An attacker secretly intercepts communication between a user and a banking website, altering messages before passing them along. What type of attack is this?
A hacker sets up a Wi-Fi network called “CoffeeShop_FreeWiFi” that looks nearly identical to the real café network. Unsuspecting customers connect and the attacker collects their traffic. This is an example of:
Which attack involves flooding the wireless frequency with strong EM signals to block legitimate traffic?
In an ARP poisoning attack, what is the attacker attempting to alter?
Faking a MAC address in an ARP poisoning attack is called:
An attacker sends a switch thousands of Ethernet frames with different MAC addresses, forcing it into broadcast mode. What attack is this?
A victim types in the URL of their bank, but is silently redirected to a fake site that steals credentials. What attack caused this?
Hackers drive around neighborhoods with laptops and Wi-Fi antennas, mapping out wireless networks and their leakage outside buildings. This is:
A company has no firewall in place. An attacker easily sends malicious traffic into the network, disrupting services. What vulnerability is being exploited?
An adversary compromises one workstation and then uses it to move laterally to other devices in the LAN. This is an example of:
If an attacker plugs into an unused switch port in a conference room, what security risk arises?
A wireless signal can be detected outside of a company's walls, allowing an attacker to attempt eavesdropping. What type of vulnerability is this?
A network without authentication allows anyone nearby to connect. Which risk does this create?
An attacker plugs in their own wireless device to a free Ethernet port and creates an unauthorized Wi-Fi network inside the LAN. This is called:
Attempting to break weak Wi-Fi encryption to steal data in transit is an example of:
Which of the following best describes the potential impact of a network vulnerability?
Why might some vulnerabilities be considered "low risk"?
Which of the following is a moderate risk vulnerability?
Which of the following is a high risk vulnerability?
A router security policy should prohibit:
A switch security policy should require which of the following?
Which of the following is a common VPN security requirement?
A wireless security policy should require:
Why might organizations disable beacon frame broadcasting on WAPs?
Adjusting wireless signal strength so it doesn’t leak outside a building is an example of:
Which encryption standard is considered secure for wireless networks today?
What is the primary role of a firewall?
A firewall that filters traffic only using packet headers is:
Which firewall can track connection state in addition to headers?
Which firewall type includes intrusion prevention and application filtering?
Firewalls use a set of rules called:
In an ACL, which rule is executed?
What does a typical ACL specify?
Which factor impacts firewall placement?
Why should each network segment have its own firewall?
Where should firewalls always be placed?
Allowing inbound SSH traffic requires what firewall rule?
If firewall rules are applied in the wrong order:
Dividing a network into smaller isolated segments is called:
Why is network segmentation useful for security?
A demilitarized zone (DMZ) is used for:
VLANs are useful because they:
Limiting the number of MAC addresses per switch port is called:
Subnetting improves security by:
A network intrusion detection system (NIDS):
Which tool can block IPs or ports in response to detected attacks?
A SIEM system is unique because it:
Which detection method compares activity to a database of known IoCs?
Which detection method can identify novel, never-seen attacks?
What is the biggest drawback of signature-based detection?
What is the main drawback of anomaly-based detection?
Hybrid detection combines:
Security teams that see too many false alerts may suffer from:
Which attack can be detected by scanning for duplicate ARP packets?
A sudden surge of Ethernet frames with many unique MAC addresses may indicate:
A sudden unexplained drop in website traffic may indicate:
Which log source might contain millions of entries per day, too much for humans to analyze alone?
AI models in threat detection output:
If an AI detection threshold is set too high:
If the threshold is set too low:
Evil-twin networks can be found by:
Jamming attacks are detected by:
Network-based indicators of compromise (IoCs) include: