Network Architecture & Security Devices
22 practice questions with explanations — 15 free to try
2 of these 22 questions are in the free 15-question taster · the full topic is part of Premium
PassNova has 22 GIAC GSEC (Security Essentials) practice questions on Network Architecture & Security Devices, each with a clear explanation. A 15-question taster is free with no sign-up; the full bank is part of PassNova Premium. Updated for 2026.
Network Architecture & Security Devices: example questions & answers
2 worked examples with answers and explanations below. Try 15 GIAC GSEC (Security Essentials) questions free in the browser; the full 22-question Network Architecture & Security Devices bank is part of PassNova Premium.
Where should an organisation place its public web server and mail relay so that compromising one of them does not give an attacker direct access to the internal LAN?
- AIn a DMZ, a screened subnet between firewall zones✓
- BOn the same VLAN as the domain controllers for easy management
- COutside the perimeter firewall with no filtering
- DOn the internal LAN, protected by the perimeter firewall
Answer: A DMZ, or screened subnet, holds internet-facing servers in their own zone: the internet can reach them only on the published ports, and they have tightly limited access inward. If one is compromised, the attacker still faces a firewall before the internal LAN. Placing them on the LAN or beside domain controllers removes that barrier, and leaving them unfiltered on the internet exposes every service they run.
A security team must feed a network sensor from a busy 10 Gbps core link and cannot afford to miss packets during traffic peaks. Why would they choose a network TAP over a switch SPAN port?
- AA SPAN port can only mirror traffic from a single VLAN
- BA SPAN port stops forwarding traffic when the sensor fails
- CA TAP passively copies every frame even at peak load✓
- DA TAP decrypts TLS so the sensor can read payloads
Answer: A network TAP is a passive device that splits the signal, so the monitoring port sees every frame, including malformed ones, whatever the load. A SPAN port relies on the switch copying traffic as a lower-priority task, so an oversubscribed mirror, for example several busy ports into one, silently drops packets. SPAN can mirror multiple ports and VLANs, a TAP never decrypts anything, and a failed sensor on a SPAN port does not interrupt production traffic.