Updated Dec-2025 Official licence for Network-and-Security-Foundation Certified by Network-and-Security-Foundation Dumps PDF [Q21-Q45]

Share

Updated Dec-2025 Official licence for Network-and-Security-Foundation Certified by Network-and-Security-Foundation Dumps PDF

Grab latest Amazon Network-and-Security-Foundation Dumps as PDF Updated on 2025

NEW QUESTION # 21
An attacker uses login data from a data breach to attempt to access another web service.
Which malicious attack strategy is represented in the scenario?

  • A. Brute-force attack
  • B. Session hijacking
  • C. Social engineering
  • D. Credential stuffing

Answer: D

Explanation:
Credential stuffingis a cyberattack where attackers use stolen username-password combinations from one breach to try logging into other services, exploiting users who reuse passwords. Automated tools test multiple credentials against multiple sites, leading to unauthorized access.
* Brute-force attacksystematically tries all possible passwords but does not use breached data.
* Session hijackingintercepts active user sessions but does not use stolen credentials.
* Social engineeringmanipulates users into revealing credentials, rather than using breached data.


NEW QUESTION # 22
A company's internal messaging system is being redesigned. The authentication procedures were so cumbersome that employees were using personal email to communicate.
What is the security principle implemented in this scenario?

  • A. Zero-trust model
  • B. Psychological acceptability
  • C. Least common mechanism
  • D. Fail-safe

Answer: B

Explanation:
Psychological acceptabilitystates that security measures should beuser-friendly and not overlyburdensome
. If security controls are too complex, users may bypass them, leading to weaker security. In this case, employees used personal email because authentication procedures were too cumbersome.
* Zero-trust modelenforces strict access control, not usability.
* Least common mechanismlimits shared resources.
* Fail-safeensures secure failure handling, not usability.


NEW QUESTION # 23
What is an IT infrastructure security tenet of the CIA triad that counters passive attacks that aim to steal or intercept data?

  • A. Availability
  • B. Confidentiality
  • C. Adaptation
  • D. Integrity

Answer: B

Explanation:
Confidentialityprotects data from unauthorized access, includingpassive attackslike eavesdropping, wiretapping, and packet sniffing. Encryption, access controls, and secure authentication mechanisms help enforce confidentiality.
* Availabilityensures uptime and system accessibility.
* Integrityensures data accuracy but does not prevent interception.
* Adaptationis not part of the CIA triad.


NEW QUESTION # 24
Which layer of the OSI model includes the TCP?

  • A. Network
  • B. Transport
  • C. Session
  • D. Application

Answer: B

Explanation:
TheTransport layer(Layer 4 of the OSI model) includes theTransmission Control Protocol (TCP), which provides reliable, connection-oriented communication. TCP ensures error-checking, sequencing, and retransmission of lost packets.
* Application layerdeals with end-user protocols like HTTP and FTP.
* Session layermanages communication sessions but not transport protocols.
* Network layerfocuses on IP addressing and routing, not transport mechanisms.


NEW QUESTION # 25
An organization's network has been the target of several cyberattacks.
Which strategy should the organization use for Wi-Fi hardening?

  • A. Implement wired equivalent privacy (WEP)
  • B. Avoid the use of asymmetric encryption
  • C. Configure RADIUS authentication
  • D. Implement a bus topology

Answer: C

Explanation:
Configuring RADIUS authenticationenhances Wi-Fi security by requiring user authentication before granting access to the network. This prevents unauthorized users from connecting and mitigates risks from rogue access points.
* WEPis outdated and insecure; WPA2/WPA3 with RADIUS should be used instead.
* A bus topologyis a network design choice, not a security measure.
* Avoiding asymmetric encryptionweakens security rather than improving it.


NEW QUESTION # 26
A company is developing a disaster recovery plan for its internal network.
What is the CIA triad component targeted in the scenario?

  • A. Innovation
  • B. Availability
  • C. Integrity
  • D. Confidentiality

Answer: B

Explanation:
Availabilityensures that systems and data remain accessible and operational, even in the event of failures or attacks. Adisaster recovery plan (DRP)focuses on restoring IT infrastructure and operations after incidents like hardware failures, cyberattacks, or natural disasters. Strategies include data backups, failover systems, and redundant architectures.
* Confidentialityfocuses on restricting unauthorized access.
* Integrityensures data remains unaltered, but does not address service continuity.
* Innovationis unrelated to the CIA triad.


