Network Security unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
Network access control (NAC)
Guest network isolation
Split tunneling
IPsec
On-path attack
SIEM
DNS poisoning and DNSSEC
Certificate validation
ARP poisoning
Incident response phases
Firewall
Denial-of-service
Short answer 1. Define or explain: MAC filtering limits
3 ptsShort answer 2. Define or explain: Least privilege on a network
3 ptsShort answer 3. Define or explain: Vulnerability scanning
3 ptsShort answer 4. Define or explain: Defense in depth
3 ptsFree response
6 ptsThis course has no free-response prompt tagged to this unit, so one from elsewhere in the course is used. It is still worth writing — the skill transfers.
A student types a web address into a browser on a laptop that has just joined a campus Wi-Fi network, and a page loads. (a) Describe what DHCP does for the laptop when it joins, and name two pieces of configuration it receives beyond its own IP address. (b) Describe how the domain name is resolved to an IP address, including what happens when the local resolver has no cached answer. (c) Explain encapsulation by describing what is added to the data as it moves down the sending host's stack. (d) The page fails to load but the student can reach a site by typing its IP address directly. State what this isolates as the likely fault and explain your reasoning.