Browse all practice questions for the Certiport Network Security Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certiport Network Security Practice Exam 2026 - Free Network Security Practice Questions and Study Guide course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • Which backup method saves all changed files since the last full backup?
  • What type of malware steals data and demands a ransom for its return?
  • Which of the following statements about network sniffing is true?
  • What is the primary purpose of a VPN?
  • What are the three types of attack surfaces?
  • What is the first action to take when a device is suspected of being infected with malware?
  • Which type of security policy defines the requirements to connect to a computer network from outside?
  • To ensure the security of sensitive data, which protocol is best avoided?
  • Which Windows application is designed to protect devices from malware?
  • True or False: Antimalware tools can completely prevent all types of cyber attacks.
  • When should a company conduct a security audit?
  • What kind of encryption does SSL VPN generally use?
  • What is the purpose of a digital certificate in network security?
  • What does the term spoofing refer to in the context of security?
  • What does DNSSEC use to create a chain of authority?
  • An access list on a router is an example of which type of firewall?
  • What type of backup includes all files and resets the archive bit?
  • Which security feature provides encryption for full drives on Windows operating systems?
  • What is a common password policy regarding password reuse?
  • What is one of the core functions of RADIUS in a network?
  • Which Windows tool is specifically used for encrypting removable drives?
  • Which of the following is NOT true regarding private browsing?
  • In the IT field, impersonation such as a person impersonating a help desk agent and asking for a password is a type of ____________________.
  • For what type of network is MAC filtering best suited?
  • An intrusion prevention system (IPS) functions as which type of control?
  • What is the procedure for applying a software restriction policy to an entire Active Directory domain?
  • In the context of network security, what does the acronym AUP stand for?
  • True or False: You cannot limit the size of audit logs.
  • What types of lists are utilized in anti-spam solutions? Choose two.
  • What should be the immediate action for mobile devices used for business if they are lost or stolen?
  • Which methods can be used to deploy security templates? Choose two.
  • Dedicated hardware firewalls are primarily which type?
  • True or False: You should always audit log on successes.
  • Which type of risk management strategy involves accepting the level of risk?
  • Which internet technology is considered to pose the greatest risk to users?
  • Which of the following statements is false about RADIUS?
  • True or False: A stateful firewall remembers the state of connections.
  • What type of VPN often requires users to connect through a web browser?
  • What characteristic defines a polymorphic virus?
  • What network security measure can help identify unauthorized access attempts?
  • Which of the following are NOT considered specific types of audits?
  • Which of the following are examples of biometric devices? Choose 2.
  • What is the defining characteristic of spoofing?
  • What form of malware allows unauthorized permissions on a system or initiates an unauthorized task?
  • What term refers to an attack that takes advantage of software vulnerabilities that are unknown to the vendor?
  • Audit logs can be used to warn off:
  • Rules set on firewalls are primarily associated with which attack surface?
  • Which Windows registry hive contains current settings for the current user?
  • What is considered the minimum length for a secure password?
  • Which of the following best describes adware?
  • When a department head wants to control permissions but is not an administrator, what should they do?
  • In which locations can system audit policies be configured?
  • What is spyware commonly thought to be?
  • Which method do audits typically use to track access to sensitive information?
  • What protocol does a VPN use to encapsulate IP packets over a public network?
  • The CEO of a company wants to prevent users from copying confidential data to removable media devices. The best protection is to ___________________.
  • Which of the following is an example of an event that should require auditing?
  • True or False: The tool used to view audit logs is called an event viewer.
  • What is the purpose of system audits in network security?
  • If a server is experiencing a high volume of packets from several computers in HR, what kind of attack might this indicate?
  • Is it true that Read Only Domain Controllers need at least one member of the domain administrators group?
  • Which of the following is a benefit of DNSSEC?
  • What is the primary function of Read Only Domain Controllers?
  • Which type of audit event is best for determining attempts to access non-Active Directory objects?
  • What is the status of WEP in current security practices?
  • Application-level firewalls are generally more or less resource-intensive than traditional firewalls?
  • Which type of malware is designed to replicate itself and spread to other machines?
