HomeSubjectsUniversityBlogAbout

Network Security (Network Perspective)

Topic in Computer Networks & Cloud Computing

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Network security is the practice of protecting data in transit and the network infrastructure from unauthorised access, misuse, interception and disruption. Items test how packet-filtering firewalls, stateful firewalls and application-level gateways differ, and where intrusion detection and prevention systems sit. Attack questions cover DoS and DDoS, ARP spoofing, man-in-the-middle, IP spoofing and SQL injection. Protocol topics include IPsec with its AH and ESP headers and tunnel versus transport modes, TLS for secure web traffic, VPNs, and AAA services such as RADIUS. Symmetric and public-key cryptography, digital certificates, patching and password policies round out the material.

Below are 30 practice questions from a pool of 210 Network Security (Network Perspective) MCQs, one of 10 topics in Computer Networks & Cloud Computing. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Network Security (Network Perspective)Easy

Q1. What is a VPN?

  1. A.A virtual public network for browsing
  2. B.A very private network with no encryption
  3. C.A secure encrypted tunnel over public networks✓ Correct
  4. D.A virtual protocol network for routing

Explanation

A VPN (Virtual Private Network) creates a secure, encrypted tunnel over a public network (like the Internet), allowing remote users to access private network resources securely.

Report an error in this question

Network Security (Network Perspective)Easy

Q2. What is a DDoS attack?

  1. A.A type of computer virus infection
  2. B.A data decryption technique for ciphertext
  3. C.A routing protocol for network traffic
  4. D.Overwhelming a target with traffic from many sources✓ Correct

Explanation

A DDoS (Distributed Denial of Service) attack floods a target system with traffic from many compromised sources, making it unavailable to legitimate users.

Report an error in this question

Network Security (Network Perspective)Easy

Q3. What does encryption do?

  1. A.Speeds up data transmission rate
  2. B.Deletes data from the storage
  3. C.Converts plaintext into ciphertext✓ Correct
  4. D.Compresses data to save space

Explanation

Encryption converts readable data (plaintext) into an unreadable format (ciphertext) using a key, protecting data confidentiality from unauthorized access.

Report an error in this question

Network Security (Network Perspective)Easy

Q4. What is a firewall?

  1. A.A hardware component inside a router
  2. B.A type of computer virus or malware
  3. C.A device that monitors and controls traffic✓ Correct
  4. D.A wall constructed from fire materials

Explanation

A firewall is a network security device or software that monitors and filters incoming and outgoing network traffic based on predefined security rules.

Report an error in this question

Network Security (Network Perspective)Easy

Q5. What is the purpose of an IDS (Intrusion Detection System)?

  1. A.To detect and alert on suspicious activity✓ Correct
  2. B.To assign IP addresses to devices
  3. C.To block all incoming network traffic
  4. D.To encrypt data during transmission

Explanation

An IDS monitors network traffic for suspicious activity and alerts administrators when potential threats are detected, but it does not actively block traffic.

Report an error in this question

Network Security (Network Perspective)Easy

Q6. What is phishing?

  1. A.A social engineering attack to steal data✓ Correct
  2. B.A feature built into firewalls
  3. C.A network communication protocol
  4. D.A type of recreational fishing activity

Explanation

Phishing is a social engineering attack where attackers send fraudulent communications (often emails) that appear to come from trusted sources to steal sensitive information.

Report an error in this question

Network Security (Network Perspective)Easy

Q7. What does SSL/TLS provide?

  1. A.Secure encrypted communication✓ Correct
  2. B.Faster network speeds overall
  3. C.IP address assignment to hosts
  4. D.File compression for storage

Explanation

SSL/TLS (Secure Sockets Layer / Transport Layer Security) provides encryption, authentication, and data integrity for communications over networks, commonly used in HTTPS.

Report an error in this question

Network Security (Network Perspective)Hard

Q8. What is the TLS 1.3 handshake improvement over TLS 1.2?

  1. A.It reduces handshake to 1-RTT with 0-RTT option✓ Correct
  2. B.It uses more round trips for security
  3. C.It removes all encryption for faster speed
  4. D.It uses significantly longer encryption keys

Explanation

TLS 1.3 reduces the handshake from 2 round trips (TLS 1.2) to 1 round trip, and supports 0-RTT resumption for previously connected clients, significantly reducing latency.

Report an error in this question

Network Security (Network Perspective)Hard

Q9. What is the BGP hijacking attack?

  1. A.A DNS spoofing attack on name servers
  2. B.A wireless deauthentication attack
  3. C.Stealing physical router hardware devices
  4. D.Announcing unauthorized IP prefixes via BGP✓ Correct

Explanation

BGP hijacking occurs when an attacker announces IP prefixes they do not own through BGP, causing Internet traffic to be misrouted through the attacker's network for interception or disruption.

Report an error in this question

Network Security (Network Perspective)Easy

Q10. What is the difference between symmetric and asymmetric encryption?

