712-50 exam dumps

712-50 practice question 301 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 301

Single answerIdentify the basic network architecture, models, protocols and components such as routers and hubs that play a role in network security

A CCISO is reviewing a regional office after several employees reported intermittent exposure of internal application sessions during troubleshooting exercises. The office network was built quickly during an acquisition and still uses a legacy Ethernet hub to connect several analyst workstations to an uplink router. The router then connects to the corporate WAN. Management wants the fastest improvement that reduces the likelihood of one workstation passively observing another workstation's traffic on the local segment without redesigning the WAN. Which action should the CCISO recommend first?

  1. A

    Replace the hub with a managed Layer 2 switch and place sensitive users in separate VLANs as needed

  2. B

    Upgrade the WAN router firmware because routers inherently prevent local packet capture between hosts on the same shared segment

  3. C

    Disable TCP and force UDP for internal applications so session traffic is less likely to be observed by neighboring hosts

  4. D

    Add another hub so each department has its own shared collision domain before the router

Show answer and explanation

Correct answer: A

Explanation

This scenario tests applied understanding of basic network architecture and components relevant to security. Hubs are legacy Layer 1 devices that repeat traffic to all connected ports, making passive eavesdropping by any connected host much easier. Switches, by contrast, operate primarily at Layer 2 and forward frames using MAC address learning, which significantly limits unnecessary frame exposure on the local segment. In enterprise practice, replacing hubs with managed switches is a standard baseline improvement, and VLANs can be used to segment users or systems with different trust levels. Routers play an important role in connecting networks and enforcing controls between subnets, but they do not remediate visibility problems inside a shared hub segment. This aligns with long-established network design and security best practices documented in common networking references and security architecture guidance, including principles reflected in NIST network segmentation guidance and vendor enterprise campus design documentation.

  • A. Correct.

    Correct. A hub operates at OSI Layer 1 and repeats incoming frames out all other ports, meaning hosts on the same segment can see traffic not intended for them. Replacing it with a switch materially improves confidentiality on the local network because a switch forwards frames based on MAC address tables rather than broadcasting all traffic to every port. Using a managed switch also enables segmentation through VLANs, which can further reduce exposure between groups and support stronger security controls. This is the most direct and practical fix for the stated problem.

  • B. Incorrect.

    Incorrect. While routers separate broadcast domains and can enforce policy between networks, they do not solve the core issue described here: traffic exposure on the local shared Ethernet segment created by the hub. Updating router firmware may be good operational hygiene, but it does not change the fact that hosts attached to the hub can passively observe local traffic before it ever reaches the router.

  • C. Incorrect.

    Incorrect. The transport protocol choice does not address the Layer 1/Layer 2 issue caused by the hub. Both TCP and UDP traffic can be captured by any host that receives the frames on a shared medium. Someone might pick this option because TCP is associated with sessions and reliability, but protocol substitution is not a valid mitigation for promiscuous capture on a hub-based segment.

  • D. Incorrect.

    Incorrect. Adding another hub would preserve the same fundamental weakness because hubs do not provide traffic isolation between attached devices. Although separate hubs could create different collision domains depending on topology, they still do not provide the switching logic needed to limit frame delivery to the intended port. This option reflects a common misconception that simply dividing users across more shared devices meaningfully improves confidentiality.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam