Unit 5: Network Security
Networking · Unit 5 · Paper 1

Network Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 5, Paper 1” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Secure protocol substitutions

2

DDoS mitigation

3

Vulnerability scanning

4

IPsec

5

Containment before eradication

6

Screened subnet (DMZ)

7

Defense in depth

8

Network segmentation

9

ARP poisoning

10

Incident evidence

11

Certificate validation

12

VPN

Short answer 1. Define or explain: On-path attack

3 pts

Short answer 2. Define or explain: Order of volatility

3 pts

Short answer 3. Define or explain: Penetration testing

3 pts

Short answer 4. Define or explain: Denial-of-service

3 pts

Free response

6 pts

Explain the principle of defense in depth as applied to a network, giving three distinct layers.

Explain what a VPN provides and identify one thing it does not protect against.

Explain the difference between authentication and authorization, and give an example of each.

Explain what 802.1X provides and where it is deployed.

Explain how a rogue access point threatens a network and describe one control that detects or prevents it.

Explain what network address translation does and state whether it should be considered a security control.