  1. A.Symmetric encryption is always much stronger
  2. B.They are the same encryption method
  3. C.Asymmetric uses a single shared key only
  4. D.Symmetric uses one key; asymmetric uses a key pair✓ Correct

Explanation

Symmetric encryption uses the same key for encryption and decryption (e.g., AES). Asymmetric uses a public key for encryption and a private key for decryption (e.g., RSA).

Report an error in this question

Network Security (Network Perspective)Hard

Q11. What is perfect forward secrecy (PFS) in cryptographic protocols?

  1. A.A type of network firewall technology
  2. B.Ensuring past sessions stay safe if keys leak✓ Correct
  3. C.Using the same encryption key forever
  4. D.A backup encryption method for storage

Explanation

PFS ensures that each session uses unique ephemeral keys. Even if the server's long-term private key is compromised, past session keys cannot be derived, protecting previously recorded traffic.

Report an error in this question

Network Security (Network Perspective)Medium

Q12. What is the purpose of a DMZ (Demilitarized Zone) in network security?

  1. A.A restricted military zone on base
  2. B.A backup network for disaster recovery
  3. C.A type of encryption algorithm used
  4. D.A segment separating internal from external networks✓ Correct

Explanation

A DMZ is a perimeter network segment that hosts public-facing services (web servers, email servers) while protecting the internal network from direct external access.

Report an error in this question

Network Security (Network Perspective)Hard

Q13. What is the difference between signature-based and anomaly-based intrusion detection?

  1. A.They are the same detection method
  2. B.Signature-based can detect brand new attacks
  3. C.Anomaly-based detection is less effective overall
  4. D.Signature matches known patterns; anomaly detects deviations✓ Correct

Explanation

Signature-based IDS matches traffic against a database of known attack signatures (fast but cannot detect new attacks). Anomaly-based IDS learns normal behavior and flags deviations (can detect unknown attacks but may have more false positives).

Report an error in this question

Network Security (Network Perspective)Medium

Q14. What is the purpose of IPSec?

  1. A.To speed up IP packet routing
  2. B.To replace TCP with a new protocol
  3. C.To assign IP addresses to devices
  4. D.To provide security services at IP layer✓ Correct

Explanation

IPSec (Internet Protocol Security) provides security at the network layer through authentication (AH), encryption (ESP), and key exchange (IKE) for secure IP communications.

Report an error in this question

Network Security (Network Perspective)Medium

Q15. What is two-factor authentication (2FA)?

  1. A.Logging into a system twice in succession
  2. B.Using two different usernames for access
  3. C.Using two different passwords to log in
  4. D.Requiring two identification factors to verify identity✓ Correct

Explanation

2FA requires two different authentication factors (something you know like a password, something you have like a phone, or something you are like a fingerprint) to verify identity.

Report an error in this question

Network Security (Network Perspective)Medium

Q16. What is a man-in-the-middle (MITM) attack?

  1. A.A brute force password cracking attack
  2. B.A type of network firewall configuration
  3. C.An attacker intercepting communication between parties✓ Correct
  4. D.A physical attack on network cables

Explanation

In a MITM attack, an attacker secretly intercepts communication between two parties, potentially reading, modifying, or injecting data without either party's knowledge.

Report an error in this question

Network Security (Network Perspective)Easy

Q17. What is malware?

  1. A.A type of firewall software
  2. B.Malicious software designed to harm✓ Correct
  3. C.Defective hardware components
  4. D.A network topology design

Explanation

Malware (malicious software) is any software intentionally designed to cause damage, including viruses, worms, trojans, ransomware, and spyware.

Report an error in this question

Network Security (Network Perspective)Hard

Q18. What is the purpose of SIEM (Security Information and Event Management)?

  1. A.Optimizing network speed and performance
  2. B.Managing email systems for organizations
  3. C.Securing file transfers between servers
  4. D.Collecting and analyzing security events for threats✓ Correct

Explanation

SIEM collects and analyzes log data from various sources (firewalls, IDS, servers) in real-time, correlating events to detect security threats, generate alerts, and support compliance reporting.

Report an error in this question

Network Security (Network Perspective)Medium

Q19. What is a honeypot in network security?

  1. A.A sweet treat left for hackers to find
  2. B.A type of firewall with extra logging
  3. C.An encryption algorithm for secure data
  4. D.A decoy system to attract and study attackers✓ Correct

Explanation

A honeypot is a deliberately vulnerable system deployed to attract attackers, allowing security teams to study attack methods, gather intelligence, and divert attacks from real systems.

Report an error in this question

Network Security (Network Perspective)Medium

Q20. What is the function of a WAF (Web Application Firewall)?

  1. A.Filtering email messages for spam
  2. B.Protecting web apps by filtering HTTP traffic✓ Correct
  3. C.Encrypting web pages for secure storage
  4. D.Blocking all web traffic on the network

Explanation

A WAF protects web applications by filtering, monitoring, and blocking malicious HTTP/HTTPS traffic, protecting against attacks like SQL injection, XSS, and CSRF.

