CST CST Network Security & Cybersecurity for Surveillance 2 — Questions and Answers
Question 1: A VPN is used in surveillance systems primarily to:
- Increase camera frame rate
- Provide encrypted remote access to the surveillance network (Correct answer)
- Extend PoE cable distances
- Synchronize time across cameras
Correct answer: Provide encrypted remote access to the surveillance network
A VPN creates an encrypted tunnel allowing technicians or administrators to securely access the surveillance network remotely.
Question 2: Which encryption standard is currently recommended for securing Wi-Fi connections used by wireless surveillance cameras in the US?
- WEP
- WPA
- WPA2-AES or WPA3 (Correct answer)
- TKIP only
Correct answer: WPA2-AES or WPA3
WPA2 with AES or WPA3 provides strong encryption for wireless surveillance cameras, while WEP and original WPA are considered insecure.
Question 3: What is the purpose of enabling HTTPS instead of HTTP on an IP camera's web interface?
- To allow faster video streaming
- To encrypt login credentials and configuration data in transit (Correct answer)
- To enable PTZ control
- To increase storage capacity
Correct answer: To encrypt login credentials and configuration data in transit
HTTPS encrypts communication between the browser and the camera's web interface, protecting credentials from being intercepted.
Question 4: A CST technician discovers that an NVR is running firmware that is 3 years out of date. What is the MOST important reason to update it?
- To improve video compression ratios
- To add support for higher resolution cameras
- To patch known security vulnerabilities (Correct answer)
- To enable cloud storage
Correct answer: To patch known security vulnerabilities
Outdated firmware may contain known, publicly disclosed vulnerabilities that attackers can exploit to compromise the device.
Question 5: What does a firewall rule denying outbound connections from an NVR to unknown external IP addresses help prevent?
- Video compression errors
- Unauthorized data exfiltration or botnet communication (Correct answer)
- Frame rate drops
- Power surge damage
Correct answer: Unauthorized data exfiltration or botnet communication
Restricting outbound traffic from NVRs prevents compromised devices from sending data externally or participating in botnet activity.
Question 6: Which of the following is an example of a man-in-the-middle (MITM) attack on a surveillance network?
- Physically cutting a camera cable
- An attacker intercepting and potentially altering unencrypted video streams (Correct answer)
- A power outage disabling cameras
- A camera lens becoming dirty
Correct answer: An attacker intercepting and potentially altering unencrypted video streams
A MITM attack occurs when an attacker intercepts traffic between two devices, which can compromise unencrypted video feeds.
A VPN is used in surveillance systems primarily to: