210-250 Sample Questions

210-250 Sample Questions & Answers

Recognizing network and web-application attack methods is weighted heaviest, alongside Windows and Linux host analysis, data sources for security monitoring, risk-management principles, hashing and PKI cryptography, and transport-layer protocols in the OSI model.

Launch the full 210-250 simulator →

Showing 8 of 17 free samples.

  1. Question 1Intermediate

    Network Concepts · Transport Layer Protocols

    A security analyst is reviewing a packet capture from a suspected reconnaissance scan. The analyst observes a sequence of packets where the source sends a TCP SYN packet to a specific port, receives a SYN-ACK from the destination, and immediately sends a RST packet. Which type of network scanning technique is being executed?

    Show answer & explanation

    Correct answer: B

    In a TCP SYN (or Half-Open) scan, the attacker sends a SYN packet. If the port is open, the target responds with SYN-ACK. The attacker then sends a RST (Reset) instead of an ACK to tear down the connection before it is fully established. This is done to avoid logging the connection on the target application layer. A TCP Connect scan would complete the handshake with an ACK.

  2. Question 2Intermediate

    Network Concepts · Network Infrastructure

    Which Cisco IOS command is used to configure a mirrored port on a switch to send a copy of network traffic to a sensor for analysis, such as an IDS or a packet capture device?

    Show answer & explanation

    Correct answer: C

    The 'monitor session' command set is used to configure Switched Port Analyzer (SPAN) on Cisco switches. The correct syntax to define the source is 'monitor session [id] source interface [interface]'. This copies traffic to the destination port for analysis.

  3. Question 3Beginner

    Network Concepts · Ethernet and IP Protocols

    While analyzing a PCAP file, an engineer observes an Ethernet frame with a Type field value of 0x0806. Which protocol is encapsulated within this frame?

    Show answer & explanation

    Correct answer: D

    The EtherType field 0x0806 identifies the payload as the Address Resolution Protocol (ARP). IPv4 uses 0x0800, and IPv6 uses 0x86DD.

  4. Question 4Beginner

    Network Concepts · Network Infrastructure

    An organization is designing a new security zone architecture. They require a zone that exposes public-facing services (Web, Email) to the internet while isolating them from the internal LAN. Which network design concept should be implemented?

    Show answer & explanation

    Correct answer: A

    A DMZ (Demilitarized Zone) is a physical or logical subnetwork that contains and exposes an organization's external-facing services to an untrusted network, usually the Internet, while keeping the internal LAN secure behind a firewall. If the DMZ is compromised, the internal network remains protected.

  5. Question 5Beginner

    Network Concepts · Network Layers and Models

    In the TCP/IP model, which layer is responsible for logical addressing and routing of packets across different networks?

    Show answer & explanation

    Correct answer: A

    The Internet Layer in the TCP/IP model (equivalent to the Network Layer in OSI) handles logical addressing (IP addresses) and routing of packets between networks.

  6. Question 6Intermediate

    Network Concepts · Ethernet and IP Protocols

    A network engineer is calculating subnets for a new branch office. The office requires 60 host IP addresses. Which CIDR notation provides the most efficient subnet size while satisfying the requirement?

    Show answer & explanation

    Correct answer: A

    A /26 subnet mask provides 6 bits for hosts (32 - 26 = 6). 2^6 = 64. Subtracting the network and broadcast addresses (64 - 2) leaves 62 usable host addresses, which efficiently covers the requirement of 60 hosts. A /27 would only provide 30 usable hosts.

  7. Question 7Beginner

    Security Concepts · Security Principles

    Which security principle focuses on ensuring that data is not modified or altered by unauthorized entities during transit or storage?

    Show answer & explanation

    Correct answer: D

    Integrity provides assurance that data has not been modified, tampered with, or corrupted. Hashing algorithms are commonly used to verify integrity.

  8. Question 8Beginner

    Security Concepts · Access Control

    A security architect is implementing an access control model where access rights are granted based on the user's job function and responsibilities within the organization. Which model is being described?

    Show answer & explanation

    Correct answer: C

    RBAC (Role-Based Access Control) assigns permissions to roles (e.g., Manager, Admin, Clerk) rather than directly to users. Users are then assigned to roles. This aligns access with job functions.

Ready for the real thing?

The full 210-250 simulator has every exam-style question, timed mode, and instant scoring.