Free ISC2 Certified in Cybersecurity practice — 6 questions on Network Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 4: Network Security
A network administrator discovers that an attacker connected to an unused switch port was able to send traffic between two VLANs that should have been isolated, by embedding one VLAN tag inside another. Which attack technique does this describe, and what is the PRIMARY mitigation?
Double tagging exploits a mismatched or default native VLAN on a trunk port to smuggle traffic across VLAN boundaries. The standard defense is to never use the default native VLAN, assign it to an unused/black-hole VLAN, and disable dynamic trunk negotiation (DTP) on ports that don't need it.
Question 2 of 6 · Domain 4: Network Security
A security architect wants to segment a network into multiple broadcast domains that can only communicate with one another if explicitly permitted by an access control policy enforced based on IP addressing. Which device should be placed between the segments to meet this requirement?
Routing decisions and IP-based ACL enforcement occur at Layer 3. A router or Layer 3 switch can inspect source/destination IP addresses and apply policy to permit or deny inter-segment traffic.
Question 3 of 6 · Domain 4: Network Security
An organization is configuring a site-to-site VPN between two corporate offices using IPsec. They need the ENTIRE original IP packet, including its header, to be encrypted and encapsulated inside a new outer IP header for transit across the public Internet. Which IPsec mode should be configured?
Tunnel mode encrypts and encapsulates the entire original IP packet (header and payload) inside a new outer IP header, which is exactly the behavior required for gateway-to-gateway site-to-site VPNs.
Question 4 of 6 · Domain 4: Network Security
Which statement BEST distinguishes an Intrusion Prevention System (IPS) from an Intrusion Detection System (IDS) in terms of network placement and capability?
An IPS sits directly in the traffic path (inline), allowing it to actively drop or block malicious packets in real time. An IDS typically monitors a copy of traffic (via SPAN/mirror port) out-of-band and can only generate alerts, not stop traffic.
Question 5 of 6 · Domain 4: Network Security
A web server begins receiving a massive volume of TCP connection requests. For each request, the server sends a SYN-ACK and reserves resources while waiting for the final ACK, but the ACK never arrives. Within minutes, the server can no longer accept legitimate connections. Which attack is being described, and which mitigation is MOST effective?
This describes a SYN flood: the attacker never completes the three-way handshake, leaving half-open connections that exhaust the server's connection backlog. SYN cookies let the server avoid reserving state until the final ACK is verified, effectively neutralizing the attack.
Question 6 of 6 · Domain 4: Network Security
A company wants to host a public-facing web server that must be reachable from the Internet while ensuring that if the server is compromised, the attacker cannot directly pivot into the internal corporate network. Which architecture BEST meets this requirement?
A screened subnet (DMZ) architecture with dual firewalls isolates the public-facing server from the internal network, applying defense in depth so that a compromise of the DMZ host requires bypassing a second firewall boundary before reaching internal assets.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code SECPREP34 — valid through Oct 11.