  • True or False: A VPN should use PPTP for tunneling.
  • In a public key infrastructure, which key is responsible for decrypting the data?
  • Does DNSSEC enhance the security of domain name system queries?
  • Which type of backup saves only files changed since the last incremental backup?
  • What malicious activity is triggered at a specific time to cause harm?
  • What security feature can be utilized to enhance access control on a network?
  • What type of malware is known for collecting user information without their consent?
  • What does BitLocker typically use to store the encryption key on a computer?
  • Which types of audits generally include tracking user access on a network?
  • Are antivirus apps guaranteed to keep the blacklist for email addresses and domains up to date?
  • Which factor is most important when considering server security?
  • What is the third step to share the "Facebook Photos" folder according to the least privilege principle?
  • True or False: A good audit plan should collect both successful and failed events.
  • What aspect of CIA is demonstrated by verifying the sender of a document?
  • What final step must be taken to ensure the appropriate access to the "Facebook Photos" folder?
  • When considering network security, what is the primary role of a firewall?
  • Which of the following represents an example of a simple, weak password?
  • What is one of the layers of defense in Microsoft’s anti-phishing strategies?
  • True or False: A certificate authority provides keys for authentication used in a digital certificate.
  • If a user is experiencing issues with a webpage not displaying the latest content, what is the first troubleshooting step?
  • What is the function of User Account Control (UAC) in Windows?
  • A digital signature included in an e-mail is used to __________.
  • Which of the following is true about WPA and WPA2?
  • Which of the following protocols is commonly used for sending secure email?
  • True or False: A VPN connects two entities over a wide area network like the internet.
  • What Windows 10 feature allows users to authenticate using biometric data such as face or fingerprint?
  • Which of the following represents a strategy for effectively managing network security?
  • What first step should you take to share a folder titled "Facebook Photos" while implementing the principle of least privilege?
  • What area of group policy can be utilized to control which applications can be executed on devices?
  • What type of malware is characterized by encrypting files and demanding ransom for decryption?
  • What impact does a worm have on a computer's performance?
  • In network security, which is more critical to monitor: successful logon attempts or failed logon attempts?
  • Which Windows registry hive stores settings for the computer as a whole?
  • Does a stateful firewall allow only packets matching known active connections while rejecting others?
  • What is the significance of the principle of least privilege in network security?
  • What type of attack uses SQL commands to manipulate data through a web application?
  • What do small software programs designed to spread from one computer to another and interfere with operations called?
  • What does a firewall primarily do in a network?
  • What is the main function of a buffer overflow?
  • What technique allows only specific devices to connect to a wireless network?
  • How does a worm typically propagate?
  • Which of the following protocols is considered unsecured and should be avoided in a server environment?
  • Is a worm typically found in most music and videos?
  • What can a network sniffer easily obtain?
  • If you copy a file or folder to a new volume, which permissions are typically applied?
  • What do grey checkboxes in the Allow column for a group's permissions represent?
  • What is the name of the segments into which a router can divide a physical network?
  • Can application-level firewalls provide content filtering?
  • What type of malware is specifically designed to replicate itself and spread to other computers?
  • What is a key feature of two-factor authentication?
  • An attacker has set up a system that tricks the user's computer into thinking the attacker is the server and tricks the server into thinking the attacker is the user's computer. What is the name of this type of attack?
  • When conducting a full backup, what happens to the archive bit?
  • Which feature would allow a user to browse without leaving a trace in most web browsers?
  • Which of the following permissions allows a user to view a folder's contents?
  • What type of software offers protection from applications that gather user information?
  • What protocol should be restricted to email servers for sending emails?
  • What is another name for a perimeter network?
  • In NTFS, which permission allows one to change permissions on a file or folder?
  • What is one primary benefit of using a firewall?
  • Which component of the CIA triad prevents unauthorized withholding of data?
  • Which principle describes a polymorphic virus's ability to avoid detection?
  • The IEEE 802.11 standard defines the name for a WLAN as the _____________.
  • What is true about how a worm operates?
  • What is the main characteristic of a differential backup?
