Skip to main content

Network Security Review Questions - 699 Verified Questions

Page 1


Network Security Review Questions

Course Introduction

Network Security is a comprehensive course that explores the principles, technologies, and practices used to protect information and systems from unauthorized access, misuse, and cyber threats. Students will learn about core topics such as cryptography, authentication, firewalls, intrusion detection systems, and virtual private networks. The course also examines various attack vectors, methods for vulnerability assessment, risk management strategies, and the implementation of security policies and best practices essential for safeguarding modern networked environments. Through theoretical study and practical exercises, students will gain the skills needed to design, assess, and maintain secure network infrastructures.

Recommended Textbook Guide to Network Defense and Countermeasures 3rd Edition by Randy Weaver

Available Study Resources on Quizplus

14 Chapters

699 Verified Questions

699 Flashcards

Source URL: https://quizplus.com/study-set/2179 Page 2

Chapter 1: Network Security Fundamentals

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43421

Sample Questions

Q1) Which type of attack causes the operating system to crash because it is unable to handle arbitrary data sent to a port?

A) RPC attacks

B) ICMP message abuse

C) malicious port scanning

D) SYN flood

Answer: A

Q2) Why might you want your security system to provide nonrepudiation?

A) to prevent a user from capturing packets and viewing sensitive information

B) to prevent an unauthorized user from logging into the system

C) to trace the origin of a worm spread through email

D) so a user can't deny sending or receiving a communication

Answer: D

Q3) Which term is best described as an attack that relies on the gullibility of people?

A) malicious code

B) script kiddie

C) back door

D) social engineering

Answer: D

To view all questions and flashcards with answers, click on the resource link above.

Page 3

Chapter 2: TCP-IP

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43422

Sample Questions

Q1) Briefly describe Network Address Translation and how it makes a network more secure.

Answer: IP addresses are valuable commodities.If attackers can find a computer's IP address,they can run a port scan to look for open ports they can xploit.By hiding IP addresses,you can prevent certain attacks.To hide the addresses of computers on your network,you can use Network Address Translation (NAT)to translate your private network's internal addresses into the address of the NAT server's external interface connected to the Internet.A private network's internal addresses are not routable on the Internet.

Q2) Which of the following addresses is a Class B IP address?

A) 126.14.1.7

B) 224.14.9.11

C) 189.77.101.6

D) 211.55.119.7

Answer: C

Q3) The TCP protocol uses a three-way handshake to create a connection.

A)True

B)False

Answer: True

To view all questions and flashcards with answers, click on the resource link above.

Page 4

Chapter 3: Network Traffic Signatures

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/43423

Sample Questions

Q1) Of what category of attack is a DoS attack an example?

A) bad header information

B) single-packet attack

C) multiple-packet attack

D) suspicious data payload

Answer: C

Q2) Packet fragmentation is not normal,and can only occur if an attack has been initiated.

A)True

B)False

Answer: True

Q3) Which type of scan has the FIN,PSH,and URG flags set?

A) Xmas scan

B) Null scan

C) FIN scan

D) SYN Scan

Answer: A

Q4) The _______________ part of a packet is the actual data sent from an application on one computer to an application on another.

Answer: payload

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Routing Fundamentals

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43424

Sample Questions

Q1) a state in which all routers on a network have up-to-date routing tables

A)ACE

B)ARP table

C)banner

D)console port

E)convergence

F)inverse mask

G)metrics

H)routing

I)stub router

j.virtual terminal

Q2) Where in an internetwork should extended ACLs be applied?

Q3) What is a dynamic route?

Q4) List the five types of Cisco router passwords.

Q5) A rollover cable is wired similarly to an Ethernet cable except that pins 7 and 8 are crossed.

A)True

B)False

Q6) Describe ACLs.

Q7) What is a distance-vector routing protocol? Give one example.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Cryptography

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43425

Sample Questions

Q1) What is a downside to using Triple DES?

A) uses only a 56-bit key

B) goes through three rounds of encryption

C) using three keys decreases security

D) requires more processing time

Q2) a type of encryption algorithm that encrypts one bit at a time

A)AES

B)block cipher

C)ciphertext

D)cryptanalysis

E)DES

F)XOR function

G)IPsec

H)key management

I)plaintext

J)stream cipher

Q3) What three conditions must be true to make a hashing algorithm secure?

Q4) What does a key derivation do?

Q5) A ________________ occurs when computing the MD5 algorithm with two different initialization vectors produces the same hash value.

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Wireless Network Fundamentals

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43426

Sample Questions

Q1) The Independent Basic Service Set is a wireless network that uses an AP.

A)True

B)False

Q2) Cosmic objects emit different types of energy,known as _________________ radiation.

Q3) the loss of signal strength resulting from the dispersion of the signal over distance

A)absorption

B)amplitude

C)antenna

D)chipping code

E)diffraction

F)fading

G)free space path loss

H)Fresnel zone

I)hopping code

J)polarization

Q4) Compare and contrast analog and digital RF signals.

Q5) Discuss how an ESS works.

Q6) Describe two of the three methods of analog modulation.

Page 8

To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Understanding Wireless Security

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43427

Sample Questions

Q1) Wireless networks are essentially the same as wired networks when it comes to the security threats each faces.

A)True

B)False

Q2) Which of the following is true about the association process?

A) it is a three-step process

B) a station first listens for beacons

C) a station first send an association request

D) the AP transmits an invitation to associate

Q3) Wireless networks are inherently secure because the original IEEE 802.11 standard addressed strong authentication and encryption.

A)True

B)False

Q4) List four issues that a wireless security policy should address.

Q5) Which layer does wireless communication rely heavily upon?

