MCQ Collection
Network Security MCQs
Network Security MCQs covering firewalls, attacks, protocols, and secure communication.
Choose an option to check your answer.
A.
captures and inspects network packets for analysis or unauthorized observation
B.
changes passwords into certificates
C.
is only a database backup
D.
is the same as patch management
Show Answer
Correct Answer: A. captures and inspects network packets for analysis or unauthorized observation
Explanation:
This is correct because Packet sniffing captures and inspects network packets for analysis or unauthorized observation.
Choose an option to check your answer.
A.
removes all need for routing
B.
makes decisions using packet header fields such as IP address, port, and protocol
C.
stores biometric logs only
D.
decrypts all traffic by default
Show Answer
Correct Answer: B. makes decisions using packet header fields such as IP address, port, and protocol
Explanation:
This is correct because Packet-filtering firewall makes decisions using packet header fields such as IP address, port, and protocol.
Choose an option to check your answer.
A.
monitors network or host activity and generates alerts for suspicious behavior
B.
is only a backup storage device
C.
always blocks traffic automatically
D.
assigns IP addresses
Show Answer
Correct Answer: C. always blocks traffic automatically
Explanation:
The misconception is "always blocks traffic automatically"; in reality, IDS monitors network or host activity and generates alerts for suspicious behavior.
Choose an option to check your answer.
A.
is used only for cable testing
B.
matches only exact known signatures
C.
looks for deviations from normal behavior that may indicate attacks
D.
means deleting all logs
Show Answer
Correct Answer: C. looks for deviations from normal behavior that may indicate attacks
Explanation:
The correct answer is that Anomaly-based detection looks for deviations from normal behavior that may indicate attacks.
Choose an option to check your answer.
A.
replaces TLS certificates entirely
B.
hides all IP addresses from routers
C.
adds cryptographic validation to DNS data to help prevent forged responses
D.
encrypts every web page payload
Show Answer
Correct Answer: C. adds cryptographic validation to DNS data to help prevent forged responses
Explanation:
The correct answer is that DNSSEC adds cryptographic validation to DNS data to help prevent forged responses.
Choose an option to check your answer.
A.
stores biometric logs only
B.
removes all need for routing
C.
understands every application context automatically
D.
makes decisions using packet header fields such as IP address, port, and protocol
Show Answer
Correct Answer: C. understands every application context automatically
Explanation:
The misconception is "understands every application context automatically"; in reality, Packet-filtering firewall makes decisions using packet header fields such as IP address, port, and protocol.
Choose an option to check your answer.
A.
replaces user training
B.
always blocks traffic automatically
C.
monitors network or host activity and generates alerts for suspicious behavior
D.
assigns IP addresses
Show Answer
Correct Answer: C. monitors network or host activity and generates alerts for suspicious behavior
Explanation:
The correct answer is that IDS monitors network or host activity and generates alerts for suspicious behavior.
Choose an option to check your answer.
A.
creates DNSSEC keys automatically
B.
detects and blocks malicious files or patterns in traffic or endpoints
C.
guarantees no user mistakes occur
D.
is a physical lock for racks only
Show Answer
Correct Answer: B. detects and blocks malicious files or patterns in traffic or endpoints
Explanation:
The correct answer is that Antivirus filtering detects and blocks malicious files or patterns in traffic or endpoints.
Choose an option to check your answer.
A.
adds cryptographic validation to DNS data to help prevent forged responses
B.
encrypts every web page payload
C.
turns DNS into a file system
D.
replaces TLS certificates entirely
Show Answer
Correct Answer: A. adds cryptographic validation to DNS data to help prevent forged responses
Explanation:
DNSSEC is best described as something that adds cryptographic validation to DNS data to help prevent forged responses.
Choose an option to check your answer.
A.
understands every application context automatically
B.
makes decisions using packet header fields such as IP address, port, and protocol
C.
removes all need for routing
D.
decrypts all traffic by default
Show Answer
Correct Answer: B. makes decisions using packet header fields such as IP address, port, and protocol
Explanation:
The correct answer is that Packet-filtering firewall makes decisions using packet header fields such as IP address, port, and protocol.
Choose an option to check your answer.
A.
is a spreadsheet formula
B.
cannot be placed inline
C.
can detect suspicious activity and actively block or prevent it according to policy
D.
only records alerts without action
Show Answer
Correct Answer: C. can detect suspicious activity and actively block or prevent it according to policy
Explanation:
The correct answer is that IPS can detect suspicious activity and actively block or prevent it according to policy.
Choose an option to check your answer.
A.
is a physical lock for racks only
B.
turns UDP into TCP
C.
detects and blocks malicious files or patterns in traffic or endpoints
D.
creates DNSSEC keys automatically
Show Answer
Correct Answer: C. detects and blocks malicious files or patterns in traffic or endpoints
Explanation:
Antivirus filtering is best described as something that detects and blocks malicious files or patterns in traffic or endpoints.