1. A company is implementing a new cloud-based application. The security team needs to ensure that data transmitted between the company's on-premises network and the cloud provider's infrastructure is encrypted and authenticated. Which protocol suite is specifically designed to provide secure communication over an IP network, commonly used in this scenario for site-to-site connections?
Network Security
A.FTP (File Transfer Protocol)
B.SNMP (Simple Network Management Protocol)
C.SMTP (Simple Mail Transfer Protocol)
D.IPsec (Internet Protocol Security)
Show answerAnswer
D. IPsec (Internet Protocol Security)
IPsec is a suite of protocols that provides cryptographic security services, including authentication and encryption, for IP communications. It's commonly used for securing VPNs, especially site-to-site connections.
2. A company requires all employees to use their corporate laptops for work, even when traveling. The security policy states that these laptops must always be connected to the corporate network securely, regardless of their physical location or the underlying internet connection. Which technology ensures continuous, secure communication back to the corporate network without requiring manual user initiation for every session?
Network Security
A.Always-On VPN
B.Split Tunnel VPN
C.Clientless VPN
D.Site-to-Site VPN
Show answerAnswer
A. Always-On VPN
An Always-On VPN automatically establishes and maintains a secure VPN connection whenever the device has internet access, ensuring continuous secure communication without user intervention.
3. A security auditor is reviewing a company's remote access solution. They note that employees connect to the internal network using a client application that encrypts all traffic and creates a secure tunnel over the public internet. What type of remote access technology is most likely being utilized?
Network Security
A.File Transfer Protocol (FTP)
B.Remote Desktop Protocol (RDP)
C.Virtual Private Network (VPN)
D.Secure Shell (SSH)
Show answerAnswer
C. Virtual Private Network (VPN)
VPNs are designed to create secure, encrypted tunnels over public networks like the internet, allowing remote users to access internal resources as if they were on the local network.
4. A cybersecurity incident response team is investigating a sophisticated attack where an attacker bypassed traditional perimeter defenses. They suspect that malicious code was executed directly on an endpoint, which then communicated with a command-and-control (C2) server. To detect such advanced threats and provide detailed visibility into endpoint activities, which security solution would be most effective?
Network Security
A.Traditional Antivirus (AV)
B.Network Intrusion Detection System (NIDS)
C.Endpoint Detection and Response (EDR)
D.Security Information and Event Management (SIEM)
Show answerAnswer
C. Endpoint Detection and Response (EDR)
EDR solutions continuously monitor endpoint activity for advanced threats, provide detailed visibility, and enable rapid response capabilities, which traditional AV and NIDS often lack for sophisticated, endpoint-centric attacks.
5. A company is experiencing slow network performance and occasional data packet loss. An administrator suspects network congestion or faulty equipment. Which core network protocol is primarily responsible for ensuring reliable, ordered, and error-checked delivery of data streams between applications?
Network Security
A.ARP
B.TCP
C.ICMP
D.UDP
Show answerAnswer
B. TCP
TCP (Transmission Control Protocol) is a connection-oriented protocol that provides reliable, ordered, and error-checked delivery of a stream of bytes between applications. It includes mechanisms for retransmission of lost packets and flow control, which directly relates to diagnosing issues like packet loss and congestion.
6. A large organization with multiple branch offices needs a solution to monitor network traffic for suspicious activity and automatically block known attack patterns in real-time. Which network security device is best suited for both detecting and preventing such malicious activities?
Network Security
A.Content Filter
B.Intrusion Prevention System (IPS)
C.Network Access Control (NAC)
D.Intrusion Detection System (IDS)
Show answerAnswer
B. Intrusion Prevention System (IPS)
An IPS actively monitors network traffic for malicious activity and can take automated actions, such as blocking traffic, to prevent attacks in real-time.
7. A global company uses a distributed network architecture with data centers and branch offices across different continents. They need a solution that can identify and block known malicious traffic patterns and signatures at the network perimeter before they reach internal systems, acting proactively. Which network security device is best suited for this proactive threat prevention?
Network Security
A.Switch
B.Router
C.Intrusion Prevention System (IPS)
D.Load Balancer
Show answerAnswer
C. Intrusion Prevention System (IPS)
An Intrusion Prevention System (IPS) actively monitors network traffic for malicious activity or policy violations and can automatically take action to block or prevent detected threats in real-time, making it ideal for proactive threat prevention at the network perimeter.
8. A company is implementing a new policy for managing mobile devices used by employees. The policy requires enforcing screen lock passcodes, remotely wiping lost devices, and ensuring specific applications are installed or restricted. Which security solution is specifically designed to centrally manage and secure mobile devices?
