Skip to main content

Nepal Engineering Council · Chapter 5

Concept of Computer Network and Network Security System

Pick an answer for each question, then open “Show answer” to check it.

169 questions in 6 syllabus topics · 18 tagged from past exams or NEC model sets.

5.1 Introduction to computer networks and physical layer

21 questions · ACtE0501

1. Which OSI layer is responsible for binary transmission?

  1. Option A: Data Link layer
  2. Option B: Network layer
  3. Option C: Physical layer
  4. Option D: Transport layer
Show hint

Actual wires and raw bits.

Show answer

Answer: C. Physical layer

Physical layer (Layer 1) handles binary transmission of raw data bits over physical media.

2. What causes propagation delay?

  1. Option A: Network congestion
  2. Option B: Router processing
  3. Option C: Physical distance
  4. Option D: Packet size
Show hint

Signal travels at finite speed.

Show answer

Answer: C. Physical distance

Propagation delay is caused by physical distance signals must travel.

3. What is the primary function of the OSI model in computer networks?

  1. Option A: To provide a standardized framework for network communication
  2. Option B: To increase network bandwidth
  3. Option C: To replace TCP/IP protocol
  4. Option D: To eliminate network latency
Show hint

OSI stands for Open Systems Interconnection. Consider what framework means in networking context.

Show answer

Answer: A. To provide a standardized framework for network communication

The OSI model provides a standardized, conceptual framework for understanding how different networking protocols work together. It divides network communication into seven distinct layers: Physical, Data Link, Network, Transport, Session, Presentation, and Application. Each layer has specific responsibilities and interfaces with adjacent layers. This layered approach allows different vendors to create compatible networking equipment and software, as long as they conform to the OSI specifications at each layer. The OSI model is fundamental to understanding network architecture because it helps troubleshoot network problems by isolating which layer the issue occurs in. For example, if you can't access a website, the OSI model helps determine whether the problem is physical (Layer 1), with protocols (Layer 3), or with your application (Layer 7).

4. How many layers are present in the TCP/IP model and what is their fundamental difference from OSI?

  1. Option A: 5 layers; TCP/IP is simpler and more practical
  2. Option B: 7 layers; identical to OSI model
  3. Option C: 4 layers; TCP/IP combines multiple OSI layers
  4. Option D: 6 layers; TCP/IP is more comprehensive
Show hint

Think about the practical implementation of networking versus theoretical frameworks.

Show answer

Answer: A. 5 layers; TCP/IP is simpler and more practical

The TCP/IP model has 5 layers: Application, Transport, Internet, Link, and Physical. Unlike the OSI model's seven layers, TCP/IP combines several layers: the Session and Presentation functions are handled by the Application layer, and the Data Link and Physical layers are combined into the Link layer. The TCP/IP model is more practical because it directly reflects how the Internet actually operates and is based on protocols that were already in use (TCP, IP, Ethernet). While OSI is a theoretical framework designed before many modern protocols existed, TCP/IP was developed from existing working protocols. The Application layer in TCP/IP includes protocols like HTTP, SMTP, FTP, and DNS, which correspond to OSI's Session, Presentation, and Application layers. The Internet layer handles routing and logical addressing (IP), corresponding to OSI's Network layer. The Transport layer manages end-to-end communication (TCP/UDP), matching OSI's Transport layer. This makes TCP/IP more aligned with real-world implementation.

5. What is the fundamental role of a network protocol?

  1. Option A: To increase bandwidth by compression
  2. Option B: To define rules and standards for communication between devices
  3. Option C: To encrypt all network traffic
  4. Option D: To eliminate packet loss
Show hint

Consider what 'protocol' means in everyday language - it's a set of rules.

Show answer

Answer: B. To define rules and standards for communication between devices

A network protocol is essentially a set of rules and standards that govern how data is transmitted, received, and processed over a network. Protocols define the format of data packets, the order of communication, error handling procedures, and how devices should respond to various situations. Without protocols, devices from different manufacturers couldn't communicate because they wouldn't understand each other's data format or timing. For example, TCP defines how data should be sent reliably with acknowledgments and retransmissions, while IP defines how to address and route packets. HTTP defines how web browsers should request web pages and how servers should respond. UDP defines a simpler, faster approach without guarantees. SMTP defines how email should be transmitted. Protocols operate at different OSI layers: physical layer protocols define electrical signals, data link protocols define frame structure, network protocols define addressing, and application protocols define how specific services work. Standardization of protocols is crucial because it allows devices, operating systems, and applications from different vendors to interoperate seamlessly.

6. What distinguishes a Hub from a Switch in network communication?

  1. Option A: Hub has more ports than Switch
  2. Option B: Hub broadcasts to all ports; Switch forwards to specific port based on MAC address
  3. Option C: Switch uses OSI Layer 3; Hub uses Layer 2
  4. Option D: Hub is faster than Switch
Show hint

Think about how each device handles incoming data frames.

Show answer

Answer: B. Hub broadcasts to all ports; Switch forwards to specific port based on MAC address

A Hub is a Layer 1 (Physical layer) device that acts as a central connection point but has no intelligence. When a hub receives data on one port, it simply broadcasts that data to all other ports. This creates several problems: increased network congestion (collisions), reduced bandwidth efficiency, and security concerns because all devices receive all traffic. Hubs are rarely used in modern networks. A Switch is a Layer 2 (Data Link layer) device that is intelligent - it learns and maintains a MAC address table. When a switch receives a frame with a destination MAC address, it looks up that address in its table and forwards the frame only to the specific port connected to that device. If the MAC address is unknown, the switch floods the frame to all ports except the incoming port. This intelligent forwarding dramatically improves network efficiency and security by reducing unnecessary traffic and preventing collision domains. A switch essentially learns which MAC addresses are attached to which ports through source MAC address learning. Modern switches also support features like VLAN (Virtual LAN), port security, and rate limiting. This is why switches have become the standard in modern networks instead of hubs, despite being more expensive initially.

7. What is the primary function of a Router in network architecture?

  1. Option A: To broadcast data to all connected devices
  2. Option B: To forward data between networks based on IP addresses
  3. Option C: To increase network bandwidth
  4. Option D: To encrypt all network traffic
Show hint

Routers work at the Network layer (Layer 3) and use logical addresses.

Show answer

Answer: B. To forward data between networks based on IP addresses

A Router is a Layer 3 (Network layer) device that operates at the logical address level (IP addresses) rather than physical addresses (MAC addresses). The primary function of a router is to forward data packets between different networks. When a router receives a packet, it examines the destination IP address and consults its routing table to determine the best path to forward the packet. If the destination is on a directly connected network, it forwards the packet directly; if not, it forwards the packet to another router (the next hop) that is closer to the destination. Routers maintain routing tables that contain information about known networks and the paths to reach them. These tables can be populated manually (static routing) or automatically via routing protocols like RIP, OSPF, or BGP. Routers are essential for creating large networks and the Internet itself - without routers, all devices would need to be on the same network. Routers also provide other important functions: they act as the demarcation point between networks (internal and external), they can filter traffic based on security policies (acting as firewalls), they can translate addresses (NAT - Network Address Translation), and they manage Quality of Service (QoS) parameters. The routing function requires routers to make intelligent decisions based on network topology, making them more complex and expensive than switches, but necessary for inter-network communication.

8. Compare twisted pair, coaxial, and fiber optic transmission media. Which offers the highest bandwidth?

  1. Option A: Twisted pair offers highest bandwidth
  2. Option B: Coaxial cable offers highest bandwidth
  3. Option C: Fiber optic offers highest bandwidth
  4. Option D: All three offer equal bandwidth
Show hint

Consider the physical properties and data transmission speeds of each medium.

Show answer

Answer: C. Fiber optic offers highest bandwidth

Transmission media are the physical channels through which data travels in networks. Twisted pair cable consists of pairs of insulated copper wires twisted together, which helps reduce electromagnetic interference. It's inexpensive, easy to install, and supports distances up to 100 meters at standard speeds. Twisted pair comes in two varieties: UTP (Unshielded Twisted Pair) and STP (Shielded Twisted Pair). Modern twisted pair (Category 5e, 6, 6a) supports speeds from 100 Mbps to 10 Gbps. Coaxial cable has a central copper conductor surrounded by insulation, a conductive shield, and an outer jacket. It offers better shielding from interference and supports longer distances than twisted pair (up to 500 meters for Ethernet). Coaxial is commonly used in cable television and was historically used in Ethernet networks (10BASE5, 10BASE2). Fiber optic cable uses light signals transmitted through thin glass or plastic fibers. It offers exceptional advantages: extremely high bandwidth (terabits per second), immunity to electromagnetic interference, very long transmission distances (tens of kilometers), higher security (difficult to tap), and lower attenuation (signal loss). Fiber optic is the preferred choice for backbone networks, long-distance communications, and modern high-speed networks. The main disadvantage of fiber is higher cost for installation and equipment. In summary: Fiber optic > Coaxial > Twisted pair in terms of bandwidth and distance capabilities.

9. What is a Bridge in network architecture and how does it differ from a Switch?

  1. Option A: Bridge connects LANs, learns MAC addresses, creates separate collision domains; differs from Switch mainly in speed and port count
  2. Option B: Bridge and Switch are identical devices
  3. Option C: Bridge operates at Layer 3 like Switch
  4. Option D: Bridge is faster than Switch
Show hint

Both are Layer 2 devices, but when was each technology developed and what features do they have?

Show answer

Answer: A. Bridge connects LANs, learns MAC addresses, creates separate collision domains; differs from Switch mainly in speed and port count

Bridges and Switches are both Layer 2 (Data Link layer) devices that learn and forward based on MAC addresses, but differ in sophistication and performance: (1) Bridge characteristics: Connects two or more LAN segments. Learns MAC addresses of devices on each port by examining source MAC of frames. Forwards frames only to ports where destination MAC is known, flooding to all ports if destination unknown. Creates separate collision domains for each port (reduces collisions). Historically used before Switches became affordable. Typically 2-4 ports. Simple logic - straightforward frame forwarding. (2) Switch characteristics: Modern equivalent of Bridge with many more ports (24-48+). Multiple forwarding engines enable simultaneous frame forwarding on different ports (parallel processing). Learning same as Bridge - builds MAC address table. VLAN support - allows logical network segmentation. Advanced features: port security, span tree protocol to prevent loops, QoS marking, port mirroring for monitoring. (3) Key differences: Port count - Bridges are simple with few ports, Switches are complex with many. Backplane capacity - Bridges have limited throughput, Switches have high-speed backplane. Cost - Bridges obsolete/rare, Switches standard and cheap. Features - Switches support many advanced features, Bridges are basic. Learning mechanism - both use same MAC learning. (4) Collision domains: Both create separate collision domains. Frame transmission on one port doesn't affect other ports. (5) Broadcast domain: Both forward broadcast frames (destination FF:FF:FF:FF:FF:FF) to all ports (creating one broadcast domain). This is why Layer 3 routing is needed to separate broadcast domains. (6) Historical context: Bridges developed in 1980s when Ethernet grew beyond single cable. Switches emerged in 1990s with technological advances making many-port, high-speed switching feasible and affordable. Bridges are now obsolete technology. (7) Use case: If you had a large LAN exceeding cable length, Bridges connected segments. Modern networks use Switches exclusively for this purpose.

10. What are the differences between OSI model and TCP/IP model regarding encapsulation?

  1. Option A: Both encapsulate data with headers, but differ in layer count and which layers combine functions
  2. Option B: Encapsulation is identical in both models
  3. Option C: TCP/IP doesn't use encapsulation
  4. Option D: OSI model has no encapsulation
Show hint

How does data get wrapped with headers as it moves down the layers?

Show answer

Answer: A. Both encapsulate data with headers, but differ in layer count and which layers combine functions

Encapsulation is the process of adding headers/trailers at each layer. Both models use encapsulation but structure differs: (1) Encapsulation process (downward): Application layer data → Transport layer adds header (TCP/UDP) creating segment → Network layer adds header (IP) creating packet → Data Link layer adds header/trailer (Ethernet) creating frame → Physical layer converts to signals. (2) Decapsulation (upward): Physical layer receives signals → Data Link layer removes frame header/trailer → Network layer removes IP header → Transport layer removes TCP/UDP header → Application receives data. (3) OSI model (7 layers): Session (Layer 5) and Presentation (Layer 6) add headers between Transport and Application. More separation of concerns. Each layer has clear responsibilities. (4) TCP/IP model (5 layers): Application layer combines OSI's Session, Presentation, and Application. Fewer layers but same fundamental concept. Reflects practical Internet implementation. (5) Naming terminology: TCP/IP calls: OSI calls: Application layer data - SDU (Service Data Unit) or PDU (Protocol Data Unit). Transport layer unit - Segment (TCP) or Datagram (UDP). Network layer unit - Packet. Data Link layer unit - Frame. Physical layer unit - Bits. (6) Encapsulation detail: Each header contains: Source/destination addresses (MAC on Data Link, IP on Network). Protocol identifier (what's in payload). Sequence/acknowledgment numbers (TCP). Checksums/length fields. Size grows from application to physical layer. Final frame typically 1500 bytes maximum (including all headers). (7) MTU (Maximum Transmission Unit): Data Link layer limit on frame size. Typically 1500 bytes for Ethernet. If IP packet exceeds MTU, fragmented into smaller packets. Each fragment has IP header. (8) OSI detailed: Physical (bits), Data Link (frame with MAC), Network (packet with IP), Transport (segment/datagram with TCP/UDP port), Session (sessions), Presentation (encryption/compression), Application (HTTP/SMTP/FTP data). (9) TCP/IP detailed: Physical (bits), Link (frame with MAC), Internet (packet with IP), Transport (segment with TCP/UDP port), Application (HTTP/SMTP/FTP data). Same fundamental concept, fewer layers. (10) Practical implication: Understanding encapsulation helps troubleshooting. Packet capture shows headers at different layers. Protocol analyzers show entire encapsulation. Network overhead from headers - large number of small packets uses more bandwidth due to header percentage.

11. Explain the concept of bandwidth vs. throughput in networks.

  1. Option A: Bandwidth is maximum capacity; throughput is actual data transferred, often less than bandwidth
  2. Option B: Bandwidth and throughput are identical
  3. Option C: Throughput is always higher than bandwidth
  4. Option D: Bandwidth only refers to wireless networks
Show hint

A network link might be rated 100 Mbps but might not achieve that in practice.

Show answer

Answer: A. Bandwidth is maximum capacity; throughput is actual data transferred, often less than bandwidth

Understanding the difference between bandwidth and throughput is crucial for network analysis: (1) Bandwidth: Theoretical maximum data transmission rate. Measured in bits per second (Mbps, Gbps, etc.). Determined by physical media and technology: Ethernet 10BASE-T = 10 Mbps, 100BASE-TX = 100 Mbps, 1000BASE-T = 1 Gbps. WiFi 802.11ac = up to 1300 Mbps theoretical. This is the link capacity - what the equipment is capable of. (2) Throughput: Actual data transmitted successfully. Measured in bits per second (Mbps, Gbps). Varies based on network conditions. Always equal to or less than bandwidth. (3) Reasons throughput < bandwidth: (a) Protocol overhead - TCP/IP headers consume bandwidth. Ethernet header 18 bytes, IP header 20+ bytes, TCP header 20+ bytes. For small packets, overhead percentage is large. (b) Collisions (in shared media) - retransmissions waste bandwidth. (c) Retransmissions - lost packets retransmitted, not counted as throughput. (d) Congestion - buffered packets experience latency. (e) Physical layer inefficiencies - encoding/framing overhead. (f) Flow control/windowing - sender limits rate. (4) Goodput: Data actually useful to application. Even less than throughput. Example: 100 Mbps link, throughput 80 Mbps (due to overhead), goodput 70 Mbps (application sees 70 Mbps useful data). (5) Efficiency calculation: Efficiency = Throughput / Bandwidth × 100%. Example: 100 Mbps link with 80 Mbps throughput = 80% efficiency. (6) Practical example: Home Internet advertised as '100 Mbps' (bandwidth). Speedtest shows 85 Mbps (throughput). Actual application sees 75 Mbps (goodput) due to TCP overhead. (7) Factors improving throughput/efficiency: Larger packets (amortize overhead). Hardware offloading (checksums, segmentation). Efficient protocols (less overhead). Good network conditions (fewer errors). (8) Measurement tools: iperf measures throughput between two endpoints. speedtest.net measures ISP speeds. Network packet analyzer captures actual traffic. (9) Capacity planning: Can't assume link will carry full bandwidth. Rule of thumb: plan for 70-80% of bandwidth. (10) Impact: Network slow? Check link utilization. If using 50 Mbps on 100 Mbps link, might not be bottleneck. If using 95 Mbps, probably congested. Understanding this distinction enables proper network design and troubleshooting.

12. Which of the following is an example of a physical layer protocol?

NEC model set
  1. Option A: Ethernet
  2. Option B: TCP
  3. Option C: HTTP
  4. Option D: ISP
Show hint

Physical layer protocols deal with actual transmission media and raw bits. Which operates at the hardware level?

Show answer

Answer: A. Ethernet

Ethernet is an example of a physical layer protocol (Layer 1 of the OSI model). Ethernet specifies: (1) Physical transmission media (copper cables, fiber optics), (2) Signal encoding (voltage levels, light pulses), (3) Physical connectors (RJ-45, SMA), (4) Transmission rates (10 Mbps, 100 Mbps, 1 Gbps, 10 Gbps), (5) Cable lengths and standards. Physical layer protocols deal with: (1) Bit transmission over physical media, (2) Hardware specifications, (3) Signal propagation. The other options operate at higher layers: (1) TCP - Transport layer (Layer 4), (2) HTTP - Application layer (Layer 7), (3) ISP - Not a protocol; stands for Internet Service Provider. Other physical layer protocols: (1) WiFi (802.11) - Wireless transmission, (2) Bluetooth - Short-range wireless, (3) RS-232/RS-485 - Serial communication. Understanding the OSI layer model helps distinguish protocol types: Layers 1-2 (Physical/Data Link) - Hardware level, Layers 3-4 (Network/Transport) - Routing/end-to-end delivery, Layers 5-7 (Session/Presentation/Application) - Software level. Ethernet remains the most common LAN protocol despite advances.

13. Which transmission media has the highest data transfer rate?

  1. Option A: Twisted Pair Cable
  2. Option B: Coaxial Cable
  3. Option C: Fiber Optic Cable
  4. Option D: Wireless
Show answer

Answer: C. Fiber Optic Cable

14. Which layer of the OSI model is responsible for end-to-end communication?

  1. Option A: Network Layer
  2. Option B: Transport Layer
  3. Option C: Session Layer
  4. Option D: Data Link Layer
Show answer

Answer: B. Transport Layer

15. Which network device operates at the Data Link Layer?

  1. Option A: Router
  2. Option B: Switch
  3. Option C: Gateway
  4. Option D: DNS Server
Show answer

Answer: B. Switch

16. Which of the following is NOT a layer in the TCP/IP model?

  1. Option A: Application Layer
  2. Option B: Internet Layer
  3. Option C: Session Layer
  4. Option D: Transport Layer
Show answer

Answer: C. Session Layer

17. Which layer of the OSI model is responsible for physical addressing?

  1. Option A: Physical Layer
  2. Option B: Data Link Layer
  3. Option C: Network Layer
  4. Option D: Transport Layer
Show answer

Answer: B. Data Link Layer

18. In the OSI model, which layer is responsible for logical addressing?

  1. Option A: Data Link Layer
  2. Option B: Network Layer
  3. Option C: Transport Layer
  4. Option D: Session Layer
Show answer

Answer: B. Network Layer

19. Which of the following is NOT a network topology?

  1. Option A: Star
  2. Option B: Ring
  3. Option C: Pyramid
  4. Option D: Mesh
Show answer

Answer: C. Pyramid

20. Which of the following is NOT a function of a router?

  1. Option A: Packet forwarding
  2. Option B: Path selection
  3. Option C: MAC address resolution
  4. Option D: Network address translation
Show answer

Answer: C. MAC address resolution

21. The primary difference between a hub and a switch is:

  1. Option A: Hubs operate at the Physical layer, switches at the Data Link layer
  2. Option B: Hubs use broadcasting, switches use selective forwarding
  3. Option C: Hubs are faster than switches
  4. Option D: Switches are half-duplex, hubs are full-duplex
Show answer

Answer: B. Hubs use broadcasting, switches use selective forwarding

5.2 Data link layer

22 questions · ACtE0502

22. Which is PPP configuration option?

  1. Option A: Encryption
  2. Option B: Compression
  3. Option C: Authentication
  4. Option D: Multiplexing
Show hint

Verifies device identity.

