Which of the following best describes the primary purpose of network segmentation?
What is a "screened subnet" (or DMZ) typically used for?
If a message needs to travel from one VLAN to a different VLAN, what type of device must it pass through?
How does port security on a switch specifically help prevent MAC flooding?
What is the key difference between a Network Intrusion Detection System (NIDS) and a Network Intrusion Prevention System (NIPS)?
Which tool is responsible for collecting data streams from multiple sources (firewalls, logs, NIDS) to detect patterns indicating a cyberattack?
Which of the following is a characteristic of signature-based detection?
What is a significant risk associated with establishing a baseline for anomaly-based detection?
Why might an organization hesitate to implement a hybrid detection model despite its effectiveness?
What phenomenon occurs when detection systems generate so many false positives that security personnel become desensitized to them?
Which of the following methods would be most effective for detecting an evil-twin attack?
If you notice that no wireless devices in a specific physical space are able to connect to the network, and you scan for electromagnetic noise, what attack are you likely investigating?
A security analyst notices an unexpected surge of ethernet frames with different MAC addresses. Which attack is likely occurring?
Which of the following indicators might suggest a DNS poisoning attack?
Why are AI algorithms increasingly necessary for threat detection in modern networks?
When configuring AI threat detection, what is the danger of setting the alert threshold too low?
A company with a small IT team has to choose between using a signature-based detection method and an anomaly-based detection method.
Which one would you recommend they use? Explain how your choice works and why it would work for them. (4 points)