A) MAC sublayer of the Network layer

B) MAC sublayer of the Data Link layer

C) LLC sublayer of the Data Link layer

D) LLC sublayer of the Transport layer

Q6) List the three types of MAC frames defined by the 802.11 standard.

Page 9

To view all questions and flashcards with answers, click on the resource link above.

Chapter 8: Intrusion Detection and Prevention Systems

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43428

Sample Questions

Q1) Where is a host-based IDPS agent typically placed?

A) on a workstation or server

B) at Internet gateways

C) between remote users and internal network

D) between two subnets

Q2) Which of the following is NOT a network defense function found in intrusion detection and prevention systems?

A) prevention

B) response

C) identification

D) detection

Q3) What is an advantage of the anomaly detection method?

A) makes use of signatures of well-known attacks

B) system can detect attacks from inside the network by people with stolen accounts

C) easy to understand and less difficult to configure than a signature-based system

D) after installation, the IDPS is trained for several days or weeks

Q4) What are the three network defense functions performed by an IDPS?

Q5) List four types of information that an NIDPS typically logs.

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Firewalls

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43429

Sample Questions

Q1) At what layer of the OSI model do proxy servers generally operate?

A) Application

B) Session

C) Transport

D) Network

Q2) Describe a packet-filtering scenario that works with the DMZ.

Q3) Stateless packet filtering keeps a record of connections that a host computer has made with other computers.

A)True

B)False

Q4) Which of the following is NOT a protocol,port pair that should be filtered when an attempt is made to make a connection from outside the company network?

A) TCP,80

B) TCP,139

C) UDP,138

D) TCP,3389

Q5) ACLs filter packets by using a __________ base to determine whether to allow a packet to pass.

Q6) What makes an effective rule base? List three points to consider.

Page 11

To view all questions and flashcards with answers, click on the resource link above.

Chapter 10: Firewall Design and Management

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43430

Sample Questions

Q1) What is a critical step you should take on the OS you choose for a bastion host?

A) ensure all security patches are installed

B) make sure it is the latest OS version

C) choose an obscure OS with which attackers are unfamiliar

D) customize the OS for bastion operation

Q2) Describe the process of network address translation.What are the two primary types of NAT?

Q3) Reverse firewalls allow all incoming traffic except what the ACLs are configured to deny.

A)True

B)False

Q4) What is the term used for a computer placed on the network perimeter that is meant to attract attackers?

A) bastion host

B) honeypot

C) proxy decoy

D) virtual server

Q5) How does a server farm and load-balancing software figure into the multiple DMZ/firewall configuration?

Page 12

Q6) How can using two firewalls help in protecting your network?

To view all questions and flashcards with answers, click on the resource link above.

Chapter 11: VPN Concepts

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43431

Sample Questions

Q1) Which of the following is NOT true about a hardware VPN?

A) should be the first choice for fast-growing networks

B) can handle more traffic than software VPNs

C) have more security vulnerabilities than software VPNs

D) create a gateway-to-gateway VPN

Q2) an IETF standard for secure authentication of requests for resource access

A)AH

B)ESP

C)GRE

D)IKE

E)IPsec

F)ISAKMP

G)Kerberos

H)KDC

I)SSL

J)TGT

Q3) _________________ based VPNs are appropriate when the endpoints are controlled by different organizations and network administrators.

Q4) Briefly describe the L2TP protocol.

Q5) Network gateways are ____________ of the VPN connection.

Page 13

To view all questions and flashcards with answers, click on the resource link above.

Chapter 12: Internet and World Wide Web Security

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43432

Sample Questions

Q1) a network architecture that divides DNS services between two servers

A)anycast addressing

B)DNSSEC

C)network access points

D)pharming

E)POP ISPs

F)security-aware resolver

G)spear phishing

H)slit DNS architecture

I)split brain DNS architecture

J)zone transfer

Q2) The term Internet and World Wide Web are different terms that mean the same thing.

A)True

B)False

Q3) Which of the following is a top-level digital certificate in the PKI chain?

A) security-aware resolver

B) trust anchor

C) DNSSEC resolver

D) RRSIG record

To view all questions and flashcards with answers, click on the resource link above. Page 14

Chapter 13: Security Policy Design and Implementation

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43433

Sample Questions

Q1) a process of analyzing the threats an organization faces

A)extranet

B)network assets

C)privileged access policy

D)risk management

E)role-based authentication

F)search warrant

G)subpoena

H)tunneling protocols

I)two-factor authentication

J)vulnerabilities

Q2) By providing _________________ through backup systems,you ensure information remains accessible if primary systems go offline.

Q3) SNA starts with the assumption that a system or network will be ________________.

Q4) Which of the following is NOT a step in threat and risk assessment?

A) Asset definition

B) Recommendation

C) Resolution

D) Threat assessment

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: On-Going Security Management

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/43434

Sample Questions

Q1) Each IDPS has _____________ that gather data passing through the gateway.

Q2) a program that gathers and consolidates events from multiple sources so that the information can be analyzed to improve network security

A)active defense in depth

B)centralized data collection

C)degaussing

D)distributed data collection

E)independent audit

F)operational audit

G)security event management program

H)social engineering

I)target-to-console ratio

J)Tinkerbell program

Q3) _______________ management involves modifying equipment,systems,software,or procedures in a sequential,planned way.

Q4) List four type of events you should monitor as part of a security event management program.

Q5) List three types of changes for which you should use change management.

Q6) What is security auditing and what type of information should be analyzed?

Page 16

To view all questions and flashcards with answers, click on the resource link above.

Turn static files into dynamic content formats.

Create a flipbook
Network Security Review Questions - 699 Verified Questions by Quizplus - Issuu