  • Which Windows registry hive is responsible for runtime information?
  • True or False: Trojan horses are designed to appear as legitimate applications.
  • Which of the following statements about dedicated hardware firewalls is true?
  • What type of permissions do grey checkboxes indicate in a permissions settings interface?
  • What does the term "buffer overflow" refer to?
  • What type of malware involves forging a fake sender address in an email?
  • What occurs during IP address spoofing?
  • Does an internet service provider know the sites visited while in private browsing mode?
  • Which statement about network address translation (NAT) is correct?
  • What technique is often used to gain unauthorized access to passwords?
  • Which of the following is considered a technical control in cybersecurity?
  • Does a worm typically corrupt or modify files?
  • What does the term 'phishing' refer to in cybersecurity?
  • Is DNSSEC proprietary to Microsoft domain name servers?
  • What type of VPN connection is typically used to link two business entities?
  • What type of attack might result in users being unable to access their email due to overloading a mail server?
  • What type of key is used to decrypt data that was encrypted with a public key?
  • Phishing primarily involves which type of online crime?
  • Is RADIUS a Cisco-proprietary protocol?
  • Which attack attempts to break passwords using a dictionary of common words and phrases?
  • Where are password policies typically established for an Active Directory domain?
  • What maps multiple internal IP addresses to a shared external IP address?
  • What are the two tools that can be used to keep servers updated and patched properly besides Windows Update?
  • Which technology allows multiple computers on an internal network to share one public address?
  • Is IPsec used to create a secure tunnel between two computing devices?
  • Which of the following is considered an advanced permission in NTFS?
  • Which two actions are part of hardening a server?
  • Which tunneling protocol is used to carry packets from unroutable IP addresses across a routable IP network?
  • By default, which websites are assigned to the trusted site zone in browser settings?
  • What does BitLocker primarily encrypt?
  • In terms of CIA, ensuring the sales department can access a document primarily relates to which aspect?
  • Which of the following is NOT a common characteristic of phishing attacks?
  • Which of the following best describes a stealth virus?
  • What is the primary reason for encrypting offline files?
  • What is the primary goal of implementing anti-spam solutions in email systems?
  • Where do most computers obtain their media access control (MAC) address?
  • In a secure dynamic DNS environment, who has the ability to create records on a DNS server?
  • What type of malware is known to gain administrator-level access and target critical system components?
  • Which format is most commonly used for digital certificates?
  • Which of the following best describes the role of HKEY_LOCAL_MACHINE?
  • Which of the following is a false statement regarding DES?
  • The number of running services on a system falls under which type of attack surface?
  • Which type of record in DNS is primarily used for directing email traffic?
  • Which of the following is NOT an NTFS permission?
  • Which protocols are used to encrypt emails? Choose 2.
  • Is "Cookie" a strong password against dictionary attacks?
  • The process of eliminating risk by choosing not to participate in an action or activity is known as?
  • What is the primary purpose of implementing an Encrypted File System (EFS) on laptops?
  • What network management tool monitors packet traffic and reports on sender, destination, and type of packet?
  • What is a VPN primarily used for?
  • What is a 'honey pot' in the context of network security?
  • What technique is used to redirect internet traffic to a fraudulent website to obtain user credentials?
  • Which of the following would be categorized as a best practice for securing digital certificates?
  • What type of attack is characterized by the inability to block unwanted ads despite user attempts?
  • What is a key benefit of the SmartScreen filter found in Internet Explorer and Microsoft Edge?
  • Which of the following statements is true regarding MAC addresses?
  • Which of the following actions best helps in managing password security within an organization?
  • Phishing attacks typically aim to obtain what type of information?
  • Does IPsec encrypt data packets using the Authentication Header (AH)?
  • Which Windows registry hive stores file extensions for applications?
  • Which type of malware is often used to modify or exploit backdoor access in a system?
  • Which type of attack is capable of stealing cookies from a user's machine?
  • What is the main benefit of using strong, unique passwords for every service?
  • What does RADIUS primarily perform in network services?
