โ† All CCP Flashcard Decks

Network Security & Communication Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Communication Protection flashcards as text
  1. Which wireless security protocol uses SAE (Simultaneous Authentication of Equals) to protect against offline dictionary attacks?

    Answer: WPA3

    WPA3 replaces WPA2's PSK handshake with SAE, which prevents offline password guessing even if an attacker captures the four-way handshake.

  2. A company wants to ensure that only authenticated and policy-compliant devices can connect to the corporate network. Which technology enforces this?

    Answer: Network Access Control (NAC)

    NAC evaluates device health posture and authentication status before granting network access, quarantining non-compliant endpoints.

  3. Which DNS security extension mechanism digitally signs DNS resource records to prevent DNS cache poisoning?

    Answer: DNSSEC

    DNSSEC uses public key cryptography to sign DNS records, allowing resolvers to verify record authenticity and detect tampering.

  4. An IDS generates an alert for legitimate traffic that matches a known attack signature. What is this called?

    Answer: False positive

    A false positive occurs when an IDS incorrectly flags benign traffic as malicious, which can lead to alert fatigue and blocking legitimate activity.

  5. Which protocol provides secure, encrypted remote command-line access to network devices and replaces Telnet?

    Answer: SSH

    SSH (Secure Shell) encrypts all traffic including authentication credentials, replacing the plaintext Telnet protocol for remote administration.

  6. A network engineer implements 802.1X on switch ports. Which component acts as the intermediary that forwards authentication requests to the authentication server?

    Answer: Authenticator

    In 802.1X, the authenticator (switch or AP) passes credentials from the supplicant (client) to the authentication server (RADIUS) without processing them.

  7. Which attack exploits the trust relationship between a DNS resolver and its cache by injecting forged DNS responses?

    Answer: DNS cache poisoning

    DNS cache poisoning corrupts a resolver's cache with fraudulent records, redirecting users to attacker-controlled servers without their knowledge.