Firewall, VPN, IDS and IPS MCQs: 11 Network Security Questions Solved
Solve 11 previous-year questions on firewalls, VPNs, IDS and IPS. Learn rule filtering, connection state, DMZ design, IPsec modes, tunnels and signatures.
KnowledgeGate Team
Exam prep & CS education

Firewall rules control traffic by connection state and network zone; IPsec and VPNs secure tunnels; IDSs alert and IPSs can prevent intrusions. Use each mechanism's main verb: firewalls allow or block, VPNs tunnel, IDSs alert and IPSs prevent.
1. Build one concrete firewall, VPN, IDS and IPS mental model
Mechanism | Primary action |
|---|---|
Firewall | Enforces an allow or deny rule |
VPN | Carries private traffic through an encrypted tunnel over a public network |
IDS | Observes activity and raises an alert |
IPS | Sits inline and can drop matching traffic |
When 10.0.0.25:49152 sends a SYN to 203.0.113.80:443, a stateful firewall records (TCP, 10.0.0.25, 49152, 203.0.113.80, 443) and permits the SYN-ACK. It denies an unrelated SYN from 198.51.100.44:54000 to 10.0.0.25:22. Use Computer Networks MCQs for wider practice.
2. Firewall rules and packet fields: Questions 1-2
Firewalls filter by IP addresses, protocols, ports and websites, but cannot guarantee stopping every malicious action.
Question 1 | UGC NET 2023
Attempt this question in the learn module
Which of the following statements A-E about firewalls in computer networks are true?
(A) Firewalls are only available as hardware devices and only examine traffic entering a network.
(B) Firewalls allow a user to set rules for network traffic.
(C) Firewalls will automatically stop all malicious traffic.
(D) Firewalls backup all data that is transmitted around a network.
(E) Firewalls can be used to block access to certain websites.
Choose the correct answer from the options given below:
A. (A), (C) and (D) Only
B. (B) and (E) Only
C. (B), (D) and (E) Only
D. (A) and (C) Only
Correct answer: B. (B) and (E) Only.
B is true because firewalls enforce policy rules, and E is possible through URL, domain or application controls. A wrongly limits firewalls to hardware and inbound traffic, C makes an absolute claim, and D describes backup.
Question 2 | UGC NET 2020
Attempt this question in the learn module
Firewall is a device that filters access to the protected network from the outside network. Firewalls can filter the packets on the basis of
(A) Source IP address
(B) Destination IP address
(C) TCP Source Port
(D) UDP Source Port
(E) TCP Destination Port
Choose the correct answer from the options given below:
A. (A), (B) and (C) Only
B. (B) and (E) Only
C. (C) and (D) Only
D. (A), (B), (C), (D) and (E) Only
Correct answer: D. (A), (B), (C), (D) and (E) Only.
Packet filters can match source and destination IP addresses and transport ports. In the example above, 10.0.0.25, 203.0.113.80, 49152, 443 and TCP are all rule inputs, so every listed field is eligible.
3. Stateful and application-aware inspection: Questions 3-4
Packet filtering reads headers, stateful inspection remembers connections, and application gateways understand application commands.
Question 3 | GATE 2007
Attempt this question in the learn module
A firewall is to be configured to allow hosts in a private network to freely open TCP connections and send packets on open connections. However, it will only allow external hosts to send packets on existing open TCP connections or connections that are being opened (by internal hosts) but not allow them to open TCP connections to hosts in the private network. To achieve this the minimum capability of the firewall should be that of
A. A combinational circuit
B. A finite automaton
C. A pushdown automaton with one stack
D. A pushdown automaton with two stacks
Correct answer: D. A pushdown automaton with two stacks.
The firewall needs an unbounded set of connection records. The stored 5-tuple lets it permit the SYN-ACK from 203.0.113.80:443 to 10.0.0.25:49152 while rejecting an unrelated SYN to port 22. Two stacks supply the required storage.
Question 4 | DSSSB 2023
Attempt this question in the learn module
Which of the following firewalls examine traffic and filter on application-specific commands such as http:post or http:get?
A. Application gateways
B. Stateful multilayer inspection firewalls
C. Circuit level gateways
D. Packet filters
Correct answer: A. Application gateways.
http:post and http:get are application commands, making an application gateway the direct match. Packet filters inspect headers, while circuit-level gateways validate sessions.
4. Two-firewall DMZ and leased-line-like privacy: Questions 5-6
A two-firewall DMZ separates Internet, DMZ and private-network policy zones. Its advantage is independent traffic control, not performance or load balancing.

