Total Questions: 25 | Time Recommended: 45 minutes
SECTION A: MULTIPLE CHOICE (Questions 1–20)
Difficulty Tier 1: Foundational Recall & Terminology (Questions 1–10)
Q1: Which firewall type inspects entire packets and maintains connection state in a dynamic
table to determine whether traffic is part of an established, legitimate session?
A) Packet-filtering firewall
B) Stateful inspection firewall
C) Circuit-level proxy firewall
D) Application-layer proxy firewall
Answer: B
Explanation: A stateful inspection firewall tracks the state of active connections and makes
decisions based on the context of traffic flows, not just static rules. It maintains a state table
to remember legitimate outgoing requests and allows only corresponding return traffic.
Q2: What is the primary security purpose of a Demilitarized Zone (DMZ) in network
architecture?
A) To encrypt all internal traffic using IPsec
B) To isolate public-facing servers from the internal trusted network
C) To replace the need for a firewall entirely
D) To provide wireless guest access without authentication
Answer: B
Explanation: A DMZ is a buffer subnet that hosts public-facing services (web servers, mail
servers, DNS) between the untrusted internet and the trusted internal network. If a DMZ
server is compromised, the attacker still faces the inner firewall protecting critical internal
assets.
Q3: Which wireless security protocol uses the Advanced Encryption Standard (AES) with a
128-bit key and introduces Simultaneous Authentication of Equals (SAE) to replace the
vulnerable four-way handshake?
A) WEP
B) WPA
, C) WPA2
D) WPA3
Answer: D
Explanation: WPA3, finalized in 2018 and now the recommended standard, uses AES-128-
GCMP and SAE (also known as Dragonfly handshake) to protect against offline dictionary
attacks and provides forward secrecy, even if the network password is compromised later.
Q4: In an Intrusion Detection System (IDS), what is the key difference between signature-
based detection and anomaly-based detection?
A) Signature-based requires machine learning; anomaly-based does not
B) Signature-based detects known attack patterns; anomaly-based detects deviations from
normal baselines
C) Signature-based only works on host systems; anomaly-based only works on networks
D) Signature-based is slower but catches zero-days; anomaly-based is faster but misses
known attacks
Answer: B
Explanation: Signature-based IDS compares traffic against a database of known attack
signatures (high accuracy for known threats, misses zero-days). Anomaly-based IDS first
establishes a baseline of normal behavior, then flags deviations (can catch unknown attacks
but may generate false positives).
Q5: Which VPN protocol operates at Layer 3 of the OSI model and provides both
authentication and encryption through the Authentication Header (AH) and Encapsulating
Security Payload (ESP) protocols?
A) SSL VPN
B) TLS VPN
C) IPsec
D) PPTP
Answer: C
Explanation: IPsec is a suite of protocols operating at the network layer (Layer 3) that
secures IP communications. AH provides connectionless integrity and data origin
authentication, while ESP provides confidentiality, integrity, and anti-replay protection.
Q6: What is the primary security benefit of Network Address Translation (NAT) in a typical
enterprise environment?