
C.DNS sinkholing
D.Split-horizon DNS
AnswerB

DNSSEC adds digital signatures to DNS records so a validating resolver can confirm that the data came from the authoritative zone and was not altered in transit. It directly addresses cache poisoning and record tampering by using a chain of trust from the root down to the zone. This matches the requirement for cryptographic validation of DNS responses.

Why this answer

DNSSEC is the only listed control that signs DNS records and lets a validating resolver verify their origin and integrity through a chain of trust. Encryption options such as DoH protect the query path but not the data's authenticity, while sinkholing and split-horizon DNS address different problems. For detecting tampering with public records, DNSSEC provides the required cryptographic assurance.

Exam trap

The trap here is confusing encryption of DNS traffic with authentication of DNS data, so a privacy feature like DoH is mistaken for an integrity control.

81
Multi-Selecthard

A security team is reviewing how their organization's DNS infrastructure could be abused. They want to reduce the risk of DNS cache poisoning and of data being smuggled out of the network through DNS queries. Which two measures best address these risks? (Choose two.)

Select 2 answers
A.Increase the default TTL on all internal DNS records so that cached entries remain valid longer
B.Deploy DNSSEC validation on the recursive resolvers so that responses can be cryptographically verified against the authoritative zone
C.Enable EDNS0 Client Subnet on the authoritative servers to return geographically accurate answers
D.Force all internal clients to use only the organization's internal recursive resolvers and block outbound DNS to external resolvers at the perimeter
E.Configure the internal resolvers to forward all queries to a public open resolver such as a large third-party service
AnswersB, D

DNSSEC adds digital signatures to DNS records, allowing a validating resolver to prove that a response genuinely came from the authoritative zone and was not altered in transit. This directly mitigates cache poisoning, because a forged or injected answer fails signature validation and is discarded rather than cached and served to internal clients. It does not by itself stop tunneling, but it is a core control for answer integrity.

Why this answer

DNSSEC validation gives resolvers cryptographic proof that answers are authentic, which neutralizes forged responses used in cache poisoning. Constraining clients to internal resolvers and blocking outbound DNS to arbitrary servers keeps all resolution inside a monitored path, enabling detection of tunneling and preventing bypass of the validating resolver. Together they cover both integrity of answers and visibility into query behavior.

Exam trap

The trap here is treating DNS performance or privacy features such as EDNS Client Subnet as security controls, when they do not authenticate answers or expose covert channels.

82
MCQmedium

A security administrator is hardening a data center switch. Management requires that only the switch's configured management station can initiate a remote CLI session, and that the switch never accept an inbound management connection from any other host. Which control should the administrator implement on the switch to meet this requirement?

A.An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22
B.BPDU Guard enabled on all access ports to prevent rogue spanning-tree devices
C.Port security configured on every access port with a maximum of one learned MAC address
D.A TACACS+ or RADIUS server that authenticates all administrative logins with individual accounts
AnswerA

Filtering inbound traffic to the management VLAN so that only the designated management host can reach the SSH service enforces exactly the stated requirement: the switch accepts remote CLI sessions only when they originate from the approved station. All other source addresses are dropped before they can reach the management plane, which also reduces the attack surface of the device itself.

Why this answer

Restricting the management plane by source address is the only control listed that limits who may initiate an administrative session. An inbound ACL bound to the management interface permits the approved management station and denies everything else, directly matching the stated policy. Authentication, port security, and loop-prevention features address different problems and leave the management service reachable from any host on the network.

Exam trap

The trap here is assuming that strong authentication alone limits who can connect to a device, when reachability filtering must be applied separately to restrict session sources.

83
MCQhard

A security analyst is investigating a network where an attacker successfully redirected traffic from a legitimate web server to a malicious server by corrupting the target domain's DNS records in a local resolver cache. Which attack technique was used?

A.SYN flood
B.DNS poisoning
C.ARP spoofing
D.Smurf attack
AnswerB

DNS poisoning corrupts a resolver's cached records, substituting a malicious IP for the legitimate domain. Because the local resolver returns the forged entry, traffic is silently redirected to the attacker's server, matching the scenario's cache corruption and redirection.

