NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
James, a network specialist joined an organization. He was provided with administrator privileges,
through which he can access the files and servers and perform administrative activities.
Which of the following information assurance principles authorizes James to access the server or system
files? - (ANSWER)Authentication
Which of the following information assurance principles ensures that the information is not modified or
tampered by any unauthorized parties? - (ANSWER)Integrity
Which of the following information assurance principles ensures that a party in a communication cannot
deny sending the message? - (ANSWER)Nonrepudiation
Which of the following network defense techniques examines the causes for attacks in networks by
using fault-finding mechanisms, security forensics techniques, and post-mortem analysis? -
(ANSWER)Reactive approach
Danny, a security professional, wants to safeguard his organization's network from hacking attempts
and virus attacks. For this reason, he follows a network defense approach that examines the causes for
attacks in the network and includes fault finding, security forensics, and post-mortem analysis
techniques.
Which of the following network defense approaches was followed by Danny in the above scenario? -
(ANSWER)Retrospective approach
Clark, a network security specialist, was assigned to secure an organization's network. Clark
implemented a network defense approach that can tackle network attacks such as DoS and DDoS and
includes security monitoring methods such as IDS, SIMS, TRS, and IPS.
Which of the following network defense approaches did Clark implement in the above scenario? -
(ANSWER)Reactive approach
Which of the following components of technical security controls protects the information passing
through the network and preserves the privacy and reliability of the data? - (ANSWER)Encryption and
protocols
,NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
Which of the following components of technical network security controls examines the network
devices and identifies weaknesses in the network? - (ANSWER)Auditing
James, a certified hacker, was appointed by an agency to perform a cyberattack against the rival
company's servers with the intention of making the services unavailable to their customers. James
performed a DoS attack on the servers but he could not make the services unavailable.
Which of the following components of technical security controls protected the servers from the DoS
attack? - (ANSWER)Network security devices
Bob has recently purchased a new laptop and enabled all the required security controls. The next day
while verifying whether all the security mechanisms were enabled on his system or not, he found that
the "firewall" was disabled. He immediately enabled the firewall option on his laptop.
Identify the component of technical security controls that Bob enabled to protect his laptop from
network-related threats. - (ANSWER)Network security devices
Which of the following protocols provides centralized authentication, authorization, and accounting
(AAA) for remote access servers to communicate with a central server? - (ANSWER)RADIUS
Which of the following protocols is an application layer protocol that provides cryptographic privacy and
authentication for network communication and enhances the security of emails? - (ANSWER)Pretty
Good Privacy (PGP) protocol
Which of the following protocols is an application layer protocol used for sending digitally signed and
encrypted email messages? - (ANSWER)S/MIME
Sally, a security professional, implemented a protocol for authenticating requests in computer networks.
The protocol implemented by Sally is based on the client-server model, and uses encryption technology
and a "ticket" mechanism to prove the identity of a user on a non-secure network.
Identify the protocol implemented by Sally in the above scenario. - (ANSWER)Kerberos
Margaret, a system administrator, regularly administers the devices connected to the organizational
network. She found that certain devices are vulnerable to sniffing attacks. To protect the device from
,NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
such attacks, Margaret employed a protocol that encrypts the entire communication between the client
and the server, including the user's password, which protects it from sniffing attacks.
Identify the protocol employed by Margaret in the above scenario. - (ANSWER)TACACS+
TACACS+ authentication involves the following steps:
1. The router and the user exchange authentication parameters
2. The server responds with the REPLY message based on the provided information
3. A user initiates the connection for authentication
4. The router sends the parameters to the server for authentication - (ANSWER)3 -> 1 -> 4 -> 2
James, a software engineer, is working from a remote location and connects his laptop to the company's
server through a VPN. The company has implemented a security protocol that provides authentication
as well as encryption of the data passing through the VPN tunnels.
Identify the network security protocol implemented by the company for secure communication. -
(ANSWER)Internet Protocol Security (IPsec)
Benson, a security professional plans to implement more stringent security practices in his organization.