Show answer

Answer: C. Authentication

PPP supports authentication protocols like PAP and CHAP.

23. What is maximum Ethernet frame size?

  1. Option A: 64 bytes
  2. Option B: 128 bytes
  3. Option C: 1024 bytes
  4. Option D: 1518 bytes
Show hint

Frame size limit.

Show answer

Answer: D. 1518 bytes

Maximum Ethernet frame is 1518 bytes including header and trailer.

24. What is drawback of forward error correction?

  1. Option A: Memory requirement
  2. Option B: Increased latency
  3. Option C: Ineffective detection
  4. Option D: Ineffective correction
Show hint

Performance impact.

Show answer

Answer: B. Increased latency

FEC increases network latency due to encoding/decoding overhead.

25. What IEEE standard for wireless?

  1. Option A: 801.11
  2. Option B: 802.11
  3. Option C: 803.11
  4. Option D: 804.11
Show hint

WiFi standard.

Show answer

Answer: B. 802.11

802.11 is IEEE standard for wireless local area networks.

26. What are the primary services provided by the Data Link layer?

  1. Option A: Routing and addressing
  2. Option B: Framing, MAC addressing, and error detection
  3. Option C: Application protocol support
  4. Option D: TCP/UDP multiplexing
Show hint

Data Link layer is Layer 2 in OSI model. What does 'link' suggest?

Show answer

Answer: B. Framing, MAC addressing, and error detection

The Data Link layer (Layer 2) is responsible for reliable communication between adjacent nodes on a network. Its primary services include: (1) Framing - breaking the data stream into manageable frames with headers and trailers, allowing the receiver to identify frame boundaries and extract data. Frames typically contain a start delimiter, source MAC address, destination MAC address, type field, payload data, and error checking information. (2) MAC addressing - using 48-bit Media Access Control addresses (burned into network interface cards) to identify devices on the local network segment. MAC addresses consist of a 24-bit vendor ID and a 24-bit device ID. (3) Error detection - detecting corrupted frames using CRC (Cyclic Redundancy Check) or checksums. If corruption is detected, the frame is typically discarded. (4) Physical addressing - mapping logical (IP) addresses to physical (MAC) addresses through protocols like ARP (Address Resolution Protocol). (5) Media access control - managing access to the physical medium through protocols like CSMA/CD (Ethernet) or token passing (Token Ring), determining when devices can transmit. (6) Link management - establishing and terminating connections between adjacent devices. The Data Link layer operates within a single network segment or LAN and doesn't provide end-to-end communication across multiple networks - that's the job of the Network layer.

27. Explain the difference between Error Detection and Error Correction in data transmission.

  1. Option A: Detection identifies errors; Correction identifies and fixes them
  2. Option B: Correction is faster than Detection
  3. Option C: Detection uses parity; Correction uses Hamming codes only
  4. Option D: No practical difference exists
Show hint

Consider what happens after an error is found.

Show answer

Answer: A. Detection identifies errors; Correction identifies and fixes them

Error Detection and Error Correction are related but distinct concepts in data transmission. Error Detection involves identifying when an error has occurred in transmitted data but does not attempt to fix it. Common error detection methods include parity checking (simple parity bit checks if number of 1s is odd or even), checksum (adding up all bytes), and CRC (Cyclic Redundancy Check - polynomial-based calculation that's more robust). When an error is detected, the typical response is to discard the corrupted frame and request retransmission (used in TCP). Error detection is simple, fast, and requires minimal overhead. Error Correction goes further - it not only detects errors but also determines which bit(s) are incorrect and fixes them without requiring retransmission. Hamming codes are a classic example, using multiple parity bits positioned at powers of 2, allowing single-bit error correction. Forward Error Correction (FEC) adds redundant information that allows reconstruction of corrupted data. Error correction requires more overhead but is valuable in scenarios where retransmission is impossible or impractical (like satellite communications or real-time streaming). In modern networks, error detection with retransmission is often preferred for local area networks (where retransmission is fast), while error correction is used for long-distance or wireless communications. TCP uses error detection (checksums) and relies on UDP or lower layers for actual validation, while sophisticated wireless protocols use FEC.

28. What is the purpose of Flow Control in data transmission?

  1. Option A: To prevent overwriting of buffers by matching sender and receiver speeds
  2. Option B: To encrypt data during transmission
  3. Option C: To increase bandwidth utilization
  4. Option D: To eliminate retransmissions
Show hint

Consider the mismatch in speeds between sender and receiver.

Show answer

Answer: A. To prevent overwriting of buffers by matching sender and receiver speeds

Flow Control is a critical mechanism that manages the rate at which data is transmitted to prevent buffer overflow at the receiver. When a sender transmits data faster than a receiver can process and store it, the receiver's buffer (temporary storage) can become full, causing data loss. Flow Control techniques prevent this situation. Two main approaches exist: (1) Stop-and-Wait - the sender transmits one frame, then waits for an acknowledgment before sending the next frame. This is simple but inefficient because the sender is idle waiting. (2) Sliding Window - the sender can transmit multiple frames before waiting for acknowledgments, using a 'window' of outstanding unacknowledged frames. The window size is negotiated based on receiver's buffer capacity. Common window sizes are 1 (same as Stop-and-Wait), 127, 2047, or 65535. The receiver indicates how much buffer space it has available in its acknowledgment messages. Examples: In HDLC (High-level Data Link Control), the sliding window protocol is implemented. In TCP, the receiver window size is communicated in the TCP header, allowing the sender to transmit up to that many bytes before requiring an acknowledgment. Xon/Xoff is a simple software-based flow control. Flow Control is essential for reliable, efficient data transmission because it ensures no data is lost due to buffer limitations while maintaining good throughput.

29. What is CSMA/CD and where is it used?

  1. Option A: It's a Data Link protocol used in Ethernet to manage media access and detect collisions
  2. Option B: It's a routing protocol for finding network paths
  3. Option C: It's an encryption method for secure transmission
  4. Option D: It's a protocol for managing IP addresses
Show hint

CSMA/CD stands for Carrier Sense Multiple Access with Collision Detection.

Show answer

Answer: A. It's a Data Link protocol used in Ethernet to manage media access and detect collisions

CSMA/CD is a Media Access Control (MAC) protocol used in traditional Ethernet networks (IEEE 802.3). It operates at the Data Link layer and determines how multiple devices share a common transmission medium. The protocol works as follows: (1) Carrier Sense - before transmitting, a device listens to the medium (carrier) to check if another device is transmitting. If the medium is idle (no carrier signal detected), the device can proceed to transmit. If busy, it waits. (2) Multiple Access - since multiple devices may listen simultaneously, more than one device might detect an idle medium and start transmitting at nearly the same time. (3) Collision Detection - when a device transmits, it simultaneously listens for signals from other devices. If the transmitted signal gets corrupted (collision is detected through signal strength or anomalies), the device stops transmitting immediately. (4) Backoff and Retry - after detecting a collision, the device waits a random backoff period (to avoid synchronized retransmissions), then retries. The backoff period increases exponentially with retry attempts (exponential backoff algorithm). CSMA/CD is used in legacy 10 Mbps and 100 Mbps Ethernet on shared media (hubs). In modern switched Ethernet, collisions are largely eliminated because switches create dedicated point-to-point links, so CSMA/CD is less relevant. Weaknesses include poor scalability - as network load increases, collisions increase, causing throughput to degrade significantly.

30. Explain the Address Resolution Protocol (ARP) and its significance in networks.

  1. Option A: ARP maps IP addresses to MAC addresses for local delivery
  2. Option B: ARP encrypts network traffic
  3. Option C: ARP manages routing between networks
  4. Option D: ARP controls bandwidth allocation
Show hint

Consider what happens when you know someone's IP but need their MAC address.

Show answer

Answer: A. ARP maps IP addresses to MAC addresses for local delivery

The Address Resolution Protocol (ARP) is essential for communication on local area networks. It solves a fundamental problem: devices on the same network segment know each other's IP addresses but need to know MAC addresses to transmit frames. ARP works as follows: When a device needs to communicate with another device whose IP address it knows, it first checks its ARP cache (local memory of IP-to-MAC mappings). If not found, it broadcasts an ARP request message on the local network asking 'Who has this IP address?' (the message is broadcast to MAC address FF:FF:FF:FF:FF:FF). The device with that IP address receives the broadcast and responds with an ARP reply containing its MAC address. The requesting device learns this mapping and caches it for future use, reducing need for repeated ARP requests. ARP cache timeout is typically 15 minutes - entries are removed to handle address changes. ARP is essential because Ethernet frames must contain MAC addresses for delivery on the local segment, but higher-layer applications work with IP addresses. Without ARP, devices couldn't determine which MAC address corresponds to a destination IP on the same network. ARP operates at Layer 2/3 boundary. Security concerns with ARP include ARP spoofing/poisoning - an attacker sends false ARP replies claiming to have a different device's IP address, causing traffic to be redirected to the attacker. ARP also has limitations: it only works on the local network segment; for inter-network communication, routing protocols handle address resolution.

31. What is Ethernet (IEEE 802.3) and its basic characteristics?

  1. Option A: A Layer 2 standard defining framing, MAC addressing, and media access
  2. Option B: A Layer 3 routing protocol
  3. Option C: An application layer protocol for web browsing
  4. Option D: A security protocol for encryption
Show hint

Ethernet is the most common local area network technology. What layer defines frame format?

Show answer

Answer: A. A Layer 2 standard defining framing, MAC addressing, and media access

Ethernet (IEEE 802.3) is the dominant Local Area Network (LAN) technology, operating at the Data Link layer. It defines standards for physical transmission, frame format, media access, and addressing. Key characteristics: (1) Frame Format - Ethernet frames contain: 7-byte preamble (synchronization), 1-byte start delimiter, 6-byte destination MAC, 6-byte source MAC, 2-byte type/length field, 46-1500 bytes of payload, and 4-byte CRC for error detection. (2) MAC Addressing - uses 48-bit (6-byte) MAC addresses in format XX:XX:XX:XX:XX:XX (hexadecimal), where first 3 bytes identify the manufacturer and last 3 bytes identify the device. (3) Media Access - uses CSMA/CD (in legacy versions) or full-duplex switched connections (modern networks). (4) Speed Standards - original 10BASE2/10BASE5 (10 Mbps over coax), 10BASE-T (10 Mbps over twisted pair), Fast Ethernet (100BASE-TX at 100 Mbps), Gigabit Ethernet (1000BASE-T at 1 Gbps), 10 Gigabit Ethernet (10GBASE-T at 10 Gbps). (5) Cable Length - varies by standard but typically 100 meters for twisted pair. (6) Maximum Frame Size - 1500 bytes payload (1518 with header/trailer), called MTU (Maximum Transmission Unit). Jumbo frames up to 9000 bytes are supported by some equipment. Ethernet's success comes from simplicity, reliability, affordability, widespread support, and continuous evolution to higher speeds. It's the standard for local networks today.

32. Compare Token Ring (IEEE 802.5) with Ethernet. What was the main advantage of Token Ring?

  1. Option A: Token Ring was deterministic - guaranteed access time, unlike Ethernet's probabilistic CSMA/CD
  2. Option B: Token Ring was cheaper than Ethernet
  3. Option C: Token Ring offered higher bandwidth
  4. Option D: Token Ring required no maintenance
Show hint

Token Ring used a token-passing mechanism. How does that differ from CSMA/CD?

Show answer

Answer: A. Token Ring was deterministic - guaranteed access time, unlike Ethernet's probabilistic CSMA/CD

Token Ring (IEEE 802.5) was an alternative to Ethernet, particularly popular in corporate networks. Unlike Ethernet's CSMA/CD approach where devices contend for medium access (causing collisions), Token Ring uses token passing: devices are arranged in a logical ring, and a special frame called a 'token' circulates around the ring. Only the device holding the token can transmit data. This created several important differences: (1) Deterministic access - every device gets a guaranteed turn to transmit (fairness), and maximum access time is predictable. This was crucial for real-time applications. (2) No collisions - since only one device transmits at a time, collisions cannot occur. (3) Tokens - when a device captures the token, it transmits data, then releases the token for the next device. If data is successfully transmitted, an acknowledgment is required before releasing the token. (4) Ring topology - devices must be connected in a ring, with tokens circulating. (5) Speeds - typically 4 Mbps or 16 Mbps, later extended to 100 Mbps. (6) Fault tolerance - loss of the token (due to device failure) requires a token monitor to generate new tokens. Despite these advantages, Token Ring became obsolete because: Ethernet improved with switching technology, making collisions less relevant; Ethernet became cheaper; Ethernet offered faster speeds; hybrid networks (Ethernet and Token Ring) created management complexity. Token Ring is now rarely encountered except in legacy systems. However, the token-passing concept influenced later technologies like FDDI (Fiber Distributed Data Interface).

33. What is PPP (Point-to-Point Protocol) and where is it commonly used?

  1. Option A: A protocol for direct connection between two devices, commonly used in dial-up, VPNs, and WAN links
  2. Option B: A protocol for local network broadcasting
  3. Option C: A routing protocol for the Internet
  4. Option D: A protocol for managing MAC addresses
Show hint

Point-to-point suggests a direct connection. Where would that be used?

Show answer

Answer: A. A protocol for direct connection between two devices, commonly used in dial-up, VPNs, and WAN links

PPP (Point-to-Point Protocol) is a Layer 2 protocol designed for direct, serial communication between two devices. It establishes reliable communication links between pairs of devices over various media (serial cables, phone lines, cellular connections, etc.). Key features: (1) Framing - PPP defines frame structure with start flag (01111110), address field (broadcast 11111111), control field (11000011 for numbered information), protocol field (identifies payload type like IP, IPX, or AppleTalk), payload, and FCS (Frame Check Sequence). (2) Link Control Protocol (LCP) - negotiates connection parameters like frame size, authentication method, and compression. (3) Network Control Protocols (NCPs) - configure network layer parameters (IP address negotiation, for example IPCP for IP Control Protocol). (4) Authentication - PPP can use PAP (Password Authentication Protocol) or CHAP (Challenge Handshake Authentication Protocol) for security. (5) Compression - optional data or header compression to improve throughput. Applications include: (1) Dial-up Internet - when modems connected computers to ISPs, PPP was the standard protocol. (2) Virtual Private Networks (VPNs) - PPP is used in PPTP (Point-to-Point Tunneling Protocol) to create secure connections. (3) Leased lines - traditional WAN links between offices used PPP. (4) Mobile networks - cellular data connections often use PPP-like mechanisms. Although superseded by Ethernet for many uses, PPP remains important for WAN and remote access scenarios.

34. What is VLAN (Virtual Local Area Network) and what benefits does network segmentation provide?

  1. Option A: VLAN logically segments networks allowing separate broadcast domains on same switch
  2. Option B: VLAN increases bandwidth
  3. Option C: VLAN encrypts traffic
  4. Option D: VLAN replaces routers
Show hint

VLANs allow logical network divisions even though devices may be physically on same switch.

Show answer

Answer: A. VLAN logically segments networks allowing separate broadcast domains on same switch

VLAN (Virtual Local Area Network) technology enables logical network segmentation providing many benefits: (1) VLAN concept: Creates separate broadcast domains on same physical switch. Devices on different VLANs cannot communicate without routing. Example: VLAN 10 (Accounting) and VLAN 20 (Engineering) on same switch - broadcast from VLAN 10 doesn't reach VLAN 20. (2) VLAN implementation: Ports tagged with VLAN ID (12-bit field allows 4096 VLANs). Tagged frames include VLAN ID in Ethernet frame. Untagged frames default to VLAN on that port. (3) VLAN types: (a) Port-based - all devices on port belong to same VLAN. (b) Protocol-based - VLAN determined by protocol type. (c) MAC-address based - devices assigned to VLAN by MAC address (complex, rarely used). (4) VLAN benefits: (a) Security - separate sensitive departments (Finance, HR). Compromised device cannot reach other VLANs without routing. (b) Traffic management - broadcast storms limited to VLAN, reducing unnecessary traffic. (c) Performance - smaller broadcast domains improve efficiency. (d) Flexibility - reorganize networks by reassigning ports without physical moves. (e) Cost - leverage existing switch infrastructure instead of buying separate switches. (f) Multicast handling - more efficient multicast using IGMP snooping within VLANs. (5) Trunk links: Ports connecting switches are trunks carrying multiple VLANs. Tagged frames indicate VLAN. Allows VLAN spanning across multiple switches. Trunks typically use higher bandwidth (10 Gbps) than access ports (1 Gbps). (6) Routing between VLANs: Requires router (or Layer 3 switch). Router receives frames from VLAN 10, forwards to VLAN 20 based on IP addresses. Creates router-on-stick configuration (single physical link carrying traffic for multiple VLANs). (7) VLAN examples: Large company: Accounting on VLAN 10, Finance on VLAN 20, Engineering on VLAN 30. All connected to same switch/VLAN infrastructure. Router provides inter-VLAN routing. Printer on VLAN 40 (management). (8) Voice VLAN: Special VLAN for VoIP phones. Separate from data VLAN for QoS priority. Phone automatically identifies Voice VLAN using LLDP protocol. (9) VLAN security considerations: VLAN hopping attacks exploit misconfigurations to access other VLANs. Requires proper VLAN configuration and native VLAN settings. (10) VLAN trunking protocol (VTP): Cisco proprietary for VLAN configuration distribution. Simplifies large network management but has security implications.

35. Explain the concept of Spanning Tree Protocol (STP) and why it's important in switched networks.

  1. Option A: STP prevents loops in switch networks by blocking redundant links while maintaining connectivity
  2. Option B: STP increases network bandwidth
  3. Option C: STP encrypts traffic
  4. Option D: STP manages VLAN configurations
Show hint

Multiple switches create redundant paths for reliability, but can cause loops. How is this handled?

Show answer

Answer: A. STP prevents loops in switch networks by blocking redundant links while maintaining connectivity

Spanning Tree Protocol (STP) is critical for switched network stability. Without it, redundant switch connections create loops causing catastrophic failures: (1) Loop problem: Ethernet frames have no TTL (Time To Live) to prevent infinite circulation. Broadcast frames flooded to all ports indefinitely. Source MAC learning gets confused with frames arriving from multiple ports. Bandwidth exhausted by looping traffic. Network becomes unusable. (2) STP solution: Creates tree topology from switch mesh removing redundant links. Selects root bridge (typically highest priority/lowest MAC). Calculates shortest paths from root. Blocks ports that would create loops, leaving one active path between any two switches. (3) STP operation: Root bridge election - switches send Bridge Protocol Data Units (BPDUs). Lowest bridge ID becomes root. Root calculates BPDU with path cost to itself. Other switches receive BPDUs, compare costs, select best path to root. Ports are designated (forward frames to root), root (connected to root), or blocked. (4) Port costs: Inversely proportional to bandwidth - 10 Mbps link=100 cost, 100 Mbps=19, 1 Gbps=4, 10 Gbps=2. Faster links have lower cost, preferred. (5) BPDU: Contains root bridge ID, cost to root, sending bridge ID. Sent every 2 seconds. Absence of BPDU for 20 seconds causes bridge to change spanning tree. (6) Port states: Disabled (no STP), Blocking (receives BPDUs only, no forwarding), Listening (30 seconds, prepares to forward), Learning (15 seconds, learns MAC addresses), Forwarding (active). Transition takes 30 seconds after topology change. (7) Rapid STP (RSTP): Improves convergence from 30+ seconds to < 1 second using different state transitions (Discarding, Learning, Forwarding). More responsive to topology changes. (8) Multiple Spanning Tree (MSTP): Allows different spanning trees for different VLAN groups, reducing blocking overhead. (9) Benefits: Network redundancy - failure of single link doesn't disconnect network. Recovery automatic. (10) Disadvantages: Blocks legitimate paths (reduces available bandwidth). Convergence time (30 seconds in STP) causes temporary outages. Overhead from BPDU processing.

