
Systems Security Certified Practitioner
Domain 6Objective 2
6.2 - Understand Network Attacks (e.g., Distributed Denial of Service (DDoS), Man-In-The-Middle (MITM), Domain Name System (DNS) Cache Poisoning) SSCP Practice Questions (Page 4)
Part of the Network and Communication Security domain, which accounts for 16% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
9concepts
16%of the exam
Questions 16–20
- 16
How does network access control (NAC) help mitigate network attacks?
Select an answer first - 17
Which of the following best describes how DNS cache poisoning works?
Select an answer first - 18
Which countermeasure is specifically designed to authenticate DNS responses and prevent cache poisoning?
Select an answer first - 19
A news website is hit by a DDoS attack that sends a massive volume of HTTP GET requests for a specific article page, causing the origin server to exhaust its CPU. The attack traffic appears to come from a botnet of compromised IoT devices. Which countermeasure would be most effective at mitigating this specific attack?
Select an answer first - 20
A financial services company suspects an attacker is performing ARP spoofing on the internal network to intercept traffic between employees and the payment gateway. The security team wants to detect this activity in real time and automatically block the offending MAC address. Which solution best meets this requirement?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.