Network Security & Protocols Flashcards
7 cards from real CPA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Network Security & Protocols flashcards as text
What is a zero-day vulnerability?
Answer: A flaw in software that is unknown to the vendor and has no patch available
A zero-day vulnerability is an undisclosed security flaw that attackers can exploit before the vendor is aware or has issued a fix.
Which protocol is used by email clients to securely retrieve messages from a mail server over an encrypted connection?
Answer: POP3 with STARTTLS or IMAPS
IMAP over SSL/TLS (IMAPS, port 993) or POP3 with STARTTLS provides encrypted retrieval of email messages from a mail server.
What does 'defense in depth' mean in network security?
Answer: Layering multiple independent security controls so that if one fails, others still protect the system
Defense in depth applies multiple overlapping security layers — firewalls, IDS, encryption, access controls — so no single failure compromises the entire system.
What is the purpose of a honeypot in network security?
Answer: Serve as a decoy system to detect, deflect, or study attacker activity
A honeypot is a deliberately vulnerable decoy system that lures attackers, allowing security teams to observe their techniques and gather threat intelligence.
What type of attack exploits trust relationships between networked systems by forging the source IP address of packets?
Answer: IP spoofing
IP spoofing forges the source IP address in packet headers to impersonate trusted hosts or conceal the attacker's origin.
What is the role of a Certificate Authority (CA) in public key infrastructure (PKI)?
Answer: Issue and digitally sign certificates that verify the identity of entities
A CA is a trusted third party that validates identities and issues digital certificates, forming the root of trust in a PKI.
Which network scanning technique sends TCP SYN packets to target ports and analyzes responses without completing the full three-way handshake?
Answer: SYN (stealth) scan
A SYN scan (half-open scan) sends SYN packets and reads SYN-ACK (open) or RST (closed) responses without completing the connection, making it stealthier than a full connect scan.