36. The PPP of the OSI model operates at

NEC model set
  1. Option A: Physical layer
  2. Option B: Data link layer
  3. Option C: Network layer
  4. Option D: Transport layer
Show hint

PPP (Point-to-Point Protocol) establishes links between two devices. What layer manages data link establishment?

Show answer

Answer: B. Data link layer

PPP (Point-to-Point Protocol) operates at the Data Link Layer (Layer 2) of the OSI model. PPP is used for: (1) Establishing direct point-to-point connections between two devices, (2) Dial-up connections (historically common), (3) Serial links between routers, (4) Authentication (PAP, CHAP), (5) Network configuration (IP address negotiation). Data link layer functions: (1) Frame formation and transmission, (2) Error detection, (3) Access control to shared media, (4) MAC addressing. PPP features: (1) Encapsulates network-layer protocols (IP, IPX, NetBEUI), (2) Provides authentication mechanisms, (3) Compression capabilities, (4) Error checking, (5) Link quality monitoring. Protocol stack for PPP connection: (1) Physical layer - Actual modem or serial line, (2) Data Link layer - PPP framing and protocol (3) Network layer - IP or other network protocol, (4) Higher layers - TCP, UDP, applications. Modern alternatives to PPP: (1) PPPoE (PPP over Ethernet), (2) L2TP (Layer 2 Tunneling Protocol), (3) Direct Ethernet connections. PPP remains important in legacy systems and specialized applications.

37. Which command is used in Windows to view the ARP cache?

NEC model set
  1. Option A: ipconfig
  2. Option B: arp -a
  3. Option C: ping
  4. Option D: netstat
Show hint

ARP maps IP addresses to MAC addresses. What Windows command displays the ARP cache?

Show answer

Answer: B. arp -a

The command 'arp -a' is used in Windows to view the ARP (Address Resolution Protocol) cache. This command displays the mapping between IP addresses and MAC addresses on the local network. Ipconfig shows IP configuration. Ping tests connectivity. Netstat shows network statistics. The arp -a command helps troubleshoot network connectivity issues by showing which IP-to-MAC mappings are cached.

38. Which flow control mechanism uses sliding window?

  1. Option A: Stop-and-Wait
  2. Option B: Go-Back-N
  3. Option C: Selective Repeat
  4. Option D: Both B and C
Show answer

Answer: D. Both B and C

39. CRC stands for:

  1. Option A: Cyclic Redundancy Check
  2. Option B: Cyclic Redundancy Code
  3. Option C: Code Redundancy Check
  4. Option D: Cyclic Repetition Check
Show answer

Answer: A. Cyclic Redundancy Check

40. IEEE 802.11 standard is related to:

  1. Option A: Ethernet
  2. Option B: Token Ring
  3. Option C: Wireless LAN
  4. Option D: Token Bus
Show answer

Answer: C. Wireless LAN

41. Which protocol is used for point-to-point connection over serial links?

  1. Option A: PPP
  2. Option B: SLIP
  3. Option C: HDLC
  4. Option D: X.25
Show answer

Answer: A. PPP

42. The maximum data rate of standard Ethernet (IEEE 802.3) is:

  1. Option A: 10 Mbps
  2. Option B: 100 Mbps
  3. Option C: 1 Gbps
  4. Option D: 10 Gbps
Show answer

Answer: A. 10 Mbps

43. Ethernet uses which multiple access protocol?

  1. Option A: CSMA/CA
  2. Option B: CSMA/CD
  3. Option C: Token Passing
  4. Option D: Polling
Show answer

Answer: B. CSMA/CD

5.3 Network layer

29 questions · ACtE0503

44. Which distance vector routing depends on?

  1. Option A: Hop counts
  2. Option B: Bandwidth
  3. Option C: Latency
  4. Option D: IP addresses
Show hint

Number of routers traversed.

Show answer

Answer: A. Hop counts

Distance vector routing uses hop count (number of router hops) as metric.

45. What is ARP (Address Resolution Protocol)?

  1. Option A: Dynamic IP binding
  2. Option B: File transfer protocol
  3. Option C: Monitoring protocol
  4. Option D: Error handling
Show hint

Finds MAC addresses.

Show answer

Answer: A. Dynamic IP binding

ARP dynamically resolves IP addresses to MAC addresses.

46. In distance vector, connected to 3 networks, initial table entries?

  1. Option A: one
  2. Option B: two
  3. Option C: three
  4. Option D: none
Show hint

One entry per connected network.

Show answer

Answer: C. three

Each connected network gets one entry in distance vector routing table.

47. What is CIDR notation purpose?

  1. Option A: Identify IP class
  2. Option B: Indicate network portion
  3. Option C: Indicate host portion
  4. Option D: Specify network bits
Show hint

Slash notation /

Show answer

Answer: D. Specify network bits

CIDR notation specifies network bits count (e.g., /24 means 24-bit network).

48. Which NOT valid IPv6 abbreviation?

  1. Option A: 2001:0db8::1
  2. Option B: 2001:db8::1
  3. Option C: ::1
  4. Option D: ::ffff:192.0.2.1
Show hint

Can't mix formats.

Show answer

Answer: A. 2001:0db8::1

Can't use leading zeros with :: compression in IPv6.

49. What does IP address contain?

  1. Option A: Network only
  2. Option B: Host only
  3. Option C: Network and host
  4. Option D: MAC address
Show hint

Two parts.

Show answer

Answer: C. Network and host

IP address has network portion and host portion.

50. What does classful addressing mean in IP networks, and what are the main classes?

  1. Option A: IP addresses divided into Classes A-E with fixed network/host portions
  2. Option B: A method to encrypt IP addresses
  3. Option C: A protocol for managing DHCP
  4. Option D: A system for routing between networks
Show hint

Classful addressing was the original IP addressing scheme. Think about different organization sizes.

Show answer

Answer: A. IP addresses divided into Classes A-E with fixed network/host portions

Classful addressing was the original IPv4 addressing scheme that divided the address space into classes for different organization sizes. IP addresses are 32-bit values, typically written in dotted decimal notation (e.g., 192.168.1.1). Classes: (1) Class A - First bit is 0. Range: 1.0.0.0 to 126.0.0.0. Structure: 8 bits for network, 24 bits for hosts. Supports 126 networks with 16.7 million hosts each. Used for very large organizations (first octet: 1-126). (2) Class B - First two bits are 10. Range: 128.0.0.0 to 191.255.0.0. Structure: 16 bits for network, 16 bits for hosts. Supports 16,384 networks with 65,536 hosts each. Used for medium-sized organizations (first octet: 128-191). (3) Class C - First three bits are 110. Range: 192.0.0.0 to 223.255.255.0. Structure: 24 bits for network, 8 bits for hosts. Supports 2.1 million networks with 256 hosts each. Used for small organizations (first octet: 192-223). (4) Class D - First four bits are 1110. Range: 224.0.0.0 to 239.255.255.255. Reserved for multicast addresses. (5) Class E - First four bits are 1111. Range: 240.0.0.0 to 255.255.255.255. Reserved for experimental use. Special addresses: 0.0.0.0 (this network), 255.255.255.255 (broadcast), 127.x.x.x (loopback for testing). Issues with classful addressing: (1) Inflexible - organizations received fixed sizes regardless of actual need, wasting addresses. (2) Rapid address exhaustion - the Internet ran out of available Class A and B addresses. This led to Classless Inter-Domain Routing (CIDR), which uses variable-length prefix notation (e.g., 192.168.1.0/24) for more efficient address allocation.

51. Explain subnetting and its benefits in network design.

  1. Option A: Dividing a network into smaller subnets for efficient address allocation and management
  2. Option B: Encrypting network traffic using subnet masks
  3. Option C: A method to increase bandwidth between networks
  4. Option D: A routing protocol for the Internet
Show hint

Subnetting divides a network address space. What advantages does that provide?

Show answer

Answer: A. Dividing a network into smaller subnets for efficient address allocation and management

Subnetting is the process of dividing a large network address space into smaller, manageable subnets using subnet masks. A subnet mask (e.g., 255.255.255.0) is a 32-bit number that identifies which portion of an IP address represents the network and which represents the host. Benefits of subnetting: (1) Efficient address allocation - instead of assigning a large block requiring millions of addresses, organizations can allocate exactly what they need, reducing waste. (2) Improved security - subnets can be isolated or placed behind firewalls, containing broadcast traffic and limiting exposure. (3) Reduced broadcast traffic - broadcast domain is limited to a subnet; broadcasts don't cross subnet boundaries (routers don't forward broadcasts). (4) Better performance - smaller broadcast domains mean less unnecessary traffic. (5) Organizational structure - subnets can align with physical locations (each floor of a building), departments, or logical functions. (6) Scalability - organizations can grow and reorganize networks more easily. Example: A Class C address 192.168.1.0/24 (mask 255.255.255.0) provides 256 addresses (0-255), where .0 is network and .255 is broadcast, leaving 254 usable addresses. By subnetting with /25 mask (255.255.255.128), we create two subnets: 192.168.1.0-127 and 192.168.1.128-255, each with 126 usable addresses. With /26 mask, we get four subnets with 62 usable addresses each. The subnet mask in CIDR notation (Classless Inter-Domain Routing) shows the number of network bits: /24 means first 24 bits are network, /25 means first 25 bits are network, etc. Subnetting calculations require understanding binary conversion and bit manipulation.

52. What is the difference between RIP, OSPF, and BGP routing protocols?

  1. Option A: RIP is distance-vector (simple, old); OSPF is link-state (moderate); BGP is path-vector (for interdomain routing)
  2. Option B: All three are identical protocols with different names
  3. Option C: BGP is the fastest protocol
  4. Option D: RIP uses hop count like the others
Show hint

These are routing protocols operating at different scales. Consider what metric each uses.

Show answer

Answer: A. RIP is distance-vector (simple, old); OSPF is link-state (moderate); BGP is path-vector (for interdomain routing)

These three protocols operate at different scopes and use different algorithms: (1) RIP (Routing Information Protocol) - Distance-Vector routing protocol. Uses hop count as metric (how many routers between source and destination). Simple but has limitations: maximum hop count is 15, limiting network size; slow convergence when networks change; high bandwidth usage for frequent updates. RIPv1 uses classful addressing; RIPv2 supports CIDR. Used in small networks or as backup, but largely obsolete. (2) OSPF (Open Shortest Path First) - Link-State routing protocol. Each router maintains complete topology map (knows about every router and link in the network). Uses Dijkstra's algorithm to calculate shortest paths based on link costs (bandwidth, delay, etc.). Advantages: supports large networks, fast convergence, efficient updates (only changes propagated), uses less bandwidth than RIP. Divides large networks into areas for scalability. Used in mid-to-large enterprise networks. (3) BGP (Border Gateway Protocol) - Path-Vector routing protocol used for interdomain (AS - Autonomous System) routing on the Internet. Instead of hop count or link costs, BGP considers the full path (sequence of ASes) to each destination, allowing for policy-based routing decisions. BGP is complex but necessary for Internet routing where policy (commercial agreements between providers) matters. These protocols operate differently: RIP sends entire routing table periodically (10-30 seconds); OSPF sends updates only when topology changes; BGP maintains long-lived connections and exchanges full routing tables at startup, then only sends changes. Understanding which protocol to use is crucial for network design.

53. Explain the concept of unicast and multicast routing.

  1. Option A: Unicast sends to one destination; multicast sends to multiple selected recipients
  2. Option B: Unicast is faster than multicast
  3. Option C: Both are identical processes
  4. Option D: Multicast is only for local networks
Show hint

Consider the difference in delivery models and the use cases.

Show answer

Answer: A. Unicast sends to one destination; multicast sends to multiple selected recipients

Unicast and multicast are two fundamental routing paradigms for different communication scenarios: (1) Unicast Routing - standard point-to-point communication where one sender transmits data to one specific destination. Routers forward packets to the destination IP address. This is what traditional routing protocols (RIP, OSPF, BGP) handle. Every data transmission requires individual copies for each recipient - if one sender wants to reach 100 recipients, 100 separate unicast flows are needed, consuming bandwidth and processing resources. Used for: web browsing, email, file transfer, TCP connections, most traditional applications. Advantage: simple, reliable, works everywhere. Disadvantage: inefficient for one-to-many communication. (2) Multicast Routing - one sender transmits data once, and the network delivers copies only to recipients who have joined the multicast group. Multicast addresses (Class D: 224.0.0.0 to 239.255.255.255) identify groups rather than individual hosts. Routing protocols like DVMRP (Distance Vector Multicast Routing Protocol) and PIM (Protocol Independent Multicast) handle multicast routing. Routers use group membership information (learned via IGMP - Internet Group Management Protocol) to forward multicast traffic only along necessary branches of the network tree. Advantages: efficient bandwidth use (single copy sent, replicated only at branch points), reduced server load, ideal for one-to-many applications. Used for: video/audio streaming, live events, software distribution, collaborative applications, real-time data feeds. Challenges: multicast routing is more complex, requires support from all routers on path, multicast addresses have limited scope (TTL controls spread), no built-in congestion control, less widely deployed on the Internet than unicast. Most Internet applications still use unicast despite its inefficiency for one-to-many scenarios.

54. What is IPv6 and what are its main advantages over IPv4?

  1. Option A: IPv6 provides larger address space (128-bit), simplified header, IPsec support, and auto-configuration
  2. Option B: IPv6 is faster than IPv4
  3. Option C: IPv6 uses different routing protocols
  4. Option D: IPv6 is only for small networks
Show hint

IPv6 was designed to overcome IPv4's limitations. What's the biggest limitation of IPv4?

Show answer

Answer: A. IPv6 provides larger address space (128-bit), simplified header, IPsec support, and auto-configuration

IPv6 is the next-generation Internet Protocol designed to replace IPv4 and overcome its fundamental limitations. Key advantages: (1) Address Space - IPv6 uses 128-bit addresses (written in hexadecimal with colons, e.g., 2001:0db8:85a3:0000:0000:8a2e:0370:7334) compared to IPv4's 32-bit. This provides 2^128 addresses (approximately 3.4 × 10^38) compared to IPv4's 2^32 (4.3 billion), effectively solving address exhaustion. (2) Simplified Header - IPv6 header is fixed 40 bytes (IPv4 minimum 20 bytes, often more with options) with fewer fields, improving routing efficiency. Optional headers are handled via extension headers, keeping base header clean. (3) Built-in IPsec - IPv6 has security in the protocol design, though IPsec is optional. (4) Auto-configuration - devices can auto-generate IP addresses using link-local addresses (fe80::/10) without DHCP, improving network bootstrap. (5) Multicast by design - IPv6 removes broadcast (one-to-all), replacing it with multicast, reducing unnecessary traffic. (6) Quality of Service - Flow label field enables better QoS handling. (7) Neighbor Discovery Protocol (NDP) - replaces ARP with a more efficient protocol. Disadvantages: IPv6 adoption has been slow because IPv4 works well enough, NAT has prolonged IPv4's life, IPv6-only networks are rare, security concerns during transition, applications need updating. The transition from IPv4 to IPv6 uses various techniques: dual-stack (devices run both), tunneling (IPv6 packets inside IPv4), translation (converting between versions). Despite advantages, IPv4 and IPv6 will likely coexist for decades.

55. What is the significance of the Network Address Translation (NAT) in modern networks?

  1. Option A: NAT translates private IP addresses to public, enabling private networks to communicate with Internet
  2. Option B: NAT encrypts network traffic
  3. Option C: NAT increases bandwidth
  4. Option D: NAT replaces DHCP
Show hint

NAT allows many devices on a private network to share one public IP address.

Show answer

Answer: A. NAT translates private IP addresses to public, enabling private networks to communicate with Internet

Network Address Translation (NAT) is crucial for modern networking, solving address scarcity and providing security: (1) Basic function: Translates source IP addresses in outgoing packets from private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) to public IP addresses. Translates destination IP in return traffic from public back to private addresses. Maintains translation table mapping private IP:port to public IP:port. (2) IPv4 address scarcity: IPv4 has only 4.3 billion addresses. NAT allows entire organizations/homes to use private addresses, sharing a few public addresses. Extends IPv4 life indefinitely (though IPv6 eventually replaces this). (3) Static NAT: Maps one private address to one public address (1:1). Used for web servers accessed from Internet. (4) Dynamic NAT: Maps private addresses to pool of public addresses (many:many). (5) Port Address Translation (PAT): Maps many private addresses to one public address using port numbers as differentiator (many:1). Router changes source port in outgoing packets. Return traffic distinguished by port. This is most common (home routers, small businesses). (6) Example: Internal device 192.168.1.100:50000 sends traffic. Router changes to 203.0.113.50:5000. Return traffic to 203.0.113.50:5000 translated back to 192.168.1.100:50000. (7) Stateful inspection: NAT device maintains state table. Unsolicited inbound traffic with no corresponding state is dropped, providing implicit firewall function. (8) Benefits: Enables private network addressing (unlimited internal addresses). Provides some security (hides internal structure). Conserves public IP addresses. (9) Limitations: Breaks peer-to-peer applications requiring two-way initiation. Complicates some protocols (VoIP, FTP, games). Violates end-to-end principle (intermediate routers modifying packets). IPv4 header checksum requires recalculation. Some applications embed IP addresses in payload (FTP), requiring complex deep packet inspection. (10) Solutions to NAT issues: UPnP (Universal Plug and Play) allows applications to request port mappings. STUN (Session Traversal Utilities for NAT) helps applications detect external address. Hole punching enables P2P through NAT. IPv6 eliminates need for NAT with abundant addresses.

56. What is ICMP (Internet Control Message Protocol) and what is its primary use?

  1. Option A: ICMP provides error reporting and diagnostics (ping, traceroute) at network layer
  2. Option B: ICMP encrypts data
  3. Option C: ICMP manages IP addresses
  4. Option D: ICMP is only for IPv6
Show hint

When you ping a server or run traceroute, what protocol is being used?

Show answer

Answer: A. ICMP provides error reporting and diagnostics (ping, traceroute) at network layer

ICMP (Internet Control Message Protocol) is Network layer protocol (IPv4) providing error reporting and diagnostic capabilities: (1) Error reporting: Destination Unreachable - no route to destination, port not open. Time Exceeded - packet's TTL reached zero (sent by routers along path). Parameter Problem - malformed packet header. Fragmentation Needed - packet requires fragmentation but DF (Don't Fragment) flag set. Source Quench - router congestion (rarely used in modern networks). (2) Query messages: Echo Request (ping) - host sends, expecting Echo Reply. Used for reachability testing and latency measurement. Timestamp Request/Reply - obtain time information. Address Mask Request/Reply - determine subnet mask. (3) Ping utility: Sends ICMP Echo Request. Waits for Echo Reply. Measures round-trip time. Indicates if destination reachable. Example: 'ping 8.8.8.8' confirms network connectivity. (4) Traceroute utility: Sends series of packets with increasing TTL values. First packet TTL=1 expires at first hop, returns Time Exceeded from first router. Second packet TTL=2 expires at second hop. Continues until reaching destination. Reveals path packets take through Internet. Shows latency at each hop. (5) Ping sweep: Sends pings to range of addresses discovering active hosts. (6) ICMP filtering: Firewalls often filter ICMP for security (prevent ping-based reconnaissance). However, filtering all ICMP breaks diagnostics. Better to filter selectively (allow replies, block requests). (7) ICMP-based attacks: Ping of Death - oversized ping packets crashing old systems (fixed in modern systems). Smurf attack - broadcast ping to network amplifying traffic to target. (8) ICMP DoS: Sending massive ping requests to target. DDoS magnified through botnets. Firewalls mitigate with rate limiting. (9) IPv6 equivalent: ICMPv6 performs similar functions in IPv6 networks. (10) Uses in networks: Debugging connectivity issues. Determining network topology. Measuring latency (ping). Discovering path characteristics (traceroute). Network monitoring - ICMP timeouts detect equipment failures.

57. Which of the following is a type of routing algorithm used in the network layer?

NEC model set
  1. Option A: Link-state routing
  2. Option B: Distance-vector routing
  3. Option C: Path-vector routing
  4. Option D: All of the above
Show hint

Network layer uses multiple routing approaches. Are all three types actually used?

Show answer

Answer: D. All of the above

All three routing algorithms (link-state, distance-vector, and path-vector) are used in the network layer. Each has different characteristics: (1) Distance-Vector Routing - Routes based on number of hops (hop count as metric). Examples: RIP (Routing Information Protocol). Each router knows only its neighbors and distances. Slow convergence but simple. (2) Link-State Routing - Each router knows complete network topology. Uses Dijkstra's algorithm. Examples: OSPF (Open Shortest Path First), IS-IS. Faster convergence, more overhead. (3) Path-Vector Routing - Maintains entire path to destination, not just hop count. Examples: BGP (Border Gateway Protocol). Used for inter-AS (Autonomous System) routing. Provides loop prevention through path tracking. Selection depends on: (1) Network size and topology, (2) Convergence requirements, (3) Bandwidth constraints, (4) Scalability needs. Modern networks often use combinations: Interior routing (OSPF within organization), Exterior routing (BGP between organizations). Each algorithm has trade-offs in complexity, overhead, and convergence time. These are fundamental concepts in network design.

58. In the TCP/IP model, which protocol is responsible for logical addressing and routing of packets between hosts?

Recalled from Jan 2026 exam
  1. Option A: TCP
  2. Option B: ICMP
  3. Option C: IP
  4. Option D: UDP
Show hint

This protocol handles the addressing and routing of packets across networks. Which one?

Show answer

Answer: C. IP

IP (Internet Protocol) is the protocol responsible for logical addressing and routing of packets between hosts in the TCP/IP model. IP operates at the Network Layer (Layer 3) and is fundamental to internet communication. It assigns logical addresses (IP addresses) to devices and determines the path (routing) that packets take through networks to reach their destination. IP can route packets through multiple intermediate networks. TCP handles end-to-end communication, ICMP is used for diagnostics, and UDP provides connectionless transport. Without IP, there would be no way to route packets across different networks.

59. Which feature is NOT supported by IPv6?

Recalled from Jan 2026 exam
  1. Option A: Multicast
  2. Option B: Unicast
  3. Option C: Broadcast
  4. Option D: Anycast
Show hint

IPv6 removed one communication mode from IPv4. Which one?

Show answer

Answer: C. Broadcast

Broadcast is NOT supported by IPv6. IPv6 removed broadcast communication, which was in IPv4. Instead, IPv6 uses multicast for one-to-many communication. Unicast (one-to-one) and anycast (one-to-nearest) are supported in IPv6. This change reduces unnecessary network traffic since multicast and anycast are more efficient than broadcast. In IPv6, if all-nodes communication is needed, all-nodes multicast address is used instead of broadcast.

60. Which of the following is an interior gateway protocol?

  1. Option A: BGP
  2. Option B: EGP
  3. Option C: OSPF
  4. Option D: None of these
Show answer

Answer: C. OSPF

61. A Class B IP address has how many bits for the network portion?

  1. Option A: 8
  2. Option B: 16
  3. Option C: 24
  4. Option D: 32
Show answer

Answer: B. 16

62. Distance Vector Routing is based on:

  1. Option A: Dijkstra's algorithm
  2. Option B: Bellman-Ford algorithm
  3. Option C: Flooding algorithm
  4. Option D: Prim's algorithm
Show answer

Answer: B. Bellman-Ford algorithm

63. Link State Routing is based on:

  1. Option A: Dijkstra's algorithm
  2. Option B: Bellman-Ford algorithm
  3. Option C: Flooding algorithm
  4. Option D: Prim's algorithm
Show answer

Answer: A. Dijkstra's algorithm

64. The protocol used for error reporting in IP is:

  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: ARP
Show answer

Answer: C. ICMP

65. IPv6 address length is:

  1. Option A: 32 bits
  2. Option B: 64 bits
  3. Option C: 128 bits
  4. Option D: 256 bits
Show answer

Answer: C. 128 bits

66. Which of the following is NOT a feature of IPv6?

  1. Option A: Larger address space
  2. Option B: Simplified header
  3. Option C: Built-in security
  4. Option D: Connectionless service
Show answer

Answer: D. Connectionless service

67. The default subnet mask for a Class C IP address is:

  1. Option A: 255.0.0.0
  2. Option B: 255.255.0.0
  3. Option C: 255.255.255.0
  4. Option D: 255.255.255.255
Show answer

Answer: C. 255.255.255.0

68. CIDR stands for:

  1. Option A: Classless Inter-Domain Routing
  2. Option B: Class-based Internet Domain Routing
  3. Option C: Classless Internet Data Routing
  4. Option D: Class-based Inter-Domain Resolution
Show answer

Answer: A. Classless Inter-Domain Routing

69. Which protocol is used for dynamically assigning IP addresses?

  1. Option A: ARP
  2. Option B: RARP
  3. Option C: DHCP
  4. Option D: ICMP
Show answer

Answer: C. DHCP

70. The TTL field in an IP packet:

  1. Option A: Specifies the packet's priority
  2. Option B: Limits the packet's lifetime
  3. Option C: Indicates the packet's size
  4. Option D: Identifies the packet's source
Show answer

Answer: B. Limits the packet's lifetime

71. Which routing protocol uses the concept of Autonomous Systems?

  1. Option A: RIP
  2. Option B: OSPF
  3. Option C: BGP
  4. Option D: EIGRP
Show answer

Answer: C. BGP

72. The protocol used to convert IP addresses to MAC addresses is:

  1. Option A: DHCP
  2. Option B: ARP
  3. Option C: RARP
  4. Option D: ICMP
Show answer

Answer: B. ARP

5.4 Transport layer

25 questions · ACtE0504

73. What term describes excessive network load?

Aasadh 2081 exam
  1. Option A: Overload
  2. Option B: Congestion
  3. Option C: Saturation
  4. Option D: Bottleneck
Show hint

Traffic exceeds link capacity.

Show answer

Answer: B. Congestion

Congestion refers to network condition where traffic exceeds available bandwidth.

74. What is the term for excessive network load?

  1. Option A: Overload
  2. Option B: Congestion
  3. Option C: Saturation
  4. Option D: Bottleneck
Show hint

Traffic exceeds capacity.

Show answer

Answer: B. Congestion

Congestion occurs when network traffic exceeds available bandwidth.

75. Transport layer protocols deal with?

  1. Option A: App to app
  2. Option B: Process to process
  3. Option C: Node to node
  4. Option D: Man to man
Show hint

Between applications/processes.

Show answer

Answer: B. Process to process

Transport layer handles communication between processes on different hosts.

76. Which protocol supports multicast?

  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: ARP
Show hint

Connectionless protocol.

Show answer

Answer: B. UDP

UDP supports multicast and broadcast transmission.

77. Which transport protocol NOT guarantee delivery?

  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: ARP
Show hint

Connectionless, no delivery guarantee.

Show answer

Answer: B. UDP

UDP is connectionless and doesn't guarantee packet delivery.

78. What connectionless protocol is standard?

  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: ARP
Show hint

No connection setup.

Show answer

Answer: B. UDP

UDP is standard connectionless transport protocol.

79. Explain the Transport layer services and the difference between TCP and UDP.

  1. Option A: TCP provides reliable, connection-oriented service; UDP provides unreliable, connectionless service
  2. Option B: TCP is always faster than UDP
  3. Option C: UDP provides guaranteed delivery
  4. Option D: Both operate at the same reliability level
Show hint

These are the two main Transport layer protocols with very different characteristics.

Show answer

Answer: A. TCP provides reliable, connection-oriented service; UDP provides unreliable, connectionless service

The Transport layer (Layer 4) provides end-to-end communication services between applications. Key services include: reliability, flow control, multiplexing (allowing multiple applications to use the network simultaneously), and ordered delivery. TCP (Transmission Control Protocol) characteristics: (1) Connection-oriented - establishes connection before data transfer via three-way handshake (SYN, SYN-ACK, ACK), then transfers data, then closes connection with four-way handshake. (2) Reliable delivery - guarantees all data arrives in order without duplication using sequence numbers and acknowledgments. (3) Flow control - manages data flow speed using TCP window size. (4) Error checking - detects corrupted segments using checksums; corrupted segments are retransmitted. (5) Congestion control - adjusts transmission rate based on network congestion using algorithms like AIMD (Additive Increase, Multiplicative Decrease). (6) Overhead - header 20+ bytes; connection setup overhead. Used for applications requiring reliability: web (HTTP), email (SMTP, POP3), file transfer (FTP), secure shell (SSH). UDP (User Datagram Protocol) characteristics: (1) Connectionless - no connection setup; sends datagrams directly to destination. (2) Unreliable - no guarantees about delivery, order, or duplication. No acknowledgments required. (3) Low overhead - header only 8 bytes; no connection setup. (4) Speed - faster than TCP because no acknowledgment delays. (5) Broadcast/multicast support - can send to multiple recipients. Used for applications tolerating loss but requiring speed: video/audio streaming, online games, VoIP, DNS queries, SNMP monitoring. Choosing between TCP and UDP depends on application requirements: use TCP when every packet matters (email, banking), use UDP when speed is more important than perfection (video calls). Some applications like QUIC try to combine reliability with UDP's speed.

80. What are ports and sockets, and how do they enable multiplexing?

  1. Option A: Ports identify processes/services; sockets are endpoints enabling multiple applications to use network simultaneously
  2. Option B: Ports and sockets are the same thing
  3. Option C: Ports only work for TCP
  4. Option D: Sockets are only for servers
Show hint

Multiplexing means multiple applications sharing one network interface. How is that achieved?

Show answer

Answer: A. Ports identify processes/services; sockets are endpoints enabling multiple applications to use network simultaneously

Ports and sockets are fundamental to multiplexing in the Transport layer: (1) Ports - 16-bit numbers (0-65535) that identify processes or services on a host. Ports allow a single host to run multiple network applications simultaneously, each receiving their data. Port ranges: Well-known ports (0-1023) reserved for standard services (HTTP=80, HTTPS=443, SMTP=25, FTP=21, SSH=22, DNS=53, etc.). Registered ports (1024-49151) for applications. Dynamic/private ports (49152-65535) for temporary use. Each application listening for incoming connections binds to a specific port. (2) Sockets - endpoints of a network connection, defined by a tuple of (IP address, port, protocol). A socket uniquely identifies an endpoint. A TCP/UDP connection consists of two sockets (one at source, one at destination). Example: (192.168.1.100, 8080, TCP) and (8.8.8.8, 53, UDP). (3) Multiplexing - the Transport layer examines destination port in arriving packets and forwards data to the correct application. This allows one host with one IP address to support dozens or hundreds of applications simultaneously. The kernel/OS maintains port-to-process mappings: when a packet arrives for port 443, the OS knows to deliver it to the web server application, not email or other services. Demultiplexing is the reverse: when an application sends data, the Transport layer adds the source port (process identifier) and destination port (service identifier), ensuring responses return to the correct process. Socket programming in languages like C/C++/Python/Java uses socket APIs to create, bind, listen, connect, send, and receive data on sockets.

81. Explain connection establishment and release in TCP.

  1. Option A: Establishment uses three-way handshake (SYN, SYN-ACK, ACK); release uses four-way handshake with FIN flags
  2. Option B: Connection is instantaneous
  3. Option C: No handshake is needed
  4. Option D: TCP has only three flags
Show hint

TCP is connection-oriented. These handshakes ensure proper connection management.

Show answer

Answer: A. Establishment uses three-way handshake (SYN, SYN-ACK, ACK); release uses four-way handshake with FIN flags

TCP connection management involves carefully orchestrated handshakes to establish and release connections reliably: (1) Connection Establishment (Three-Way Handshake): Step 1 - SYN: Client sends TCP segment with SYN flag set, initial sequence number (ISN), and may include other options like maximum segment size. This indicates desire to establish connection. Step 2 - SYN-ACK: Server receives SYN, sends back segment with SYN and ACK flags set. ACK acknowledges client's sequence number, SYN includes server's ISN. Step 3 - ACK: Client sends ACK confirming server's sequence number. At this point, connection is established. Both sides have agreed on initial sequence numbers and are ready to exchange data. (2) Connection Release (Four-Way Handshake): Step 1 - FIN: One side (typically client) sends TCP segment with FIN flag, indicating no more data to send. Step 2 - ACK: Other side acknowledges FIN. This side can still send data (half-close state). Step 3 - FIN: Server (or other side) sends its own FIN when finished sending. Step 4 - ACK: Client acknowledges server's FIN. Connection fully closed. Why so complex? The handshakes ensure: (1) Both sides are active and ready before data exchange. (2) Both sides agree on initial sequence numbers to prevent confusion with old packets. (3) Graceful shutdown with orderly termination. (4) If one side crashes, the other can detect via timeout. States: LISTEN, SYN_SENT, SYN_RECEIVED, ESTABLISHED, FIN_WAIT_1, FIN_WAIT_2, CLOSE_WAIT, LAST_ACK, TIME_WAIT, CLOSED. TIME_WAIT state lasts 2MSL (Maximum Segment Lifetime) to ensure delayed packets don't interfere with new connections using same port.

82. What is congestion control in TCP and why is it necessary?

  1. Option A: Algorithms to manage transmission rate preventing network congestion and collapse
  2. Option B: Encrypting network traffic
  3. Option C: A method to increase bandwidth
  4. Option D: A routing protocol
Show hint

Without congestion control, what would happen if many TCP connections started at once?

Show answer

Answer: A. Algorithms to manage transmission rate preventing network congestion and collapse

Congestion control is critical for TCP and Internet stability. Without it, multiple simultaneous connections could overwhelm network links, causing packet loss, timeouts, and retransmissions, leading to network collapse (congestion collapse). TCP congestion control maintains stability while maximizing throughput. Key concepts: (1) Congestion window (cwnd) - sender's limit on amount of outstanding data (bytes not yet acknowledged). Cwnd starts small (typically 1 segment ≈ 1460 bytes), grows during data transmission, and shrinks during congestion. (2) Slow Start - when connection begins or after packet loss, cwnd starts at 1 segment and doubles each round trip time (RTT) until reaching ssthresh (slow start threshold), achieving exponential growth. (3) Congestion Avoidance - once cwnd reaches ssthresh, growth becomes linear (additive increase), adding one segment per RTT. (4) Packet Loss Detection: Timeout - if ack not received in time, assume congestion; ssthresh = cwnd/2, cwnd = 1, restart slow start. Fast Retransmit - receiver sends duplicate acks for out-of-order packets; sender retransmits missing packet without waiting for timeout. (5) Additive Increase, Multiplicative Decrease (AIMD) - increase rate gradually, decrease aggressively when congestion detected (sawtooth behavior). Modern algorithms: Tahoe (basic slow start/congestion avoidance), Reno (added fast recovery), NewReno (improved fast recovery), CUBIC (modern, suitable for high bandwidth links), BBR (rate-based instead of window-based). Congestion control is end-to-end responsibility of TCP endpoints, not the network. The network provides signals (packet loss, delay) that TCP interprets as congestion. Some networks also support ECN (Explicit Congestion Notification) where routers mark packets instead of dropping them.

83. What is QoS (Quality of Service) and how does it enable different service levels for network traffic?

  1. Option A: QoS prioritizes traffic based on type/importance ensuring consistent service levels
  2. Option B: QoS increases bandwidth
  3. Option C: QoS prevents packet loss entirely
  4. Option D: QoS encrypts network traffic
Show hint

QoS allows important traffic like VoIP to be prioritized over less critical traffic.

Show answer

Answer: A. QoS prioritizes traffic based on type/importance ensuring consistent service levels

QoS (Quality of Service) is set of techniques ensuring applications receive necessary resources and performance. Essential when network capacity is limited: (1) Traffic classification: Mark traffic based on source/destination IP, ports, protocol, DSCP (Differentiated Services Code Point), IEEE 802.1p (CoS - Class of Service), or application type. Different applications require different treatment (VoIP vs. file backup). (2) Queuing disciplines: Packets waiting in buffer are served according to priority. Strict Priority Queuing (SPQ) - high-priority queues served first, can starve low-priority. Weighted Fair Queuing (WFQ) - each priority gets percentage of bandwidth. Class-Based WFQ (CBWFQ) - administrators define classes and weights. Low Latency Queuing (LLQ) - interactive traffic gets priority while ensuring throughput. (3) Traffic shaping/policing: Shape - smooth traffic to specified rate, buffering excess. Police - drop excess traffic beyond specified rate. Prevents traffic bursts from consuming all bandwidth. (4) Bandwidth reservation: Reserve percentage of link for specific application (VoIP gets 20%, file backup gets 30%). Remaining 50% shared as available. (5) DSCP (Differentiated Services Code Point): IP header field (6 bits) marking traffic class. Routers/switches respect DSCP markings. Example: EF (Expedited Forwarding) for VoIP, AF (Assured Forwarding) for video, BE (Best Effort) for general traffic. (6) Benefits: VoIP quality - jitter/latency-sensitive traffic prioritized. Video streaming - consistent bitrate ensuring smooth playback. File backup - can run with lower priority, not disrupting critical applications. Game responsiveness - player input prioritized. Interactive protocol (SSH/Telnet) - keyboard input prioritized over background transfers. (7) QoS parameters managed: Bandwidth - guaranteed/maximum rate. Latency - maximum delay acceptable. Jitter - consistency of delay. Packet loss - percentage of packets dropped. (8) Implementation points: At ingestion (edge routers mark traffic). In the network (core routers forward according to marks). At egress (output queued according to priority). End-to-end QoS requires cooperation across path. (9) Challenges: Complex configuration - many parameters to tune. Measurement - determining if QoS achieves goals. Not all networks support QoS (Internet best-effort). (10) Modern use: Enterprise networks heavily use QoS. ISPs offer QoS guarantees in SLAs. Cloud providers implement QoS. Home networks increasingly support QoS (prioritizing streaming over P2P).

84. Which protocol is responsible for error detection and correction at the transport layer?

NEC model set
  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: ARP
Show hint

Which transport protocol ensures reliable delivery? Which one is connectionless and unreliable?

Show answer

Answer: A. TCP

TCP (Transmission Control Protocol) is responsible for error detection and correction at the transport layer (Layer 4). TCP provides: (1) Error detection - Checksums detect corruption, (2) Error correction - Retransmission of lost/corrupted packets, (3) Sequence numbers - Track packet order, (4) Acknowledgments - Confirm successful delivery, (5) Flow control - Prevent sender overwhelming receiver, (6) Connection management - Established connection before data transfer. Other protocols' functions: (1) UDP - No error correction, just error detection (checksum only), best-effort delivery, (2) ICMP - Error reporting and diagnostics (ping, traceroute), (3) ARP - Address resolution (IP to MAC mapping), operates between layers. TCP reliability mechanisms: (1) Positive acknowledgments - Receiver sends ACK, (2) Timeout and retransmission - Resend if no ACK received, (3) Sequence numbers - Detect duplicates/reordering, (4) Checksums - Detect corruption. Trade-off: TCP has overhead (headers, acknowledgments) but ensures reliability. UDP is faster but unreliable. Applications choosing protocol: (1) TCP for email, web, file transfer (reliability critical), (2) UDP for streaming, gaming, VoIP (speed more important than occasional loss). TCP's reliability comes at a cost - it's slower than UDP.