For this reason, he uses a protocol that provides cryptographic security by encrypting the email
messages and digitally signing them to ensure confidentiality, integrity, and nonrepudiation of
messages.
Which of the following protocols was employed by Benson in the above scenario? - (ANSWER)S/MIME
Identify the access control terminology that is referred to as an explicit resource on which an access
restriction is imposed. - (ANSWER)Object
Given below are the steps involved in the access control mechanism.
1. Once the identification is successful, the system provides the user access to use the system
2. A user provides their credentials while logging into the system
3. The system then allows the user to perform only those operations for which the user has been
authorized
, NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
4. The system validates the user with the database on the basis of the provided credentials - (ANSWER)2
-> 4 -> 1 -> 3
James, a network administrator, was assigned a task to create a standard access control model for the
organization's confidential data. He implemented an access control model that determines the usage
and access policies for the users. After its implementation, only users with appropriate access rights can
access the resource.
Which of the following access control models James has implemented in the above scenario? -
(ANSWER)Mandatory access control (MAC)
Which of the following access control models can be termed as need-to-know access model where the
decision can be taken by an owner to provide or deny access to specific user or a group of users? -
(ANSWER)Discretionary access control
Identify the access control model in which the access permissions are beyond the user control, which
implies that users cannot amend the access policies created by the system. - (ANSWER)Role Based
Access Controls
Benila, a security professional, implemented cryptography-based authentication to ensure strong
authentication in her organization. She employed an authentication mechanism that needs a device
embedded with a small computer chip that stores personal information of the employee for
identification.
Identify the type of authentication employed by Benila in the above scenario. - (ANSWER)Smart card
authentication
Ronnie, a security professional got many tickets stating that certain miscreants have been accessing the
files with the credentials of the employees and they are creating havoc in the organization. To prevent
such incidents, Ronnie implemented an authentication mechanism that identifies human characteristics
for authenticating people.
Which of the following types of authentication did Ronnie implement in the above scenario? -
(ANSWER)Biometric authentication
| WITH COPLETE SOLUTION!!
James, a network specialist joined an organization. He was provided with administrator privileges,
through which he can access the files and servers and perform administrative activities.
Which of the following information assurance principles authorizes James to access the server or system
files? - (ANSWER)Authentication
Which of the following information assurance principles ensures that the information is not modified or
tampered by any unauthorized parties? - (ANSWER)Integrity
Which of the following information assurance principles ensures that a party in a communication cannot
deny sending the message? - (ANSWER)Nonrepudiation
Which of the following network defense techniques examines the causes for attacks in networks by
using fault-finding mechanisms, security forensics techniques, and post-mortem analysis? -
(ANSWER)Reactive approach
Danny, a security professional, wants to safeguard his organization's network from hacking attempts
and virus attacks. For this reason, he follows a network defense approach that examines the causes for
attacks in the network and includes fault finding, security forensics, and post-mortem analysis
techniques.
Which of the following network defense approaches was followed by Danny in the above scenario? -
(ANSWER)Retrospective approach
Clark, a network security specialist, was assigned to secure an organization's network. Clark
implemented a network defense approach that can tackle network attacks such as DoS and DDoS and
includes security monitoring methods such as IDS, SIMS, TRS, and IPS.
Which of the following network defense approaches did Clark implement in the above scenario? -
(ANSWER)Reactive approach
Which of the following components of technical security controls protects the information passing
through the network and preserves the privacy and reliability of the data? - (ANSWER)Encryption and
protocols
,NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
Which of the following components of technical network security controls examines the network
devices and identifies weaknesses in the network? - (ANSWER)Auditing
James, a certified hacker, was appointed by an agency to perform a cyberattack against the rival
company's servers with the intention of making the services unavailable to their customers. James
performed a DoS attack on the servers but he could not make the services unavailable.
Which of the following components of technical security controls protected the servers from the DoS
attack? - (ANSWER)Network security devices
Bob has recently purchased a new laptop and enabled all the required security controls. The next day
while verifying whether all the security mechanisms were enabled on his system or not, he found that
the "firewall" was disabled. He immediately enabled the firewall option on his laptop.
