โ† All COMPTIA Flashcard Decks

Network+ Network Security Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Security flashcards as text
  1. Which type of IDS/IPS detection method identifies threats by looking for deviations from a learned baseline of normal behavior?

    Answer: Anomaly-based detection

    Anomaly-based detection establishes a baseline of normal traffic patterns and flags deviations, making it effective against novel attacks.

  2. An attacker sends thousands of SYN packets without completing the three-way handshake. What attack is being performed?

    Answer: SYN flood

    A SYN flood exhausts a server's connection table by sending SYN packets and never sending the final ACK, leaving half-open connections.

  3. Which security framework uses the concept of 'never trust, always verify' as its core principle?

    Answer: Zero Trust

    Zero Trust assumes no user or device is inherently trusted, requiring continuous verification regardless of network location.

  4. What is the function of a RADIUS server in network security?

    Answer: Provides centralized authentication, authorization, and accounting for network access

    RADIUS (Remote Authentication Dial-In User Service) centralizes AAA services, allowing network devices to authenticate users against a single server.

  5. Which attack technique involves an attacker sending a spoofed ICMP echo request to a network broadcast address to amplify a DoS attack?

    Answer: Smurf attack

    A Smurf attack sends spoofed ICMP echo requests to a broadcast address so all hosts on that network reply to the victim's spoofed source IP.

  6. What does DNSSEC add to standard DNS to prevent DNS cache poisoning?

    Answer: Digital signatures to validate DNS records

    DNSSEC uses public-key cryptography to digitally sign DNS records, allowing resolvers to verify that responses are authentic and unmodified.

  7. Which tool is commonly used to perform a man-in-the-middle attack on a LAN by combining ARP poisoning with traffic capture?

    Answer: Ettercap

    Ettercap is an open-source tool that automates ARP poisoning and traffic interception, enabling MITM attacks on local network segments.