Report an error in this question

Network Security (Network Perspective)Medium

Q21. What is the difference between stateful and stateless firewalls?

  1. A.Stateless firewalls are more secure overall
  2. B.Stateful tracks connections; stateless filters packets individually✓ Correct
  3. C.They are the same type of firewall
  4. D.Stateful firewalls cannot track any connections

Explanation

Stateful firewalls maintain a table of active connections and make decisions based on the context of traffic flows. Stateless firewalls evaluate each packet independently based on rules.

Report an error in this question

Network Security (Network Perspective)Hard

Q22. What is DNS cache poisoning?

  1. A.Physically destroying DNS server hardware
  2. B.Clearing the DNS cache on all resolvers
  3. C.A DNS backup and recovery method
  4. D.Injecting false DNS entries to redirect users✓ Correct

Explanation

DNS cache poisoning injects false DNS records into a resolver's cache, causing users to be redirected to malicious IP addresses when querying the poisoned domain name.

Report an error in this question

Network Security (Network Perspective)Hard

Q23. What is the principle of zero trust security?

  1. A.Having zero security measures on the network
  2. B.Trusting only traffic from external sources
  3. C.Trusting all internal network traffic by default
  4. D.Never trust, always verify every access request✓ Correct

Explanation

Zero trust security assumes no implicit trust based on network location. Every access request is fully authenticated, authorized, and encrypted, whether from inside or outside the network.

Report an error in this question

Network Security (Network Perspective)Medium

Q24. What is the difference between IDS and IPS?

  1. A.IPS only detects without blocking
  2. B.IDS actively blocks all traffic
  3. C.They are identical in function
  4. D.IDS only alerts; IPS also blocks threats✓ Correct

Explanation

IDS (Intrusion Detection System) monitors and alerts. IPS (Intrusion Prevention System) monitors and actively takes action to block or prevent detected threats in real-time.

Report an error in this question

Network Security (Network Perspective)Hard

Q25. What is a zero-day vulnerability?

  1. A.A vulnerability that takes zero days to fix
  2. B.A vulnerability with zero security impact
  3. C.An unknown flaw exploited before a patch exists✓ Correct
  4. D.A vulnerability found on the software release day

Explanation

A zero-day vulnerability is a software flaw unknown to the vendor that attackers exploit before a patch is available. The term 'zero-day' refers to zero days of patch availability.

Report an error in this question

Network Security (Network Perspective)Medium

Q26. What is port scanning?

  1. A.A type of data encryption technique
  2. B.A method to permanently close all ports
  3. C.Physically inspecting network port hardware
  4. D.Discovering open ports and services on a target✓ Correct

Explanation

Port scanning sends packets to specific ports on a target to determine which ports are open, closed, or filtered, helping identify available services and potential vulnerabilities.

Report an error in this question

Network Security (Network Perspective)Medium

Q27. What is ARP spoofing?

  1. A.Repairing corrupted ARP table entries
  2. B.A DNS poisoning attack on resolvers
  3. C.A routing protocol attack on BGP routers
  4. D.Sending fake ARPs to link attacker MAC to valid IP✓ Correct

Explanation

ARP spoofing sends fake ARP messages to associate the attacker's MAC address with a legitimate IP address, enabling traffic interception (man-in-the-middle) on a LAN.

Report an error in this question

Network Security (Network Perspective)Hard

Q28. What is the difference between IPSec tunnel mode and transport mode?

  1. A.Tunnel encrypts entire packet; transport encrypts payload only✓ Correct
  2. B.Transport mode encrypts the entire IP packet
  3. C.They are identical in operation and security
  4. D.Tunnel mode provides less security than transport

Explanation

In tunnel mode, the entire original IP packet is encrypted and encapsulated with a new IP header (used in VPNs). In transport mode, only the payload is encrypted while the original IP header remains intact.

Report an error in this question

Network Security (Network Perspective)Easy

Q29. What is a digital certificate?

  1. A.An electronic document binding key to identity✓ Correct
  2. B.A type of password for user accounts
  3. C.A printed diploma for graduates
  4. D.An IP address assigned to a server

Explanation

A digital certificate is an electronic document issued by a Certificate Authority (CA) that binds a public key to an entity's identity, enabling secure communications.

Report an error in this question

Network Security (Network Perspective)Hard

Q30. What is network segmentation and why is it important for security?

  1. A.Creating one large flat network for simplicity
  2. B.Dividing networks into segments to limit attacks✓ Correct
  3. C.A type of data encryption for networks
  4. D.Disconnecting all network cables physically

Explanation

Network segmentation divides a network into isolated segments, each with its own security policies. This limits an attacker's ability to move laterally across the network if one segment is compromised.

Report an error in this question

Ready to test yourself on Network Security (Network Perspective)?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Network Security (Network Perspective) Quiz