โ† All CCP Flashcard Decks

Network Security & Threat Mitigation Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Threat Mitigation flashcards as text
  1. A company wants to detect internal threats by monitoring for unusual data transfers at night on their network. Which solution is best suited for this?

    Answer: Network Traffic Analysis (NTA) / Network Detection and Response (NDR)

    NTA/NDR tools continuously analyze network traffic patterns to detect anomalies such as unusual data exfiltration, making them ideal for identifying insider threats.

  2. What is the effect of enabling BPDU Guard on a switch port configured for PortFast?

    Answer: Shuts down the port if a BPDU is received, blocking rogue switches

    BPDU Guard disables a PortFast-enabled port if it receives a Bridge Protocol Data Unit (BPDU), protecting the STP topology from rogue or misconfigured switches.

  3. Which attack type involves an attacker gradually exfiltrating small amounts of data over time to avoid detection thresholds?

    Answer: Low-and-slow data exfiltration

    Low-and-slow exfiltration involves stealing data in small increments over an extended period to stay below alert thresholds and avoid triggering DLP or anomaly detection systems.

  4. What is the primary security benefit of using TLS 1.3 over TLS 1.2 for network communications?

    Answer: TLS 1.3 provides faster handshakes and removes support for weak cipher suites

    TLS 1.3 streamlines the handshake to one round-trip, removes legacy weak algorithms (RC4, MD5, SHA-1, RSA key exchange), and mandates forward secrecy, improving both speed and security.

  5. An organization receives a ransom demand after a threat actor encrypts files accessed via an open SMB port. What immediate mitigation should be applied?

    Answer: Block TCP port 445 at the perimeter firewall and segment SMB traffic internally

    Blocking port 445 externally and restricting SMB to only necessary internal segments prevents ransomware from spreading via SMB vulnerabilities like those exploited by EternalBlue.

  6. Which network security control is specifically designed to detect and mitigate rogue DHCP servers on a LAN?

    Answer: DHCP snooping

    DHCP snooping is a layer-2 switch feature that validates DHCP messages and blocks responses from untrusted ports, preventing rogue DHCP servers from hijacking IP assignment.

  7. What distinguishes an Advanced Persistent Threat (APT) from a typical cyberattack in network security?

    Answer: APTs are prolonged, targeted campaigns by sophisticated actors maintaining long-term access

    APTs are long-term, stealthy intrusion campaigns carried out by skilled adversaries who establish persistent access to gather intelligence or cause damage over an extended period.