โ† All CCP Flashcard Decks

Network Security & Communication Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Communication Protection flashcards as text
  1. Which firewall architecture uses a DMZ to host public-facing services while protecting the internal network?

    Answer: Three-legged firewall

    A three-legged (screened subnet) firewall architecture creates a DMZ as a separate network segment between external and internal zones.

  2. An organization wants to encrypt email in transit between mail servers. Which protocol standard should they implement?

    Answer: STARTTLS with TLS

    STARTTLS upgrades an existing SMTP connection to TLS, encrypting email messages as they travel between mail transfer agents.

  3. Which tunneling protocol creates a point-to-point connection and is commonly used with IPsec for remote access VPNs on Windows?

    Answer: L2TP

    L2TP provides the tunneling mechanism while IPsec provides encryption, and together they form L2TP/IPsec, widely used for Windows remote access VPNs.

  4. A security analyst sees a sudden spike in UDP traffic to port 19 on internal hosts from external sources. Which attack is likely occurring?

    Answer: Chargen amplification DDoS

    The Character Generator (Chargen) service on UDP port 19 can be abused as an amplifier for DDoS reflection attacks by sending spoofed UDP requests.

  5. Which BGP security mechanism uses cryptographic certificates to validate that an AS is authorized to announce a specific IP prefix?

    Answer: RPKI (Resource Public Key Infrastructure)

    RPKI allows network operators to cryptographically associate an AS with its authorized IP prefixes using Route Origin Authorizations (ROAs).

  6. An attacker sends a TCP SYN packet, receives a SYN-ACK, but never completes the handshake. This is repeated thousands of times. What attack is this?

    Answer: SYN flood DoS attack

    A SYN flood exhausts server connection tables by sending thousands of SYN requests without completing the three-way handshake, denying service to legitimate users.

  7. Which network monitoring protocol should be avoided due to community string transmission in cleartext, and replaced with its more secure version?

    Answer: SNMPv1/v2c

    SNMPv1 and v2c transmit community strings (acting as passwords) in plaintext; SNMPv3 should be used instead as it provides authentication and encryption.