Applications
Comprehensive Objective Assessment (Qns &
Ans)
2025
Question 1 (Multiple Choice)
Question:
Which of the following security protocols is most commonly used
to establish secure, site-to-site VPN connections by providing
encryption, data integrity, and mutual authentication at the
network layer?
A) SSL/TLS
B) IPSec
C) SSH
D) RADIUS
©2025
, Correct ANS:
B) IPSec
Rationale:
IPSec operates at the network layer and is widely employed for
secure VPN connections. It encrypts data, ensures integrity, and
authenticates communicating endpoints, which makes it ideal for
connecting disparate networks securely.
---
Question 2 (Fill in the Blank)
Question:
In a Zero Trust Network Architecture, every access request is
subject to ________ to ensure that no implicit trust is granted
based solely on network location.
Correct ANS:
continuous verification
Rationale:
©2025
,Zero Trust models assume that no user or device is inherently
trusted—even if they reside within the corporate network.
Continuous verification (through authentication and authorization
checks) is essential to enforce strict access controls at every
request.
---
Question 3 (True/False)
Question:
Advanced next-generation intrusion detection systems (NGIDS)
today increasingly integrate machine learning algorithms to
improve the detection of sophisticated threats while reducing false
positives.
Correct ANS:
True
Rationale:
NGIDS are evolving to include adaptive machine learning
techniques that continuously learn normal network behavior. This
allows them to more accurately flag anomalies and reduce the
false positive rate compared to traditional signature-based
systems.
©2025
, ---
Question 4 (Multiple Response)
Question:
Select all the advanced techniques commonly implemented within
Software Defined Networking (SDN) security architectures:
A) Centralized policy management
B) Dynamic flow control
C) Distributed Denial-of-Service (DDoS) mitigation
D) Manual configuration of routing tables
Correct ANS:
A, B, C
Rationale:
SDN security leverages centralized controllers to manage policies,
dynamically adjusts network flows to adapt to threats, and can
integrate DDoS mitigation strategies. Manual configuration is
contrary to the automated, dynamic nature of SDN.
---
©2025