Prep – Complete Network Security & Cryptography Study
Course Code: SY0-701
Name: CompTIA Security+ (SY0-701) Ultimate Exam Prep
Topic: Complete Network Security & Cryptography Study
Academic Year: 2026/2027
1. An infrastructure engineer is hardening a corporate web server to enforce
TLS 1.3. Which cryptographic improvement or feature represents a
fundamental security update in TLS 1.3 over legacy TLS 1.2 configurations?
A. Mandatory usage of static RSA key exchanges to streamline token
distribution.
B. Complete deprecation of static RSA and custom Diffie-Hellman
handshakes to enforce forward secrecy.
C. Integration of MD5-based message authentication codes for lower
, computing overhead.
D. Exclusive fallback support for SSL 3.0 backward compatibility.
CORRECT ANSWER: B
RATIONALE: TLS 1.3 completely removes support for static RSA key
exchange algorithms. By doing so, it mandates that all key exchanges must
use ephemeral mechanisms (like ECDHE or DHE), which inherently
provide perfect forward secrecy (PFS). This ensures that even if a server's
long-term private key is compromised in the future, past session traffic
cannot be decrypted. Distractors A, C, and D are incorrect because static
RSA lacks forward secrecy, MD5 is cryptographically broken and banned,
and SSL 3.0 is highly insecure and obsolete.
2. A network security analyst is monitoring outbound web traffic and notices a
user connecting to a remote site via HTTPS. The analyst wants to protect the
user's privacy by ensuring passive observers cannot read the destination
domain name in the initial plaintext handshake. Which modern capability or
extension solves this issue?
A. OCSP Stapling
B. HTTP Strict Transport Security (HSTS)
C. Encrypted Client Hello (ECH)
D. Extended Validation (EV) Certificates
CORRECT ANSWER: C
RATIONALE: Encrypted Client Hello (ECH), an extension integrated
with TLS 1.3, encrypts the Server Name Indication (SNI) component of the
initial client greeting. This prevents on-path network observers or ISP
monitors from determining which specific domain or website a user is
visiting. Distractor A is a certificate validation enhancement; distractor B
forces browsers to use HTTPS over HTTP; distractor D is a legacy
certificate validation type that does not hide handshake metadata.
3. When deploying a site-to-site IPsec VPN between two corporate gateways
across the public internet, a security architect must choose a protocol that
ensures packet data payload confidentiality, integrity, and source
authentication. Which protocol framework fulfills all these demands?
A. Authentication Header (AH)
B. Internet Key Exchange version 2 (IKEv2)
, C. Encapsulating Security Payload (ESP)
D. Layer 2 Tunneling Protocol (L2TP)
CORRECT ANSWER: C
RATIONALE: Encapsulating Security Payload (ESP) is the IPsec
protocol that provides confidentiality (encryption) along with data origin
authentication, integrity checking, and anti-replay protection. Distractor A
(AH) provides authentication and integrity but explicitly does not offer
confidentiality/encryption. Distractor B (IKEv2) manages the control-plane
key exchanges and security associations but does not transport user payload
packets. Distractor D (L2TP) is a tunneling protocol that lacks native
encryption entirely and relies on IPsec for protection.
4. A network security team is configuring an IPsec VPN tunnel to protect
communications between two remote branches. The entire original IP
packet, including its source and destination IP headers, must be completely
encrypted and placed within a new outer IP packet wrapper. Which
operational mode must be selected?
A. Transport Mode
B. Tunnel Mode
C. Promiscuous Mode
D. Pass-through Mode
CORRECT ANSWER: B
RATIONALE: Tunnel Mode encapsulates the entire original IP packet
(both payload and original headers) inside a brand new IP header, encrypting
the inner contents completely. This is the industry-standard mode for
gateway-to-gateway (site-to-site) VPN architectures. Distractor A (Transport
Mode) only encrypts the payload while leaving the original IP headers intact
and visible, making it typical for host-to-host links. Distractors C and D are
not valid IPsec operational encapsulation modes.
5. A security technician is troubleshooting a remote access failure and looks at
the network handshake logs. The system is attempting to establish security
associations (SAs) and generate dynamic symmetric keys over an untrusted
WAN. Which protocol's primary function is to handle this security
negotiation and key setup?
A. Internet Key Exchange (IKE)
, B. Simple Network Management Protocol (SNMP)
C. Secure Shell Version 2 (SSHv2)
D. Dynamic Host Configuration Protocol (DHCP)
CORRECT ANSWER: A
RATIONALE: Internet Key Exchange (IKE / IKEv2) is a component
of the IPsec suite designed to authenticate tunnel endpoints, negotiate
encryption parameters (ciphers, hashes), and establish the Security
Associations (SAs) required for secure data transit. Distractor B is used for
device monitoring; distractor C is for secure remote terminal access;
distractor D dynamically distributes IP addresses.
6. An administrator is configuring a corporate wireless network to meet the
highest security baselines. They replace the legacy WPA2 standard with
WPA3-Enterprise. Which specific cryptographic standard does WPA3
mandate to secure enterprise authentication mechanisms?
A. TKIP with RC4 key mixing
B. Simultaneous Authentication of Equals (SAE) or 192-bit CNSA-
compliant suites
C. Weak Initialization Vectors with 64-bit DES
D. Static WEP keys with Pre-Shared Passwords
CORRECT ANSWER: B
RATIONALE: WPA3-Enterprise mandates robust cryptographic
profiles, supporting up to a 192-bit cryptographic suite aligned with the
Commercial National Security Algorithm (CNSA) guidelines (utilizing
AES-GCM and SHA-384). For personal networks, WPA3 leverages
Simultaneous Authentication of Equals (SAE) to replace the vulnerable
WPA2 4-way pre-shared key handshake. Distractors A, C, and D reference
broken, deprecated cryptographic practices like TKIP, RC4, DES, and WEP.
7. A coffee shop chain wishes to deploy a public Wi-Fi network that requires
no user password entry but still ensures that data sent over the air between
each individual device and the access point is uniquely encrypted to prevent
local eavesdropping. Which WPA3 deployment feature should be
implemented?
A. WPA3-Personal with a shared passphrase
B. Opportunistic Wireless Encryption (OWE)