Network Security & Best Practices Flashcards
7 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Best Practices flashcards as text
Which type of network attack involves an attacker sending gratuitous ARP replies to associate their MAC address with a legitimate IP address?
Answer: ARP poisoning
ARP poisoning (ARP spoofing) corrupts the ARP cache of hosts by sending fake ARP replies, redirecting traffic to the attacker.
A company needs to allow remote employees to securely access internal resources over the internet as if they were on the local network. Which solution best meets this need?
Answer: Remote Access VPN
A remote access VPN creates an encrypted tunnel from an individual user's device to the corporate network, providing secure access to internal resources.
What does 'two-factor authentication' (2FA) require that single-factor authentication does not?
Answer: Verification using two different categories of credentials (e.g., password + OTP)
2FA requires credentials from two different categories: something you know (password), something you have (token), or something you are (biometric).
Which network security tool monitors and analyzes traffic in real time to detect and potentially block malicious activity?
Answer: Intrusion Detection/Prevention System (IDS/IPS)
An IDS detects suspicious traffic and alerts administrators, while an IPS can also actively block or drop malicious packets in real time.
A technician needs to prevent rogue devices from sending forged ARP responses on a VLAN. DHCP snooping is already enabled. What additional feature should be configured?
Answer: Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI) uses the DHCP snooping binding table to validate ARP packets and drop those with spoofed IP-to-MAC mappings.
Which of the following best describes a 'zero-day' vulnerability?
Answer: A vulnerability that is publicly known and has an available exploit before a patch exists
A zero-day vulnerability is one that is unknown to the vendor or has no available patch, giving defenders 'zero days' to prepare.
What is the role of a Certificate Authority (CA) in Public Key Infrastructure (PKI)?
Answer: To issue, sign, and revoke digital certificates that bind public keys to identities
A Certificate Authority is a trusted entity that issues digital certificates, cryptographically binding a public key to a verified identity.