Why this answer

DNS poisoning (also called DNS cache poisoning or DNS spoofing) is the attack where an attacker injects forged DNS records into a resolver's cache, causing the resolver to return a malicious IP address for a legitimate domain. This matches the scenario exactly: the target domain's records were corrupted in a local resolver cache, redirecting traffic to a malicious server. The other options describe volumetric or Layer 2 attacks unrelated to DNS record manipulation.

Exam trap

The trap here is confusing DNS poisoning with ARP spoofing — both redirect traffic, but ARP spoofing works at Layer 2 by manipulating MAC-to-IP mappings, while DNS poisoning corrupts name resolution records in a resolver cache.

How to eliminate wrong answers

Option A is wrong because a SYN flood is a Layer 4 denial-of-service attack that exhausts TCP connection state by sending many SYN packets without completing the handshake — it does not alter DNS records or redirect traffic. Option C is wrong because ARP spoofing operates at Layer 2 by sending forged ARP replies to associate an attacker's MAC with a legitimate IP, enabling man-in-the-middle on a LAN, not DNS cache corruption. Option D is wrong because a Smurf attack is an ICMP amplification DoS that sends spoofed broadcast pings to a network, causing many hosts to reply to a victim — it has nothing to do with DNS records.

84
Multi-Selectmedium

Which TWO of the following are methods to defend against SYN flood attacks? (Select TWO)

Select 2 answers
A.Enabling IP routing
B.Using UDP instead of TCP
C.Increasing the SYN backlog queue size
D.SYN cookies
E.Disabling TCP timestamps
AnswersC, D

Enlarging the SYN backlog queue lets the server hold more half-open connections before exhausting the table, absorbing bursts rather than dropping legitimate handshakes. It directly mitigates the stem's SYN flood constraint by raising the volume of pending requests the TCP stack tolerates.

Why this answer

Option C (Increasing the SYN backlog queue size) is correct because a SYN flood exhausts the backlog of half-open connections; enlarging the backlog lets the server hold more pending SYNs so legitimate clients can still complete the three-way handshake before the queue overflows. Option D (SYN cookies) is correct because it eliminates the need to store half-open state: the server encodes connection parameters into the SYN-ACK sequence number and only allocates resources when the final ACK returns, so spoofed SYNs cannot exhaust memory. Option A (Enabling IP routing) is unrelated to SYN flood mitigation and would only forward packets between interfaces, potentially worsening exposure.

Option B (Using UDP instead of TCP) is not a defense—SYN floods are specific to TCP's handshake, and switching protocols changes the application entirely rather than protecting it. Option E (Disabling TCP timestamps) has no effect on SYN flood resistance; timestamps are an optional TCP extension for RTT measurement and PAWS, not a resource-exhaustion control.

Exam trap

The trap here is confusing general TCP hardening features (timestamps, routing) with actual SYN flood mitigations — candidates often pick 'increase backlog' as the only answer and miss SYN cookies, or select UDP as a workaround without realizing it breaks the protocol.

85
MCQmedium

An organization is planning to deploy a remote access VPN for employees. The solution must support strong encryption, mutual authentication, and work through firewalls without requiring additional ports. Which technology is most suitable?

A.L2TP/IPsec
B.PPTP
C.IPsec tunnel mode
D.SSL/TLS VPN
AnswerD

SSL/TLS VPN tunnels over TCP 443, so it traverses existing firewall rules without opening extra ports, satisfying that constraint. It supports strong encryption and mutual authentication through client certificates, letting the organisation verify both user and server identities during the remote access session.

Why this answer

SSL/TLS VPNs (e.g., clientless or client-based SSL VPNs) use TLS over TCP port 443, which is almost universally allowed through firewalls, and they support strong encryption (AES) and mutual authentication via certificates or client certificates. Because they ride on standard HTTPS, no additional ports need to be opened, satisfying all stated requirements.

Exam trap

The trap is choosing IPsec-based options (L2TP/IPsec or IPsec tunnel mode) for 'works through firewalls without additional ports,' when only SSL/TLS VPN on TCP 443 reliably meets that requirement.

