Network Security & Threat Mitigation Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Threat Mitigation flashcards as text
Which type of attack involves an adversary intercepting and potentially altering communications between two parties without their knowledge?
Answer: Man-in-the-middle (MitM) attack
A man-in-the-middle attack occurs when an attacker secretly intercepts and relays messages between two parties who believe they are communicating directly.
What is the primary purpose of network segmentation in a defense-in-depth strategy?
Answer: Limit lateral movement by containing breaches to isolated zones
Network segmentation divides a network into isolated zones so that a compromise in one segment cannot easily spread to others, limiting lateral movement.
A security team detects a high volume of UDP packets flooding a target server. Which attack type does this most likely represent?
Answer: UDP flood DDoS attack
A UDP flood is a volumetric DDoS attack that overwhelms the target with large numbers of UDP packets, exhausting network resources.
Which protocol is commonly used to securely manage network devices remotely, replacing the insecure Telnet protocol?
Answer: SSH
SSH (Secure Shell) provides encrypted remote management of network devices, making it the secure replacement for plaintext Telnet.
What does a stateful firewall track that a stateless packet filter does not?
Answer: The state of active network connections
A stateful firewall maintains a connection state table to track active sessions, allowing it to make context-aware filtering decisions.
Which mitigation technique is most effective against SYN flood attacks?
Answer: Implementing SYN cookies
SYN cookies allow servers to respond to SYN requests without allocating resources until the three-way handshake is complete, defeating SYN floods.
An attacker sends crafted ICMP packets to a broadcast address, causing multiple hosts to reply to a victim. What attack is this?
Answer: Smurf attack
A Smurf attack uses ICMP echo requests sent to a broadcast address with a spoofed victim source IP, causing all hosts on the network to flood the victim with replies.