210-250 Sample Questions & Answers
Recognizing network and web-application attack methods is weighted heaviest, alongside Windows and Linux host analysis, data sources for security monitoring, risk-management principles, hashing and PKI cryptography, and transport-layer protocols in the OSI model.
Launch the full 210-250 simulator →Showing 8 of 17 free samples.
- Question 1Intermediate
Network Concepts · Transport Layer Protocols
A security analyst is reviewing a packet capture from a suspected reconnaissance scan. The analyst observes a sequence of packets where the source sends a TCP SYN packet to a specific port, receives a SYN-ACK from the destination, and immediately sends a RST packet. Which type of network scanning technique is being executed?
Show answer & explanation
Correct answer: B
In a TCP SYN (or Half-Open) scan, the attacker sends a SYN packet. If the port is open, the target responds with SYN-ACK. The attacker then sends a RST (Reset) instead of an ACK to tear down the connection before it is fully established. This is done to avoid logging the connection on the target application layer. A TCP Connect scan would complete the handshake with an ACK.
- Question 2Intermediate
Network Concepts · Network Infrastructure
Which Cisco IOS command is used to configure a mirrored port on a switch to send a copy of network traffic to a sensor for analysis, such as an IDS or a packet capture device?
Show answer & explanation
Correct answer: C
The 'monitor session' command set is used to configure Switched Port Analyzer (SPAN) on Cisco switches. The correct syntax to define the source is 'monitor session [id] source interface [interface]'. This copies traffic to the destination port for analysis.
- Question 3Beginner
Network Concepts · Ethernet and IP Protocols
While analyzing a PCAP file, an engineer observes an Ethernet frame with a Type field value of 0x0806. Which protocol is encapsulated within this frame?
Show answer & explanation
Correct answer: D
The EtherType field 0x0806 identifies the payload as the Address Resolution Protocol (ARP). IPv4 uses 0x0800, and IPv6 uses 0x86DD.
- Question 4Beginner
Network Concepts · Network Infrastructure
An organization is designing a new security zone architecture. They require a zone that exposes public-facing services (Web, Email) to the internet while isolating them from the internal LAN. Which network design concept should be implemented?
Show answer & explanation
Correct answer: A
A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the Internet, while keeping the internal LAN secure behind a firewall. If the DMZ is compromised, the internal network remains protected.
- Question 5Beginner
Network Concepts · Network Layers and Models
In the TCP/IP model, which layer is responsible for logical addressing and routing of packets across different networks?
Show answer & explanation
Correct answer: A
The Internet Layer in the TCP/IP model (equivalent to the Network Layer in OSI) handles logical addressing (IP addresses) and routing of packets between networks.
- Question 6Intermediate
Network Concepts · Ethernet and IP Protocols
A network engineer is calculating subnets for a new branch office. The office requires 60 host IP addresses. Which CIDR notation provides the most efficient subnet size while satisfying the requirement?
Show answer & explanation
Correct answer: A
A /26 subnet mask provides 6 bits for hosts (32 - 26 = 6). 2^6 = 64. Subtracting the network and broadcast addresses (64 - 2) leaves 62 usable host addresses, which efficiently covers the requirement of 60 hosts. A /27 would only provide 30 usable hosts.
- Question 7Beginner
Security Concepts · Security Principles
Which security principle focuses on ensuring that data is not modified or altered by unauthorized entities during transit or storage?
Show answer & explanation
Correct answer: D
Integrity provides assurance that data has not been modified, tampered with, or corrupted. Hashing algorithms are commonly used to verify integrity.
- Question 8Beginner
Security Concepts · Access Control
A security architect is implementing an access control model where access rights are granted based on the user's job function and responsibilities within the organization. Which model is being described?
Show answer & explanation
Correct answer: C
RBAC (Role-Based Access Control) assigns permissions to roles (e.g., Manager, Admin, Clerk) rather than directly to users. Users are then assigned to roles. This aligns access with job functions.
Ready for the real thing?
The full 210-250 simulator has every exam-style question, timed mode, and instant scoring.