How to eliminate wrong answers

Option A is wrong because L2TP/IPsec uses UDP ports 500 and 4500 and IP protocol 50 (ESP), which often require firewall changes and can be blocked by NAT, failing the 'no additional ports' requirement. Option B is wrong because PPTP is obsolete and insecure, using weak MS-CHAPv2 authentication and RC4 encryption, and it uses TCP 1723 and GRE (protocol 47), which many firewalls block. Option C is wrong because IPsec tunnel mode also relies on ESP/IKE ports and protocols that frequently need explicit firewall rules and can struggle with NAT traversal, so it does not meet the 'work through firewalls without additional ports' criterion as cleanly as SSL/TLS VPN.

86
MCQeasy

A security analyst is reviewing network traffic and notices a large number of ICMP echo requests from a single source to multiple destinations within the organization's network. The analyst suspects a reconnaissance attempt. Which type of attack is most likely being performed?

A.Ping of death
B.Smurf attack
C.Ping sweep
D.ICMP flood
AnswerC

A ping sweep involves sending ICMP echo requests to multiple IP addresses to determine which hosts are active. This is a common reconnaissance technique used to map a network. The scenario describes ICMP echo requests from a single source to multiple destinations, which is characteristic of a ping sweep. Thus, it is the most likely attack.

Why this answer

A ping sweep is a reconnaissance technique that uses ICMP echo requests to identify live hosts on a network. The scenario describes a single source sending ICMP echo requests to multiple destinations, which matches the pattern of a ping sweep. Other ICMP-based attacks like Smurf, Ping of Death, and ICMP flood have different characteristics and objectives.

Exam trap

The trap here is confusing a ping sweep, which is for host discovery, with an ICMP flood, which is a denial-of-service attack.

87
MCQeasy

Which transport layer protocol is used by DNS for its queries and responses, and why is it appropriate?

A.UDP, because it guarantees packet ordering.
B.TCP, because it provides error checking and retransmission.
C.TCP, because reliability is critical for DNS resolution.
D.UDP, because it is connectionless and fast, suitable for short exchanges.
AnswerD

DNS queries and responses use UDP port 53, whose connectionless datagram model avoids handshake overhead and suits the short request-response exchanges typical of name resolution. This satisfies the requirement for a fast transport matching DNS's small, self-contained message pattern.

Why this answer

DNS primarily uses UDP on port 53 because queries and responses are typically small, single-packet exchanges where the low overhead and lack of connection setup make UDP fast and efficient. TCP is used only for large responses (e.g., zone transfers or DNSSEC) or when truncation occurs.

Exam trap

SSCP often tests the misconception that DNS uses TCP for reliability; candidates pick TCP because they associate reliability with critical services, but DNS is designed around UDP's speed with application-level retry logic.

How to eliminate wrong answers

Option A is wrong because UDP does not guarantee packet ordering — it is connectionless and provides no ordering or delivery guarantees; DNS relies on application-level retries and transaction IDs. Option B is wrong because while TCP does provide error checking and retransmission, DNS does not use TCP for typical queries due to the overhead; TCP is reserved for specific cases like zone transfers (AXFR) and large responses. Option C is wrong because reliability is not the primary driver for DNS query transport; UDP's speed and low overhead are preferred, and reliability is handled at the application layer with retries.

88
MCQeasy

A company is deploying a new wireless network and wants to ensure that only authorized devices can connect. The security team decides to use a method that requires a supplicant, authenticator, and authentication server. Which technology should be implemented?

A.WPA2-Enterprise
B.WEP with 802.1X
C.WPA2-Personal
D.MAC address filtering
AnswerA

WPA2-Enterprise implements IEEE 802.1X, which uses a supplicant on the client, an authenticator (the access point), and an authentication server (typically RADIUS). This allows for centralized authentication and per-user or per-device credentials, ensuring that only authorized devices can connect. It meets the requirement of using the three-party model and provides strong security for enterprise wireless networks.

Why this answer

WPA2-Enterprise uses IEEE 802.1X, which defines the supplicant (client), authenticator (access point), and authentication server (RADIUS). This architecture enables strong, centralized authentication, ensuring that only devices with valid credentials can join the network. The other options either lack the three-party model or rely on weak security mechanisms.

Exam trap

The trap here is equating any wireless security with the 802.1X framework, when in fact only WPA2-Enterprise (and WPA3-Enterprise) implements the supplicant-authenticator-authentication server model.

