Firewall, VPN, IDS and IPS MCQs: 11 Network Security Questions Solved

Solve 11 previous-year questions on firewalls, VPNs, IDS and IPS. Learn rule filtering, connection state, DMZ design, IPsec modes, tunnels and signatures.

KnowledgeGate Team

Exam prep & CS education

Updated 24 Sep 20267 min read

Firewall rules control traffic by connection state and network zone; IPsec and VPNs secure tunnels; IDSs alert and IPSs can prevent intrusions. Use each mechanism's main verb: firewalls allow or block, VPNs tunnel, IDSs alert and IPSs prevent.

1. Build one concrete firewall, VPN, IDS and IPS mental model

Mechanism

Primary action

Firewall

Enforces an allow or deny rule

VPN

Carries private traffic through an encrypted tunnel over a public network

IDS

Observes activity and raises an alert

IPS

Sits inline and can drop matching traffic

When 10.0.0.25:49152 sends a SYN to 203.0.113.80:443, a stateful firewall records (TCP, 10.0.0.25, 49152, 203.0.113.80, 443) and permits the SYN-ACK. It denies an unrelated SYN from 198.51.100.44:54000 to 10.0.0.25:22. Use Computer Networks MCQs for wider practice.

2. Firewall rules and packet fields: Questions 1-2

Firewalls filter by IP addresses, protocols, ports and websites, but cannot guarantee stopping every malicious action.

Question 1 | UGC NET 2023

Attempt this question in the learn module

Which of the following statements A-E about firewalls in computer networks are true?

(A) Firewalls are only available as hardware devices and only examine traffic entering a network.

(B) Firewalls allow a user to set rules for network traffic.

(C) Firewalls will automatically stop all malicious traffic.

(D) Firewalls backup all data that is transmitted around a network.

(E) Firewalls can be used to block access to certain websites.

Choose the correct answer from the options given below:

  • A. (A), (C) and (D) Only

  • B. (B) and (E) Only

  • C. (B), (D) and (E) Only

  • D. (A) and (C) Only

Correct answer: B. (B) and (E) Only.

B is true because firewalls enforce policy rules, and E is possible through URL, domain or application controls. A wrongly limits firewalls to hardware and inbound traffic, C makes an absolute claim, and D describes backup.

Question 2 | UGC NET 2020

Attempt this question in the learn module

Firewall is a device that filters access to the protected network from the outside network. Firewalls can filter the packets on the basis of

(A) Source IP address

(B) Destination IP address

(C) TCP Source Port

(D) UDP Source Port

(E) TCP Destination Port

Choose the correct answer from the options given below:

  • A. (A), (B) and (C) Only

  • B. (B) and (E) Only

  • C. (C) and (D) Only

  • D. (A), (B), (C), (D) and (E) Only

Correct answer: D. (A), (B), (C), (D) and (E) Only.

Packet filters can match source and destination IP addresses and transport ports. In the example above, 10.0.0.25, 203.0.113.80, 49152, 443 and TCP are all rule inputs, so every listed field is eligible.

3. Stateful and application-aware inspection: Questions 3-4

Packet filtering reads headers, stateful inspection remembers connections, and application gateways understand application commands.

Question 3 | GATE 2007

Attempt this question in the learn module

A firewall is to be configured to allow hosts in a private network to freely open TCP connections and send packets on open connections. However, it will only allow external hosts to send packets on existing open TCP connections or connections that are being opened (by internal hosts) but not allow them to open TCP connections to hosts in the private network. To achieve this the minimum capability of the firewall should be that of

  • A. A combinational circuit

  • B. A finite automaton

  • C. A pushdown automaton with one stack

  • D. A pushdown automaton with two stacks

Correct answer: D. A pushdown automaton with two stacks.

The firewall needs an unbounded set of connection records. The stored 5-tuple lets it permit the SYN-ACK from 203.0.113.80:443 to 10.0.0.25:49152 while rejecting an unrelated SYN to port 22. Two stacks supply the required storage.

Question 4 | DSSSB 2023

Attempt this question in the learn module

Which of the following firewalls examine traffic and filter on application-specific commands such as http:post or http:get?

  • A. Application gateways

  • B. Stateful multilayer inspection firewalls

  • C. Circuit level gateways

  • D. Packet filters

Correct answer: A. Application gateways.

http:post and http:get are application commands, making an application gateway the direct match. Packet filters inspect headers, while circuit-level gateways validate sessions.

4. Two-firewall DMZ and leased-line-like privacy: Questions 5-6

A two-firewall DMZ separates Internet, DMZ and private-network policy zones. Its advantage is independent traffic control, not performance or load balancing.

Two-firewall DMZ: FW1 allows the Internet into the DMZ web server on TCP 443 only, and FW2 lets only that server reach the database.

Question 5 | Indian Space Research Organization 2018

Attempt this question in the learn module

What is one advantage of setting up a DMZ(Demilitarized Zone) with two firewalls?

