01. Which of the following is an effective mitigation against Distributed Denial-of-Service (DDoS) attacks in a cloud environment?
a) Implementing strong password policies
b) Using web application firewalls (WAFs)
c) Deploying intrusion detection systems (IDS)
d) Utilizing cloud-based DDoS protection services
02. A network engineer is testing the network throughput between Linux servers in a hybrid environment. The engineer needs to measure bandwidth between the servers on premises and servers in the cloud to validate network throughput against the ISP SLA.
Which of the following is the best tool for this task?
a) iperf
b) tcpdump
c) netcat
d) netstat
03. You are reviewing the configuration of a recently deployed IPS to ensure it follows hardened security practices. Which configurations should be validated?
(Choose TWO)
a) Disable remote administrative access over HTTP
b) Rely only on default alert logging
c) Integrate with centralized authentication such as LDAP or RADIUS
d) Allow anonymous read-only login
e) Enable insecure management protocols for support access
04. A company operates in a hybrid cloud environment and needs security guidance to harden and protect its services. Which of the following would best protect the environment?
a) Cloud Controls Matrix
b) MITRE ATT&CK framework
c) OWASP Top Ten
d) CIS Benchmarks
05. A link shows late collisions, interface errors, poor throughput, and TCP retransmissions after one side was manually configured for full duplex while the other uses autonegotiation. What is the most likely cause?
a) MTU fragmentation
b) Asymmetric routing
c) Duplex mismatch
d) VLAN misconfiguration
06. Why might a network administrator receive failed login attempts from unknown IP addresses on port 22?
a) DoS attack
b) Brute-force attack
c) DNS amplification
d) VLAN hopping
07. A network engineer suspects high latency between edge routers and cloud gateways during business hours and needs flow-level evidence plus visual latency trends. Which tools or techniques should be used?
(Select TWO)
a) NetFlow collector
b) Packet capture only
c) BGP route injection
d) Latency heatmaps from monitoring tools
e) Manual IP renumbering
08. When analyzing traceroute output, what does a consistent timeout (* * *) at a specific hop most commonly indicate?
a) DNS misconfiguration
b) ICMP filtering, rate limiting, or a device not responding to probes
c) Packet fragmentation only
d) MTU discovery failure only
09. A company that hosts its website in a private data center receives reports that the company's website is now pointing to a website with offensive material. No changes were made to the network, and the company's website appears normal from the internal network.
Which of the following attacks is the company most likely experiencing?
a) BGP hijack
b) Out-of-band
c) Evil twin
d) On-path
10. An organization uses a managed service provider for its network infrastructure. The organization decides to switch to another provider and implement the latest network technologies available in the market. As part of the transformation, different documents need to be prepared.
Which of the following documents would be the most valuable for a network architect to use?
a) Low-level designs
b) Flow diagrams
c) Runbooks
d) Baselines