QUESTIONS WITH CORRECT ANSWERS 2025
AQfirewallQ-QCORRECTQANSWERQ-
anyQsoftwareQorQhardwareQdeviceQthatQprotectsQaQsystemQorQnetworkQbyQblockingQunwantedQnetworkQtra
ffic.QFirewallsQgenerallyQareQconfiguredQtoQstopQsuspiciousQorQunsolicitedQincomingQtrafficQthroughQaQproc
essQcalledQimplicitQdeny.
AQstatefulQfirewallQ-QCORRECTQANSWERQ-
AQstatefulQfirewallQdoesQtrackQtheQactiveQstateQofQaQconnectionQandQisQableQtoQmakeQdecisionsQbasedQonQt
heQcontentsQofQaQnetworkQpacketQasQitQrelatesQtoQtheQstateQofQtheQconnection.
statelessQfirewallQ-QCORRECTQANSWERQ-
doesQnotQtrackQtheQactiveQstateQofQaQconnectionQasQitQreachesQtheQfirewall.QItQallowsQorQblocksQtrafficQbas
edQonQsomeQstaticQvalueQassociatedQwithQthatQtraffic.
AnQaccessQcontrolQlistQ(ACL)Q-QCORRECTQANSWERQ-
aQlistQofQobjectsQwithQpermissionsQattachedQtoQthoseQobjects.QTheQlistQspecifiesQwhichQentitiesQ(suchQasQin
dividuals)QhaveQtheQrightsQtoQaccessQspecificQresourcesQandQtoQwhatQextentQthoseQresourcesQmayQbeQmo
difiedQ(ifQatQall).
ImplicitQdenyQ-QCORRECTQANSWERQ-
TheQprincipleQthatQestablishesQthatQeverythingQthatQisQnotQexplicitlyQallowedQisQdenied.
AQVPNQconcentratorQ-QCORRECTQANSWERQ-
AQsingleQdeviceQthatQincorporatesQadvancedQencryptionQandQauthenticationQmethodsQinQorderQtoQhandle
QaQlargeQnumberQofQVPNQtunnels.
RemoteQaccessQvs.Qsite-to-siteQ-QCORRECTQANSWERQ-
AQremoteQaccessQVPNQconnectsQindividualQremoteQusersQtoQtheQprivateQnetwork,QwhereasQaQsite-to-
siteQVPNQconnectsQtwoQprivateQnetworksQtogether.
InternetQProtocolQSecurityQ(IPSec)Q-QCORRECTQANSWERQ-anQopen-
sourceQprotocolQframeworkQforQsecurityQdevelopmentQwithinQtheQTCP/IPQfamilyQofQprotocolQstandards.QIP
SecQisQnotQapplicationQdependentQasQitQoperatesQatQtheQnetworkQlayerQ(layerQ3)QofQtheQOSIQmodel.
, IPSecQtransportQmodeQ-QCORRECTQANSWERQ-
IPSecQencryptsQjustQtheQIPQpayload,QleavingQtheQIPQpacketQheaderQunchangedQsoQitQcanQbeQeasilyQroutedQt
hroughQtheQinternet
IPSecQtunnelQmodeQ-QCORRECTQANSWERQ-bothQtheQpacketQcontentsQandQheaderQareQencrypted.
IPSec,QAuthenticationQHeaderQ(AH)Q-QCORRECTQANSWERQ-
OneQofQtheQtwoQprotocolsQusedQinQIPSec,QAuthenticationQHeaderQ(AH)QprovidesQauthenticationQforQtheQor
iginQofQtransmittedQdataQasQwellQasQintegrityQandQprotectionQagainstQreplayQattacks.
IPSec,QEncapsulationQSecurityQPayloadQ(ESP)Q-QCORRECTQANSWERQ-
OneQofQtheQtwoQprotocolsQusedQinQIPSec,QprovidesQtheQsameQfunctionalityQasQAuthenticationQHeaderQ(AH
),QwithQtheQadditionQofQencryptionQtoQsupportQtheQconfidentialityQofQtransmittedQdata.
SplitQtunnelQvs.QfullQtunnelQ-QCORRECTQANSWERQ-
WhenQaQdeviceQisQconnectedQtoQtheQVPNQinQfullQtunnelQmode,QallQnetworkQtrafficQisQsentQthroughQtheQtun
nelQandQencrypted.QInQsplitQmode,QonlyQsomeQofQtheQtrafficQisQsentQthroughQtheQtunnelQandQencrypted.
TLS/SSLQ(TransportQLayerQSecurityQandQSecureQSocketsQLayer)Q-QCORRECTQANSWERQ-
SecureQSocketsQLayerQ(SSL)QandQTransportQLayerQSecurityQ(TLS)QareQsecurityQprotocolsQthatQcombineQdigit
alQcertificatesQforQauthenticationQwithQpublicQkeyQdataQencryption.
Always-onQVPNQ-QCORRECTQANSWERQ-SomeQVPNQconcentratorsQsupportQanQalways-
onQcapabilityQsoQthatQtheQuser'sQdeviceQwillQautomaticallyQconnectQtoQtheQVPNQanyQtimeQitQhasQanQIntern
etQconnection.
NIPSQ(network-basedQintrusionQpreventionQsystem)Q-QCORRECTQANSWERQ-
AQnetworkQintrusionQpreventionQsystemQ(NIPS)QmonitorsQsuspiciousQtrafficQonQtheQnetworkQandQreactsQin
QrealQtimeQtoQblockQit.
NIDSQ(network-basedQintrusionQdetectionQsystem)Q-QCORRECTQANSWERQ-
AQNIDSQprimarilyQusesQpassiveQhardwareQsensorsQtoQmonitorQtrafficQonQaQspecificQsegmentQofQtheQnetwor
k.QItQcanQsniffQtrafficQandQsendQalertsQaboutQanomaliesQorQconcerns.