Objective 4.3N10-009

4.3 Given a scenario, apply network security features, defense techniques, and solutions.

Objective 4.3 sits in Network Security, which carries 14% of the Network+ exam. The questions below are original, written from the official objective title above, and each explanation cites the CompTIA page it rests on.

Objective title verbatim from the official objectives. CompTIA exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

Network SecurityModerate

A technician configures a switch port connected to one desktop as a static-access port in VLAN 20 rather than a dynamic trunk. What security benefit results from this configuration?

Correct.

The concept

Device hardening reduces attack surface by limiting what a switch port is permitted to carry.

Why this answer

A static-access port assigned to VLAN 20 forwards only that VLAN's traffic, unlike a trunk that could carry many VLANs and be manipulated.

  • This is correct: static-access assignment restricts the port to VLAN 20 traffic only.
  • BVLAN assignment has no effect on frame encryption; that is a separate control.
  • CStatic-access configuration is a Layer 2 setting and performs no RADIUS authentication.
  • DVLAN membership does not filter by traffic type such as multicast.
Read the sourceCisco: Configuring VLANs
Verified against cisco.com · 2026-07-27
device hardeningvlanstatic-access port

Now you: objective 4.3 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

Network SecurityModerate

A team enables ESP on a site to site tunnel and asks what the payload actually gains. Which set of services does RFC 4303 name?

Sample question 2 of 3

Network SecurityHard

An engineer inspects an IPsec packet and finds the ESP header sitting before an encapsulated IP header. Which mode is in use?

Sample question 3 of 3

Network SecurityHard

A configuration enables ESP encryption with no integrity mechanism alongside it. Against which attacker does RFC 4303 say this generally still defends?

Full Network+ question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Network Security