WorksheetsSemester 1 Exam Review: Unit 3 Securing Networks
Total questions: 15
Worksheet time: 8mins
An attacker intercepts and alters data as it travels between a client and a server. Which attack is occurring?
On-path (Man-in-the-Middle)
MAC flooding
Injection
DNS poisoning
Network logs show repeated, unsolicited ARP replies mapping the gateway IP to a new MAC address. What attack does this indicate?
MAC flooding
ARP poisoning
Evil twin
DNS poisoning
An attacker performs a MAC flooding attack to force a switch into a hub-like state, broadcasting traffic. What is the attacker's PRIMARY goal?
Denial of service
Traffic interception
Credential theft
Lateral movement
An attacker compromises one workstation and then uses it to access additional systems across the internal network. This behavior is known as:
Injection
Lateral movement
On-path attack
MAC flooding
Which control MOST directly limits lateral movement after a device is compromised?
Network segmentation
Signature-based detection
Strong encryption
Log aggregation
Which segmentation technique isolates public-facing servers from the internal network?
VLANs
Subnetting
Screened subnet (DMZ)
Firewall rule logging
A rogue wireless access point mimics a legitimate SSID to trick users into connecting. Which attack is this?
DNS poisoning
Evil twin
MAC flooding
ARP poisoning
Which wireless defense MOST directly reduces the risk of an evil twin attack?
Disabling beacon frames
Controlling signal strength
Network authentication (802.1X)
Strong encryption (WPA3)
A firewall evaluates packets only based on source, destination, and port, without tracking sessions. This firewall is BEST described as:
Next-generation
Stateful
Application-layer
Stateless
A firewall rule set denies TCP port 443 traffic from 10.0.0.0/8 before allowing HTTPS traffic from all sources. Which change would allow HTTPS access?
Move the deny rule below the allow rule
Replace the firewall with an IDS
Enable stateful inspection
Remove ICMP rules
Which tool collects logs from many sources and allows analysts to correlate events across the network?
NIPS
NIDS
SIEM
Firewall
Which detection method compares current behavior to a baseline to identify unusual activity?
Signature-based
Hybrid
Rule-based
Anomaly-based
Duplicate ARP replies appearing in network logs are MOST likely an indicator of:
MAC flooding
ARP poisoning
Injection
Evil twin
Why does unsanitized user input increase the risk of injection attacks?
It allows attackers to intercept traffic
It allows attackers to add unintended commands
It exposes MAC addresses
It weakens encryption
How does defense in depth reduce the impact of a successful network breach?
It prevents all attacks
It replaces the need for detection tools
It ensures only one control can fail
It limits attacker movement and damage
