A user is connected to the corporate network. Under a zero-trust approach, should that network location alone be enough to grant access to a sensitive service?
5 Network Security Online Quiz Questions
Use this free practice quiz with 20 questions to review 5 Network Security, test your knowledge, and prepare for your next test or exam.
A correctly encrypted connection can still involve a compromised endpoint. Does encryption alone make that endpoint secure?
- A
True
- B
False
What is the standard acronym for DNS over TLS, the method that encrypts the client-to-resolver DNS exchange using TLS?
To make a firewall rule specific, document its source, destination, service, and .
A company needs to protect IP traffic between two security gateways for a VPN. Which protocol is designed to protect traffic at the network layer?
- A
SSH
- B
IPsec
- C
SNMPv3
- D
DNS over HTTPS
A network team needs a management protocol that supports authentication and encryption options. Which protocol best fits this requirement?
- A
Traditional DNS
- B
UDP
- C
SNMPv3
- D
HTTP
What is the name of the practice of dividing a network into separate zones and controlling communication between them?
As part of network monitoring, watch for unexpected traffic or .
A public website needs to access a database. Which firewall policy best limits exposure while allowing the required service to work?
- A
Allow both the web server and database to accept connections directly from any Internet address.
- B
Allow HTTPS from the Internet to the web server, and allow the database to accept connections only from that web server.
- C
Allow all traffic between the Internet and the internal network, then rely on monitoring to identify misuse.
- D
Block all connections to the web server and database, including the web server's connection to the database.
A company is designing remote access for administrators. Select all practices that support secure remote access.
- A
Use an approved VPN or other protected access method.
- B
Require strong authentication.
- C
Limit remote users to the permissions they need.
- D
Expose device administration directly to the Internet for convenience.
- E
Grant every remote user unrestricted access once authenticated.
Select all statements that correctly describe DNS over TLS (DoT) and DNS over HTTPS (DoH).
- A
DNS over TLS encrypts the client-to-resolver exchange.
- B
DNS over HTTPS encrypts the client-to-resolver exchange.
- C
Either protocol hides all network metadata from every observer.
- D
Either protocol guarantees that the requested destination is safe.
An administrator connects to a server using SSH. What should the administrator verify to help confirm the identity of the remote host?
- A
A certificate that proves the user's device has no malware.
- B
The remote host's key, which helps verify the identity of the host.
- C
A DNS response that guarantees the server is trustworthy.
- D
A firewall rule that automatically authenticates every SSH user.
An organization wants to reduce the impact of a network intrusion even if one security control fails. Describe a coordinated set of network-defense practices and explain how the practices work together to limit or detect the intrusion.
A network application uses IP and TCP to send data. Do those protocols, by themselves, encrypt or authenticate the communication?
- A
True
- B
False
A packet needs to travel from a device on one network to a server on a different network. Which device type forwards the packet between those networks?
- A
A router
- B
A switch
- C
A host-based firewall
- D
A DNS resolver
A network administrator wants a firewall to recognize whether packets belong to an already established connection. Which firewall capability is needed?
- A
Filtering only by fixed addresses and ports
- B
Tracking connection state
- C
Translating names into network information
- D
Connecting devices within a local network
An administrator needs a protocol for securely administering a server remotely and transferring a file to it. Which protocol best fits this use?
- A
DNS
- B
IP
- C
SSH
- D
UDP
A server needs its own traffic control, including when its network location changes. Which firewall deployment places the control directly on that server?
- A
A perimeter firewall appliance
- B
A cloud firewall control
- C
A router access-control list
- D
A software firewall on the server
A browser communicates with a website using HTTP carried over Transport Layer Security. What is the name of this protocol?
Before redesigning network traffic controls, a team needs to identify the devices, services, and communication paths that already exist. What planning activity should it perform?