NEW QUESTION # 27
A library has a network that allows patrons to use their mobile devices to connect to the internet.
Which type of network is described?

  • A. SAN
  • B. PAN
  • C. WLAN
  • D. MAN

Answer: C

Explanation:
AWireless Local Area Network (WLAN)enables wireless connectivity within a defined geographic area, such as a library, office, or coffee shop. WLANs use Wi-Fi technology to allow users to access the internet without physical cables.
* Storage Area Networks (SANs)are used for data storage and do not provide internet connectivity to users.
* Metropolitan Area Networks (MANs)cover larger areas, such as cities, and are not used within a single building.
* Personal Area Networks (PANs)connect personal devices like smartphones and laptops over short distances, such as via Bluetooth, but do not support public internet access.


NEW QUESTION # 28
An organization is updating its information security policies in order to comply with thePersonal Information Protection and Electronic Documents Act (PIPEDA).
What should this organization expect to be required under this legislation?

  • A. Notify individuals each time their personal information is viewed
  • B. Disclose the software used to protect personal data
  • C. Compensate individuals for revenue from the sale of their information
  • D. Securely dispose of personally identifiable information

Answer: D

Explanation:
PIPEDArequires businesses in Canada to protectpersonal informationthrough security measures andproper disposal practices. This includessecure deletion of personal data when no longer neededto prevent unauthorized access.
* Compensating individuals for data salesis not a legal requirement.
* Notifying individuals of each data accessis unnecessary unless required by a breach.
* Disclosing security softwareis not mandated by PIPEDA.


NEW QUESTION # 29
Which statement describes the Integrity tenet of IT security?

  • A. It involves transmitting network data without any errors.
  • B. It requires the encryption of sensitive data transmission.
  • C. It involves keeping systems accessible for network users.
  • D. It requires that network applications be accessible to users.

Answer: A

Explanation:
Integrityin IT security ensures that data remains accurate, unaltered, and trustworthy throughout its lifecycle.
This means that data transmission should occurwithout errorsand should not be modified by unauthorized parties. Mechanisms like checksums, hashing, and digital signatures help maintain integrity.
* Encryption (B)enhances confidentiality, not integrity.
* Accessibility (C and D)relates to availability, not integrity.


NEW QUESTION # 30
In order to reduce the risk of insider attacks, a company assigns role-based permissions to its users.
Which network security concept does this scenario address?

  • A. Authentication
  • B. Accounting
  • C. Availability
  • D. Authorization

Answer: D

Explanation:
Authorizationis the process of granting specific access rights and permissions based on user roles. By implementingRole-Based Access Control (RBAC), organizations ensure that users only have access to resources necessary for their job functions, reducing the risk of insider threats.
* Authenticationverifies identity but does not control access.
* Accountinglogs activities but does not restrict access.
* Availabilityensures system uptime but is unrelated to permissions.


NEW QUESTION # 31
An organization has experienced rogue access points in the past and wants to take actions to mitigate this type of attack.
What should this organization do?

  • A. Use server-side validation
  • B. Disallow ICMP packets on the firewall
  • C. Use monitor mode scanning
  • D. Require complex passwords

Answer: C

Explanation:
Monitor mode scanningallows administrators to detect unauthorized or rogue access points broadcasting in the network. This technique, along withwireless intrusion detection systems (WIDS), helps identify and block unauthorized devices.
* Requiring complex passwordsenhances security but does not prevent rogue APs.
* Server-side validationsecures applications, not wireless networks.
* Disallowing ICMP packetsis a security measure but does not address rogue APs.


NEW QUESTION # 32
A company wants to use a cloud service to obtain virtual machines with pre-installed and configured software.
Which cloud service model should be used?

  • A. Platform as a Service (PaaS)
  • B. Software as a Service (SaaS)
  • C. Function as a Service (FaaS)
  • D. Infrastructure as a Service (IaaS)

Answer: A

Explanation:
Platform as a Service (PaaS)provides a pre-configured computing environment that includes an operating system, runtime, and development tools, making it ideal for developers who want a ready-to-use platform.
Examples include Google App Engine and Microsoft Azure App Services.
* SaaSprovides fully hosted applications, not just pre-configured virtual machines.
* IaaSprovides infrastructure without pre-installed software.
* FaaSexecutes specific functions without persistent infrastructure.


