โ† All CCP Flashcard Decks

Network Security & Communication Protection Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security & Communication Protection flashcards as text
  1. A security engineer needs to prevent eavesdropping on inter-VLAN traffic within a switched network. Which attack does proper VLAN segmentation primarily mitigate?

    Answer: VLAN hopping

    VLAN hopping exploits trunk port misconfigurations to access traffic across VLANs, which proper segmentation and disabling DTP prevents.

  2. Which IPsec mode encapsulates the entire original IP packet, including its header, making it suitable for site-to-site VPN tunnels?

    Answer: Tunnel mode

    Tunnel mode wraps the entire original IP packet in a new IP header, hiding internal addressing and making it ideal for gateway-to-gateway VPNs.

  3. An organization deploys a network device that inspects traffic up to Layer 7 and can block application-specific threats. What type of device is this?

    Answer: Next-Generation Firewall (NGFW)

    NGFWs perform deep packet inspection at Layer 7, enabling application awareness and the ability to detect and block sophisticated application-layer threats.

  4. Which protocol is used to securely exchange encryption keys over an insecure channel without prior shared secrets?

    Answer: Diffie-Hellman

    Diffie-Hellman key exchange allows two parties to establish a shared secret over an untrusted channel without transmitting the secret itself.

  5. A penetration tester discovers that a web application reflects user input directly in HTTP responses. Which network-layer control would BEST limit exploitation?

    Answer: Web Application Firewall (WAF)

    A WAF inspects HTTP/HTTPS traffic and can detect and block XSS and injection attacks by filtering malicious input patterns before they reach the application.

  6. Which TLS component proves the server's identity to the client during the handshake process?

    Answer: Digital certificate

    The server presents a digital certificate signed by a trusted CA, allowing the client to verify the server's identity before establishing an encrypted session.

  7. An attacker intercepts and alters packets between two hosts without either party detecting the change. What type of attack is this?

    Answer: Man-in-the-Middle (MitM) attack

    A MitM attack positions the attacker between two communicating parties to intercept, read, and potentially modify traffic in transit.