Identify the component of technical security controls that Bob enabled to protect his laptop from
network-related threats. - (ANSWER)Network security devices
Which of the following protocols provides centralized authentication, authorization, and accounting
(AAA) for remote access servers to communicate with a central server? - (ANSWER)RADIUS
Which of the following protocols is an application layer protocol that provides cryptographic privacy and
authentication for network communication and enhances the security of emails? - (ANSWER)Pretty
Good Privacy (PGP) protocol
Which of the following protocols is an application layer protocol used for sending digitally signed and
encrypted email messages? - (ANSWER)S/MIME
Sally, a security professional, implemented a protocol for authenticating requests in computer networks.
The protocol implemented by Sally is based on the client-server model, and uses encryption technology
and a "ticket" mechanism to prove the identity of a user on a non-secure network.
Identify the protocol implemented by Sally in the above scenario. - (ANSWER)Kerberos
Margaret, a system administrator, regularly administers the devices connected to the organizational
network. She found that certain devices are vulnerable to sniffing attacks. To protect the device from
,NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
such attacks, Margaret employed a protocol that encrypts the entire communication between the client
and the server, including the user's password, which protects it from sniffing attacks.
Identify the protocol employed by Margaret in the above scenario. - (ANSWER)TACACS+
TACACS+ authentication involves the following steps:
1. The router and the user exchange authentication parameters
2. The server responds with the REPLY message based on the provided information
3. A user initiates the connection for authentication
4. The router sends the parameters to the server for authentication - (ANSWER)3 -> 1 -> 4 -> 2
James, a software engineer, is working from a remote location and connects his laptop to the company's
server through a VPN. The company has implemented a security protocol that provides authentication
as well as encryption of the data passing through the VPN tunnels.
Identify the network security protocol implemented by the company for secure communication. -
(ANSWER)Internet Protocol Security (IPsec)
Benson, a security professional plans to implement more stringent security practices in his organization.
For this reason, he uses a protocol that provides cryptographic security by encrypting the email
messages and digitally signing them to ensure confidentiality, integrity, and nonrepudiation of
messages.
Which of the following protocols was employed by Benson in the above scenario? - (ANSWER)S/MIME
Identify the access control terminology that is referred to as an explicit resource on which an access
restriction is imposed. - (ANSWER)Object
Given below are the steps involved in the access control mechanism.
1. Once the identification is successful, the system provides the user access to use the system
2. A user provides their credentials while logging into the system
3. The system then allows the user to perform only those operations for which the user has been
authorized
, NDE - EXAM PRACTICE - FINAL | NEW 355 QUESTIONS AND ANSWERS | 2025/2026 UPDATE
| WITH COPLETE SOLUTION!!
4. The system validates the user with the database on the basis of the provided credentials - (ANSWER)2
-> 4 -> 1 -> 3
James, a network administrator, was assigned a task to create a standard access control model for the
organization's confidential data. He implemented an access control model that determines the usage
and access policies for the users. After its implementation, only users with appropriate access rights can
access the resource.
Which of the following access control models James has implemented in the above scenario? -
(ANSWER)Mandatory access control (MAC)
Which of the following access control models can be termed as need-to-know access model where the
decision can be taken by an owner to provide or deny access to specific user or a group of users? -
(ANSWER)Discretionary access control
Identify the access control model in which the access permissions are beyond the user control, which
implies that users cannot amend the access policies created by the system. - (ANSWER)Role Based
Access Controls
Benila, a security professional, implemented cryptography-based authentication to ensure strong
authentication in her organization. She employed an authentication mechanism that needs a device
embedded with a small computer chip that stores personal information of the employee for
identification.
Identify the type of authentication employed by Benila in the above scenario. - (ANSWER)Smart card
authentication
Ronnie, a security professional got many tickets stating that certain miscreants have been accessing the
files with the credentials of the employees and they are creating havoc in the organization. To prevent
such incidents, Ronnie implemented an authentication mechanism that identifies human characteristics
for authenticating people.
Which of the following types of authentication did Ronnie implement in the above scenario? -
(ANSWER)Biometric authentication