NSE_2 NSE 2 - Technical Introduction to Cybersecurity Practice Questions
Prepare for NSE_2 with more than an answer.
- Level
- Fundamentals
- Valid for
- 2 years
Domains covered on the exam 7
- Cryptography and the Public Key Infrastructure15%
- Secure Networking20%
- Authentication and Access Control15%
- Secure Remote Access12%
- Endpoint Security13%
- Secure Data and Applications13%
- Cloud Security and Virtualization12%
- 1
A multinational corporation is replacing its expensive MPLS lines with a solution that can intelligently route traffic over multiple paths (Broadband, LTE, MPLS) based on application performance requirements. Which technology provides this capability?
Show answer details
Correct answer: C
SD-WAN abstracts the underlying transport links and uses software to route traffic intelligently based on application needs, latency, jitter, and cost, allowing the use of cheaper broadband alongside or instead of MPLS.
- 2
What is the primary function of a Sandbox in a modern cybersecurity architecture?
Show answer details
Correct answer: C
A Sandbox provides a secure, isolated environment where suspicious files are detonated (executed) to analyze their behavior. This is crucial for detecting zero-day threats and polymorphic malware that signature-based tools might miss.
- 3
Which of the following best describes the core concept of SASE (Secure Access Service Edge)?
Show answer details
Correct answer: C
SASE (Secure Access Service Edge) combines wide area networking (WAN) capabilities (like SD-WAN) with comprehensive network security functions (like SWG, CASB, ZTNA) into a single, cloud-delivered service model.
graph TD subgraph SASE["SASE Platform"] direction TB Net[Networking / SD-WAN] Sec[Security / FWaaS / ZTNA / CASB] Net --- Sec end User[Remote User] --> SASE Branch[Branch Office] --> SASE SASE --> Cloud[Cloud Apps] SASE --> HQ[Data Center] - 4
A financial institution is upgrading its data transmission standards. The CISO requires a solution where the sender uses a key to encrypt data that can be decrypted by any recipient possessing the corresponding public key, but the recipient cannot use that public key to decrypt messages meant for the sender. Which cryptographic concept is being described?
Show answer details
Correct answer: C
Asymmetric encryption uses a pair of keys: a public key for encryption and a private key for decryption (or vice versa for signing). This allows for secure communication without sharing a secret key beforehand, unlike symmetric encryption.
- 5
An administrator is configuring a VPN for a remote branch office. To ensure data integrity during transit, they need to select a mechanism that generates a fixed-size string from the input data, where any change to the input results in a completely different string. Which mechanism should be chosen?
Show answer details
Correct answer: D
Hashing algorithms (like SHA-256) create a unique fixed-size digest of data. If even a single bit of the data changes, the hash changes drastically (avalanche effect), which is used to verify data integrity.
- 6
In a Public Key Infrastructure (PKI) environment, a user needs to validate that a web server's certificate is legitimate and has not been forged. Which component of the PKI hierarchy is the ultimate source of trust that issues and signs the root certificate?
Show answer details
Correct answer: D
The Certificate Authority (CA) is the trusted entity that issues digital certificates. The Root CA is the top of the trust hierarchy, and its signature validates the authenticity of the certificates it issues.
graph TD RootCA[Root Certificate Authority] -->|Signs| InterCA[Intermediate CA] InterCA -->|Signs| ServerCert[Server Certificate] Client[User Browser] -->|Trusts| RootCA Client -->|Validates| ServerCert