85. Which protocol provides connectionless, unreliable service?

NEC model set
  1. Option A: TCP
  2. Option B: UDP
  3. Option C: ICMP
  4. Option D: HTTP
Show hint

UDP doesn't establish connections and doesn't guarantee delivery. This matches which protocol?

Show answer

Answer: B. UDP

UDP (User Datagram Protocol) provides connectionless, unreliable service. Unlike TCP which establishes connections and guarantees delivery, UDP sends datagrams without connection setup and doesn't guarantee they arrive. UDP has lower overhead and latency, making it suitable for real-time applications like voice/video where speed matters more than reliability. Applications include DNS, DHCP, streaming media, and online gaming.

86. Which protocol is best suited for real-time operating systems in the transport layer?

Recalled from Jan 2026 exam
  1. Option A: TCP
  2. Option B: UDP
  3. Option C: SCTP
  4. Option D: DCCP
Show hint

Real-time systems prioritize speed over reliability. Which transport protocol offers lower latency?

Show answer

Answer: B. UDP

UDP (User Datagram Protocol) is best suited for real-time operating systems in the transport layer. UDP is connectionless and provides faster, low-latency communication compared to TCP, which has overhead from connection establishment and acknowledgment mechanisms. Real-time systems require predictable, low-latency delivery even at the cost of occasional data loss. TCP provides reliability guarantees but introduces delays unsuitable for time-critical applications. UDP's simplicity and speed make it ideal for real-time systems like robotics, industrial control, and live streaming where timing is more critical than perfect reliability.

87. Which of the following is a connection-oriented protocol?

  1. Option A: UDP
  2. Option B: IP
  3. Option C: TCP
  4. Option D: ICMP
Show answer

Answer: C. TCP

88. A socket is identified by:

  1. Option A: IP address only
  2. Option B: Port number only
  3. Option C: IP address and port number
  4. Option D: MAC address
Show answer

Answer: C. IP address and port number

89. The transport layer protocol that provides reliable data transfer is:

  1. Option A: UDP
  2. Option B: TCP
  3. Option C: IP
  4. Option D: ICMP
Show answer

Answer: B. TCP

90. Which of the following is NOT a transport layer function?

  1. Option A: Congestion control
  2. Option B: Flow control
  3. Option C: Routing
  4. Option D: Error control
Show answer

Answer: C. Routing

91. The three-way handshake is used in:

  1. Option A: TCP connection establishment
  2. Option B: UDP transmission
  3. Option C: IP routing
  4. Option D: ARP resolution
Show answer

Answer: A. TCP connection establishment

92. In TCP, flow control is implemented using:

  1. Option A: Checksum
  2. Option B: Sequence numbers
  3. Option C: Window size
  4. Option D: Acknowledgments
Show answer

Answer: C. Window size

93. The slow start algorithm is used for:

  1. Option A: Flow control
  2. Option B: Congestion control
  3. Option C: Error control
  4. Option D: Access control
Show answer

Answer: B. Congestion control

94. Which of the following is a connectionless protocol?

  1. Option A: TCP
  2. Option B: UDP
  3. Option C: HTTP
  4. Option D: FTP
Show answer

Answer: B. UDP

95. The maximum segment size in TCP is determined during:

  1. Option A: Connection establishment
  2. Option B: Data transfer
  3. Option C: Connection termination
  4. Option D: None of these
Show answer

Answer: A. Connection establishment

96. Which of the following is NOT a field in the TCP header?

  1. Option A: Sequence number
  2. Option B: Time to live
  3. Option C: Window size
  4. Option D: Acknowledgment number
Show answer

Answer: B. Time to live

97. Which of the following is NOT a characteristic of UDP?

  1. Option A: Connectionless
  2. Option B: Unreliable
  3. Option C: Low overhead
  4. Option D: Flow control
Show answer

Answer: D. Flow control

5.5 Application layer

30 questions · ACtE0505

98. Which is NOT an application layer protocol?

Aasadh 2081 exam
  1. Option A: FTP
  2. Option B: SMTP
  3. Option C: HTTP
  4. Option D: TCP
Show hint

TCP is a transport layer protocol, not application layer.

Show answer

Answer: D. TCP

TCP (Transmission Control Protocol) operates at the transport layer, while FTP, SMTP, and HTTP are application layer protocols.

99. What is port used for HTML?

Aasadh 2081 exam
  1. Option A: 80
  2. Option B: 443
  3. Option C: 21
  4. Option D: 25
Show hint

Default HTTP port.

Show answer

Answer: A. 80

Port 80 is the standard port for HTTP/HTML web traffic.

100. How many TCP connections does FTP use?

  1. Option A: 1
  2. Option B: 2
  3. Option C: 3
  4. Option D: 4
Show hint

Control and data connections.

Show answer

Answer: B. 2

FTP uses 2 TCP connections: one for control commands and one for data transfer.

101. What is main function of application layer?

  1. Option A: Data transmission
  2. Option B: Routing
  3. Option C: User to system interface
  4. Option D: Error checking
Show hint

User application services.

Show answer

Answer: C. User to system interface

Application layer provides interface between user applications and network.

102. Which is NOT email protocol?

  1. Option A: POP
  2. Option B: IMAP
  3. Option C: FTP
  4. Option D: SMTP
Show hint

File transfer, not email.

Show answer

Answer: C. FTP

FTP is file transfer protocol. POP, IMAP, SMTP are email protocols.

103. Which HTTP method sends data to server?

  1. Option A: GET
  2. Option B: POST
  3. Option C: PUT
  4. Option D: DELETE
Show hint

Submits data.

Show answer

Answer: B. POST

POST sends data to server for processing.

104. Which email protocol sends mail?

  1. Option A: POP
  2. Option B: IMAP
  3. Option C: SMTP
  4. Option D: HTTP
Show hint

Outgoing mail.

Show answer

Answer: C. SMTP

SMTP (Simple Mail Transfer Protocol) sends emails.

105. What is HTTP and HTTPS, and how does HTTPS provide security?

  1. Option A: HTTP is application protocol for web; HTTPS adds encryption via TLS/SSL
  2. Option B: HTTPS is slower than HTTP
  3. Option C: HTTPS only works with certain browsers
  4. Option D: Both use identical methods
Show hint

The S in HTTPS stands for Secure. How is the security achieved?

Show answer

Answer: A. HTTP is application protocol for web; HTTPS adds encryption via TLS/SSL

HTTP (HyperText Transfer Protocol) and HTTPS (HTTP Secure) are Application layer protocols for web communication: (1) HTTP - plaintext protocol where client (browser) sends requests to server, server sends back responses. Features: stateless (each request independent), request methods (GET for retrieval, POST for submission, PUT, DELETE, etc.), status codes (200 OK, 404 Not Found, 500 Server Error, etc.), headers for metadata, body for content. Insecure because all data travels in plaintext - passwords, personal information, session cookies are visible to anyone monitoring network. Port 80 by default. (2) HTTPS - same HTTP protocol but wrapped with TLS/SSL encryption. TLS 1.2 or 1.3 encrypts all data: Uses asymmetric cryptography (public-key) for initial handshake where client and server establish shared secret. Asymmetric encryption (like RSA) allows secure key exchange. Uses symmetric cryptography (like AES) for actual data encryption using the shared secret - symmetric is faster than asymmetric. Server presents certificate proving its identity (signed by trusted Certificate Authority). Provides three security services: (a) Confidentiality - encryption prevents eavesdropping. (b) Integrity - message authentication codes prevent tampering. (c) Authentication - certificates verify server identity (browser checks certificate validity, expiration, and issuer). Port 443 by default. (3) Certificate - issued by Certificate Authority (CA), contains server's public key, identity information, and CA's digital signature. Browser verifies certificate: is it from trusted CA? Has it expired? Does domain match? Browser maintains list of trusted root CAs. HTTPS overhead: initial handshake requires extra round trips; encryption/decryption uses CPU. But modern protocols and hardware acceleration make overhead negligible. HTTPS is now standard for any site handling sensitive data or authentication, and browsers warn when visiting unencrypted sites.

106. Explain FTP (File Transfer Protocol) and its limitations compared to modern alternatives.

  1. Option A: FTP transfers files using plaintext commands/data; insecure and uses two connections
  2. Option B: FTP is the most secure file transfer method
  3. Option C: FTP uses encryption by default
  4. Option D: FTP operates at Network layer
Show hint

FTP is an old protocol. What are its problems in modern security-conscious environments?

Show answer

Answer: A. FTP transfers files using plaintext commands/data; insecure and uses two connections

FTP (File Transfer Protocol) is one of the oldest Internet protocols for transferring files between computers. It operates at the Application layer and uses TCP connections. Characteristics: (1) Architecture - FTP uses two TCP connections: Control connection (port 21) for commands and responses, and Data connection (port 20 for active mode, or client's ephemeral port for passive mode) for file transfer. This dual-connection model is unusual and complicates firewall rules. (2) Commands - plaintext commands like USER, PASS, LIST, GET (RETR), PUT (STOR), DELETE, MKD, RMD. All commands and responses travel unencrypted. (3) Security Issues: Plaintext passwords and commands - credentials and commands visible to anyone monitoring traffic. Vulnerable to interception and man-in-the-middle attacks. No encryption. (4) Active vs. Passive mode - Active: server initiates data connection from port 20 to client's port. Passive: client initiates data connection to server's high-numbered port. Firewalls often block active mode. (5) Limitations: Insecure, single-threaded (transfers one file at a time), no resume capability in basic FTP, complex protocol with firewalls, slow for large files. Modern alternatives: (1) SFTP (SSH File Transfer Protocol) - file transfer over SSH (Secure Shell), encrypted, uses single connection, much more secure. (2) SCP (Secure Copy) - secure alternative to copying files. (3) HTTPS - many sites use web interfaces for file download/upload over secure HTTPS. (4) rsync - efficient for synchronizing directories, supports compression and partial transfers. (5) Nextcloud/IPFS - modern cloud-based file sharing. FTP is still used in legacy systems, but should be replaced with SFTP for new deployments. Many web hosts offer both FTP and SFTP for file management.

107. What is DNS (Domain Name System) and why is it essential for the Internet?

  1. Option A: DNS translates domain names to IP addresses, enabling user-friendly internet access
  2. Option B: DNS encrypts network traffic
  3. Option C: DNS manages IP addressing
  4. Option D: DNS routes packets through networks
Show hint

When you type google.com, how does your browser know the IP address?

Show answer

Answer: A. DNS translates domain names to IP addresses, enabling user-friendly internet access

DNS (Domain Name System) is the Internet's distributed database that translates human-readable domain names (like google.com) to machine-readable IP addresses (like 142.251.41.14). It's fundamental to Internet usability because remembering IP addresses is impractical. How DNS works: (1) Hierarchical structure - root nameservers, top-level domain (TLD) nameservers (.com, .org, .net, .uk, etc.), and authoritative nameservers for specific domains. (2) Query process: User's browser sends DNS query to recursive resolver (typically ISP's DNS server or public resolver like 8.8.8.8). Resolver contacts root nameserver, which directs to appropriate TLD server. Resolver contacts TLD server, which directs to authoritative nameserver for the domain. Authoritative nameserver returns IP address. (3) Caching - resolvers cache results for TTL (Time To Live) duration, typically 300-86400 seconds. Local caching on client computers prevents repeated queries. (4) Record types: A records map domain to IPv4, AAAA to IPv6, CNAME for aliases, MX for mail servers, TXT for text records, NS for nameservers, SOA for zone information. (5) DNS security issues: DNS is unencrypted (queries visible). DNS amplification attacks use DNS servers for DDoS. DNS poisoning (cache poisoning) redirects traffic to attacker's site. DNSSEC adds cryptographic signatures to prevent poisoning. DoH (DNS over HTTPS) and DoT (DNS over TLS) encrypt DNS queries for privacy. (6) Distributed nature - no single point of failure, load distributed across millions of nameservers. (7) Caching reduces load on authoritative servers. Without DNS, the Internet would be unusable - no one would memorize IP addresses for thousands of sites. Internationalizing domain names (IDN) allows non-ASCII characters. DNS infrastructure is so critical that disruptions affect entire regions.

108. What are P2P (Peer-to-Peer) applications and how do they differ from client-server models?

  1. Option A: P2P treats all nodes as peers with equal roles; client-server has centralized servers
  2. Option B: P2P is always faster
  3. Option C: P2P uses different protocols
  4. Option D: P2P requires authentication
Show hint

Consider the distribution of functionality in each model.

Show answer

Answer: A. P2P treats all nodes as peers with equal roles; client-server has centralized servers

P2P and client-server are fundamental architectural models for network applications: (1) Client-Server model: Centralized architecture with dedicated servers providing services (HTTP, SMTP, DNS) and clients requesting services. Advantages: Centralized control, easier to secure, easier to manage, single point of truth for data. Disadvantages: Server is bottleneck, single point of failure, scaling requires powerful servers. Examples: Web servers, email servers, databases. (2) P2P model: Decentralized architecture where each node (peer) can act as both client and server. Each peer participates in providing and consuming services. Advantages: Scalable (adding more peers increases capacity), resilient (no single point of failure, continues working if some peers fail), efficient (resources distributed across peers), democratic (no central authority). Disadvantages: Complex to maintain consistency, harder to secure, difficult to manage, peers may be unreliable or malicious, finding content requires discovery mechanisms. Examples: BitTorrent (file sharing), Skype, Bitcoin, IPFS. (3) Hybrid models: Many systems use both approaches. P2P with discovery server (Skype uses central server to establish initial connection, then P2P for calls). Torrent sites use central servers to list files, but P2P for downloading. (4) P2P challenges: NAT traversal (peers behind firewalls/routers), bandwidth asymmetry (download faster than upload), peer reliability (peers can disconnect), search/discovery (finding desired content), security/privacy. Different P2P protocols: DHT (Distributed Hash Table) like Kademlia for decentralized lookup, gossip protocols for information propagation, proof-of-work for distributed consensus (blockchain). P2P is increasingly important for: cryptocurrency (Bitcoin), decentralized storage (IPFS), content distribution (torrents), VoIP (Skype), applications demanding resilience and censorship resistance.

109. What is Socket Programming and what APIs are typically used?

  1. Option A: Programming model for network communication using socket objects with APIs like Berkeley sockets
  2. Option B: A method to encrypt data
  3. Option C: A routing algorithm
  4. Option D: Only applicable to servers
Show hint

Sockets are endpoints of network communication. How are they created and used programmatically?

Show answer

Answer: A. Programming model for network communication using socket objects with APIs like Berkeley sockets

Socket programming is the process of writing applications that communicate over networks using socket APIs. A socket is an endpoint of network communication - applications create sockets, bind them to addresses/ports, and send/receive data through them. APIs: (1) Berkeley sockets - original API developed in BSD Unix, now standard across Unix/Linux/Windows. Key functions: socket() creates socket, bind() associates socket with address/port, listen() marks socket as accepting connections (server), accept() accepts incoming connection, connect() initiates connection (client), send()/recv() exchange data on TCP, sendto()/recvfrom() for UDP, close() terminates socket. (2) Windows Sockets (Winsock) - Microsoft's implementation of Berkeley sockets for Windows, mostly compatible. (3) Modern language libraries: C/C++ use raw Berkeley sockets or wrapper libraries. Python sockets module provides high-level interface. Java provides Socket and ServerSocket classes. C# TcpClient, TcpListener. Go net package. (4) Socket families: AF_INET (IPv4), AF_INET6 (IPv6), AF_LOCAL/AF_UNIX (local interprocess communication). (5) Socket types: SOCK_STREAM (TCP, reliable ordered delivery), SOCK_DGRAM (UDP, unreliable). Example TCP server: socket() -> bind() -> listen() -> accept() in loop for each client -> send()/recv() -> close(). Example TCP client: socket() -> connect() -> send()/recv() -> close(). Socket programming allows building custom applications (not just HTTP, SMTP, etc.) communicating over networks. Most modern frameworks abstract socket details (web frameworks handle HTTP), but understanding sockets is important for systems programming, games, real-time applications, embedded systems. Asynchronous socket programming with multiplexing (select(), poll(), epoll()) handles multiple concurrent connections efficiently.

110. What is the concept of an Application Server and how does it differ from web servers?

  1. Option A: Application servers execute business logic; web servers serve static content
  2. Option B: They are identical
  3. Option C: Application servers are faster
  4. Option D: Web servers execute more complex logic
Show hint

Consider what processing is needed for different types of requests.

Show answer

Answer: A. Application servers execute business logic; web servers serve static content

Web servers and application servers have different roles in web application architecture: (1) Web servers (Apache, Nginx, IIS): Primarily serve static content (HTML, CSS, JavaScript, images, documents). Handle HTTP/HTTPS requests, process GET/POST, manage connections, serve files from disk. Lightweight, fast, efficient for static content. Limited processing - can run scripts (CGI, PHP) but not ideal for complex business logic. (2) Application servers (Tomcat, JBoss, Websphere, Node.js, Django, Flask): Execute dynamic application code (Java, Python, C#, Node.js, etc.), manage database connections, business logic, session management, transactions, security. Heavier, more resource-intensive than web servers. Can access databases, perform computations, generate dynamic responses. (3) Typical architecture: Client requests web server (port 80/443). Web server serves static files directly or forwards dynamic requests to application server (port 8080 or other). Application server executes code, returns response to web server, which forwards to client. This separation provides: Load balancing (multiple application servers behind one web server), security isolation, performance optimization (fast web server for static content). (4) Modern frameworks: Some frameworks (Node.js, Django) bundle web and application functionality. Frameworks increasingly handle both roles, simplifying deployment. (5) Examples: Classic setup: Apache web server + Tomcat application server for Java. WordPress: Apache/Nginx + PHP application server. Node.js: single process handles both web and application. (6) Responsibilities: Web server: connection management, static file serving, SSL termination, caching, load balancing. Application server: session management, transaction handling, database pooling, business logic execution, dynamic content generation. Understanding this distinction helps in designing scalable, maintainable architectures.

111. What are traffic analyzer tools (MRTG, PRTG, SNMP, Packet Tracer, Wireshark) used for?

  1. Option A: Monitoring, analyzing, and visualizing network traffic for troubleshooting and performance optimization
  2. Option B: Encrypting network traffic
  3. Option C: Increasing bandwidth
  4. Option D: Replacing routers
Show hint

These tools help understand what's happening on your network. What might you monitor?

Show answer

Answer: A. Monitoring, analyzing, and visualizing network traffic for troubleshooting and performance optimization

Traffic analyzers are essential network management tools: (1) SNMP (Simple Network Management Protocol) - framework for collecting information from network devices. Devices report metrics (CPU, memory, bandwidth, errors) to SNMP server. Managers query devices via SNMP requests. SNMP traps are unsolicited notifications from devices. Enables centralized monitoring of entire network infrastructure. Collects MIBs (Management Information Bases) - standardized sets of metrics. (2) MRTG (Multi Router Traffic Grapher) - monitoring tool specifically for traffic on network links. Uses SNMP to collect interface statistics (bytes in/out). Creates graphs showing traffic trends over time. Lightweight, designed for 24/7 monitoring. Visualizes link utilization, helping identify congestion. (3) PRTG (Paessler Router Traffic Grapher) - commercial successor to MRTG with more features. Monitors bandwidth, CPU, memory, disk, applications, websites. Creates detailed reports and alerts. Web-based interface for easy access. Supports notifications when thresholds exceeded. (4) Wireshark - packet sniffer and analyzer. Captures live traffic on network interfaces and displays packet-by-packet details. Shows all protocol layers: Ethernet frames, IP headers, TCP/UDP segments, application data. Incredibly detailed for troubleshooting. Can filter by protocol, IP address, port, etc. Can follow TCP streams. Analyzes captured .pcap files. Shows issues like retransmissions, out-of-order packets, protocol violations. (5) Packet Tracer - Cisco's network simulation tool for learning and testing network designs. Simulates routers, switches, hosts, links. Configure devices, simulate traffic, observe behavior. Great for studying network concepts and practicing configuration. (6) Uses: Troubleshooting (identify bottlenecks, packet loss, connection failures), capacity planning (understand current usage and predict future), security monitoring (detect unusual traffic patterns, intrusions), performance optimization (identify inefficient routing, congestion), SLA verification (confirm promised service levels). Modern networks often combine tools: SNMP for high-level monitoring, Wireshark for detailed packet analysis, PRTG/MRTG for trending. These tools are invaluable for network administrators.

