Network Security & Threat Mitigation Flashcards
7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Threat Mitigation flashcards as text
Which attack targets the ARP protocol to associate the attacker's MAC address with a legitimate IP address on a local network?
Answer: ARP spoofing
ARP spoofing (or ARP poisoning) sends fake ARP replies to map the attacker's MAC to a legitimate IP, enabling traffic interception on the local network.
What is the purpose of implementing 802.1X authentication on a network?
Answer: Authenticate devices before granting network access via a RADIUS server
802.1X is a port-based Network Access Control (NAC) standard that requires devices to authenticate (typically via RADIUS) before they can access the network.
An attacker exploits a switch's CAM table overflow to make it behave like a hub, enabling traffic sniffing. What is this attack called?
Answer: MAC flooding
MAC flooding overwhelms a switch's CAM table by sending frames with many fake source MAC addresses, causing the switch to broadcast frames to all ports like a hub.
Which of the following best describes a zero-day exploit in the context of network threats?
Answer: An exploit targeting a vulnerability with no available patch
A zero-day exploit targets a vulnerability that is unknown to the vendor and therefore has no patch or defense available at the time of the attack.
What security mechanism does DNSSEC provide to protect DNS infrastructure?
Answer: Digitally signs DNS records to verify their authenticity and integrity
DNSSEC uses digital signatures to cryptographically verify the authenticity and integrity of DNS records, protecting against cache poisoning and spoofing.
In network threat mitigation, what does the principle of 'least privilege' require when applied to firewall rules?
Answer: Only the minimum necessary ports and protocols should be allowed
Applying least privilege to firewall rules means only permitting the specific traffic required for business functions and blocking everything else by default.
Which technique do attackers use to evade network-based intrusion detection by sending overlapping or out-of-order TCP fragments?
Answer: Session splicing / fragmentation evasion
Fragmentation or session-splicing evasion splits malicious payloads across multiple TCP or IP fragments so that signature-based IDS systems fail to reassemble and match patterns.