  • A. You can control where traffic goes in the three networks

  • B. You can do stateful packet filtering

  • C. You can do load balancing

  • D. Improve network performance

Correct answer: A. You can control where traffic goes in the three networks.

FW1 controls Internet-to-DMZ traffic and FW2 controls DMZ-to-private traffic. Thus 172.16.10.20 has no unrestricted route to 10.0.0.0/24. The defining advantage is control across three zones.

Question 6 | UGC NET 2018

Attempt this question in the learn module

Which of the following statement/s is/are  true ?

(i) Firewalls can screen traffic going into or out of an organization.

(ii) Virtual private networks can stimulate an old leased network to provide certain desirable properties.

Choose the correct answer from the code given below:

  • A. (i) only

  • B. (ii) only

  • C. Both (i) and (ii)

  • D. Neither (i) nor (ii)

Correct answer: C. Both (i) and (ii).

Statement (i) is true because firewalls screen inbound and outbound traffic. Statement (ii) uses “stimulate” for a VPN providing leased-line-like privacy over shared infrastructure, without creating a dedicated line.

5. IPsec modes and the extra tunnel header: Questions 7-9

Transport mode retains the original IP header. Tunnel mode protects the original packet and adds a new outer IP header for routing between tunnel endpoints.

IPsec transport mode keeps the original IP header, while tunnel mode wraps the packet in a new outer header between the two gateways.

Question 7 | UGC NET 2015

Attempt this question in the learn module

Which are two modes of IP security ?

  • A. Transport and certificate

  • B. Transport and tunnel

  • C. Certificate and tunnel

  • D. Preshared and transport

Correct answer: B. Transport and tunnel.

IPsec uses transport and tunnel modes. Certificate and preshared refer to authentication or key management, not packet-processing modes.

Question 8 | Indian Space Research Organization 2009

Attempt this question in the learn module

Use of IPSEC in tunnel mode results in

  • A. IP packet with same header

  • B. IP packet with new header

  • C. IP packet without header

  • D. No changes in IP packet

Correct answer: B. IP packet with new header.

The 10.0.1.10 -> 10.0.2.20 packet becomes the protected inner packet. Tunnel gateways add the routable outer header 203.0.113.10 -> 198.51.100.20; they do not remove the original header.

Question 9 | TPSC 2025

Attempt this question in the learn module

_______ creates an isolated passage across a public network that enables computing devices to communicate and receive data discreetly as though they were directly linked to the private network.

  • A. Visual Private Network

  • B. Virtual Protocol Network

  • C. Virtual Protocol Networking

  • D. Virtual Private Network

Correct answer: D. Virtual Private Network.

The isolated passage is a VPN tunnel. Public gateways 203.0.113.10 and 198.51.100.20 carry protected private traffic across a shared network.

6. IDS and IPS signatures and stack awareness: Questions 10-11

A signature represents a known attack pattern. An IDS alerts on matches, an inline IPS may block them, and anomaly detection compares activity with a learned baseline.

Question 10 | BPSC 2024

Attempt this question in the learn module

When discussing IDS/IPS, what is a signature?

  • A. Attack Definition File

  • B. It is used to authorize the users on a network

  • C. An electronic signature used to authenticate the identity of a user on the network

  • D. More than one of the above

  • E. None of the above

Correct answer: A. Attack Definition File.

A signature is an attack definition, not a digital signature or authorisation rule. A rule named S-104 might match USER root followed by three failed logins within 10 seconds. An IDS alerts; an IPS may terminate the connection.

Question 11 | BPSC 2024

Attempt this question in the learn module

What are the characteristics of stack based IDS?

  • A. It is programmed to interpret a certain series of packets

  • B. It models the normal usage of the network as a noise characterization

  • C. They are integrated closely with the TCP/IP stack and watch packets

  • D. More than one of the above

  • E. None of the above

Correct answer: D. More than one of the above.

A and C describe packet-sequence interpretation and TCP/IP stack integration, so both apply. B describes anomaly-based modelling of normal behaviour.

7. Answer pattern, trap map and next step

Answer strip: 1-B, 2-D, 3-D, 4-A, 5-A, 6-C, 7-B, 8-B, 9-D, 10-A, 11-D.

Review misses by topic:

  • Questions 1-2: firewall claims and rule fields.

  • Questions 3-4: inspection depth and connection state. Then practise flags and state with TCP and UDP MCQs: 12 Solved Transport Layer Questions.

  • Questions 5-9: DMZ and VPN boundaries.

  • Questions 10-11: detection vocabulary.

Retry misses after 24 hours, then redo all 11 after 7 days without the answers. Continue through CS Fundamentals for Exams and Placements.

For sequenced GATE study, continue with GATE Guidance by Sanchit Sir. For placement-oriented core CS revision, use CS Fundamentals for Placements by Sanchit Sir. Keep the four verbs clear, then attempt the questions again without the explanations.