112. Explain DHCP (Dynamic Host Configuration Protocol) and its role in network administration.

  1. Option A: DHCP automatically assigns IP addresses and network configuration to devices
  2. Option B: DHCP encrypts network traffic
  3. Option C: DHCP routes packets between networks
  4. Option D: DHCP manages DNS servers
Show hint

Without DHCP, network administrators would need to manually configure each device.

Show answer

Answer: A. DHCP automatically assigns IP addresses and network configuration to devices

DHCP (Dynamic Host Configuration Protocol) automates IP address assignment and network configuration, essential for network scalability: (1) DHCP process (DORA): Discovery - client broadcasts DHCP DISCOVER message seeking DHCP server. Offer - DHCP server responds with DHCP OFFER containing available IP address and configuration. Request - client broadcasts DHCP REQUEST accepting the offered address. Acknowledgment - server sends DHCP ACK confirming assignment. Client now has IP address, lease duration, gateway, DNS servers, other parameters. (2) Address lease: IP address is assigned for limited duration (24 hours typical). Client must renew before expiration. If not renewed, address returns to pool for reassignment. Prevents address depletion from devices that fail without releasing addresses. (3) Configuration parameters: IP address and subnet mask. Default gateway (router to exit network). DNS server addresses. NTP server, domain name, and other options via option field. (4) DHCP server considerations: DHCP server maintains pool of available addresses. Tracks assigned addresses and leases. Can exclude certain addresses for servers. Can configure address ranges for different device types. (5) DHCP relay: DHCP uses broadcast (limited to local segment). In multi-subnet networks, DHCP relay agent on each subnet forwards broadcasts to central DHCP server. (6) Static DHCP: DHCP server can be configured with MAC address to always assign same IP (useful for servers, printers). (7) Benefits: Eliminates manual configuration. Enables network mobility (devices get new addresses joining different networks). Simplifies administration (changes IP pool in DHCP, all devices automatically reconfigure). Prevents address conflicts (DHCP prevents duplicate assignments). (8) Limitations: Dependency on DHCP server (failure prevents new device connection). Initial configuration chicken-and-egg problem (device needs IP to contact DHCP server to get IP). Solved via link-local addresses (APIPA). Potential security - any DHCP server on network can respond (rogue DHCP attacks). (9) DHCP snooping: Switch feature preventing rogue DHCP servers by allowing trusted ports to send DHCP offers. (10) Comparison with static IP: Static IP needed for servers/infrastructure. DHCP for client devices. DHCP essential for large networks with frequent device changes.

113. What is SNMP (Simple Network Management Protocol) and what information can it collect from network devices?

  1. Option A: SNMP collects device statistics (CPU, memory, traffic, errors) for network monitoring and management
  2. Option B: SNMP encrypts network traffic
  3. Option C: SNMP configures routers
  4. Option D: SNMP is only for servers
Show hint

SNMP is a monitoring protocol. What metrics would you want to monitor on your network devices?

Show answer

Answer: A. SNMP collects device statistics (CPU, memory, traffic, errors) for network monitoring and management

SNMP (Simple Network Management Protocol) enables centralized monitoring and management of network devices: (1) Architecture: Manager (monitoring station) queries agents (software on managed devices). Agents respond with requested information. Agents can also send unsolicited traps (notifications of events). (2) MIB (Management Information Base): Hierarchical database of manageable objects. Each object has OID (Object Identifier) like 1.3.6.1.2.1.1.3.0 (system uptime). MIBs standardized for different device types. Example: IF-MIB for interface statistics. (3) SNMPv1 (original): Simple but limited. Plaintext community string (password). No authentication of responses. Vulnerable to spoofing and eavesdropping. Still widely used despite known vulnerabilities. (4) SNMPv2c: Improved with 64-bit counters (SNMPv1 limited to 32-bit). Bulk retrieval capability. Plaintext community string remains security issue. (5) SNMPv3: Adds security: User/password authentication. Encryption (DES/3DES) of messages. HMAC for integrity verification. Recommended for new deployments. (6) Operations: GET - retrieve single object value. GET-NEXT - retrieve next object (walk through tables). GET-BULK - retrieve many objects efficiently. SET - modify device configuration remotely. TRAP - unsolicited notification from agent. (7) Monitored objects: System: uptime, contact, description. Interfaces: bandwidth, speed, errors, discards, packets in/out. Routing: routing table, ARP table. TCP/UDP: connection counts, statistics. Host resources: CPU load, memory usage, running processes. (8) Example data collection: Check router interface traffic to detect congestion. Monitor server CPU/memory for capacity planning. Check for link errors indicating physical layer problems. Count TCP connections for security analysis. (9) SNMP polling: Manager sends GET requests periodically (every 5 minutes typical). Responses graphed for trends. Thresholds configured - alerts if CPU > 80%, interface down, errors > threshold. (10) Tools: MRTG/PRTG use SNMP for monitoring. Nagios, Zabbix, Prometheus collect SNMP data. Network device dashboards use SNMP. (11) Security issues: SNMPv1/v2c send plaintext community strings (easily captured). Writable community strings allow remote device configuration. SNMP can be used for DDoS amplification attacks. Recommendation: Use SNMPv3 with strong authentication or isolate SNMP traffic in management VLAN.

114. Which application layer protocol is used for sending and receiving emails?

NEC model set
  1. Option A: HTTP
  2. Option B: FTP
  3. Option C: SMTP
  4. Option D: POP
Show hint

SMTP is for sending. POP/IMAP are for receiving. This question asks about 'sending and receiving', but specifically look for sending.

Show answer

Answer: C. SMTP

SMTP (Simple Mail Transfer Protocol) is the application layer protocol used for sending emails. Combined with POP3 or IMAP for receiving: (1) SMTP - Sends emails from client to mail server and between mail servers (Port 25 for relay, 587 for clients), (2) POP3 (Post Office Protocol) - Retrieves emails from server (Port 110), (3) IMAP (Internet Message Access Protocol) - Advanced retrieval with server-side storage (Port 143). Complete email communication: (1) User writes email in mail client, (2) SMTP sends email to sender's mail server, (3) SMTP relays between mail servers, (4) SMTP delivers to recipient's mail server, (5) Recipient uses POP3 or IMAP to retrieve. SMTP features: (1) Text-based protocol (like HTTP), (2) Uses TCP port 25, 587, or 465 (secure), (3) Commands like MAIL FROM, RCPT TO, DATA, (4) Can be secured with STARTTLS or SSL/TLS. Other email protocols: (1) HTTP - Web access to email (Gmail, Outlook web), (2) FTP - File transfer (not email), (3) LDAP - Directory services for email addresses. Modern variations: (1) OAuth for authentication, (2) DKIM/SPF for spam prevention, (3) SMTPS for encrypted transmission. SMTP remains essential for email delivery.

115. Port number 25 is associated with which protocol?

NEC model set
  1. Option A: a) HTTP
  2. Option B: b) FTP
  3. Option C: c) SMTP
  4. Option D: d) Telnet
Show hint

Port 25 is the standard email sending port. Which protocol uses it?

Show answer

Answer: C. c) SMTP

Port 25 is associated with SMTP (Simple Mail Transfer Protocol), used for sending emails. HTTP uses port 80, HTTPS uses 443, FTP uses ports 20-21, Telnet uses port 23. SMTP port 25 is the default for mail servers to relay messages. Port 587 is also used for SMTP with TLS encryption. Understanding common port numbers is essential for network administration and security.

116. What does FTP stand for?

NEC model set
  1. Option A: a) File Transfer Protocol
  2. Option B: b) Fast Transfer Process
  3. Option C: c) File Transmission Program
  4. Option D: d) File Transfer Program
Show hint

FTP is a protocol for transferring files between computers. What's its full form?

Show answer

Answer: A. a) File Transfer Protocol

FTP stands for File Transfer Protocol. It's a standard protocol for transferring files between computers over a network. FTP uses two connections: control connection (port 21) for commands and data connection (port 20) for actual file transfer. FTP has largely been replaced by SFTP (Secure FTP) over SSH due to security concerns. FTP transmits credentials in plain text, making it vulnerable to interception.

117. Which protocol is used for secure web browsing?

  1. Option A: HTTP
  2. Option B: HTTPS
  3. Option C: FTP
  4. Option D: SMTP
Show answer

Answer: B. HTTPS

118. DNS primarily translates:

  1. Option A: IP addresses to MAC addresses
  2. Option B: Domain names to IP addresses
  3. Option C: URLs to domain names
  4. Option D: MAC addresses to IP addresses
Show answer

Answer: B. Domain names to IP addresses

119. The protocol used for transferring files over the internet is:

  1. Option A: HTTP
  2. Option B: SMTP
  3. Option C: FTP
  4. Option D: SNMP
Show answer

Answer: C. FTP

120. Which tool is used for network traffic analysis?

  1. Option A: Wireshark
  2. Option B: PuTTY
  3. Option C: WinSCP
  4. Option D: DNS
Show answer

Answer: A. Wireshark

121. Which protocol is used for sending emails?

  1. Option A: POP3
  2. Option B: IMAP
  3. Option C: SMTP
  4. Option D: HTTP
Show answer

Answer: C. SMTP

122. Which of the following is a P2P application?

  1. Option A: Email
  2. Option B: Web browsing
  3. Option C: BitTorrent
  4. Option D: FTP
Show answer

Answer: C. BitTorrent

123. Socket programming is primarily used for:

  1. Option A: Network monitoring
  2. Option B: Network security
  3. Option C: Network management
  4. Option D: Network communication
Show answer

Answer: D. Network communication

124. The port number for HTTP is:

  1. Option A: 21
  2. Option B: 25
  3. Option C: 80
  4. Option D: 110
Show answer

Answer: C. 80

125. Which protocol is used for retrieving emails from a mail server?

  1. Option A: SMTP
  2. Option B: HTTP
  3. Option C: POP3
  4. Option D: FTP
Show answer

Answer: C. POP3

126. SNMP is used for:

  1. Option A: Network management
  2. Option B: Email transfer
  3. Option C: File transfer
  4. Option D: Web browsing
Show answer

Answer: A. Network management

127. The port number for HTTPS is:

  1. Option A: 80
  2. Option B: 443
  3. Option C: 8080
  4. Option D: 21
Show answer

Answer: B. 443

5.6 Network security

42 questions · ACtE0506

128. Which NOT physical layer vulnerability?

  1. Option A: Physical damage
  2. Option B: Keystroke logging
  3. Option C: Physical theft
  4. Option D: Unauthorized access
Show hint

Software attack, not physical.

Show answer

Answer: B. Keystroke logging

Keystroke logging is software vulnerability, not physical layer vulnerability.

129. What is access control mechanism?

  1. Option A: Firewall
  2. Option B: IDS
  3. Option C: Password
  4. Option D: Encryption
Show hint

Blocks unauthorized traffic.

Show answer

Answer: A. Firewall

Firewall is primary access control mechanism filtering network traffic.

130. Which cryptography principle prevents replay?

  1. Option A: Confidentiality
  2. Option B: Integrity
  3. Option C: Availability
  4. Option D: Non-repudiation
Show hint

Proves origin.

Show answer

Answer: D. Non-repudiation

Non-repudiation ensures sender can't deny sending message.

131. What prevents DoS attacks?

  1. Option A: Packet filtering
  2. Option B: Traffic shaping
  3. Option C: Port scanning
  4. Option D: MAC filtering
Show hint

Limits flood traffic.

Show answer

Answer: B. Traffic shaping

Traffic shaping limits rates preventing denial of service.

132. What is IPSec tunnel mode?

  1. Option A: Privacy, integrity, authenticity
  2. Option B: Fast transfer
  3. Option C: Encryption only
  4. Option D: Compression
Show hint

Full protection.

Show answer

Answer: A. Privacy, integrity, authenticity

IPSec tunnel mode provides privacy, integrity, and authenticity.

133. What are the main types of Computer Security threats and attacks?

  1. Option A: Malware, social engineering, network attacks (DoS, MITM), eavesdropping, injection attacks
  2. Option B: Only viruses threaten security
  3. Option C: Security threats are theoretical
  4. Option D: All attacks require physical access
Show hint

Consider different ways attackers compromise systems.

Show answer

Answer: A. Malware, social engineering, network attacks (DoS, MITM), eavesdropping, injection attacks

Computer security threats are diverse and evolving. Major types: (1) Malware (malicious software): Viruses - self-replicating, require user action, infect files. Worms - self-replicating, spread without user action, exploit vulnerabilities. Trojans - appear legitimate, hide malicious payload. Ransomware - encrypts files, demands payment for decryption. Spyware/Adware - monitor/display unwanted content. Rootkits - hide malicious code from detection. (2) Social engineering - manipulating people into disclosing information or compromising security: Phishing - fake emails/websites mimicking legitimate services. Spear phishing - targeted phishing with personalized information. Pretexting - creating fictional scenarios to extract information. Baiting - leaving infected USB drives in public places. Tailgating - unauthorized physical access following legitimate users. (3) Network attacks: DoS (Denial of Service) - overwhelming target with traffic/requests making it unavailable. DDoS - distributed DoS from multiple sources. MITM (Man-in-the-Middle) - intercepting communication between parties. Eavesdropping - listening to unencrypted communications. DNS poisoning - redirecting to malicious sites. (4) Injection attacks: SQL injection - inserting malicious SQL in input fields. XSS (Cross-Site Scripting) - injecting scripts into web pages. Command injection - executing arbitrary commands. (5) Weak passwords/authentication - password cracking, brute force attacks, credential reuse. (6) Unpatched vulnerabilities - attackers exploit known but unfixed security holes. (7) Insecure configurations - default passwords, unnecessary services enabled. (8) Insider threats - employees or contractors with malicious intent. (9) Advanced threats: Zero-day exploits - attacks using unknown vulnerabilities. APT (Advanced Persistent Threat) - sophisticated, targeted attacks. Botnets - networks of compromised computers. Defending requires: Updates/patches, strong authentication, encryption, firewalls, IDS/IPS, security awareness training, backups.

134. Explain the basic principles of cryptography and symmetric vs. asymmetric encryption.

  1. Option A: Cryptography ensures confidentiality; symmetric uses same key for both parties; asymmetric uses public-private key pair
  2. Option B: All encryption uses the same method
  3. Option C: Cryptography only protects emails
  4. Option D: Asymmetric is always faster
Show hint

Consider how keys are shared and used differently.

Show answer

Answer: A. Cryptography ensures confidentiality; symmetric uses same key for both parties; asymmetric uses public-private key pair

Cryptography is the science of encoding information to prevent unauthorized access. Principles: (1) Confidentiality - preventing eavesdropping, ensuring only intended recipients read messages. (2) Integrity - detecting tampering, ensuring messages haven't been altered. (3) Authentication - verifying sender identity. (4) Non-repudiation - sender cannot deny sending message. Symmetric encryption: Uses single shared secret key for both encryption (plaintext + key -> ciphertext) and decryption (ciphertext + key -> plaintext). Examples: DES (56-bit, obsolete), AES (128/192/256-bit, modern standard), RC4, Blowfish. Advantages: Fast, suitable for bulk data encryption, small ciphertext. Disadvantages: Key must be securely shared with all parties, scaling to many parties is difficult, challenge is secure key distribution - how do parties exchange the key over untrusted networks? Used for: Encrypting files, database encryption, VPN tunnels, bulk communication. Asymmetric encryption: Uses public-private key pair. Public key encrypts, private key decrypts (or vice versa). Private key is kept secret, public key is shared openly. Examples: RSA, ECC (Elliptic Curve Cryptography), DSA. Advantages: Solves key distribution problem - no need to share secret keys. Enables digital signatures. Easy to scale to many parties. Disadvantages: Slower than symmetric (cryptographic overhead), larger ciphertext. Used for: Key exchange, digital signatures, authentication, small data encryption. Hybrid approach (used in practice): Asymmetric encryption for secure key exchange (sender encrypts symmetric key with recipient's public key), then symmetric encryption for actual data (much faster). TLS uses this approach. Strength depends on key size: RSA 2048-bit ≈ AES 112-bit security. Modern cryptography requires: Strong algorithms (AES, RSA-2048+), proper key management, random key generation, regular updates as computing power increases. Cryptographic protocols like TLS/SSL, IPsec, PGP, Kerberos combine these concepts.

135. Explain RSA algorithm and its role in public-key cryptography.

  1. Option A: RSA uses prime factorization difficulty for encryption/decryption with public-private key pair
  2. Option B: RSA uses symmetric keys
  3. Option C: RSA is only for signatures
  4. Option D: RSA is obsolete
Show hint

RSA security relies on the mathematical difficulty of factoring large numbers.

Show answer

Answer: A. RSA uses prime factorization difficulty for encryption/decryption with public-private key pair

RSA (Rivest-Shamir-Adleman) is the most widely used public-key cryptography algorithm. How RSA works: (1) Key generation: Choose two large prime numbers p and q (each 1024+ bits). Compute n = p × q (this is the modulus, 2048+ bits for security). Compute φ(n) = (p-1) × (q-1) (Euler's totient function). Choose public exponent e (commonly 65537) where gcd(e, φ(n)) = 1. Compute private exponent d such that (e × d) mod φ(n) = 1. Public key is (e, n), private key is (d, n). (2) Encryption: To send message M to someone with public key (e, n): C = M^e mod n (C is ciphertext). (3) Decryption: Recipient with private key (d, n) computes: M = C^d mod n. (4) Security: Relies on fact that factoring n back into p and q is computationally hard with current algorithms. If attacker could factor n, they could compute d from e and n, compromising private key. Security grows with key size: 2048-bit is current minimum recommendation. 4096-bit for long-term security. (5) Digital signatures: RSA can also sign messages: Sender signs with private key (S = M^d mod n), receiver verifies with public key (M = S^e mod n). (6) Hybrid use: RSA is slow for large data, so used for encrypting small symmetric keys. Symmetric key then encrypts bulk data. (7) Attacks: Padding attacks exploit patterns. Modern RSA uses PKCS#1 v2.0 (OAEP) padding to prevent these. (8) Key management: Public key can be freely distributed. Private key must be protected (stored securely, never transmitted). Certificate authorities (CAs) verify and sign public keys. (9) Limitations: Slow compared to symmetric, key generation is computationally intensive. RSA remains cornerstone of public-key infrastructure (PKI), though elliptic curve cryptography (ECC) offers equivalent security with smaller keys.

136. What are Digital Signatures and how do they ensure authentication and non-repudiation?

  1. Option A: Digital signatures use private key to create verifiable proof of authorship, preventing repudiation
  2. Option B: Digital signatures encrypt messages
  3. Option C: Digital signatures are only for legal documents
  4. Option D: Digital signatures don't provide authentication
Show hint

How can a recipient prove that only the sender could have created a message?