  • What term describes the method of analyzing and classifying information based on its sensitivity?
  • Which NTFS permission allows a user to change a file's content?
  • Which statement is true about a stealth virus?
  • When processing application-level queries, how do application-level firewalls compare to traditional firewalls?
  • Threat modelling identifies potential threats and vulnerabilities from whose point of view?
  • What happens to folders that have EFS encryption when moved to a different volume?
  • Which of the following best defines 'vulnerability' in the context of information security?
  • Which of the following is NOT a characteristic of a denial of service attack?
  • Which step follows sharing the "Facebook Photos" folder with read-share permission when implementing least privilege?
  • Which software provides protection from destructive bits of code loaded onto a computer without the user's knowledge?
  • You can surf the web without leaving a history trail of the sites you visit by using what feature in Internet Explorer or Microsoft Edge?
  • What type of malware takes advantage of undisclosed vulnerabilities?
  • When operating in private browsing mode, does the workplace know which sites are visited?
  • Which of the following should be considered when implementing security measures for email?
  • Which statement about RADIUS is true?
  • What is an effective method to prevent an attack on a company server that uses cookie-related misdirection?
  • When will BitLocker use software-based encryption?
  • When you copy folders that have been encrypted through EFS within the same volume, what happens to their encryption?
  • Once auditing requirements are established, what must be considered about the logs?
  • Do application-level firewalls support caching?
  • For what purpose is a Remote Wipe feature primarily used on mobile devices?
  • Which of the following is a function of RADIUS?
  • What is the primary goal of a disaster recovery plan (DRP)?
  • When connecting a laptop to a home router, which combination of security and encryption should be selected for optimal protection?
  • What email filtering technique verifies that an email is from a trusted IP address?
  • Which security feature allows users to recover encrypted files?
  • What effect does installing an anti-malware app often have on existing malware areas in Windows security?
  • Which type of backup captures all files that have changed since the last full backup?
  • In the CIA triad, which principle is concerned with preventing erroneous modification of data?
  • What does the "C" in CIA stand for when discussing network security?
  • An acceptable use policy (AUP) is an example of what type of control?
  • What indicates that an attack is not being eradicated by anti-malware programs?
  • Which group scopes are defined by Active Directory?
  • Where can a domain user account's password be reset on a Windows Server?
  • In private browsing, what typically happens to the browsing history?
  • What is one of the main functions of IPsec?
  • What is the potential risk associated with not securing data on company laptops?
  • Which type of DNS record is used to lookup an associated host or domain name by its IP address?
  • What type of malware includes programs that block the user from accessing their data?
  • Which of the following is a common technique used to secure a Wi-Fi network?
  • What is the primary purpose of a firewall in a network?
  • What is a security device that generates a random number used for a second form of authentication?
  • Do Read Only Domain Controllers have any benefits regarding management requirements?
  • If your email program is blocking emails from a certain sender, what is the best option?
  • What type of malware is designed to replicate itself and spread to other machines?
  • Does a virus need a carrier in order to propagate itself?
  • What is an example of a tool used for managing desktop data center and cloud configurations?
  • Which of the following is NOT a group scope defined by Active Directory?
  • Which tool is commonly used to manage and filter network traffic in cybersecurity?
  • Which software category encompasses protection from various threats, including spyware and viruses?
  • Which of the following best describes the function of a firewall?
  • A person buying something securely from a website will receive a _________ key to encrypt sensitive data.
  • Which of the following consists of fraudulent emails that appear to be from a legitimate source requesting personal information?
  • What provides an encrypted connection between a remote user and an enterprise network?
  • Which password is considered the strongest based on complexity?
  • Which is a primary purpose of encryption in network security?
  • Before access control can happen in a physical security context, what must occur?
  • Which of the following is a common feature of phishing attacks?
  • Which of the following protocols are part of IPsec? Choose three.
  • What is one effective way to protect your computer from hackers and malicious software?
  • What should you do second when sharing the "Facebook Photos" folder under the principle of least privilege?
  • What does the minimum password age policy enforce in an organization?
  • Which encryption algorithm is classified as asymmetric?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy