โ† All COMPTIA Flashcard Decks

Network+ Network Security Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Security flashcards as text
  1. Which attack sends unsolicited ARP replies to poison a host's ARP cache and redirect traffic?

    Answer: ARP poisoning

    ARP poisoning (ARP spoofing) sends gratuitous ARP replies to associate an attacker's MAC with a legitimate IP, enabling man-in-the-middle attacks.

  2. What is the primary purpose of a honeynet?

    Answer: Lure attackers into an isolated environment to study their techniques

    A honeynet is a network of honeypots designed to attract attackers and gather intelligence on their tools and methods.

  3. Which protocol provides mutual authentication and encrypts 802.1X EAP exchanges using TLS tunnels?

    Answer: PEAP

    PEAP (Protected EAP) wraps EAP in a TLS tunnel, providing server authentication via certificate and protecting inner EAP credentials.

  4. A company wants to prevent users from accessing social media during work hours. Which security control is BEST suited?

    Answer: Content/URL filtering

    Content/URL filtering (typically via a proxy or next-gen firewall) inspects URLs and blocks access to categories like social media.

  5. In the context of firewalls, what does a stateful inspection firewall track that a basic packet filter does not?

    Answer: The state of active TCP/UDP connections

    Stateful inspection firewalls maintain a connection state table to verify that incoming packets belong to an established or related connection.

  6. Which wireless security attack exploits the TKIP implementation in WPA to recover keystream bytes?

    Answer: TKIP MIC exploit (Beck-Tews)

    The Beck-Tews attack exploits weaknesses in WPA's TKIP MIC (Michael) algorithm to inject short packets and recover keystream.

  7. What distinguishes a zero-day vulnerability from other security vulnerabilities?

    Answer: No patch or fix is publicly available at the time of exploitation

    A zero-day vulnerability is one that is exploited before the vendor has released a patch, giving defenders zero days to protect themselves.