89
MCQhard

A security analyst is investigating a potential attack on a network. The analyst observes a large number of ICMP echo request packets with spoofed source IP addresses being sent to a subnet's broadcast address. Many hosts on the subnet are replying, causing network congestion. Which type of attack is this?

A.Smurf attack
B.Ping of death
C.Fraggle attack
D.SYN flood
AnswerA

A Smurf attack involves sending ICMP echo requests to a broadcast address with a spoofed source IP (the victim's IP). All hosts on the subnet respond to the victim, amplifying the traffic and causing a denial of service. This matches the scenario exactly.

Why this answer

The Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed source IP. All hosts on the subnet reply to the spoofed victim, amplifying traffic and causing a denial of service. The scenario describes exactly this: ICMP echo requests to a broadcast address with spoofed source, causing many replies and congestion.

Exam trap

The trap here is mixing up Smurf and Fraggle attacks. Smurf uses ICMP, while Fraggle uses UDP. The scenario specifies ICMP, so Smurf is correct.

90
Multi-Selectmedium

A security auditor is reviewing the configuration of a remote access VPN. Which TWO features are considered best practices for securing the VPN connection?

Select 2 answers
A.Using IKEv2 with pre-shared keys only
B.Disabling encryption to reduce latency
C.Implementing multi-factor authentication (MFA)
D.Enabling split tunneling for all traffic to improve performance
E.Using TLS 1.3 with mandatory forward secrecy
AnswersC, E

Multi-factor authentication satisfies the auditor's requirement by adding a second verification factor beyond the password, defeating credential-stuffing and stolen-password attacks against the VPN gateway. Even if an attacker captures valid domain credentials, the missing second factor blocks authentication. Microsoft Entra ID Conditional Access can enforce MFA specifically for VPN sign-ins.

Why this answer

Option C is correct because implementing multi-factor authentication (MFA) ensures that even if a user's credentials are compromised, an additional verification factor (such as a TOTP code or hardware token) is required before the VPN tunnel is established, directly mitigating credential-based attacks. Option E is correct because TLS 1.3 with mandatory forward secrecy (using ephemeral key exchanges like ECDHE) ensures that session keys cannot be retroactively decrypted even if the server's long-term private key is later compromised, which is a recognized best practice for protecting VPN control and data channels. Option A is not a best practice because IKEv2 with pre-shared keys only lacks per-user authentication and scalability, and PSKs are vulnerable to offline dictionary attacks; certificate-based or EAP-based authentication is preferred.

Option B is incorrect because disabling encryption removes confidentiality and integrity protections, defeating the purpose of a VPN. Option D is incorrect because enabling split tunneling for all traffic can bypass corporate security controls (such as inspection and DLP) and expose the endpoint and internal network to threats, so it is not a security best practice.

Exam trap

The trap is selecting performance-oriented options (split tunneling, disabling encryption) as 'best practices'; the exam expects candidates to prioritize confidentiality and strong authentication over latency.

91
Multi-Selecthard

A security administrator is reviewing a network diagram and identifies several controls intended to reduce the attack surface of a demilitarized zone (DMZ). Which TWO controls best limit the impact of a compromised DMZ host on the internal network? (Choose two.)

Select 2 answers
A.Enable promiscuous mode on the DMZ switch ports so that monitoring tools can capture all traffic.
B.Deploy the DMZ on the same VLAN as internal servers to simplify administration and monitoring.
C.Enforce strict firewall rules that permit only required outbound flows from the DMZ to specific internal hosts and ports.
D.Use a separate network segment with a firewall between the DMZ and the internal network, and require authentication for any DMZ-to-internal connection.
E.Allow all outbound traffic from the DMZ to any destination so that services can reach update servers without interference.
AnswersC, D

Egress filtering from the DMZ prevents a compromised host from freely reaching internal systems, so an attacker cannot pivot broadly. By allowing only the specific internal destinations and ports that the service legitimately needs, the administrator contains the blast radius. This is a core principle of DMZ design and directly limits lateral movement.

Why this answer

Limiting the impact of a compromised DMZ host depends on restricting what that host can reach. Strict egress rules from the DMZ and a separate firewall with authentication for DMZ-to-internal connections both enforce least privilege at the boundary. Sharing a VLAN with internal servers or allowing unrestricted egress removes containment, and promiscuous mode on production ports increases exposure rather than reducing it.

