Network+ Network Security Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Network Security flashcards as text
Which VPN protocol operates at Layer 2 and is commonly used to create tunnels over which other protocols (like IPSec) are layered?
Answer: L2TP
L2TP (Layer 2 Tunneling Protocol) creates a Layer 2 tunnel but provides no encryption itself, so it is almost always paired with IPSec for security.
A network technician notices that a switch's CPU utilization spikes to 100% after a host begins flooding the network with frames containing random source MAC addresses. What attack is occurring?
Answer: MAC flooding
MAC flooding overwhelms a switch's CAM table with fake MAC entries, causing it to fail open and broadcast all frames like a hub, enabling traffic interception.
What is the purpose of IPSec's Authentication Header (AH)?
Answer: Provides data integrity and origin authentication but not confidentiality
IPSec AH provides integrity and authentication by hashing packet headers and payload, but it does not encrypt data, so it offers no confidentiality.
Which security concept ensures that no single person has enough access to compromise a critical system or process without collusion?
Answer: Separation of duties
Separation of duties divides critical tasks among multiple people so that fraud or error requires collusion between at least two parties.
What type of certificate allows a single certificate to secure multiple hostnames listed in the Subject Alternative Name (SAN) field?
Answer: Multi-domain (SAN) certificate
A multi-domain or SAN certificate explicitly lists multiple FQDNs in the Subject Alternative Name extension, securing all listed hostnames under one certificate.
Which attack specifically targets the process of obtaining or renewing a TLS certificate by impersonating a domain owner to a certificate authority?
Answer: CA impersonation / BGP hijacking for certificate fraud
Attackers can hijack BGP routes or compromise DNS to redirect certificate validation traffic, tricking a CA into issuing a certificate for a domain they don't own.
What is the role of a Security Information and Event Management (SIEM) system?
Answer: Aggregate and correlate logs from multiple sources to detect and investigate security incidents
A SIEM collects logs and events from across the environment, normalizes them, and applies correlation rules to identify potential security incidents.