TechNuggets Academy

Networking, Protocols, and Network Security

Free GIAC Security Essentials practice — 6 questions on Networking, Protocols, and Network Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Networking, Protocols, and Network Security
A packet capture shows TCP segments sent to multiple ports on a target host. Each segment has only the FIN flag set, with no preceding SYN observed for any of the connections. Open ports produce no response at all; closed ports respond with RST/ACK. Which scan technique is being used, and why does it evade some perimeter defenses?
A scan that sends only the FIN flag with no open-port response and RST/ACK from closed ports is a classic FIN scan. It evades stateless filters/ACLs that are configured to only inspect and block inbound SYN packets as 'new connection attempts,' since a lone FIN never matches that rule.
Question 2 of 6 · Networking, Protocols, and Network Security
A penetration tester demonstrates that crafting Ethernet frames with two stacked 802.1Q tags allows traffic to jump from the guest VLAN onto an isolated finance VLAN, because the trunk's native VLAN is configured to match the guest VLAN. Which single change BEST mitigates this double-tagging VLAN hopping attack?
Double-tagging attacks work because the outer tag matches the native VLAN and gets stripped by the first switch, exposing the inner tag to a VLAN it shouldn't reach. Assigning the native VLAN to an unused ID that no access port uses breaks this assumption and neutralizes the attack.
Question 3 of 6 · Networking, Protocols, and Network Security
A perimeter firewall has one rule permitting outbound traffic from the internal network to the internet. Users report that response traffic from external web servers (SYN-ACK, data packets) is being dropped. The engineer wants return traffic permitted automatically without manually opening inbound rules for every possible ephemeral port. Which firewall capability should be enabled?
Stateful inspection maintains a connection table for each session; when it sees the outbound SYN, it automatically permits the matching inbound SYN-ACK and subsequent packets without requiring a static inbound allow rule for every ephemeral port.
Question 4 of 6 · Networking, Protocols, and Network Security
During a wireless assessment, an attacker forces retransmission of message 3 of the WPA2 4-way handshake, causing the client to reinstall an already-in-use encryption key with a reset nonce and replay counter. Which attack is being performed, and which wireless technology is architecturally designed to prevent this class of issue?
Forcing retransmission of message 3 to trigger key/nonce reinstallation describes the KRACK attack against WPA2's 4-way handshake. WPA3 replaces this handshake with SAE (Dragonfly), which is designed to prevent this specific nonce-reuse weakness.
Question 5 of 6 · Networking, Protocols, and Network Security
An external attacker successfully performs a full zone transfer (AXFR) against an organization's authoritative DNS server, revealing every internal hostname and IP address in the zone. Which control would have BEST prevented this reconnaissance technique?
AXFR should only be permitted to authorized secondary name servers, enforced by IP-based ACLs and/or TSIG cryptographic authentication. This directly prevents unauthorized parties from requesting and receiving the full zone.
Question 6 of 6 · Networking, Protocols, and Network Security
Which statement BEST differentiates anomaly-based network intrusion detection from signature-based detection?
Anomaly-based detection builds a statistical baseline of 'normal' behavior and alerts on deviations, which allows it to catch novel/zero-day attacks that have no known signature, at the cost of a higher false-positive rate compared to signature matching.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →