Network Security Goals, Threats and Attacks MCQs: 12 Solved Questions
Solve 12 network-security MCQs covering confidentiality, integrity, attack types, spoofing, DDoS and protection properties. Every answer has a clear explanation and a link to practise the question again.
KnowledgeGate Team
Exam prep & CS education

Network-security questions become difficult when one changed verb turns confidentiality into integrity, spoofing into sniffing, or replay into modification. Confidentiality, integrity, authentication and availability provide the first map; replay, spoofing, DDoS, SSL and cryptographic properties supply the cases. Choose an option before reading its explanation. For the wider subject route, use GATE CS Exam Preparation.
Security goals and attack types: the reference model for all 12 questions
Security goal | Meaning | Most direct attack mapping |
|---|---|---|
Confidentiality | Only authorised parties can read data | Interception |
Integrity | Data is not altered without detection | Modification |
Availability | Authorised users can obtain the service when needed | Interruption |
Authentication | Identity or message origin is verified | Fabrication |
Nonrepudiation | A party cannot credibly deny a recorded action | Evidence against denial |
Classify the action before naming the attack. Ask what the adversary reads, changes, blocks or invents, then map that action to the security property that fails.
Consider a private software-release manifest: Package 4.2, checksum 9f3a, approved by build service at 10:30. Interception exposes the manifest to an unauthorised reader, breaking confidentiality. Modification changes the package version or checksum, breaking integrity. Interruption prevents clients from retrieving the release, breaking availability. Fabrication inserts a release record the build service never approved, breaking origin authentication and integrity. One attack can violate several goals, but the table identifies its most direct effect.
For deception, malware and common-impact classification, use Cyber Threats and Attacks MCQs. Formal security goals determine the answer here; later questions apply them to replay, spoofing, DDoS, SSL and the integrity calculation.
Network security MCQs 1-3: confidentiality, integrity, authentication and nonrepudiation
Question 1
UGC NET 2019, Computer Science, Paper 2 (December)
Consider the following statements with respect to network security: (a) Message confidentiality means that the sender and the receiver expect privacy (b) Message integrity means that the data must arrive at the receiver exactly as they were sent. (c) Message authentication means the receiver is ensured that the message is coming from the intended sender Which of the statements is (are) correct?
A. Only (a) and (b)
B. Only (a) and (c)
C. Only (b) and (c)
D. (a), (b) and (c)
Correct answer: D. (a), (b) and (c).
Privacy maps to confidentiality, unchanged arrival to integrity, and assurance of the intended sender to authentication. All three statements are correct. Full solution for Question 1.
Question 2
RSSB 2022, Computer Science, SCI - Paper 2
In context of network security, match the following –
Column – I
(P) Fabrication
(Q) Modification
(R) Interception
Column – II
1.Message confidentiality
2.Message integrity
3.Authentication
A. P-1, Q-3, R-2
B. P-2, Q-1, R-3
C. P-3, Q-1, R-2
D. P-3, Q-2, R-1
Correct answer: D. P-3, Q-2, R-1.
Interception threatens confidentiality, modification threatens integrity, and fabrication defeats authentication by creating a false message or origin claim. This gives P-3, Q-2, R-1. Full solution for Question 2.
Question 3
DSSSB 2023, Computer Science, TGT
Which of the following security services protects against repudiation?
A. Nonrepudiation
B. Access control
C. Authentication
D. Data integrity
Correct answer: A. Nonrepudiation.
Nonrepudiation links a party to an action with evidence that resists later denial. Authentication verifies identity, access control governs permission, and integrity detects changes. Full solution for Question 3.
Network security MCQs 4-6: replay, DNS spoofing and IP spoofing
Question 4
UGC NET 2016, Computer Science, Paper 2 (August)
An attacker sits between the sender and receiver, captures a valid message , and retransmits it after some time without altering the information. This attack is called ______.
A. Denial of service attack
B. Replay attack
C. Simple attack
D. Complex attack
Correct answer: B. Replay attack.
A valid message retransmitted later without alteration is a replay. Nonces, timestamps or sequence values can supply the missing freshness check. Full solution for Question 4.
Question 5
ISRO 2016, Computer Science
When a DNS server accepts and uses incorrect information from a host that has no authority giving that information, then it is called:
A. DNS lookup
B. DNS hijacking
C. DNS spoofing
D. None of the mentioned
Correct answer: C. DNS spoofing.
Forged, unauthorised DNS information identifies DNS spoofing or cache poisoning; hijacking is a broader redirection category. Contrast it with legitimate DNS in Application Layer MCQs: 12 Solved DNS, HTTP, Email. Full solution for Question 5.
Question 6
UGC NET 2019, Computer Science, Paper 2 (June)
The ability to inject packets into the Internet with a false source address is known as
A. Man-in-the-middle attack
B. IP phishing
C. IP sniffing
D. IP spoofing
Correct answer: D. IP spoofing.
