Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2 logo

Systems Security Certified Practitioner

Domain 6Objective 2

6.2 - Understand Network Attacks (e.g., Distributed Denial of Service (DDoS), Man-In-The-Middle (MITM), Domain Name System (DNS) Cache Poisoning) SSCP Practice Questions (Page 6)

Part of the Network and Communication Security domain, which accounts for 16% of the SSCP exam. ISC2 does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–13 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)

31questions here
7free pages
9concepts
16%of the exam

Questions 26–30

  1. 26application · medium

    Users at a mid-sized company report that typing a well-known banking URL into their browsers sometimes loads a fraudulent login page that closely mimics the real bank. The issue is intermittent and affects multiple users across different offices. An IDPS alert shows unusual DNS responses from the company's internal resolver. Which action would most directly address the root cause?

    Select an answer first
  2. 27foundation · easy

    Which of the following is a common attack vector used in a distributed denial of service (DDoS) attack?

    Select an answer first
  3. 28expert · hard

    A cloud-based SaaS provider is experiencing a DDoS attack that targets its API endpoints with a mix of volumetric UDP floods and application-layer HTTP requests. The provider wants to mitigate both types of attacks while maintaining low latency for legitimate API calls. The provider has a limited budget and cannot afford a dedicated DDoS mitigation appliance. Which approach best meets these requirements?

    Select an answer first
  4. 29application · medium

    A hospital allows employees to connect personal laptops to the guest Wi-Fi network. After a series of malware infections spread from compromised personal devices to the medical records system, the IT director wants to prevent unmanaged devices from reaching internal resources. Which control would most directly enforce this policy at the network layer?

    Select an answer first
  5. 30foundation · easy

    Which countermeasure is specifically designed to absorb and distribute massive amounts of DDoS traffic across a global network of servers?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “SSCP” is a trademark of its owner, used for identification only.