MCQ Collection
Network Security MCQs
Network Security MCQs covering firewalls, attacks, protocols, and secure communication.
Choose an option to check your answer.
A.
is a DNS cache attack
B.
cannot use encryption
C.
is only for one user laptop
D.
connects separate networks securely over an untrusted network
Show Answer
Correct Answer: C. is only for one user laptop
Explanation:
The misconception is "is only for one user laptop"; in reality, Site-to-site VPN connects separate networks securely over an untrusted network.
Choose an option to check your answer.
A.
is a denial-of-service tool
B.
is a password reset method
C.
is a DNS record type
D.
provides authentication and integrity for IP packets but not payload confidentiality
Show Answer
Correct Answer: D. provides authentication and integrity for IP packets but not payload confidentiality
Explanation:
This is correct because AH in IPsec provides authentication and integrity for IP packets but not payload confidentiality.
Choose an option to check your answer.
A.
is the same as a firewall rule
B.
stores a private key in plain text for everyone
C.
is a UDP port scanner
D.
binds an identity to a public key through a certificate authority or trust model
Show Answer
Correct Answer: B. stores a private key in plain text for everyone
Explanation:
The misconception is "stores a private key in plain text for everyone"; in reality, Digital certificate binds an identity to a public key through a certificate authority or trust model.
Choose an option to check your answer.
A.
is a DNS cache attack
B.
connects separate networks securely over an untrusted network
C.
is only for one user laptop
D.
is a packet capture file format
Show Answer
Correct Answer: B. connects separate networks securely over an untrusted network
Explanation:
The correct answer is that Site-to-site VPN connects separate networks securely over an untrusted network.
Choose an option to check your answer.
A.
provides authentication and integrity for IP packets but not payload confidentiality
B.
is a DNS record type
C.
is a password reset method
D.
provides only wireless channel scanning
Show Answer
Correct Answer: D. provides only wireless channel scanning
Explanation:
The misconception is "provides only wireless channel scanning"; in reality, AH in IPsec provides authentication and integrity for IP packets but not payload confidentiality.
Choose an option to check your answer.
A.
binds an identity to a public key through a certificate authority or trust model
B.
is a UDP port scanner
C.
contains only a MAC address
D.
stores a private key in plain text for everyone
Show Answer
Correct Answer: A. binds an identity to a public key through a certificate authority or trust model
Explanation:
The correct answer is that Digital certificate binds an identity to a public key through a certificate authority or trust model.
Choose an option to check your answer.
A.
prevents all spoofing automatically
B.
captures and inspects network packets for analysis or unauthorized observation
C.
changes passwords into certificates
D.
is only a database backup
Show Answer
Correct Answer: B. captures and inspects network packets for analysis or unauthorized observation
Explanation:
The correct answer is that Packet sniffing captures and inspects network packets for analysis or unauthorized observation.
Choose an option to check your answer.
A.
provides only wireless channel scanning
B.
is a DNS record type
C.
is a denial-of-service tool
D.
provides authentication and integrity for IP packets but not payload confidentiality
Show Answer
Correct Answer: D. provides authentication and integrity for IP packets but not payload confidentiality
Explanation:
The correct answer is that AH in IPsec provides authentication and integrity for IP packets but not payload confidentiality.
Choose an option to check your answer.
A.
creates a protected tunnel for traffic across an untrusted network
B.
broadcasts traffic to all users
C.
is a replacement for all backups
D.
removes authentication requirements
Show Answer
Correct Answer: A. creates a protected tunnel for traffic across an untrusted network
Explanation:
The correct answer is that VPN creates a protected tunnel for traffic across an untrusted network.
Choose an option to check your answer.
A.
captures and inspects network packets for analysis or unauthorized observation
B.
is only a database backup
C.
changes passwords into certificates
D.
is the same as patch management
Show Answer
Correct Answer: A. captures and inspects network packets for analysis or unauthorized observation
Explanation:
Packet sniffing is best described as something that captures and inspects network packets for analysis or unauthorized observation.
Choose an option to check your answer.
A.
can provide confidentiality, integrity, and authentication for IP packets
B.
is a plain text logging format only
C.
is used only by printers
D.
does not support encryption
Show Answer
Correct Answer: A. can provide confidentiality, integrity, and authentication for IP packets
Explanation:
The correct answer is that ESP in IPsec can provide confidentiality, integrity, and authentication for IP packets.
Choose an option to check your answer.
A.
creates a protected tunnel for traffic across an untrusted network
B.
stores DNS zones only
C.
is a replacement for all backups
D.
removes authentication requirements
Show Answer
Correct Answer: A. creates a protected tunnel for traffic across an untrusted network
Explanation:
VPN is best described as something that creates a protected tunnel for traffic across an untrusted network.