Network Security & Communication Protection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Communication Protection flashcards as text
Which wireless security protocol uses SAE (Simultaneous Authentication of Equals) to protect against offline dictionary attacks?
Answer: WPA3
WPA3 replaces WPA2's PSK handshake with SAE, which prevents offline password guessing even if an attacker captures the four-way handshake.
A company wants to ensure that only authenticated and policy-compliant devices can connect to the corporate network. Which technology enforces this?
Answer: Network Access Control (NAC)
NAC evaluates device health posture and authentication status before granting network access, quarantining non-compliant endpoints.
Which DNS security extension mechanism digitally signs DNS resource records to prevent DNS cache poisoning?
Answer: DNSSEC
DNSSEC uses public key cryptography to sign DNS records, allowing resolvers to verify record authenticity and detect tampering.
An IDS generates an alert for legitimate traffic that matches a known attack signature. What is this called?
Answer: False positive
A false positive occurs when an IDS incorrectly flags benign traffic as malicious, which can lead to alert fatigue and blocking legitimate activity.
Which protocol provides secure, encrypted remote command-line access to network devices and replaces Telnet?
Answer: SSH
SSH (Secure Shell) encrypts all traffic including authentication credentials, replacing the plaintext Telnet protocol for remote administration.
A network engineer implements 802.1X on switch ports. Which component acts as the intermediary that forwards authentication requests to the authentication server?
Answer: Authenticator
In 802.1X, the authenticator (switch or AP) passes credentials from the supplicant (client) to the authentication server (RADIUS) without processing them.
Which attack exploits the trust relationship between a DNS resolver and its cache by injecting forged DNS responses?
Answer: DNS cache poisoning
DNS cache poisoning corrupts a resolver's cache with fraudulent records, redirecting users to attacker-controlled servers without their knowledge.