Network Security
A.Security Information and Event Management (SIEM)
B.Mobile Device Management (MDM)
C.Data Loss Prevention (DLP)
D.Network Access Control (NAC)
Show answerAnswer
B. Mobile Device Management (MDM)
MDM solutions provide centralized management capabilities for mobile devices, allowing organizations to enforce security policies, manage applications, and perform remote actions like wiping data.
9. A security analyst is investigating a potential data breach where sensitive employee records were exfiltrated from an internal server. The investigation reveals that the attacker gained access through a web application vulnerability and then used this access to move laterally within the network. Which security measure, if properly implemented, would have been most effective in preventing the lateral movement of the attacker to the sensitive data server?
Network Security
A.Implementing a robust antivirus solution on all workstations.
B.Network segmentation between the web application server and the sensitive data server.
C.Regular security awareness training for employees.
D.Stronger password policies for user accounts.
Show answerAnswer
B. Network segmentation between the web application server and the sensitive data server.
Network segmentation would isolate the web application server from the sensitive data server, making lateral movement significantly harder even after an initial compromise, thereby limiting the blast radius.
10. A security team is implementing a new policy for mobile device security. Employees frequently use personal smartphones and tablets for work-related tasks, including accessing corporate email and cloud applications. The policy aims to enforce security configurations, manage applications, and remotely wipe data if a device is lost or stolen, without necessarily owning the devices. Which solution is most appropriate for achieving these goals?
Network Security
A.Mobile Device Management (MDM)
B.Virtual Private Network (VPN)
C.Basic Antivirus Software
D.Firewall on each device
Show answerAnswer
A. Mobile Device Management (MDM)
Mobile Device Management (MDM) solutions allow organizations to enforce security policies, manage applications, configure settings, and remotely control (e.g., wipe) mobile devices, even if they are personally owned (BYOD), making it ideal for the described scenario.
11. A healthcare organization is designing its network infrastructure and must ensure that patient records (PHI) are strictly isolated from the general administrative network and guest Wi-Fi. Access to PHI must be restricted to authorized medical personnel only. Which network design principle is most critical for achieving this separation and access control?
Network Security
A.Load Balancing
B.Redundant Network Links
C.Flat Network Topology
D.Network Segmentation
Show answerAnswer
D. Network Segmentation
Network segmentation involves dividing a network into smaller, isolated sub-networks. This is crucial for isolating sensitive data like PHI, restricting access, and containing potential breaches, directly addressing the stated requirements.
12. A security analyst is investigating a suspected intrusion on the corporate network. They observe unusual outbound traffic patterns and multiple failed login attempts on a critical server. To gain real-time visibility into these activities and correlate events from various network devices and applications, which security solution should the analyst primarily rely on?
Network Security
A.Firewall
B.Intrusion Detection System (IDS)
C.Antivirus Software
D.Security Information and Event Management (SIEM)
Show answerAnswer
D. Security Information and Event Management (SIEM)
A SIEM system collects, aggregates, and correlates log data and security events from various sources across the network, providing a centralized platform for real-time monitoring, incident detection, and analysis of security incidents.
13. A system administrator is tasked with securing all endpoints within the organization, including laptops, desktops, and servers. The goal is to detect and respond to advanced threats, such as fileless malware and sophisticated ransomware, beyond what traditional antivirus can handle. Which security solution specifically focuses on comprehensive endpoint protection and response capabilities?
Network Security
A.Data Loss Prevention (DLP)
B.Endpoint Detection and Response (EDR)
C.Network Access Control (NAC)
D.Unified Threat Management (UTM)
Show answerAnswer
B. Endpoint Detection and Response (EDR)
Endpoint Detection and Response (EDR) solutions go beyond traditional antivirus by continuously monitoring endpoint activity, collecting data, and using advanced analytics to detect and respond to sophisticated threats like fileless malware and ransomware, providing comprehensive endpoint protection.
14. A company policy mandates that all data exchanged between its internal network and its cloud-hosted applications must be encrypted in transit and authenticated. The company uses Amazon Web Services (AWS) for its cloud infrastructure. Which security measure is most appropriate for securing this communication?
Network Security
A.Virtual Private Cloud (VPC)
B.Security Groups
C.TLS/SSL Encryption
D.Direct Connect
Show answerAnswer
C. TLS/SSL Encryption
TLS/SSL encryption is the primary protocol used to secure data in transit over networks, including between on-premises and cloud environments. It provides both encryption and authentication, fulfilling the policy requirement for securing data exchange.
15. A system administrator is configuring a new web server that will host a public-facing e-commerce application. To ensure that only legitimate web traffic (HTTP/HTTPS) can reach the server and to prevent other types of network attacks, which network protocol ports should be explicitly opened on the firewall for this server?
