N10-009 · Domain 5 of 5 by weight

Network Security

By · Updated 2026-07-13

Exam weight
14%
Approx. questions
~13
Topics
4

Network Security accounts for 14% of the CompTIA Network+ — roughly 13 of the 90 questions you will see. It is the lightest domain on the exam — worth knowing, but not worth over-investing in at the expense of heavier ones.

What this domain actually tests

The smallest domain on the exam, and effectively a preview of Security+. If you intend to take that next, the time you spend here pays twice.

The concepts: defence in depth (layered controls, so no single failure is fatal), zero trust (never trust, always verify; no implicit trust from network location), and least privilege.

Authentication, authorisation, and accounting (AAA)who you are, what you may do, and what you did. RADIUS and TACACS+ are the protocols; the tested difference is that TACACS+ separates authentication, authorisation, and accounting and encrypts the entire payload, while RADIUS encrypts only the password.

The traps

The attacks, paired with their mitigations — because the exam asks them as pairs, not as definitions:

AttackWhat it isMitigation
Rogue DHCP serverAn attacker hands out bad addresses and gatewaysDHCP snooping
ARP poisoningAttacker maps their MAC to the gateway's IPDynamic ARP Inspection
VLAN hoppingTraffic reaches a VLAN it should notDisable auto-trunking, change the native VLAN
MAC floodingOverflow the switch's CAM table so it floods trafficPort security
On-path (MITM)Traffic silently interceptedTLS, certificate validation
DDoSOverwhelm with trafficRate limiting, upstream scrubbing
Evil twinA rogue AP impersonating a legitimate SSIDWPA3, wireless IPS, user awareness

That table is most of the domain. Learn the pairing, because a question describing the symptom expects the mitigation, and vice versa.

DHCP snooping and Dynamic ARP Inspection get confused. Snooping stops a rogue DHCP server. DAI stops ARP spoofing. They are different attacks with similar-sounding switch features.

Port security limits which MAC addresses may use a switch port — it is the answer to both MAC flooding and to "stop people plugging unauthorised devices into the wall."

Physical security counts. Locked racks, badge access, mantraps, and cameras appear, and candidates find them easy to forget precisely because they are not technical.

How to study it

Build the attack-to-mitigation table above and drill it in both directions: given the attack, name the control; given the control, name what it prevents. The exam asks both ways.

Then get the DHCP-snooping-versus-DAI distinction cold, since it is the pair most likely to trip you.

At 14% this is the smallest domain — around twelve questions — so do not over-invest. But note that almost everything in it reappears, expanded, on Security+. If that is your next exam, treat this domain as an early down payment rather than a chore.

What this domain covers

  • Security concepts: defense in depth, zero trust
  • Authentication, authorization, and encryption
  • Network attacks and mitigation techniques
  • Physical security and segmentation

These are the topics Prepa uses to generate N10-009 practice questions for this domain, so your practice is weighted the way the exam is.

The other N10-009 domains

For the full exam format, scoring, and a study plan, read the CompTIA Network+ (N10-009) Study Guide.

Related reading