Network+ Network Security: 227 practice questions
12 of the 227 Network Security questions in the Certsqill Network+ bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for Network+? Take the free 5-min readiness check →
1. TLS for browser traffic: Which feature directly satisfies the requirement?
- WPA3 wireless accessWPA3 protects a wireless local-area connection, not the browser session across untrusted networks.
- TLS for browser traffic ✓TLS protects the browser application session with confidentiality and integrity across untrusted networks.
- Full-disk encryptionFull-disk encryption protects stored data on devices, not data while it traverses networks.
- IPsec tunnel across untrusted networksIPsec can protect network-layer traffic, but the requirement specifically calls for securing the browser application session without a network tunnel.
TLS directly protects the browser application session while it crosses untrusted networks.
2. Full-disk encryption: Which feature directly satisfies the requirement?
- File hashingHashing can detect changes, but it does not make stored laptop contents confidential after loss.
- TLSTLS protects network sessions, but it does not protect files stored locally while the laptop is powered off.
- Data loss preventionData loss prevention can control handling or transmission, but it does not inherently encrypt every local disk sector.
- Full-disk encryption ✓Full-disk encryption protects the operating system, files, and local temporary data when the device is not unlocked.
Full-disk encryption protects comprehensive laptop storage when the device is powered off or locked.
3. PKI: Which feature directly satisfies the requirement?
- VLANVLAN segmentation separates local broadcast domains, but it does not authenticate server certificates.
- MFAMFA strengthens user authentication, but it does not establish a web server’s certificate trust chain.
- PKI ✓PKI provides certificate issuance, chain validation, and trusted certification authorities for scalable service identity verification.
- NATNAT changes address translation behavior, but it provides no certificate identity or trust validation.
PKI scales certificate trust through certification authorities and validated identity chains.
4. Hardware token: Which feature directly satisfies the additional-factor requirement?
- Hardware token ✓A hardware token supplies a possession factor, which differs from the password’s knowledge factor.
- Single sign-onSingle sign-on changes application authentication flow, but it does not inherently add a different authentication factor.
- UsernameA username identifies an account but is not an authentication factor providing independent proof of identity.
- Security questionA security question is another knowledge factor, so it does not provide factor diversity with a password.
A hardware token provides a possession factor alongside the password’s knowledge factor.
5. RADIUS: Which feature directly satisfies the requirement?
- LDAPLDAP provides directory access, but wireless access points commonly use another protocol for centralized AAA exchanges.
- SAMLSAML carries federated identity assertions, but it is not the common access-point AAA protocol described.
- TACACS+TACACS+ is commonly associated with device administration rather than routine wireless network access AAA.
- RADIUS ✓RADIUS commonly provides centralized authentication, authorization, and accounting for network access devices.
RADIUS is commonly used by network access devices for centralized authentication, authorization, and accounting.
6. LDAP directory service: Which feature directly meets the requirement?
- SAML assertionSAML carries federated authentication claims, but it is not the directory database or lookup protocol requested.
- RADIUS authenticationRADIUS commonly supports network access AAA, but it does not provide the requested general-purpose identity directory.
- TACACS+ administrationTACACS+ commonly supports device-administration AAA, but it is not an application identity directory.
- LDAP directory service ✓LDAP provides a directory protocol for centrally storing and querying identities, groups, and attributes used by applications.
LDAP directly supplies centralized directory storage and lookup for identities, groups, and application attributes.
7. SAML assertion exchange: Which feature meets this requirement?
- SAML assertion exchange ✓SAML assertions let an identity provider send signed authentication claims to relying web applications without sharing passwords.
- TACACS+ authorization replyTACACS+ authorization supports device administration, but it does not federate browser authentication with partner applications.
- LDAP bind requestAn LDAP bind authenticates to a directory, but it does not provide signed web federation claims between organizations.
- RADIUS Access-AcceptA RADIUS response supports network access decisions, not browser-based federated identity claims for partner applications.
SAML provides signed federation assertions from the venue identity provider to partner web applications.
8. Least-privilege RBAC role: Which feature most directly enforces this limited job-based access?
- Least-privilege RBAC role ✓A narrowly defined role grants only required permissions, limiting instructors to approved course-material operations.
- Single sign-onSSO reduces repeated logins, but it does not restrict the permissions granted after authentication.
- Multifactor authenticationMFA strengthens identity verification, but it does not define which actions an authenticated instructor may perform.
- Accounting recordsAccounting records document activity, but they do not prevent instructors from receiving excessive permissions.
A least-privilege RBAC role grants only the instructor permissions required for course-material uploads.
9. Geofencing policy: Which feature directly enforces that location restriction?
- Geofencing policy ✓Geofencing evaluates device location against a defined boundary and can restrict application use outside that area.
- Device allowlistingAllowlisting restricts approved devices or identities, but it does not enforce where those devices may operate.
- Device posture assessmentPosture checks evaluate device health or configuration, not the device's geographic position.
- Time-based accessTime-based access limits hours of use, but it cannot determine whether a device is inside the boundary.
Geofencing uses device location to enforce an application boundary around the airport operating area.
10. Surveillance camera: Which physical security feature most directly provides that evidence?
- Electronic door lockA lock controls access but does not by itself provide visual evidence of who entered.
- Motion detectorA motion detector signals movement but generally cannot identify the person involved.
- Badge readerA badge reader records credential use, but it may not prove which person physically entered using that credential.
- Surveillance camera ✓A camera records visual evidence that can help investigators identify the entrant.
A surveillance camera provides visual evidence for identifying the entrant.
11. Isolated honeypot segment: Which feature is required?
- Guest wireless SSIDA guest SSID may separate wireless clients, but it does not inherently isolate a wired or routed honeypot.
- Isolated honeypot segment ✓A separate isolated segment limits the decoy's connectivity and helps prevent compromise from reaching production systems.
- Port mirroring sessionPort mirroring copies traffic for observation, but it does not restrict the honeypot's network reachability.
- Production VLAN membershipPlacing the honeypot with production systems increases possible attack paths instead of containing the decoy.
An isolated honeypot segment contains the intentionally exposed system away from production resources.
12. Availability: Which CIA security property is the primary requirement?
- Availability ✓Availability requires systems and services to remain accessible when users need them, including during a component failure.
- ConfidentialityConfidentiality protects information from unauthorized disclosure, but the stated priority is continued service access.
- NonrepudiationNonrepudiation supports proof of an action or origin, not continued availability during infrastructure failure.
- IntegrityIntegrity protects information from unauthorized alteration, but it does not primarily address service continuity.
Availability is the CIA property concerned with keeping the exhibit accessible during a server failure.
215 more Network Security questions
The remaining 215 questions in this domain are part of the full Network+ bank — 1678 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your Network+ readiness — freeOther Network+ domains
- Network Troubleshooting — 398 questions →
- Networking Concepts — 389 questions →
- Network Implementation — 348 questions →
- Network Operations — 316 questions →
- All 1678 Network+ questions →