Exam trap

The trap here is treating monitoring or administrative convenience features, such as promiscuous mode or a shared VLAN, as security controls when they actually widen the attack surface.

92
Multi-Selectmedium

An organization is designing network segmentation to protect sensitive data. Which TWO of the following are effective methods for implementing network segmentation?

Select 2 answers
A.Honeypots
B.NAT
C.Firewalls
E.VLANs
AnswersC, E

Firewalls enforce segmentation by inspecting traffic and permitting or denying flows between network zones according to rule sets, so sensitive-data segments stay isolated from untrusted areas. They satisfy the stem's requirement for an effective segmentation method by providing policy-based control at zone boundaries.

Why this answer

Firewalls (C) are a core segmentation control because they enforce policy between zones—filtering traffic by IP address, port, and protocol (e.g., allowing only TCP 443 from a DMZ to an internal subnet)—thereby restricting lateral movement toward sensitive data. VLANs (E) segment a switched network at Layer 2 by logically isolating broadcast domains, so hosts in different VLANs cannot communicate directly without a Layer 3 device, which is a standard way to separate sensitive systems from general user traffic. Honeypots (A) are deception/detection decoys, not segmentation mechanisms, since they attract and log attackers rather than partition traffic.

NAT (B) translates addresses (e.g., private RFC 1918 to public) for connectivity and concealment, but it does not by itself enforce segmentation between internal zones. Port security (D) limits which MAC addresses may use a switch port to prevent unauthorized devices or MAC flooding, but it does not create separate network segments or control inter-zone traffic.

Exam trap

The trap is selecting port security or NAT as segmentation methods — port security is port-level access control, and NAT is address translation, neither of which segments networks or enforces inter-segment policy.

93
MCQhard

A security engineer is hardening a data center network against VLAN hopping attacks. The core switches currently use 802.1Q trunking on all inter-switch links, and unused access ports are left in the default VLAN. Which configuration change best mitigates VLAN hopping while preserving legitimate trunk operation?

A.Disable Dynamic Trunking Protocol (DTP) on all access ports and place unused ports in an unused VLAN.
B.Change all access ports to trunk ports and enable Dynamic Trunking Protocol (DTP) negotiation.
C.Enable BPDU Guard and Root Guard on all trunk ports to block VLAN hopping frames.
D.Configure all inter-switch links as access ports in VLAN 1 to simplify the topology.
AnswerA

Disabling DTP prevents an attacker from negotiating a trunk on an access port, and moving unused ports out of the default VLAN removes a common double-tagging target. This preserves legitimate trunks on trusted links while closing the two main VLAN hopping vectors: switch spoofing and double tagging against the native VLAN.

Why this answer

VLAN hopping typically relies on DTP negotiation on an access port or on double tagging through the native VLAN. Disabling DTP on access ports stops an attacker from forming a trunk, and moving unused ports to an unused VLAN removes an easy double-tagging target. Legitimate trunks remain functional on trusted inter-switch links, so segmentation is preserved while the attack surface is reduced.

Exam trap

The trap here is assuming that Spanning Tree protection features such as BPDU Guard or Root Guard also prevent VLAN hopping, when they actually address a different attack class.

94
Multi-Selectmedium

Which TWO of the following are characteristics of a Smurf attack? (Select TWO)

Select 2 answers
A.Requires fragmented packets
B.Uses ICMP echo requests
C.Exploits TCP SYN handshake
D.Targets DNS resolvers
E.Amplifies traffic by using broadcast addresses
AnswersB, E

The attacker sends ICMP echo requests with a spoofed source address to a network's broadcast address, so every host replies to the victim. This ICMP echo mechanism is the defining traffic characteristic of a Smurf attack.

Why this answer

Smurf attacks send ICMP echo requests to a broadcast address with a spoofed source IP, causing all hosts to reply to the victim, leading to amplification.

95
MCQhard

During a penetration test, a security analyst captures a packet containing a gratuitous ARP reply that associates the attacker's MAC address with the default gateway's IP address. This is a classic indicator of which attack?