Question 5 | Indian Space Research Organization 2018
Attempt this question in the learn module
What is one advantage of setting up a DMZ(Demilitarized Zone) with two firewalls?
A. You can control where traffic goes in the three networks
B. You can do stateful packet filtering
C. You can do load balancing
D. Improve network performance
Correct answer: A. You can control where traffic goes in the three networks.
FW1 controls Internet-to-DMZ traffic and FW2 controls DMZ-to-private traffic. Thus 172.16.10.20 has no unrestricted route to 10.0.0.0/24. The defining advantage is control across three zones.
Question 6 | UGC NET 2018
Attempt this question in the learn module
Which of the following statement/s is/are true ?
(i) Firewalls can screen traffic going into or out of an organization.
(ii) Virtual private networks can stimulate an old leased network to provide certain desirable properties.
Choose the correct answer from the code given below:
A. (i) only
B. (ii) only
C. Both (i) and (ii)
D. Neither (i) nor (ii)
Correct answer: C. Both (i) and (ii).
Statement (i) is true because firewalls screen inbound and outbound traffic. Statement (ii) uses “stimulate” for a VPN providing leased-line-like privacy over shared infrastructure, without creating a dedicated line.
5. IPsec modes and the extra tunnel header: Questions 7-9
Transport mode retains the original IP header. Tunnel mode protects the original packet and adds a new outer IP header for routing between tunnel endpoints.

Question 7 | UGC NET 2015
Attempt this question in the learn module
Which are two modes of IP security ?
A. Transport and certificate
B. Transport and tunnel
C. Certificate and tunnel
D. Preshared and transport
Correct answer: B. Transport and tunnel.
IPsec uses transport and tunnel modes. Certificate and preshared refer to authentication or key management, not packet-processing modes.
Question 8 | Indian Space Research Organization 2009
Attempt this question in the learn module
Use of IPSEC in tunnel mode results in
A. IP packet with same header
B. IP packet with new header
C. IP packet without header
D. No changes in IP packet
Correct answer: B. IP packet with new header.
The 10.0.1.10 -> 10.0.2.20 packet becomes the protected inner packet. Tunnel gateways add the routable outer header 203.0.113.10 -> 198.51.100.20; they do not remove the original header.
Question 9 | TPSC 2025
Attempt this question in the learn module
_______ creates an isolated passage across a public network that enables computing devices to communicate and receive data discreetly as though they were directly linked to the private network.
A. Visual Private Network
B. Virtual Protocol Network
C. Virtual Protocol Networking
D. Virtual Private Network
Correct answer: D. Virtual Private Network.
The isolated passage is a VPN tunnel. Public gateways 203.0.113.10 and 198.51.100.20 carry protected private traffic across a shared network.
6. IDS and IPS signatures and stack awareness: Questions 10-11
A signature represents a known attack pattern. An IDS alerts on matches, an inline IPS may block them, and anomaly detection compares activity with a learned baseline.
Question 10 | BPSC 2024
Attempt this question in the learn module
When discussing IDS/IPS, what is a signature?
A. Attack Definition File
B. It is used to authorize the users on a network
C. An electronic signature used to authenticate the identity of a user on the network
D. More than one of the above
E. None of the above
Correct answer: A. Attack Definition File.
A signature is an attack definition, not a digital signature or authorisation rule. A rule named S-104 might match USER root followed by three failed logins within 10 seconds. An IDS alerts; an IPS may terminate the connection.
Question 11 | BPSC 2024
Attempt this question in the learn module
What are the characteristics of stack based IDS?
A. It is programmed to interpret a certain series of packets
B. It models the normal usage of the network as a noise characterization
C. They are integrated closely with the TCP/IP stack and watch packets
D. More than one of the above
E. None of the above
Correct answer: D. More than one of the above.
A and C describe packet-sequence interpretation and TCP/IP stack integration, so both apply. B describes anomaly-based modelling of normal behaviour.
7. Answer pattern, trap map and next step
Answer strip: 1-B, 2-D, 3-D, 4-A, 5-A, 6-C, 7-B, 8-B, 9-D, 10-A, 11-D.
Review misses by topic:
Questions 1-2: firewall claims and rule fields.
Questions 3-4: inspection depth and connection state. Then practise flags and state with TCP and UDP MCQs: 12 Solved Transport Layer Questions.
Questions 5-9: DMZ and VPN boundaries.
Questions 10-11: detection vocabulary.
Retry misses after 24 hours, then redo all 11 after 7 days without the answers. Continue through CS Fundamentals for Exams and Placements.
For sequenced GATE study, continue with GATE Guidance by Sanchit Sir. For placement-oriented core CS revision, use CS Fundamentals for Placements by Sanchit Sir. Keep the four verbs clear, then attempt the questions again without the explanations.
Keep learning

Computer Networks Basics & Criteria MCQs: 12 Solved Questions with Explanations
Solve 12 Computer Networks questions, then use clear explanations and worked criteria checks to separate similar terms confidently.

TCP Timers, RTT Estimation & SWS: 10 Solved MCQs and NATs
Solve 10 TCP exam questions covering timer roles, Silly Window Syndrome, recursive RTT estimates, Jacobson/Karels RTO and Karn's rule.

RSA Algorithm MCQs: 12 Solved Questions with Step-by-Step Explanations
Practise RSA key generation, modular inverses, encryption, signatures and defining equations, with concise working for conceptual and numerical answers.

Network Security Goals, Threats and Attacks MCQs: 12 Solved Questions
Solve 12 network-security MCQs covering confidentiality, integrity, attack types, spoofing, DDoS and protection properties. Every answer has a clear explanation and a link to practise the question again.