โ† All CAP Flashcard Decks

Network Security Fundamentals Flashcards

7 cards from real CAP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Fundamentals flashcards as text
  1. What is the difference between a whitelist (allowlist) and a blacklist (blocklist) approach in network access control?

    Answer: Whitelisting denies all except explicitly permitted; blacklisting permits all except explicitly denied

    Whitelisting (default-deny) blocks all traffic except what is explicitly permitted, while blacklisting (default-allow) permits all traffic except what is explicitly blocked.

  2. Which attack technique involves sending specially crafted ICMP packets to crash or degrade a target system's availability?

    Answer: Ping of Death

    The Ping of Death sends oversized or malformed ICMP packets that exceed protocol limits, causing target systems to crash or become unstable.

  3. In the RMF process, which step involves assessing the effectiveness of implemented security controls including network controls?

    Answer: Assess

    The Assess step (Step 4 of RMF) involves testing and evaluating security controls, including network controls, to determine if they are implemented correctly and operating as intended.

  4. What is the purpose of network time synchronization (NTP) from a security perspective?

    Answer: To ensure consistent, accurate timestamps across devices for log correlation and forensics

    Accurate time synchronization ensures log entries across devices have consistent timestamps, which is critical for correlating security events and conducting forensic investigations.

  5. Which type of firewall rule configuration follows the principle of 'implicit deny' at the end of the ruleset?

    Answer: Default-deny or deny-all rule at the bottom

    A default-deny (implicit deny) rule at the end of a firewall ruleset ensures any traffic not explicitly permitted by a prior rule is automatically blocked.

  6. What security control should be implemented to detect and prevent a rogue DHCP server from distributing incorrect network configuration to clients?

    Answer: DHCP snooping

    DHCP snooping is a Layer 2 switch security feature that validates DHCP messages and only permits DHCP responses from trusted (authorized) server ports.

  7. A security assessor discovers that a federal system transmits sensitive data over an unencrypted HTTP connection internally. Under NIST 800-53, which control is most directly violated?

    Answer: SC-8: Transmission Confidentiality and Integrity

    NIST SP 800-53 SC-8 requires that systems implement cryptographic mechanisms to protect the confidentiality and integrity of data during transmission.