Network Security
A.Port 25 (SMTP) and Port 110 (POP3)
B.Port 21 (FTP) and Port 23 (Telnet)
C.Port 22 (SSH) and Port 3389 (RDP)
D.Port 80 (HTTP) and Port 443 (HTTPS)
Show answerAnswer
D. Port 80 (HTTP) and Port 443 (HTTPS)
HTTP (Port 80) and HTTPS (Port 443) are the standard ports for web traffic, which is essential for a public-facing e-commerce application.
16. A security team is designing a network architecture for a new data center. They want to implement a highly available and secure perimeter that allows public access to web servers while strictly protecting internal databases. The design includes redundant firewalls and routers, placing the web servers in a neutral zone, and isolating internal resources. What specific network topology concept are they primarily applying?
Network Security
A.Bus topology
B.Demilitarized Zone (DMZ)
C.Ring topology
D.Star topology
Show answerAnswer
B. Demilitarized Zone (DMZ)
A DMZ is a neutral zone, typically between two firewalls, used to host public-facing services like web servers, protecting the internal network from direct access.
17. A company is upgrading its network infrastructure and is considering using a protocol that ensures reliable, ordered, and error-checked delivery of data streams. Which of the following core network protocols best fits this description?
Network Security
A.TCP (Transmission Control Protocol)
B.ICMP (Internet Control Message Protocol)
C.UDP (User Datagram Protocol)
D.ARP (Address Resolution Protocol)
Show answerAnswer
A. TCP (Transmission Control Protocol)
TCP is a connection-oriented protocol that provides reliable, ordered, and error-checked delivery of data, making it suitable for applications requiring high data integrity.
18. A small office is setting up its first network and wants to ensure that all internal devices can communicate with each other and with the internet securely. They are on a limited budget and need a device that can manage network traffic, assign IP addresses, and provide basic firewall capabilities. Which network device would best meet these requirements?
Network Security
A.Wireless Router
B.Hub
C.Repeater
D.Modem
Show answerAnswer
A. Wireless Router
A wireless router combines the functions of a router (traffic management, IP assignment via DHCP), a switch (connecting multiple devices), and often a basic firewall, making it ideal for a small office with internet connectivity needs.
19. A network administrator is configuring a new Wi-Fi network for a school and needs to select the strongest encryption protocol available to protect sensitive student data. The network will support modern devices. Which Wi-Fi security standard should be prioritized?
Network Security
A.WPA
B.WPA2
C.WEP
D.WPA3
Show answerAnswer
D. WPA3
WPA3 is the latest and most secure Wi-Fi security standard, offering enhanced encryption, protection against brute-force attacks, and improved privacy compared to its predecessors.
20. A company is implementing a new security policy that requires all remote employees to securely access the corporate network as if they were physically present in the office. They need a solution that encrypts all traffic and provides a secure tunnel over the public internet. Which technology should they choose?
Network Security
A.SMTP
B.HTTP/S
C.VPN
D.DNS
Show answerAnswer
C. VPN
A Virtual Private Network (VPN) creates a secure, encrypted tunnel over a public network (like the internet), allowing remote users to access internal resources as if they were directly connected to the corporate network.
21. A network administrator is troubleshooting connectivity issues in a corporate office. They observe that devices on different floors cannot communicate with each other, even though they are all connected to the same physical network infrastructure. What network topology characteristic might be causing this issue if logical separation is intended?
Network Security
A.Star topology
B.Bus topology
C.VLANs
D.Mesh topology
Show answerAnswer
C. VLANs
VLANs (Virtual Local Area Networks) are used to logically segment a network, meaning devices on different VLANs cannot communicate without a Layer 3 device (router), even if on the same physical switch.
22. A small business wants to protect its internal network from unauthorized access while allowing employees to browse the internet. Which network device is primarily responsible for filtering incoming and outgoing network traffic based on a defined set of security rules?
Network Security
A.Switch
B.Router
C.Access Point
D.Firewall
Show answerAnswer
D. Firewall
A firewall is specifically designed to enforce security policies by controlling network traffic, making it the primary device for this protection.
23. A manufacturing company operates several industrial control systems (ICS) that are critical for production and cannot tolerate downtime. To protect these systems from external threats while allowing limited, controlled access for remote monitoring and maintenance, which network security architecture should be implemented to create a demilitarized zone (DMZ) for the ICS?
