Free CompTIA Network+ practice — 6 questions on Network Security, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Network Security
An attacker connects a laptop to an access switch port and crafts frames with two 802.1Q tags: the outer tag matches the port's native VLAN and the inner tag matches a restricted VLAN. The first switch strips the outer tag (since it matches native VLAN) and forwards the frame with the inner tag intact to the trunk, allowing the frame to land on the restricted VLAN on a downstream switch. Which single mitigation BEST prevents this specific attack?
Double-tagging VLAN hopping relies on the outer tag matching the native (untagged) VLAN of the trunk so it gets stripped. Moving the native VLAN to an unused, dedicated VLAN ID removes the exploitable overlap between native VLAN and any access VLAN, defeating the technique.
Question 2 of 6 · Network Security
A network engineer configures port security on an access switch with a maximum of 2 MAC addresses per port. Security policy requires that when a violation occurs, the port must immediately go into an err-disabled state requiring manual administrator intervention to recover, and an SNMP trap must be generated. Which violation mode satisfies this requirement?
The 'shutdown' violation mode (the Cisco default) disables the port completely (err-disabled), generates a syslog message and SNMP trap, and requires an administrator to manually re-enable the port (or configure err-disable recovery). This matches the requirement for administrator intervention and alerting.
Question 3 of 6 · Network Security
A rogue employee connects an unauthorized wireless router to a wired switch port in a break room. The rogue device begins issuing IP leases to nearby wired clients, causing intermittent connectivity failures across the floor as clients receive conflicting gateway information. Which switch feature, once properly configured, would have prevented this outcome?
DHCP snooping distinguishes trusted ports (facing legitimate DHCP servers) from untrusted ports (facing end users). DHCP server messages (OFFER, ACK) arriving on an untrusted port are dropped, which stops a rogue DHCP server plugged into an access port from handing out leases.
Question 4 of 6 · Network Security
A company requires an IPsec VPN tunnel that provides confidentiality (payload encryption) in addition to data integrity and origin authentication for all traffic crossing the tunnel. Which IPsec component must be used to meet this requirement?
ESP provides encryption (confidentiality) of the payload along with optional integrity and authentication, making it the only listed option capable of meeting all three stated requirements including encryption.
Question 5 of 6 · Network Security
In an 802.1X deployment, a switch port is configured to require authentication before granting network access to a connected laptop. The laptop runs client software that supplies credentials, and a backend server validates those credentials using RADIUS before the switch unblocks the port. Which role does the SWITCH play in this 802.1X exchange?
In 802.1X, the switch (or wireless AP) is the authenticator: it controls the physical/logical port state, relays credentials between the supplicant and the authentication server, and only unblocks the port after receiving approval from the authentication server.
Question 6 of 6 · Network Security
Users on a corporate campus report intermittent disconnections from the legitimate SSID, followed by automatic reconnection to a network with the identical SSID and a stronger signal, after which their traffic seems to be intercepted. Wireless spectrum analysis reveals a second access point broadcasting the same SSID and BSSID characteristics as the legitimate AP but with different backend connectivity. Which control specifically detects and helps mitigate this type of attack going forward?
This scenario describes an evil twin / rogue AP attack combined with deauthentication to force clients to associate with the attacker's AP. A WIPS continuously monitors RF spectrum for rogue/duplicate APs and unauthorized BSSIDs, can alert administrators, and can actively contain rogue APs, making it the purpose-built control for detecting and mitigating this attack.
Ready for the real thing?
The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.
undefined$34.99 with code E0363753E03D522425F4 — valid through Sep 23.