NEW QUESTION # 33
What is the component of the CIA triad for IT security that requires that IP packets be retransmitted if the receiving host has an invalid checksum value?

  • A. Availability
  • B. Consistency
  • C. Integrity
  • D. Confidentiality

Answer: C

Explanation:
Integrityin theCIA (Confidentiality, Integrity, Availability) triadensures that data is not altered in an unauthorized manner. In networking, integrity mechanisms such as checksums, message authentication codes (MACs), and digital signatures verify that transmitted data has not been tampered with. If an IP packet has an invalid checksum, the system detects corruption and requests retransmission, ensuring data integrity.
* Confidentialityprotects against unauthorized access but does not ensure data consistency.
* Availabilityensures that resources are accessible but does not verify data correctness.
* Consistencyis not a formal component of the CIA triad.


NEW QUESTION # 34
Users of a network have been experiencing issues. In the course of troubleshooting, an administrator wants to test DNS resolution against a host.
Which command in Linux should be used for this purpose?

  • A. ifconfig
  • B. dig
  • C. netstat
  • D. traceroute

Answer: B

Explanation:
Thedigcommand in Linux is used for DNS troubleshooting. It queries DNS records and provides detailed information about domain name resolutions.
* traceroutetracks the path packets take to a destination but does not diagnose DNS.
* netstatlists active connections, not DNS records.
* ifconfigis used for managing network interfaces.


NEW QUESTION # 35
A start-up company wants to build its computer network by starting with the base-level resources offered by a cloud service. In this way, the company won't have to buy physical hardware but canstill have complete control over operating systems and other software.
Which cloud service model should be used?

  • A. Infrastructure as a Service (IaaS)
  • B. Software as a Service (SaaS)
  • C. Function as a Service (FaaS)
  • D. Platform as a Service (PaaS)

Answer: A

Explanation:
Infrastructure as a Service (IaaS)provides virtualized computing resources, including virtual machines, storage, and networking, while allowing users full control over operating systems and applications. Examples include AWS EC2 and Google Compute Engine.
* SaaSprovides ready-to-use applications (e.g., Google Docs).
* FaaSruns code in response to events (e.g., AWS Lambda).
* PaaSprovides development environments but not full infrastructure control.


NEW QUESTION # 36
Which component of the IT securityCIA triadis a driver for enabling data encryption?

  • A. Availability
  • B. Confidentiality
  • C. Integrity
  • D. Application

Answer: B

Explanation:
Confidentialityensures that sensitive information is protected from unauthorized access.Encryptionis a key mechanism used to maintain confidentiality by converting readable data into a secure format that can only be accessed with a decryption key.
* Integrityensures data is not altered improperly but does not directly relate to encryption.
* Availabilityfocuses on system uptime and accessibility.
* Applicationis not a component of the CIA triad.


NEW QUESTION # 37
When setting up a network, a technician needs a router that connects computers together and connects computers to the internet.
Which router should be used?

  • A. Core router
  • B. Broadband router
  • C. Inter-provider border router
  • D. Subscriber edge router

Answer: B

Explanation:
A broadband router is a type of network router that connects multiple computers within a local network while also providing internet access. It functions as a gateway between the local network and the internet by handling data packet transmission and routing. Broadband routers are widely used in small offices and homes because they offer essential networking services, including DHCP, NAT, and sometimes wireless connectivity.
* Inter-provider border routersare used by ISPs to route data between different providers and do not serve as an internet gateway for end users.
* Subscriber edge routersare typically deployed at the edge of an ISP's network to connect subscriber networks but do not provide full internet routing functionalities.
* Core routersoperate at the backbone level of a network, facilitating high-speed data transfer but not connecting end-user devices directly.


NEW QUESTION # 38
An attacker issues commands to access a file on a network drive and overwrite it with new data.
What is the purpose of the attack?

  • A. Data export
  • B. Denial of availability
  • C. Launch point
  • D. Data modification

Answer: D

Explanation:
Data modification attacksinvolve unauthorized changes to stored data, altering information to mislead, disrupt, or destroy integrity. Attackers may modify logs, transactions, or records for fraud or sabotage.
* Launch pointis when a system is used to attack others.
* Data exportis the theft of data.
* Denial of availabilitymakes data inaccessible, but does not necessarily modify it.


NEW QUESTION # 39
A company is ensuring that its network protocol meets encryption standards.
What is the CIA triad component targeted in the scenario?