Show answer

Answer: A. Digital signatures use private key to create verifiable proof of authorship, preventing repudiation

Digital signatures are cryptographic mechanisms providing authentication, integrity, and non-repudiation. How they work: (1) Signing process: Sender creates hash of message (fingerprint that changes if message altered). Hash is encrypted with sender's private key - this is the signature. Message and signature are sent to recipient. (2) Verification process: Recipient decrypts signature using sender's public key, recovering the hash. Recipient creates hash of received message. If hashes match, signature is valid - message came from holder of private key and wasn't altered. (3) Why it works: Only holder of private key can create valid signatures. Public key decryption is verification - if signature was created with private key, public key decryption works. Hash function properties: small change in message produces completely different hash (prevents modification). (4) Authentication - verifies sender's identity because only sender has private key. Recipient trusts sender's public key was genuinely the sender's (via certificate from trusted CA). (5) Non-repudiation - sender cannot deny creating signature because only they have private key. In legal context, digital signature proves message definitely came from claimed sender. (6) Integrity - hash verification detects any tampering. Even one bit change causes hash mismatch. (7) Algorithms: RSA (public-key operation), DSA (Digital Signature Algorithm), ECDSA (Elliptic Curve DSA). (8) Hash functions: MD5 (obsolete), SHA-1 (weak), SHA-256 (secure), SHA-3. (9) Certificates: Public keys are distributed via digital certificates - documents signed by trusted CAs attesting to key ownership. Certificate includes identity (name, email, organization), public key, CA signature, validity period. (10) Applications: Email (S/MIME, PGP), code signing (software distribution), document signing (PDFs), software updates, cryptocurrencies (blockchain). Digital signatures are essential for trust in digital communications and are legally recognized in many jurisdictions.

137. Explain how PGP (Pretty Good Privacy) secures email communications.

  1. Option A: PGP encrypts/signs emails using combination of symmetric and asymmetric cryptography
  2. Option B: PGP is only for government agencies
  3. Option C: PGP uses only symmetric encryption
  4. Option D: PGP encrypts transmission only, not content
Show hint

PGP is a complete email security solution. How does it use different encryption types?

Show answer

Answer: A. PGP encrypts/signs emails using combination of symmetric and asymmetric cryptography

PGP (Pretty Good Privacy) is a comprehensive email security system providing encryption and authentication for email messages. It uses a hybrid approach combining strengths of different cryptographic techniques: (1) Email encryption process: Sender creates symmetric session key (random key for one-time use). Content is encrypted with session key using symmetric encryption (fast, suitable for bulk data). Session key is encrypted with recipient's public key using asymmetric encryption. Both encrypted content and encrypted session key are sent. Recipient decrypts session key with their private key, then uses it to decrypt content. (2) Email signing process: Sender creates hash of message, encrypts hash with sender's private key (creates signature), sends message with signature. Recipient decrypts signature with sender's public key, creates hash of received message, compares hashes to verify authenticity. (3) Key management: Uses web of trust instead of centralized CAs. Users sign each other's keys, creating trust relationships. Key server networks allow public key distribution. (4) Features: Encryption - confidentiality of email content. Digital signatures - authentication and non-repudiation of sender. Compression - data compressed before encryption for efficiency. Armor - converts binary data to ASCII text for email compatibility. (5) File format: Message is divided into encrypted blocks. Each block contains encrypted symmetric key and encrypted content. Recipients use private key to decrypt symmetric key, then decrypt content. (6) Versions: PGP (commercial/proprietary), GPG (GNU Privacy Guard - open source implementation of OpenPGP standard). (7) Usage: Encrypts entire email body, filename (if attaching files), but not email headers (to, from, subject are visible - limitation of email system, not PGP). (8) Challenges: Key management complexity (users must manage private keys, obtain public keys), low adoption (most people don't use PGP), integration with email clients varies. (9) Limitations: Only secures email content, not metadata. Vulnerable if private key is compromised. Requires trust relationships for key verification. (10) Modern alternatives: S/MIME uses certificate-based approach (similar but relies on CAs). TLS secures email transmission (not content). End-to-end encrypted email services (ProtonMail, Tutanota). PGP remains important for high-security communications despite adoption challenges.

138. Explain SSL/TLS (Secure Sockets Layer/Transport Layer Security) and its role in securing TCP connections.

  1. Option A: SSL/TLS encrypts TCP connections using certificates, providing confidentiality and server authentication
  2. Option B: SSL/TLS only works with HTTP
  3. Option C: SSL/TLS prevents packet loss
  4. Option D: SSL/TLS is only for government communications
Show hint

TLS sits between application and transport layers, securing the connection.

Show answer

Answer: A. SSL/TLS encrypts TCP connections using certificates, providing confidentiality and server authentication

SSL (Secure Sockets Layer) and its successor TLS (Transport Layer Security) are cryptographic protocols that secure communication over TCP connections. TLS operates between Application and Transport layers. How it works: (1) Handshake process (occurs before data transfer): Client sends ClientHello with TLS version, supported cipher suites, random number. Server responds with ServerHello selecting cipher suite, random number, sends certificate containing public key. Client verifies certificate (valid, not expired, trusted issuer, domain matches). Both compute shared secret using key exchange algorithm (typically Diffie-Hellman): Client generates secret, encrypts with server's public key, sends. Server decrypts with private key. Both derive encryption/authentication keys from shared secret and their random numbers. Key derivation ensures keys are fresh for each session. Client/server exchange Finished messages confirming handshake success. (2) Data transfer: All subsequent data encrypted with negotiated cipher (AES-GCM, ChaCha20-Poly1305, etc.). Symmetric encryption is fast, provides confidentiality. MAC (Message Authentication Code) detects tampering. (3) Certificates: Server sends certificate proving identity. Certificate contains public key, subject name, issuer (CA) name, validity dates, and CA's digital signature. Client verifies: Is certificate signed by trusted CA? Has it expired? Does domain match request? This prevents MITM attacks - attacker cannot use own certificate without creating forgery (unless they compromise CA). (4) Cipher suites: Combination of algorithms for key exchange, encryption, and integrity. Example: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 uses ECDHE for key exchange, RSA for authentication, AES-256-GCM for encryption/integrity. (5) Versions: SSL 2.0 (deprecated), SSL 3.0 (deprecated), TLS 1.0 (deprecated), TLS 1.1 (deprecated), TLS 1.2 (widely used), TLS 1.3 (modern, faster). TLS 1.3 removed unnecessary complexity, reduced handshake from 2 round trips to 1, added 0-RTT capability. (6) Uses: HTTPS (HTTP over TLS, port 443), email (IMAPS, POP3S), VPN (OpenVPN, IPSec), messaging apps, payment systems, APIs. (7) Benefits: Confidentiality - encryption prevents eavesdropping. Authentication - certificates verify server identity. Integrity - MACs detect tampering. Forward secrecy - past sessions remain secure even if private key compromised (with perfect forward secrecy like ECDHE). (8) Limitations: Certificate infrastructure complexity, CA trust issues, performance overhead (mitigation with hardware acceleration, session resumption). (9) Modern considerations: Certificate transparency (logs verify CAs issue proper certificates), OCSP (Online Certificate Status Protocol) checks revocation, pinning (verify specific certificates/keys). TLS is essential for Internet security - most web traffic is HTTPS.

139. What is IPsec (Internet Protocol Security) and how does it protect network layer communications?

  1. Option A: IPsec encrypts and authenticates IP packets, providing VPN and network-level security
  2. Option B: IPsec only works with IPv6
  3. Option C: IPsec prevents routing attacks only
  4. Option D: IPsec is slower than TLS
Show hint

IPsec operates at the Network layer (Layer 3), securing IP packets themselves.

Show answer

Answer: A. IPsec encrypts and authenticates IP packets, providing VPN and network-level security

IPsec (Internet Protocol Security) is a suite of protocols providing encryption and authentication at the Network layer (Layer 3). Unlike TLS (which protects individual connections), IPsec protects all traffic between two endpoints. Components: (1) AH (Authentication Header) - provides authentication and integrity checking. Receiver computes hash of packet, compares with sender's hash to verify packet not tampered. Does not encrypt. (2) ESP (Encapsulating Security Payload) - provides encryption and optional authentication. Encrypts payload (and optionally header), adds authentication. More comprehensive protection than AH. Typically preferred over AH alone. (3) IKE (Internet Key Exchange) - negotiates and establishes security associations (SAs) - agreements on encryption algorithm, keys, and authentication method. IKEv1 and IKEv2 available. (4) Modes: Transport mode - encrypts/authenticates only payload, leaving headers intact. Tunnel mode - encapsulates entire IP packet inside new IP packet. Tunnel mode is used for VPNs. (5) SA (Security Association) - unidirectional security policy between two endpoints specifying: encryption algorithm (DES, 3DES, AES), authentication algorithm (HMAC-MD5, HMAC-SHA), key material, SA lifetime. Both direction require separate SAs (inbound and outbound). (6) VPN use: Organizations use IPsec to create secure tunnels between offices over Internet. Branch office router establishes IPsec tunnel with headquarters router. All traffic between offices encrypted/authenticated through tunnel. Transparent to applications. (7) Benefits: Network-layer protection - protects all traffic (all applications, all protocols) automatically. Firewall-friendly - can be deployed without application changes. Transparent to applications. Suitable for site-to-site VPNs. (8) Deployment: Gateway-to-gateway (office-to-office), host-to-gateway (remote user to office), host-to-host (between computers). (9) Limitations: Complex configuration, key management overhead, performance impact due to encryption, not suitable for selective per-connection protection (operates at packet level, not connection level like TLS). (10) Comparison with TLS: TLS is application-level (protects specific connections), simpler deployment, per-application. IPsec is network-level (protects all traffic), more comprehensive, transparent. Both have roles: TLS for APIs/web/email/applications, IPsec for VPNs/network security. Modern VPNs increasingly use protocols like WireGuard (simpler, faster) instead of IPsec.

140. What is VPN (Virtual Private Network) and what security benefits does it provide?

  1. Option A: VPN creates encrypted tunnel over public network, ensuring confidentiality and making location appear different
  2. Option B: VPN guarantees immunity from all attacks
  3. Option C: VPN only works on local networks
  4. Option D: VPN encrypts passwords only
Show hint

VPN creates a virtual private network. What benefits come from tunneling over public networks?

Show answer

Answer: A. VPN creates encrypted tunnel over public network, ensuring confidentiality and making location appear different

VPN (Virtual Private Network) is technology creating secure, encrypted connection through untrusted networks (typically the Internet). Types: (1) Site-to-site VPN - connects entire office networks. Remote office router connects to headquarters router via VPN tunnel. All traffic between offices goes through encrypted tunnel. Transparent to users. Uses: Connecting branch offices, disaster recovery, cloud backup. Typically based on IPsec or MPLS. (2) Remote access VPN - allows individual users to securely connect to office network from anywhere. User runs VPN client, authenticates, receives IP address on office network. All traffic routed through encrypted tunnel to office. Uses: Telecommuting, traveling employees, contractors accessing corporate network. (3) VPN protocols: IPsec (network layer), L2TP (layer 2), PPTP (older, weak security), OpenVPN (open source, flexible), WireGuard (modern, simple, fast), IKEv2 (good for mobile). Benefits: (1) Confidentiality - encryption prevents eavesdropping on public networks. Traffic appears encrypted to ISPs, networks, snoopers. (2) Authentication - VPN authenticates users/devices before granting access. (3) Integrity - ensures traffic not modified in transit. (4) Privacy - ISP cannot see what websites you visit (destination appears as VPN server). IP address appears as VPN server's, not true location. (5) Security on public WiFi - protects traffic on untrusted networks like airport WiFi. (6) Bypassing geographic restrictions - appearing from different location enables access to geo-blocked content. Issues/misconceptions: (1) VPN does not provide complete anonymity - VPN provider can log traffic, knows your true identity from payment. (2) VPN does not protect against malware - software still gets infected. (3) VPN does not speed up Internet - typically adds latency due to tunneling. (4) VPN does not make you completely anonymous - websites can still track you via cookies, browser fingerprinting. (5) Trust matters - VPN provider has access to all traffic; choose trustworthy provider with no-log policy. Uses: Privacy protection (hiding from ISP/government), accessing corporate resources remotely, bypassing censorship (with caution - many countries restrict VPNs), security on public WiFi. Concerns: VPN is critical for privacy but should be combined with other security practices (strong passwords, 2FA, anti-malware).

141. Explain WEP (Wired Equivalent Privacy) and why it was replaced.

  1. Option A: WEP is insecure wireless encryption standard; flawed IV handling and key size enabled practical attacks
  2. Option B: WEP is still secure
  3. Option C: WEP prevented all wireless attacks
  4. Option D: WEP worked differently at network layer
Show hint

WEP was designed for wireless LANs but had serious security flaws. What were they?

Show answer

Answer: A. WEP is insecure wireless encryption standard; flawed IV handling and key size enabled practical attacks

WEP (Wired Equivalent Privacy) was the original security standard for IEEE 802.11 wireless networks, intended to provide equivalent security to wired networks. Unfortunately, it had critical cryptographic flaws: (1) Architecture: Uses 40-bit or 104-bit (weak), RC4 stream cipher, 24-bit initialization vector (IV). Key + IV passed to RC4 to generate keystream, which XORs with plaintext to create ciphertext. Receiver uses same key + IV to decrypt. (2) IV weaknesses: (a) IV space too small - with 24-bit IV, only 2^24 = 16 million possible IVs. In typical network, IVs repeat within hours, allowing IV collisions. (b) IV chosen predictably - many implementations increment IV sequentially. (c) IV transmitted unencrypted in packet header. (3) Cryptographic attacks: (a) IV collision allows attacker to detect pattern: if same IV used with same key, XOR of two ciphertexts reveals information about plaintexts. (b) RC4 biases - keystream not perfectly random; statistical biases enable plaintext recovery. (c) FMS attack - Fluhrer, Mantin, and Shamir discovered practical method to recover key. (d) Klein's attack - more efficient key recovery. (4) Key recovery: Attacker captures traffic, collects ciphertexts with duplicate IVs, uses biases in RC4 keystream to recover key. Modern attacks recover 104-bit key in minutes from modest traffic. (5) Authentication weakness: CRC-32 used for integrity check is not cryptographically secure - attacker can flip bits and adjust checksum without detection. (6) Replacement: WPA (Wi-Fi Protected Access) improved security but retained some RC4. WPA2 (IEEE 802.11i) replaced WEP with CCMP (Counter Mode with CBC-MAC using AES), much stronger. WPA3 adds further improvements. (7) Lesson: WEP shows importance of cryptographic rigor. Design by non-experts, weak algorithms, poor IV handling created systematic failure. Security through obscurity (not publishing algorithm) delayed discovery. All WEP networks compromised. Modern wireless still encounters WEP on legacy equipment - should avoid. WEP networks provide false sense of security.

142. What is a Firewall and what filtering techniques does it use?

  1. Option A: Firewall controls traffic between networks using packet filtering, stateful inspection, or proxy methods
  2. Option B: Firewalls prevent all network attacks
  3. Option C: Firewalls only work at physical layer
  4. Option D: Firewalls eliminate need for other security
Show hint

Firewalls are the first line of defense at network boundary. How do they decide what traffic to allow?

Show answer

Answer: A. Firewall controls traffic between networks using packet filtering, stateful inspection, or proxy methods

Firewall is a network security device controlling incoming/outgoing traffic based on security policies. Types: (1) Packet-filtering firewalls - examines individual packets, makes allow/deny decision based on rules. Rules check: source IP, destination IP, protocol (TCP/UDP), source port, destination port, packet flags. Stateless - each packet examined independently without considering previous packets or connection context. Advantages: simple, fast, low overhead. Disadvantages: cannot detect advanced attacks, vulnerable to IP spoofing, rules can be complex and conflicting. Example rule: 'Allow TCP port 80 (HTTP) from any source to 192.168.1.100'. (2) Stateful firewalls - tracks connection state (established, listening, closing). Remembers outgoing connections and automatically allows return traffic. Examines packet in context of previous packets. Much more intelligent: blocks unsolicited inbound traffic automatically, prevents certain DoS attacks, enables better rule design. Example: allowing return traffic from server to client without explicit rule because outgoing request was allowed. (3) Proxy firewalls - applications connect through proxy instead of directly. Proxy makes request on behalf of client, receives response, forwards to client. Acts as intermediary for all traffic. Deep inspection possible (can examine application layer). Types: web proxy (HTTP/HTTPS), SOCKS proxy (general-purpose), circuit-level proxy. Example: organization's employees access Internet through proxy; proxy monitors content, enforces policies, caches responses. (4) Next-Generation Firewalls (NGFW) - combine packet filtering, stateful inspection, proxy functions plus: DPI (Deep Packet Inspection) - examines payload for malware/intrusions. Application-aware - understands application protocols (Facebook, YouTube, etc.), enables policy enforcement at application level. IDS/IPS capabilities - detects/prevents intrusions. (5) Rules and policies: Default-deny (block everything except explicitly allowed) vs. default-allow (allow everything except explicitly blocked). Default-deny is more secure but more work to maintain. Rules processed in order; first matching rule applies. Rules should be minimal - only allow necessary traffic. (6) Rule examples: 'Allow TCP port 443 (HTTPS) from 0.0.0.0/0 (anywhere) to 192.168.1.100 (web server)' - allows external HTTPS access. 'Allow TCP port 22 (SSH) from 10.0.0.0/8 (internal) to 192.168.1.50 (admin server)' - allows internal SSH access. 'Deny TCP port 445 (SMB) from anywhere to anywhere' - blocks Windows file sharing from external networks. (7) Limitations: Firewalls cannot protect against threats originating inside network. Cannot stop encrypted malware/exploits. Cannot detect application logic flaws. Encrypted traffic appears opaque. (8) Placement: Perimeter firewalls protect network boundary (external-internal). Host-based firewalls on individual computers. Both layers recommended (defense in depth). Types of access control: ACLs (Access Control Lists) - traditional rules on routers. Stateful inspection - connection tracking. Proxy inspection - application layer. Modern firewalls combine all approaches.

143. What is a Proxy Server and what security/privacy benefits does it provide?

  1. Option A: Proxy server acts as intermediary between clients and servers, hiding IP addresses and controlling access
  2. Option B: Proxy servers increase bandwidth
  3. Option C: Proxy servers encrypt all traffic automatically
  4. Option D: Proxy servers are only for web traffic
Show hint

Proxy means 'agent' or 'representative'. How does a proxy represent clients?

Show answer

Answer: A. Proxy server acts as intermediary between clients and servers, hiding IP addresses and controlling access

Proxy servers are intermediaries between clients and servers providing multiple benefits: (1) Web proxy (HTTP/HTTPS): Client connects to proxy instead of web server. Proxy fetches content from web server. Returns content to client. Benefits: (a) IP address hiding - web server sees proxy's IP, not client's true IP. (b) Caching - popular content cached, reducing bandwidth and latency for repeated access. (c) Access control - organization controls what sites employees visit. (d) Content filtering - blocks inappropriate/dangerous sites. (e) Data anonymity - hiding true IP prevents tracking. (f) Malware protection - proxy can scan downloaded content. (2) Reverse proxy: Sits in front of web servers. Clients connect to reverse proxy. Reverse proxy forwards to actual servers. Benefits: (a) Load balancing - distributes requests across multiple servers. (b) Compression - reverse proxy compresses responses before sending to clients. (c) SSL offloading - proxy handles encryption/decryption, reducing server load. (d) Security - hides server details from outside world. (e) Caching - improves response times. (3) SOCKS proxy: Generic proxy for any protocol (not just HTTP). TCP and UDP. Applications must be SOCKS-aware. (4) Transparent proxy: Intercepts traffic without requiring client configuration. ISPs use transparent proxies. Clients don't know proxy exists. (5) Proxy in security: Man-in-the-Middle (MITM) on purpose. Deep packet inspection (DPI) examines content. Stops malware downloads. Enforces security policies. (6) Limitations: Proxy knows everything about traffic (privacy concern). Single point of failure (if proxy down, no connection). Performance impact (latency added). HTTPS proxying requires certificate installation. P2P applications may bypass proxy. (7) Proxy chain: Multiple proxies in sequence. Client → Proxy 1 → Proxy 2 → Web Server. Anonymity improves with multiple proxies (Tor network). But latency increases. (8) Home proxy vs. organizational: Home users might use anonymizing proxy for privacy. Organizations use proxy for access control and security. (9) Tools: Squid (open source proxy), Tinyproxy (lightweight), nginx (can act as proxy), Charles (debugging proxy for developers). (10) Privacy considerations: Using proxy doesn't prevent actual anonymity if proxy logs traffic. Many free proxies monetize data. Paid VPNs with no-log policy more trustworthy. HTTPS provides end-to-end encryption regardless of proxy.