A false source IP address defines IP spoofing. Sniffing observes traffic, phishing deceives a person, and a man-in-the-middle adversary occupies the communication path. Full solution for Question 6.
Network security MCQs 7-9: DDoS mechanisms and attacker motivation
Question 7
RSSB 2022, Computer Science, SCI - Paper 2
What does DDoS stand for?
A. Data Denial-of-Service
B. Distributed Denial-of-Service
C. Distributed Data of Server
D. Distribution of Data Service
Correct answer: B. Distributed Denial-of-Service.
The abbreviation expands to Distributed Denial-of-Service. Multiple systems generate the disruptive traffic, and the target is availability. Full solution for Question 7.
Question 8
IBPS 2023
Which type of DDoS attack uses spoofed ICMP echo requests sent to broadcast addresses, causing multiple systems to flood the victim with ICMP reply packets?
A. SYN Flood
B. Ping of Death
C. Smurf Attack
D. DNS Amplification
E. UDP Flood
Correct answer: C. Smurf Attack.
The attacker spoofs the victim's address, sends ICMP echo requests to a broadcast address, and makes many hosts reply to the victim. That ICMP broadcast amplification identifies a Smurf attack. Full solution for Question 8.
Question 9
RSSB 2022, Computer Science, BCI-Paper2
Hacktivism is –
A. a process of break into systems and dig out its information and make it public.
B. gaining access to systems with intention to fix the identified weaknesses.
C. a test technique used for an existing internet infrastructure and find its loopholes.
D. the act of hacking a computer system, for politically or socially motivated purpose.
Correct answer: D. the act of hacking a computer system, for politically or socially motivated purpose.
Motive is the discriminator: hacktivism connects hacking with a political or social cause. The other choices describe disclosure, remediation or testing without that motive. Full solution for Question 9.
Network security MCQs 10-12: protection properties and one integrity numerical
Question 10
ISRO 2007 and BEL 2007, Computer Science
SSL is not responsible for:
A. Mutual authentication of client & server
B. Secret communication
C. Data integrity protection
D. Error detection and correction
Correct answer: D. Error detection and correction.
SSL protects confidentiality, integrity and authentication in the question's conceptual scope. General error detection and correction belongs to reliability mechanisms. Full solution for Question 10.
Question 11
ISRO 2018, Computer Science
Avalanche effect in cryptography
A. Is desirable property of cryptographic algorithm
B. Is undesirable property of cryptographic algorithm
C. Has no effect on encryption algorithm
D. None of the above
Correct answer: A. Is desirable property of cryptographic algorithm.
A strong avalanche effect makes a small input or key change produce a large, unpredictable output change. This desirable diffusion hides exploitable relationships. Full solution for Question 11.
Question 12
UGC NET 2019, Computer Science, Paper 2 (June)
A Web application and its support environment has not been fully fortified against attack. Web engineers estimate that the likelihood of repelling an attack is only 30 percent. The application does not contain sensitive or controversial information, so the threat probability is 25 percent. What is the integrity of the web application?
A. 0.625
B. 0.725
C. 0.775
D. 0.825
Correct answer: D. 0.825.
Use integrity = 1 - exposure, where exposure = threat probability × vulnerability. Repelling probability is 30% = 0.30, so vulnerability is 1 - 0.30 = 0.70; threat probability is 25% = 0.25, so exposure is 0.25 × 0.70 = 0.175; therefore integrity is 1 - 0.175 = 0.825. Full solution for Question 12.
How exams test network-security goals, threats and attacks
Use this four-step check:
Identify the protected goal.
Identify exactly what the attacker does.
Separate the mechanism from the motive.
Convert percentages to decimals before calculating.
For example, changing checksum 9f3a to checksum 77bc is modification, so the direct loss is integrity. In the numerical, the same disciplined approach gives 1 - [0.25 × (1 - 0.30)] = 1 - (0.25 × 0.70) = 1 - 0.175 = 0.825.
The traps are authentication versus nonrepudiation, forged DNS data called generic hijacking, spoofing mistaken for sniffing, and DDoS detached from availability. The short version: learn the five goals, classify the attack action, then use packet clues to separate replay, DNS spoofing, IP spoofing and Smurf attacks.
Continue with GATE Guidance by Sanchit Sir, then use the GATE Test Series for timed practice. After one day, revisit misses and explain why each distractor fails.
Keep learning

Computer Networks Basics & Criteria MCQs: 12 Solved Questions with Explanations
Solve 12 Computer Networks questions, then use clear explanations and worked criteria checks to separate similar terms confidently.

TCP Timers, RTT Estimation & SWS: 10 Solved MCQs and NATs
Solve 10 TCP exam questions covering timer roles, Silly Window Syndrome, recursive RTT estimates, Jacobson/Karels RTO and Karn's rule.

RSA Algorithm MCQs: 12 Solved Questions with Step-by-Step Explanations
Practise RSA key generation, modular inverses, encryption, signatures and defining equations, with concise working for conceptual and numerical answers.

Firewall, VPN, IDS and IPS MCQs: 11 Network Security Questions Solved
Solve 11 previous-year questions on firewalls, VPNs, IDS and IPS. Learn rule filtering, connection state, DMZ design, IPsec modes, tunnels and signatures.