MCQ Collection
Network Security MCQs
Network Security MCQs covering firewalls, attacks, protocols, and secure communication.
Choose an option to check your answer.
A.
encrypts wireless traffic
B.
prevents VLAN hopping
C.
overloads a switch MAC address table to affect normal switching behavior
D.
is a DNSSEC validation process
Show Answer
Correct Answer: C. overloads a switch MAC address table to affect normal switching behavior
Explanation:
MAC flooding is best described as something that overloads a switch MAC address table to affect normal switching behavior.
Choose an option to check your answer.
A.
is a decoy system or service designed to attract and study attackers
B.
is a default password list
C.
is a DNS resolver requirement
D.
is only a cable tester
Show Answer
Correct Answer: A. is a decoy system or service designed to attract and study attackers
Explanation:
This is correct because Honeypot is a decoy system or service designed to attract and study attackers.
Choose an option to check your answer.
A.
is designed only for wired Ethernet
B.
stores passwords in DNS records
C.
uses stronger protection than WEP and commonly relies on AES-CCMP in enterprise or personal modes
D.
requires no authentication
Show Answer
Correct Answer: B. stores passwords in DNS records
Explanation:
The misconception is "stores passwords in DNS records"; in reality, WPA2 uses stronger protection than WEP and commonly relies on AES-CCMP in enterprise or personal modes.
Choose an option to check your answer.
A.
prevents VLAN hopping
B.
is a DNSSEC validation process
C.
encrypts wireless traffic
D.
overloads a switch MAC address table to affect normal switching behavior
Show Answer
Correct Answer: D. overloads a switch MAC address table to affect normal switching behavior
Explanation:
This is correct because MAC flooding overloads a switch MAC address table to affect normal switching behavior.
Choose an option to check your answer.
A.
is a decoy system or service designed to attract and study attackers
B.
is a DNS resolver requirement
C.
is a primary production database
D.
is only a cable tester
Show Answer
Correct Answer: C. is a primary production database
Explanation:
The misconception is "is a primary production database"; in reality, Honeypot is a decoy system or service designed to attract and study attackers.
Choose an option to check your answer.
A.
is identical to plain HTTP
B.
stores passwords in DNS records
C.
uses stronger protection than WEP and commonly relies on AES-CCMP in enterprise or personal modes
D.
is designed only for wired Ethernet
Show Answer
Correct Answer: C. uses stronger protection than WEP and commonly relies on AES-CCMP in enterprise or personal modes
Explanation:
The correct answer is that WPA2 uses stronger protection than WEP and commonly relies on AES-CCMP in enterprise or personal modes.
Choose an option to check your answer.
A.
encrypts wireless traffic
B.
is a DNSSEC validation process
C.
hardens switch port security
D.
overloads a switch MAC address table to affect normal switching behavior
Show Answer
Correct Answer: C. hardens switch port security
Explanation:
The misconception is "hardens switch port security"; in reality, MAC flooding overloads a switch MAC address table to affect normal switching behavior.
Choose an option to check your answer.
A.
is a primary production database
B.
is a decoy system or service designed to attract and study attackers
C.
is a default password list
D.
is only a cable tester
Show Answer
Correct Answer: B. is a decoy system or service designed to attract and study attackers
Explanation:
The correct answer is that Honeypot is a decoy system or service designed to attract and study attackers.
Choose an option to check your answer.
A.
is a DNSSEC signing algorithm only
B.
is a file compression format
C.
defines stronger security mechanisms for wireless LANs, including RSN concepts
D.
is a Tor relay type
Show Answer
Correct Answer: C. defines stronger security mechanisms for wireless LANs, including RSN concepts
Explanation:
The correct answer is that 802.11i defines stronger security mechanisms for wireless LANs, including RSN concepts.
Choose an option to check your answer.
A.
is a social engineering method
B.
is used only by printers
C.
does not support encryption
D.
can provide confidentiality, integrity, and authentication for IP packets
Show Answer
Correct Answer: D. can provide confidentiality, integrity, and authentication for IP packets
Explanation:
ESP in IPsec is best described as something that can provide confidentiality, integrity, and authentication for IP packets.
Choose an option to check your answer.
A.
is a replacement for all backups
B.
creates a protected tunnel for traffic across an untrusted network
C.
stores DNS zones only
D.
removes authentication requirements
Show Answer
Correct Answer: B. creates a protected tunnel for traffic across an untrusted network
Explanation:
This is correct because VPN creates a protected tunnel for traffic across an untrusted network.
Choose an option to check your answer.
A.
prevents all spoofing automatically
B.
is only a database backup
C.
changes passwords into certificates
D.
captures and inspects network packets for analysis or unauthorized observation
Show Answer
Correct Answer: A. prevents all spoofing automatically
Explanation:
The misconception is "prevents all spoofing automatically"; in reality, Packet sniffing captures and inspects network packets for analysis or unauthorized observation.