Network Security & Communication Protection Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Communication Protection flashcards as text
A company implements micro-segmentation in their data center. What is the PRIMARY security benefit of this approach?
Answer: Lateral movement prevention between workloads
Micro-segmentation enforces granular east-west traffic controls between individual workloads, limiting an attacker's ability to move laterally after an initial compromise.
Which protocol is used by SSL/TLS to authenticate the Record Layer and protect against message tampering during transmission?
Answer: HMAC
TLS uses HMAC (Hash-based Message Authentication Code) to provide data integrity and authentication for each record transmitted in the session.
An attacker exploits a misconfigured open DNS resolver to amplify a DDoS attack. What makes DNS suitable for amplification attacks?
Answer: Small DNS queries can return much larger responses
DNS amplification works because a small forged query (e.g., ANY record request) can return a response many times larger, overwhelming the spoofed victim's bandwidth.
Which Zero Trust principle requires that all network traffic be verified regardless of whether it originates inside or outside the corporate perimeter?
Answer: Never trust, always verify
The Zero Trust principle of 'never trust, always verify' eliminates implicit trust based on network location, requiring continuous verification of all connections.
A network security engineer deploys honeypots on the internal network. What is the PRIMARY purpose of these systems?
Answer: Detect and analyze attacker behavior after perimeter breach
Honeypots are decoy systems designed to attract attackers, allowing defenders to detect lateral movement and study attacker techniques in a controlled environment.
Which email authentication mechanism publishes a DNS record specifying which mail servers are authorized to send email on behalf of a domain?
Answer: SPF
SPF (Sender Policy Framework) uses a DNS TXT record to list IP addresses and mail servers authorized to send email for a domain, helping detect spoofing.
During a network security assessment, a tester captures traffic and notices passwords transmitted in plaintext on TCP port 23. Which vulnerable service is in use?
Answer: Telnet
Telnet operates on TCP port 23 and transmits all data, including usernames and passwords, in cleartext, making it highly susceptible to eavesdropping.