144. What is a BGP (Border Gateway Protocol) Hijack and how could it be prevented?

  1. Option A: BGP hijack is when attacker announces false IP prefixes routing traffic to attacker; prevented with RPKI/BGPsec
  2. Option B: BGP hijack only affects small networks
  3. Option C: All BGP hijacks are government attacks
  4. Option D: BGP hijack cannot be prevented
Show hint

BGP relies on trust between routers. What happens if a router claims to own IP addresses it doesn't?

Show answer

Answer: A. BGP hijack is when attacker announces false IP prefixes routing traffic to attacker; prevented with RPKI/BGPsec

BGP hijacking is serious routing attack exploiting BGP's trust model: (1) BGP basics recap: BGP is Internet's routing protocol. Each AS (Autonomous System) announces IP prefixes it 'owns'. Routers believe these announcements. Packets routed to announced origin. (2) Hijack mechanism: Attacker operates AS or compromises AS. Announces IP prefix claiming to own it. Other ASes believe announcement. Route traffic through attacker's AS. Attacker can intercept, modify, or discard traffic. (3) Real-world example: 2008 Pakistan YouTube hijack - Pakistan Telecom announced YouTube prefix, hijacking traffic intended for YouTube. Users worldwide couldn't access YouTube. (4) Types of hijacks: (a) Prefix hijack - announce entire IP block. (b) Sub-prefix hijack - announce smaller block within legitimate block (more specific route preferred). (c) Path hijack - claim shorter path to legitimate prefix. (5) Impact: Traffic interception (MITM attacks). Traffic dropping (DoS). Data modification. Eavesdropping. BGP hijack affects large-scale traffic, not just one connection. (6) Prevention methods: (a) RPKI (Resource Public Key Infrastructure) - Certification Authority signs route origins. ASes can verify route announcements. Routers validate signatures before accepting routes. Deployment is improving but adoption still low. (b) BGPsec - cryptographic path validation. Prevents route path forgery. More secure than RPKI but complex. (c) ROA (Route Origin Authorization) - AS publishes which prefixes it originates. RPKI validates against ROA. (d) Monitoring - detecting unusual announcements (suddenly appearing routes, suspicious ASes). (e) Route filtering - filtering obvious invalid routes (private IP ranges, never-routable space). (f) ASPA (AS Path Authentication) - validates entire path not just origin. (7) Current state: RPKI adoption increasing but still < 50% of routes signed. BGPsec rarely deployed due to complexity. Internet vulnerable to hijacking. (8) Detection: RPKI-invalid routes could be filtered. Monitoring services watch for suspicious announcements. Large providers implement filters. (9) Historical incidents: AS7007 incident (2010) - accidentally announced entire Internet. Pakistan YouTube (2008). Google DNS (2010). AWS (2020). Many undiscovered incidents suspected. (10) Future: RPKI deployment essential. BGPsec eventual standard. Path validation becoming requirement. ASPA adds another layer.

145. What is AES (Advanced Encryption Standard) and why is it considered secure?

  1. Option A: AES is symmetric encryption using 128/192/256-bit keys with mathematical security through substitution-permutation network
  2. Option B: AES uses asymmetric encryption
  3. Option C: AES was broken in 2015
  4. Option D: AES is only for classified information
Show hint

AES is the modern standard for symmetric encryption. Why did government adopt it?

Show answer

Answer: A. AES is symmetric encryption using 128/192/256-bit keys with mathematical security through substitution-permutation network

AES (Advanced Encryption Standard) is most widely used symmetric encryption algorithm, adopted as US government standard: (1) Selection process: NIST held competition for replacement of DES (broken due to small 56-bit key). Rijndael algorithm selected (Belgian design). Standardized as FIPS 197 in 2001. (2) Key sizes: AES-128 (128-bit key, 10 rounds). AES-192 (192-bit key, 12 rounds). AES-256 (256-bit key, 14 rounds). Larger key = more rounds = higher security but slower. AES-128 sufficient for non-classified information. AES-256 for long-term classified information. (3) Block size: 128-bit fixed. Plaintext split into 16-byte blocks. Each block independently encrypted (though modes combine blocks). (4) Rounds: Sequence of substitutions and permutations: SubBytes - substitution table (S-box) replaces bytes. ShiftRows - rows shifted by different amounts. MixColumns - matrix multiplication in Galois field. AddRoundKey - XOR with round key derived from original key. (5) Why secure: (a) No known practical attacks against full AES. (b) Key size sufficient - even AES-128 has 2^128 possible keys. Brute force infeasible. (c) Mathematical properties - S-boxes designed to resist linear/differential cryptanalysis. (d) Proven against known attack types. (e) 20+ years analysis with no breaks (unlike DES after ~25 years). (6) Modes of operation: ECB (Electronic Codebook) - insecure, identical plaintext blocks produce identical ciphertext blocks. CBC (Cipher Block Chaining) - each block XORed with previous ciphertext, requires IV. CTR (Counter) - converts block cipher to stream cipher using counter. GCM (Galois/Counter Mode) - authenticated encryption (confidentiality + integrity). (7) Authenticated encryption: GCM provides both encryption and authentication in one operation. Prevents tampering. Modern TLS uses AES-GCM. (8) Hardware acceleration: Modern processors have AES instructions (AES-NI), making AES very fast in hardware. Negligible performance overhead. (9) Quantum computing: AES-256 resistant to quantum attacks (Grover's algorithm reduces security to equivalent 128-bit classical). AES-128 vulnerable (Grover reduces to 64-bit equivalent). Recommendation: use AES-256 for long-term security. (10) Deployment: Every secure connection uses AES (TLS). Encrypted messaging (Signal, WhatsApp). File encryption (BitLocker, FileVault). Password managers. Database encryption. Military/government communications. AES is ubiquitous in modern security infrastructure.

146. What is a Man-in-the-Middle (MITM) attack and what defenses prevent it?

  1. Option A: MITM attack where attacker intercepts communication; prevented with encryption, certificates, and mutual authentication
  2. Option B: MITM only works on wireless networks
  3. Option C: MITM cannot be detected
  4. Option D: Encryption alone prevents all MITM attacks
Show hint

MITM requires attacker to position themselves between two communicating parties.

Show answer

Answer: A. MITM attack where attacker intercepts communication; prevented with encryption, certificates, and mutual authentication

Man-in-the-Middle (MITM) attack is sophisticated attack where attacker intercepts and potentially modifies communication: (1) Basic MITM mechanism: Attacker positions themselves between two communicating parties (Alice and Bob). Can be on same network (ARP spoofing), control network (ISP level), or control routing (BGP hijack). Attacker relays communications between Alice and Bob while eavesdropping. May modify messages transparently. Alice and Bob unaware of attack. (2) ARP spoofing: Attacker sends ARP replies claiming their MAC address is the gateway. Victims' ARP cache updated. Traffic to gateway routes to attacker instead. Attacker forwards traffic to actual gateway. Transparent MITM. (3) DNS spoofing: Attacker controls DNS response. User requests IP of 'bank.com', attacker responds with attacker's IP. User visits attacker's fake bank site, enters credentials. Credential harvesting attack. (4) MITM with HTTPS: Attacker can still MITM if victim doesn't verify certificate. Attacker uses own certificate. Browser shows certificate warning (if victim notices). Self-signed certificate raises red flags. However, users often click through warnings. (5) SSL stripping: Attacker downgrades HTTPS to HTTP. User sees normal-looking HTTP site without encryption awareness. Attacker sees all plaintext traffic. Works if victim doesn't explicitly use HTTPS. Modern browsers (HSTS) prevent this. (6) Defense methods: (a) Encryption - even if eavesdropped, ciphertext useless to attacker. Only works with proper key distribution. (b) Certificates - verify you're talking to who you think. CAs sign certificates proving identity. Protects against MITM if certificates validated properly. (c) Mutual authentication - both sides verify each other's identity. (d) HTTPS - encrypts transport, validates certificate. HSTS forces HTTPS. Certificate pinning - app trusts specific certificate/key, prevents unauthorized certificates. (e) VPN - all traffic encrypted end-to-end through tunnel. (f) 2FA - even if password captured, second factor needed. (g) Network segmentation - trusted networks only. (h) ARP security - static ARP entries, DHCP snooping. (i) Monitoring - intrusion detection noticing suspicious patterns. (7) Modern challenges: Wildcards in certificates (*.example.com) less restrictive. Self-signed certificates sometimes accepted. Users ignoring warnings. Encrypted traffic hides MITM from detection. (8) Certificate pinning: Mobile apps can pin certificates. Even valid certificate from CA might not be accepted if it doesn't match pinned cert. Protects against compromised CAs. (9) HSTS (HTTP Strict Transport Security): Header telling browsers to always use HTTPS. Prevents SSL stripping if pre-loaded. (10) MITM relevance: Still dangerous attack. Public WiFi common venue. Corporate networks vulnerable to insider MITM. Nation-state MITM attacks (intercepting international undersea cables). Defending requires multiple layers: encryption (TLS), certificate validation, monitoring, user awareness.

147. What is Denial of Service (DoS) and how does DDoS differ from traditional DoS?

  1. Option A: DoS is one attacker; DDoS uses many attackers/sources creating amplified attack making it harder to block
  2. Option B: DoS and DDoS are identical
  3. Option C: DDoS is only possible on government networks
  4. Option D: DoS cannot be mitigated
Show hint

The difference is in the number of sources. How does multiple sources complicate mitigation?

Show answer

Answer: A. DoS is one attacker; DDoS uses many attackers/sources creating amplified attack making it harder to block

Denial of Service (DoS) and Distributed DoS (DDoS) attacks make services unavailable by overwhelming targets: (1) DoS attack: Single attacker sends excessive traffic/requests to target. Overwhelms target's resources (bandwidth, CPU, memory). Service becomes unavailable to legitimate users. Examples: SYN flood (many TCP SYN packets), UDP flood (many UDP packets), HTTP flood (many web requests). (2) DDoS attack: Multiple attack sources (compromised computers, botnets) simultaneously attack target. Amplifies attack magnitude. Makes source blocking impossible (too many sources). Overwhelms larger bandwidth targets. (3) Botnet: Network of compromised computers controlled by attacker. Commonly created with malware. Infected computers become 'bots'. Thousands/millions of bots under attacker control. Used for DDoS without victims' knowledge. (4) DoS attack methods: (a) Bandwidth saturation - floods target with high-volume traffic (UDP, ICMP floods). Uses all available bandwidth. (b) Protocol exploitation - sends malformed packets exploiting bugs. Example: Ping of Death, Teardrop attack (fixed in modern systems). (c) Application layer - high-volume legitimate-looking requests. Harder to distinguish from real traffic. Example: HTTP flood. (d) Slowloris - sends HTTP requests slowly, causing server to hold connections. (e) Amplification - attacker sends small requests to third-party servers (DNS, NTP), which respond to target with large responses. (5) DDoS methods: Usually bandwidth-based (multiple sources = massive volume). Harder to stop because traffic appears from many locations. ISP cannot easily null-route traffic (would need to block all sources). (6) DDoS mitigation: (a) Rate limiting - routers drop excess traffic. (b) Blackhole routing - drop all traffic to target (nuclear option, service down but not disrupted). (c) DDoS mitigation services (CloudFlare, Akamai, AWS Shield) - absorb attack, filter bad traffic. (d) Redundancy - distributed infrastructure disperses attack. (e) Firewalls - drop suspicious traffic. (f) IDS/IPS - detect/block attack patterns. (g) BGP flowspec - upstream routers drop attack traffic. (h) Network monitoring - quick detection enables faster response. (7) Defenses against DoS: Patch vulnerabilities (protocol exploits). Configure timeouts to prevent resource exhaustion. Implement access controls. Firewall rules dropping suspicious patterns. Load balancing distributing traffic. Redundancy providing capacity. (8) Legal consequences: DoS/DDoS illegal in most countries. Felony charges, fines, imprisonment possible. Even 'testing' without permission is illegal. (9) Legitimate uses: Stress testing (with permission). Security testing (authorized penetration testing). (10) Impact: Entire services down for hours. Financial loss (lost transactions, reputational damage). Examples: 2016 Dyn attack (affected major sites), 2020 AWS attacks (GitHub, Twitter, others), gaming servers frequently targeted.

148. Which of the following is not a common type of firewall?

NEC model set
  1. Option A: Packet-filtering firewall
  2. Option B: Stateful inspection firewall
  3. Option C: Proxy firewall
  4. Option D: Encryption firewall
Show hint

Common firewalls are based on filtering approaches. Is encryption itself a firewall type?

Show answer

Answer: D. Encryption firewall

Encryption firewall is not a common firewall type. Common firewall types: (1) Packet-filtering firewall - Examines individual packets based on rules (IP addresses, ports, protocols), operates at network layer, fast but limited intelligence. (2) Stateful inspection firewall (stateful packet filtering) - Tracks connection states and context, remembers previous packets, more intelligent than basic filtering. (3) Proxy firewall (application gateway) - Intercepts and analyzes application-layer traffic, acts as intermediary between internal and external networks, can understand specific protocols (HTTP, FTP, SMTP). Encryption is a security mechanism, not a firewall. Other security functions: (1) VPN (Virtual Private Network) - Creates encrypted tunnels, (2) IDS/IPS (Intrusion Detection/Prevention System) - Monitors for attacks, (3) DLP (Data Loss Prevention) - Prevents data leakage. Modern firewalls: (1) Next-Generation Firewalls (NGFW) - Combine multiple approaches, deep packet inspection, (2) Cloud firewalls - For cloud environments, (3) Endpoint firewalls - Software firewalls on individual devices. Firewalls work at different levels: Layer 3-4 (network layer firewalls) or Layer 7 (application firewalls). The question tests understanding that encryption is complementary security, not a firewall classification.

149. Which layer of the OSI model does SSL (Secure Sockets Layer) operate on?

NEC model set
  1. Option A: a) Application
  2. Option B: b) Transport
  3. Option C: c) Network
  4. Option D: d) Data Link
Show hint

SSL provides encryption for data in transit. Between application and network, which layer?

Show answer

Answer: B. b) Transport

SSL (Secure Sockets Layer) operates on the Transport Layer (Layer 4) of the OSI model. It sits between the application layer and transport layer, providing encryption for data in transit. SSL/TLS encapsulates application layer data and encrypts it before passing to the network layer. This is why HTTPS (HTTP over SSL) provides secure web browsing. Modern systems use TLS (Transport Layer Security), the successor to SSL.

150. Which type of firewall examines individual packets (checking source/destination addresses and ports) to make allow/block decisions?

Recalled from Jan 2026 exam
  1. Option A: Application-level firewall
  2. Option B: Packet-filtering firewall
  3. Option C: Stateful-inspection firewall
  4. Option D: Circuit-level gateway
Show hint

This firewall type makes decisions based on packet headers. What is it called?

Show answer

Answer: B. Packet-filtering firewall

Packet-filtering firewall is the type that examines individual packets by checking source/destination addresses and ports to make allow/block decisions. Packet-filtering firewalls operate at the Network Layer (Layer 3) and examine packet headers. They are simple, fast, and have low overhead but offer limited security compared to more sophisticated firewalls. Stateful-inspection firewalls track connection states. Application-level firewalls examine application layer data. Circuit-level gateways operate at Layer 5. Packet-filtering is the most basic but still widely used firewall approach.

151. RSA is an example of:

  1. Option A: Symmetric key cryptography
  2. Option B: Asymmetric key cryptography
  3. Option C: Hash function
  4. Option D: Digital signature
Show answer

Answer: B. Asymmetric key cryptography

152. Which of the following is used for securing email?

  1. Option A: SSL
  2. Option B: PGP
  3. Option C: IPsec
  4. Option D: WEP
Show answer

Answer: B. PGP

153. WEP is used to secure:

  1. Option A: Wired networks
  2. Option B: Wireless networks
  3. Option C: Email communication
  4. Option D: Web browsing
Show answer

Answer: B. Wireless networks

154. IPsec operates at which layer of the OSI model?

  1. Option A: Application Layer
  2. Option B: Transport Layer
  3. Option C: Network Layer
  4. Option D: Data Link Layer
Show answer

Answer: C. Network Layer

155. A firewall is primarily used for:

  1. Option A: Virus detection
  2. Option B: Data encryption
  3. Option C: Access control
  4. Option D: Data compression
Show answer

Answer: C. Access control

156. SSL operates at which layer of the OSI model?

  1. Option A: Application Layer
  2. Option B: Transport Layer
  3. Option C: Network Layer
  4. Option D: Data Link Layer
Show answer

Answer: B. Transport Layer

157. Which of the following is NOT a type of firewall?

  1. Option A: Packet filtering firewall
  2. Option B: Stateful inspection firewall
  3. Option C: Proxy firewall
  4. Option D: Encryption firewall
Show answer

Answer: D. Encryption firewall

158. Which of the following is a passive security attack?

  1. Option A: Denial of Service
  2. Option B: Eavesdropping
  3. Option C: Data modification
  4. Option D: Masquerading
Show answer

Answer: B. Eavesdropping

159. VPN stands for:

  1. Option A: Virtual Private Network
  2. Option B: Virtual Public Network
  3. Option C: Virtual Protocol Network
  4. Option D: Virtual Personal Network
Show answer

Answer: A. Virtual Private Network

160. The primary purpose of a digital signature is:

  1. Option A: Encryption
  2. Option B: Authentication
  3. Option C: Compression
  4. Option D: Error detection
Show answer

Answer: B. Authentication

161. Which of the following is NOT a type of cryptographic attack?

  1. Option A: Brute force attack
  2. Option B: Dictionary attack
  3. Option C: Man-in-the-middle attack
  4. Option D: Ping of death attack
Show answer

Answer: D. Ping of death attack

162. Symmetric key cryptography uses:

  1. Option A: Different keys for encryption and decryption
  2. Option B: Same key for encryption and decryption
  3. Option C: Public key for encryption
  4. Option D: Private key for decryption only
Show answer

Answer: B. Same key for encryption and decryption

163. Which of the following is a symmetric key algorithm?

  1. Option A: RSA
  2. Option B: AES
  3. Option C: Diffie-Hellman
  4. Option D: ECC
Show answer

Answer: B. AES

164. A hash function is used for:

  1. Option A: Encryption
  2. Option B: Decryption
  3. Option C: Message integrity
  4. Option D: Key exchange
Show answer

Answer: C. Message integrity

165. Which of the following is a hash algorithm?

  1. Option A: AES
  2. Option B: RSA
  3. Option C: SHA-256
  4. Option D: DES
Show answer

Answer: C. SHA-256

166. SSL has been replaced by:

  1. Option A: TLS
  2. Option B: IPsec
  3. Option C: PGP
  4. Option D: SSH
Show answer

Answer: A. TLS

167. The primary weakness of WEP is:

  1. Option A: Short key length
  2. Option B: Weak encryption algorithm
  3. Option C: No authentication
  4. Option D: All of these
Show answer

Answer: B. Weak encryption algorithm

168. Which of the following is NOT a wireless security protocol?

  1. Option A: WEP
  2. Option B: WPA
  3. Option C: WPA2
  4. Option D: WPS
Show answer

Answer: D. WPS

169. Which of the following is a denial of service attack?

  1. Option A: Phishing
  2. Option B: SYN flooding
  3. Option C: SQL injection
  4. Option D: Cross-site scripting
Show answer

Answer: B. SYN flooding

Questions from bibhushansaakha/MCQ (MIT License, © 2024 Bibhushan Saakha) and SamirWagle/NECPrep. Exact duplicates are shown once. Where the source’s answer is missing, repeated, or disagrees between copies, the question carries a note. Questions are sorted into the official NEC syllabus topics; a few that sit between two topics may be filed under either.