TechNuggets Academy

Network and Communications Security

Free Systems Security Certified Practitioner practice — 6 questions on Network and Communications Security, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Domain 6: Network and Communications Security
A security analyst reviews packet captures from a company's switched network and finds a frame carrying two 802.1Q VLAN tags: an outer tag matching the trunk's native VLAN and an inner tag matching a restricted finance VLAN. The frame originated from a workstation connected to a standard access port. This is evidence of which attack, and what is the BEST countermeasure?
This describes VLAN hopping via double tagging, which relies on the switch stripping only the outer tag (matching the native VLAN) and forwarding the inner-tagged frame onto the trunk. Moving the native VLAN to an unused, non-routed VLAN and disabling automatic trunk negotiation (DTP) on access ports removes the exploitable condition — attacker frames can no longer ride the native VLAN across a trunk.
Question 2 of 6 · Domain 6: Network and Communications Security
Two hosts on the same switched segment report intermittent connectivity failures and unusually high latency. Packet captures show one host is receiving frames destined for the default gateway's MAC address, but the frames actually originate from an unauthorized machine spoofing the gateway's IP-to-MAC binding. Which switch-level control specifically prevents this attack?
This is ARP cache poisoning/spoofing. Dynamic ARP Inspection (DAI) validates ARP packets against the trusted IP-to-MAC bindings built by DHCP snooping, dropping ARP replies that don't match a legitimate binding — directly stopping forged gateway ARP replies.
Question 3 of 6 · Domain 6: Network and Communications Security
An organization must establish a site-to-site VPN to a partner network, but the partner's ISP performs NAT on the tunnel endpoint's public address before traffic reaches the internet. The VPN must still provide confidentiality, integrity, and origin authentication of the encapsulated payload. Which IPsec configuration should be selected?
ESP provides confidentiality (encryption) plus integrity and authentication of the payload, and tunnel mode encapsulates the entire original IP packet inside a new IP header — required for site-to-site VPNs. Because NAT rewrites IP header fields, NAT-T (encapsulating ESP inside UDP port 4500) is required so the NAT device doesn't corrupt the IPsec header, which is checksummed/authenticated.
Question 4 of 6 · Domain 6: Network and Communications Security
A penetration tester captures a WPA2-Personal 4-way handshake over the air and successfully recovers the passphrase using an offline dictionary attack on commodity hardware. The organization wants a wireless authentication upgrade that makes this specific offline attack infeasible even with a weak passphrase. Which capability of the replacement protocol achieves this?
WPA3-Personal replaces the WPA2 4-way handshake with SAE (the Dragonfly handshake), a zero-knowledge password-authenticated key exchange. Each authentication attempt derives a unique session key and an attacker who captures the exchange cannot perform an offline dictionary/brute-force attack, because SAE requires active, rate-limited interaction with the AP for every guess and provides forward secrecy.
Question 5 of 6 · Domain 6: Network and Communications Security
Which statement correctly differentiates a circuit-level gateway firewall from an application-layer (proxy) firewall?
A circuit-level gateway (e.g., SOCKS proxy) operates at the Session layer, confirming that the TCP handshake is legitimate and relaying traffic without examining the application payload — it's faster but less granular. An application-layer proxy fully terminates and re-establishes the connection, parsing Layer 7 protocol data (like HTTP headers/content) to enforce detailed filtering rules.
Question 6 of 6 · Domain 6: Network and Communications Security
A network intrusion detection sensor is connected directly to a standard access port on a Layer 2 switch. Analysts notice the sensor only alerts on broadcast traffic and packets specifically addressed to its own interface, missing nearly all attacker traffic flowing between other hosts on the segment. Which configuration change resolves this visibility gap?
Unlike a hub, a switch forwards unicast frames only to the destination port, so a NIDS on a normal access port never sees traffic between other hosts. Configuring the port as a SPAN/mirror port copies traffic from specified source ports or VLANs to the sensor's port, restoring the full visibility a NIDS needs to detect attacks between other hosts.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →