โ† All CAP Flashcard Decks

Network Security Fundamentals Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Fundamentals flashcards as text
  1. Which encryption protocol is considered insecure and should NOT be used for securing wireless networks?

    Answer: WEP

    WEP (Wired Equivalent Privacy) uses weak RC4 encryption and has known cryptographic flaws that allow it to be cracked in minutes.

  2. What is the purpose of a Security Information and Event Management (SIEM) system in network security?

    Answer: To aggregate, correlate, and analyze security event logs across the network

    A SIEM collects and correlates log data from multiple sources to detect security incidents and support incident response and compliance reporting.

  3. Under NIST SP 800-53, which control family specifically addresses network boundary protection?

    Answer: System and Communications Protection (SC)

    NIST SP 800-53 SC (System and Communications Protection) controls cover network boundary protection, including firewalls, encryption, and secure communications.

  4. What does an Intrusion Prevention System (IPS) do that an Intrusion Detection System (IDS) does not?

    Answer: Actively blocks or drops malicious traffic in real time

    An IPS actively blocks or drops malicious traffic inline, while an IDS only detects and alerts without taking preventive action.

  5. Which VPN protocol is commonly used with IPsec to provide site-to-site connectivity and operates at Layer 3?

    Answer: L2TP/IPsec

    L2TP/IPsec combines L2TP tunneling with IPsec encryption and authentication, commonly used for site-to-site Layer 3 VPN connectivity.

  6. What is the purpose of network flow data (e.g., NetFlow) in security monitoring?

    Answer: To provide summary metadata about network communications for anomaly detection

    NetFlow and similar flow data provide metadata (source, destination, ports, volume) that enables baseline modeling and anomaly detection without capturing full packet payloads.

  7. Which concept ensures that network traffic between two security zones always passes through a security enforcement point?

    Answer: Choke point

    A choke point is a single enforced passage between zones that ensures all inter-zone traffic is inspected and controlled by security devices.