Network+ Network Security Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Network Security flashcards as text
Which type of IDS/IPS detection method identifies threats by looking for deviations from a learned baseline of normal behavior?
Answer: Anomaly-based detection
Anomaly-based detection establishes a baseline of normal traffic patterns and flags deviations, making it effective against novel attacks.
An attacker sends thousands of SYN packets without completing the three-way handshake. What attack is being performed?
Answer: SYN flood
A SYN flood exhausts a server's connection table by sending SYN packets and never sending the final ACK, leaving half-open connections.
Which security framework uses the concept of 'never trust, always verify' as its core principle?
Answer: Zero Trust
Zero Trust assumes no user or device is inherently trusted, requiring continuous verification regardless of network location.
What is the function of a RADIUS server in network security?
Answer: Provides centralized authentication, authorization, and accounting for network access
RADIUS (Remote Authentication Dial-In User Service) centralizes AAA services, allowing network devices to authenticate users against a single server.
Which attack technique involves an attacker sending a spoofed ICMP echo request to a network broadcast address to amplify a DoS attack?
Answer: Smurf attack
A Smurf attack sends spoofed ICMP echo requests to a broadcast address so all hosts on that network reply to the victim's spoofed source IP.
What does DNSSEC add to standard DNS to prevent DNS cache poisoning?
Answer: Digital signatures to validate DNS records
DNSSEC uses public-key cryptography to digitally sign DNS records, allowing resolvers to verify that responses are authentic and unmodified.
Which tool is commonly used to perform a man-in-the-middle attack on a LAN by combining ARP poisoning with traffic capture?
Answer: Ettercap
Ettercap is an open-source tool that automates ARP poisoning and traffic interception, enabling MITM attacks on local network segments.