Network Segmentation & Infrastructure
Firewalls & Filtering
Security Monitoring & Placement
Remote Access & VPNs
Admin Workstations & Management
100

This Layer 2 technology groups switch ports logically to separate broadcast domains and map them to distinct Layer 3 IP subnets.

What is a Virtual Local Area Network (VLAN)?

100

This basic type of firewall inspects only Layer 3 and Layer 4 packet headers without tracking the state of connections.

What is a packet filtering (stateless) firewall?

100

This passive device or switch feature copies network traffic from a physical port to an intrusion detection sensor without interfering with the original cable path.

What is a Test Access Point (TAP) or Port Mirror (SPAN)?

100

This remote administration protocol uses public key cryptography to encrypt terminal management sessions on TCP port 22.

What is Secure Shell (SSH)?

100

This dedicated server acts as a single, hardened intermediary host that administrators must log into before connecting to internal production systems.

What is a jump server (or bastion host)?

200

This physical network topology design restricts a system completely by disconnecting it from all other external and internal networks, requiring manual updates via removable media.

What is an air gap (physical isolation)?

200

This table is maintained by a Layer 4/5 firewall to track active two-way TCP handshakes and determine whether incoming packets are new or established.

What is a state table?

200

If a network security appliance fails, this operational mode ensures continuous network availability by allowing all traffic to pass through uninspected.

What is fail-open?

200

In an IPsec VPN, this specific protocol header provides data encryption, confidentiality, and integrity, unlike Authentication Header (AH) which provides integrity only.

What is Encapsulation Security Payload (ESP)?

200

Dedicated computers that are strictly reserved for administrative tasks and isolated from standard email and web browsing are known as these.

What are Secure Administrative Workstations (SAWs)?

300

When designing security zones, this perimeter network segment contains public-facing hosts (such as web and mail servers) to isolate them from internal private databases.

What is a Screened Subnet (or Demilitarized Zone / DMZ)?

300

Unlike standard network firewalls, this specialized security tool inspects Layer 7 payloads specifically for web application attacks such as SQL injection and XSS.

What is a Web Application Firewall (WAF)?

300

This is the operational distinction between an IDS and an IPS when an exploit signature is detected.

What is passive logging/alerting (IDS) versus active inline blocking/mitigation (IPS)?


300

This IPsec operational mode encrypts the entire original IP packet and adds a new IP header, making it suitable for site-to-site connections across the public internet.

What is tunnel mode?

300

Managing network devices using a physical console cable or a dedicated, isolated management VLAN completely separate from standard production traffic is known as this.

What is Out-of-Band (OOB) management?

400

In an IEEE 802.1X implementation, these are the three specific roles involved in network port authentication.

What are the Supplicant, Authenticator (switch), and Authentication Server (RADIUS)?

400

A security appliance combines a traditional firewall, intrusion prevention, anti-malware, spam filtering, and content filtering into a single manageable platform.

What is a Unified Threat Management (UTM) (or NGFW)?

400

An inline proxy deployed between clients and the internet that intercepts outbound web sessions without requiring any endpoint browser configuration is known as this type of proxy.

What is a transparent proxy?

400

During Phase 1 of the Internet Key Exchange (IKE) negotiation, this data structure is formed between peers to authenticate identities and establish the management tunnel.

What is a Security Association (SA)?

400

This protocol allows a central directory (like Active Directory) to handle authentication, authorization, and accounting for network switches and VPN gateways.

What is RADIUS (or TACACS+)?

500

An administrator notices that an access switch drops incoming packets when an unauthorized MAC address connects to an interface. Which port security feature was implemented, and what protocol framework passes the user credentials over LAN?

What are MAC filtering/limiting and EAPoL (EAP over LAN)?

500

A network engineer must deploy a firewall policy that allows internal clients to reach the web while blocking uninitiated inbound traffic. What TCP keyword or mechanism ensures returning packets are permitted through an ACL?

What is the established parameter (stateful inspection)?

500

An organization places a firewall appliance directly inline on a link, but configures it to operate transparently at Layer 2 without an assigned IP default gateway. What is this firewall architecture called?

What is a bridged (or transparent) firewall?

500

A remote worker accesses internal corporate web applications over HTTPS via a web browser without installing dedicated client software. What remote access architecture is being leveraged?

What is clientless / HTML5 remote desktop (or SSL/TLS portal)?

500

When connecting via SSH to a newly provisioned jump host for the first time, what cryptographic artifact does the client inspect and cache to prevent Man-in-the-Middle attacks?

What is the server's public host key (or key fingerprint)?

M
e
n
u