  • A. Availability
  • B. Confidentiality
  • C. Consistency
  • D. Integrity

Answer: B

Explanation:
Confidentialityin IT security ensures that sensitive data remains private and protected from unauthorized access. Encryption is a key measure used to maintain confidentiality by encoding data so that only authorized users can access it.
* Integrityensures that data remains accurate and unchanged.
* Availabilityensures that data is accessible when needed.
* Consistencyis not a component of the CIA triad.


NEW QUESTION # 40
A company is developing a data protection methodology in order to improve data protection measures.
What is a strategy that should be used?

  • A. Increase wireless access point range
  • B. Implement wired equivalent privacy (WEP)
  • C. Use a variable network topology
  • D. Enhance physical resource security

Answer: D

Explanation:
Enhancing physical resource securityensures that servers, networking devices, and data storage facilities are protected from unauthorized physical access, theft, or tampering. This includes measures like biometric authentication, surveillance, and restricted access zones.
* Using a variable network topologydoes not directly protect data.
* Increasing wireless access point rangemay improve connectivity but does not enhance security.
* WEPis weak and should not be used for data protection.


NEW QUESTION # 41
When setting up a network, a technician needs a router that creates an access point.
Which router should be used?

  • A. Wireless router
  • B. Core router
  • C. Broadband router
  • D. Inter-provider border router

Answer: A

Explanation:
Awireless routeris designed to create an access point that allows wireless devices to connect to a network. It combines the functions of a traditional router with a wireless access point, enabling communication between wired and wireless devices. These routers use Wi-Fi standards (e.g., 802.11ac, 802.11ax) to transmit data wirelessly.
* Broadband routersprimarily provide internet connectivity but do not necessarily include Wi-Fi functionality unless specified.
* Core routershandle large-scale data routing in the backbone of networks but are not designed for access point creation.
* Inter-provider border routersfunction at an ISP level for routing traffic between different networks, not for providing user access.


NEW QUESTION # 42
After recently experiencing a security breach, a company is working on improving its database security. As a part of its security governance strategies, the company is developing a database security checklist.
Which component is important to include in this checklist?

  • A. Restricting physical access to locations where data is housed
  • B. Disclosing any instances of breaches of personal data
  • C. Outsourcing data management to third-party vendors
  • D. Developing algorithms for secure access to data

Answer: A

Explanation:
Restricting physical accessto data storage facilities is a critical part of database security. Even with strong cybersecurity measures,unauthorized physical accessto servers can lead to breaches. Security strategies includebiometric authentication, surveillance cameras, and restricted entry zones.
* Disclosing breachesis required by compliance laws but does not protect data proactively.
* Developing algorithmsimproves security but is not a fundamental checklist item.
* Outsourcing data managementcan introduce security risks if not properly controlled.


NEW QUESTION # 43
Which layer of the OSI model includes HTTP?

  • A. Network
  • B. Transport
  • C. Session
  • D. Application

Answer: D

Explanation:
TheApplication layer(Layer 7 of the OSI model) includesHypertext Transfer Protocol (HTTP), which is used for web communication. This layer provides network services directly to applications and users.
* Network layerdeals with IP addressing and packet routing.
* Session layermanages connections but does not include HTTP.
* Transport layerensures reliable data transmission but does not handle application protocols.


NEW QUESTION # 44
A company is specifically worried about buffer overflow attacks.
Which strategy should be used as a mitigation against this type of attack?

  • A. Use server-side validation
  • B. Disable caching
  • C. Implement intrusion protection software
  • D. Detect code vulnerabilities

Answer: D

Explanation:
Detecting code vulnerabilitiesthroughregular security audits, code reviews, and static analysis toolshelps prevent buffer overflow attacks. Developers should implementbounds checking,memory-safe programming languages, and input validationto mitigate risks.
* Disabling cachingdoes not prevent buffer overflow attacks.
* Server-side validationhelps with input security but does not directly address buffer overflows.
* Intrusion protection softwaremay detect attacks but does not prevent vulnerabilities in code.


NEW QUESTION # 45
......

Latest Network-and-Security-Foundation Exam Dumps WGU Exam from Training: https://www.testkingit.com/WGU/latest-Network-and-Security-Foundation-exam-dumps.html

Newly Released Network-and-Security-Foundation Dumps for Courses and Certificates Certified: https://drive.google.com/open?id=1fW6YWPHdt4Pmrdl_NH_ZJb5I2UtIgERy