โ† All CCP Flashcard Decks

Network Security & Threat Mitigation Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Threat Mitigation flashcards as text
  1. Which technology creates an encrypted tunnel over a public network to securely connect remote users to an organization's internal network?

    Answer: VPN

    A Virtual Private Network (VPN) establishes an encrypted tunnel that allows remote users to securely access internal corporate resources over the internet.

  2. What is the role of an Intrusion Prevention System (IPS) compared to an Intrusion Detection System (IDS)?

    Answer: IPS actively blocks malicious traffic; IDS only detects and alerts

    An IPS is deployed inline and can actively block or drop malicious traffic, while an IDS monitors traffic passively and generates alerts without blocking.

  3. Which network attack exploits trust relationships between systems by forging the source IP address of packets?

    Answer: IP spoofing

    IP spoofing involves crafting packets with a falsified source IP address to impersonate trusted systems or conceal the attacker's identity.

  4. In the context of wireless security, what does a deauthentication attack accomplish?

    Answer: Forces clients to disconnect from an access point

    A deauthentication attack sends forged 802.11 deauth frames to disconnect clients from a wireless access point, which can be used to capture handshakes or cause disruption.

  5. What is the primary function of a DMZ (Demilitarized Zone) in network architecture?

    Answer: To provide a buffer zone for publicly accessible servers between the internet and internal network

    A DMZ is a subnet that exposes external-facing services (web, email, DNS) to the internet while isolating the internal network from direct external access.

  6. Which protocol is most commonly used to carry out DNS amplification DDoS attacks?

    Answer: UDP

    DNS amplification attacks use UDP because DNS queries are small but responses can be much larger, and UDP requires no handshake, enabling high-volume spoofed floods.

  7. A network administrator wants to prevent unauthorized devices from accessing the corporate LAN via switch ports. Which feature should be configured?

    Answer: Port security with MAC address limiting

    Port security allows administrators to restrict which MAC addresses can connect to a switch port, preventing unauthorized devices from accessing the network.