A.ARP spoofing
B.DHCP spoofing
C.MAC cloning
D.DNS poisoning
AnswerA

A gratuitous ARP reply that binds the gateway's IP to the attacker's MAC is the defining signature of ARP spoofing, poisoning victims' ARP caches so traffic destined for the gateway is redirected to the attacker for interception or modification.

Why this answer

A gratuitous ARP reply is an ARP packet sent without a prior request, typically used to announce a change in MAC-to-IP mapping. In this case, the attacker sends a gratuitous ARP reply claiming that the default gateway's IP address now maps to the attacker's MAC address. This poisons the ARP cache of other hosts on the network, causing them to send traffic destined for the gateway to the attacker instead.

This is the defining characteristic of ARP spoofing (also called ARP poisoning).

Exam trap

SSCP often tests the distinction between ARP spoofing and DHCP spoofing, as both can redirect traffic but operate at different layers and use different protocols; candidates may confuse the two if they overlook the specific mention of gratuitous ARP.

How to eliminate wrong answers

Option B is wrong because DHCP spoofing involves a rogue DHCP server offering false IP configuration (including a malicious default gateway), not a gratuitous ARP reply associating an attacker's MAC with the gateway's IP. Option C is wrong because MAC cloning (or MAC spoofing) refers to changing a device's MAC address to impersonate another device, but it does not inherently involve sending gratuitous ARP replies to poison ARP caches; the attack described is specifically about manipulating ARP mappings. Option D is wrong because DNS poisoning involves corrupting DNS cache records to redirect domain name resolution, not ARP traffic; it operates at the application layer (DNS) rather than the data link layer (ARP).

96
MCQhard

A security engineer is deploying a Network Intrusion Detection System (NIDS) on a switched network. The engineer needs to ensure the NIDS can monitor all traffic passing through a critical switch port that connects to a server. Which technology should be configured on the switch to copy traffic from the server port to the NIDS monitoring port?

A.Link Aggregation Control Protocol (LACP)
B.Port mirroring (SPAN)
C.Spanning Tree Protocol (STP)
D.Virtual LAN (VLAN) trunking
AnswerB

Port mirroring, often called Switched Port Analyzer (SPAN) on Cisco switches, copies frames from one or more source ports to a designated destination port where a monitoring device is connected. This allows the NIDS to see all traffic passing through the server port without disrupting network flow. It is the standard method for enabling intrusion detection on switched networks.

Why this answer

Port mirroring (SPAN) is the correct technology because it copies traffic from a source port to a destination port, allowing a NIDS to monitor all traffic without being inline. STP, VLAN trunking, and LACP serve different purposes: loop prevention, carrying multiple VLANs, and link aggregation, respectively. None of them replicate traffic to a monitoring port.

Port mirroring is essential for passive monitoring in switched environments.

Exam trap

The trap here is assuming that any port that carries traffic (like a trunk or LACP bundle) will automatically provide full visibility to a monitoring device.

97
MCQhard

A security administrator is configuring a firewall to allow outbound web traffic from internal users. The firewall must inspect the application layer data to block malicious URLs. Which type of firewall should be used?

A.Application proxy firewall
B.Stateless packet filter
C.Stateful firewall
D.Network Access Control (NAC) system
AnswerA

An application proxy firewall terminates and inspects traffic at Layer 7, examining HTTP request contents including URLs. This satisfies the requirement to inspect application-layer data and block malicious URLs, which packet-filtering firewalls cannot achieve since they only examine headers.

Why this answer

An application proxy firewall is correct because it operates at the application layer (Layer 7) and can inspect HTTP/HTTPS traffic to block malicious URLs. It acts as an intermediary, terminating the client connection and initiating a new one to the server, allowing deep inspection of application data. This meets the requirement to inspect application layer data for outbound web traffic.

Exam trap

The trap is assuming that a stateful firewall can inspect URLs because it tracks connections, but stateful firewalls only track state at Layers 3-4; application layer inspection requires a proxy or NGFW.

How to eliminate wrong answers

Option B is wrong because a stateless packet filter only examines headers (IP, port, protocol) and cannot inspect application layer payloads like URLs. Option C is wrong because a stateful firewall tracks connection state but still does not inspect application layer data such as HTTP URLs; it operates at Layers 3 and 4. Option D is wrong because NAC systems control device access to the network based on policy, not inspect outbound web traffic for malicious URLs.