Network Security
A.Screened Subnet (Triple-Homed) DMZ
B.Single Firewall DMZ
C.No DMZ, direct internet access
D.Dual-Homed Host DMZ
Show answerAnswer
A. Screened Subnet (Triple-Homed) DMZ
A Screened Subnet (Triple-Homed) DMZ, also known as a three-legged DMZ, uses two firewalls: one between the internet and the DMZ, and another between the DMZ and the internal network. This provides the highest level of security for critical systems like ICS by creating two layers of defense and strict control over traffic flow, ideal for sensitive environments.
24. A security auditor is reviewing the configuration of a corporate firewall. The auditor notices a rule that permits 'any' source IP address to connect to an internal web server (port 80/TCP) but restricts access to only 'trusted' destination IP addresses. This rule is directly followed by a rule that implicitly denies all other traffic. What is the most significant security concern with this specific firewall rule related to the internal web server?
Network Security
A.It exposes the web server to potential attacks from any external source.
B.It allows any internal user to access the web server.
C.It only allows access to port 80, not 443.
D.It prevents the web server from initiating outbound connections.
Show answerAnswer
A. It exposes the web server to potential attacks from any external source.
The rule permits 'any' source IP address to connect to the internal web server on port 80 (HTTP). This means the web server is publicly accessible via HTTP, making it vulnerable to various attacks from the entire internet, regardless of the 'trusted' destination restriction which is misapplied (destination refers to the target of the connection, not the source).
25. A security team is deploying a new web application that will handle sensitive customer data. They need to ensure that all communication between the client's browser and the web server is encrypted and that the server's identity is verified. Which protocol combination should be implemented?
Network Security
A.HTTPS with TLS
B.Telnet with SSH
C.HTTP with FTP
D.SMTP with POP3
Show answerAnswer
A. HTTPS with TLS
HTTPS (Hypertext Transfer Protocol Secure) combines HTTP with TLS (Transport Layer Security) to provide encrypted communication and server identity verification for web traffic. This ensures data confidentiality and integrity, and authenticates the server to the client.
A type of Virtual Private Network that automatically establishes and maintains a secure connection to a corporate network whenever the device has internet connectivity, without requiring manual user initiation.
Ensures continuous security and policy enforcement for remote devices.
Enhances compliance and reduces security risks for mobile users.
Can be configured to enforce full tunnel or split tunnel depending on policy.
A technology that creates a secure, encrypted connection over a less secure network, such as the internet, allowing remote users to access private network resources.
Encrypts data between the client and the VPN server.
Creates a 'tunnel' for secure communication.
Allows remote users to appear as if they are physically on the corporate network.
A cybersecurity solution that continuously monitors and collects data from endpoint devices, enabling the detection, investigation, and response to advanced threats.
Provides deep visibility into endpoint activities (processes, file changes, network connections).
Uses behavioral analytics and machine learning to detect anomalies.
Facilitates rapid incident response and threat hunting.
A core protocol of the Internet protocol suite that provides reliable, ordered, and error-checked delivery of a stream of bytes between applications running on hosts communicating over an IP network.
A network security device that monitors network traffic for malicious activity and automatically takes actions to prevent detected threats in real-time.
Actively blocks or drops malicious traffic.
Operates inline with network traffic.
Can use signature-based, anomaly-based, or policy-based detection.
A security solution that centralizes the collection, storage, and analysis of security logs and events from across an organization's IT infrastructure to provide real-time threat detection and compliance reporting.
Aggregates logs from various sources (servers, firewalls, applications).
Correlates security events to identify patterns and potential incidents.
Cryptographic protocols that provide secure communication over a computer network, primarily used for encrypting and authenticating data in transit between a client and a server.
A network device that combines the functions of a router, a switch, a wireless access point, and often a basic firewall to connect multiple devices to a local network and the internet.
The latest security protocol for Wi-Fi networks, offering robust encryption and improved protection against common attacks compared to older standards.
Uses 192-bit cryptographic strength in Enterprise mode.
Provides 'Simultaneous Authentication of Equals' (SAE) for stronger password-based authentication.
Offers enhanced privacy in open networks with 'Opportunistic Wireless Encryption' (OWE).
A network architecture that uses two firewalls to create a highly secure demilitarized zone (DMZ), completely isolating it from both the external network (internet) and the internal private network.
Employs two firewalls for enhanced security.
One firewall faces the internet, the other faces the internal network.
The process of examining firewall rulesets to identify potential vulnerabilities, misconfigurations, or unintended access permissions that could compromise network security.
The amount and type of risk that an organization is willing to pursue or retain in order to achieve its objectives. It's a high-level statement set by senior management and influences strategic decisions.
An approach to systems engineering that incorporates privacy and data protection into the entire lifecycle of technology, from the initial design phase to deployment and beyond. It emphasizes proactive rather than reactive measures.
Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.