Network Security & Protocols Flashcards
7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Protocols flashcards as text
Which type of firewall inspects traffic all the way up to the application layer?
Answer: Next-generation firewall (NGFW)
An NGFW performs deep packet inspection at the application layer, identifying and controlling applications regardless of port or protocol.
What is the difference between symmetric and asymmetric encryption?
Answer: Symmetric uses one shared key; asymmetric uses a public/private key pair
Symmetric encryption uses a single shared key for both encryption and decryption, while asymmetric encryption uses a mathematically linked public/private key pair.
Which attack involves sending a large volume of ICMP echo requests to overwhelm a target?
Answer: Ping flood (ICMP flood)
A ping flood overwhelms a target by sending massive numbers of ICMP echo request packets, consuming bandwidth and processing resources.
What does VLAN stand for, and what security benefit does it provide?
Answer: Virtual LAN; segments network traffic to limit broadcast domains and isolate systems
A VLAN (Virtual Local Area Network) logically segments a physical network, isolating traffic between groups and reducing the attack surface.
Which protocol is used to securely transfer files over a network using SSH?
Answer: SFTP
SFTP (SSH File Transfer Protocol) uses SSH to provide encrypted file transfer, replacing the plaintext FTP protocol.
What is the purpose of network segmentation in security?
Answer: To limit lateral movement of attackers by dividing the network into isolated zones
Network segmentation divides a network into smaller zones so that a breach in one segment cannot easily spread to others.
Which layer of the OSI model does TLS primarily operate at?
Answer: Layer 6 (Presentation)
TLS operates at the Presentation layer (Layer 6) of the OSI model, providing encryption, authentication, and data integrity for application-layer protocols.