98
MCQhard

During a security audit, a penetration tester successfully extracts the PMKID from a wireless beacon. What information can be derived from this attack?

A.The PMK (pairwise master key) directly
B.The ability to crack the passphrase offline
C.The encryption keys used in the session
D.The PSK (pre-shared key) directly
AnswerB

Extracting the PMKID from a single beacon frame enables offline brute-force or dictionary attacks against the WPA2 passphrase, without requiring a full four-way handshake capture or client interaction. This satisfies the scenario's constraint: deriving the network passphrase from minimal captured data.

Why this answer

The PMKID attack captures the PMKID from a wireless beacon or association frame, which is derived from the PMK and other values. This PMKID can be used to perform an offline brute-force or dictionary attack against the passphrase (PSK). The attacker cannot directly derive the PMK or PSK from the PMKID, but can attempt to crack the passphrase offline.

Exam trap

SSCP often tests the distinction between the PMKID and the actual keys, and candidates may incorrectly assume that capturing the PMKID directly yields the PSK or PMK, when in fact it only enables an offline cracking attempt.

How to eliminate wrong answers

Option A is wrong because the PMK (pairwise master key) cannot be directly derived from the PMKID; the PMKID is a hash of the PMK and other values, and reversing it is computationally infeasible. Option C is wrong because the encryption keys used in the session (such as the PTK) are derived after a successful 4-way handshake and are not exposed by the PMKID. Option D is wrong because the PSK (pre-shared key) is the passphrase itself, and it cannot be directly extracted from the PMKID; it must be cracked offline.

99
MCQeasy

Which of the following network protocols operates on TCP port 22 and provides secure remote administration of network devices?

A.SSH
C.RDP
D.FTP
AnswerA

SSH listens on TCP port 22 and encrypts the entire session, providing secure remote administration of network devices. Telnet offers similar administration but transmits credentials in cleartext on port 23, so SSH uniquely satisfies both the port and security constraints.

Why this answer

SSH (Secure Shell) operates on TCP port 22 and provides encrypted remote administration of network devices, replacing insecure protocols like Telnet. It uses strong cryptography for authentication and session confidentiality, making it the standard for secure CLI management of routers, switches, and servers.

Exam trap

The trap here is confusing port numbers and protocol purposes — candidates may associate RDP with 'remote administration' and pick it, forgetting that RDP is GUI-based on port 3389, while the question specifies TCP port 22 and secure CLI administration.

How to eliminate wrong answers

Option B is wrong because Telnet uses TCP port 23 and transmits all data, including credentials, in cleartext, offering no confidentiality or integrity. Option C is wrong because RDP uses TCP port 3389 and provides graphical remote desktop access to Windows systems, not secure CLI administration of network devices. Option D is wrong because FTP uses TCP ports 20/21 for file transfer and does not provide remote administration or encryption (unless FTPS/SFTP variants are used).

100
MCQeasy

A network administrator is configuring a demilitarized zone (DMZ) to host a public web server. The server must be accessible from the internet but should be isolated from the internal network. Which of the following is the primary security benefit of placing the web server in a DMZ?

A.It provides encryption for all traffic to and from the web server.
B.It prevents all attacks against the web server by filtering malicious traffic.
C.It automatically patches the web server against vulnerabilities.
D.It limits the exposure of the internal network if the web server is compromised.
AnswerD

The primary security benefit of a DMZ is to isolate publicly accessible services from the internal network. If the web server is compromised, the attacker is contained within the DMZ and cannot directly access internal resources. Firewalls between the DMZ and internal network restrict traffic, adding a layer of defense. This segmentation limits the blast radius of a security breach.

Why this answer

The primary security benefit of a DMZ is to isolate public-facing services from the internal network. If the web server in the DMZ is compromised, the attacker cannot directly access internal systems because firewalls restrict traffic between the DMZ and the internal network. This segmentation limits the damage.

Other options describe encryption, prevention, or patching, which are not inherent to a DMZ.

Exam trap

The trap here is confusing the DMZ's isolation benefit with other security controls like encryption or patching, which are separate measures.

← PreviousPage 2 of 2 · 100 questions total

Ready to test yourself?

Try a timed practice session using only Sscp Network Security questions.