Unit 5: Network Security
Networking · Unit 5 · Paper 3

Network Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 5, Paper 3” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

On-path attack

2

DDoS mitigation

3

Rogue access point and evil twin

4

Wireless security standards

5

Network segmentation

6

Screened subnet (DMZ)

7

Penetration testing

8

Defense in depth

9

Denial-of-service

10

Chain of custody

11

Stateful inspection

12

Port security as one layer of defense

Short answer 1. Define or explain: ARP poisoning

3 pts

Short answer 2. Define or explain: MAC filtering limits

3 pts

Short answer 3. Define or explain: Site-to-site vs remote-access VPN

3 pts

Short answer 4. Define or explain: Least privilege on a network

3 pts

Free response

6 pts

Explain the principle of defense in depth as applied to a network, giving three distinct layers.

Explain what a VPN provides and identify one thing it does not protect against.

Explain the difference between authentication and authorization, and give an example of each.

Explain what 802.1X provides and where it is deployed.

Explain how a rogue access point threatens a network and describe one control that detects or prevents it.

Explain what network address translation does and state whether it should be considered a security control.