Security Fundamentals
298 questions
A network security engineer is categorizing security threats and mapping them to appropriate defense controls. Match each security incident description on the left with the corresponding primary defense control on the right.
Click a left item, then click its matching right item
Items
Matches
An organization is deploying a Cisco AnyConnect Remote Access VPN solution for remote employees. The security policy mandates that all corporate traffic destined for internal enterprise subnets must be encrypted and forwarded through the VPN tunnel, while standard internet traffic should bypass the tunnel and route directly out the user's local network interface to preserve corporate WAN bandwidth. Additionally, remote clients must dynamically acquire private IP addresses and internal DNS server settings upon successful authentication. Which combination of VPN features and tunneling configurations meets these requirements?
An analyst monitoring a campus switch network detects an active Man-in-the-Middle (MitM) attack where an unauthorized host broadcasts gratuitous ARP replies containing its own MAC address mapped to the IP address of the default gateway. Which Layer 2 security control should be implemented to prevent this specific threat by validating incoming ARP requests and responses against a trusted binding database?
An enterprise risk assessment identifies that an unpatched buffer overflow flaw exists in a legacy database server daemon. An unauthorized external entity creates custom code to capitalize on this flaw, exposing sensitive customer records to unauthorized modification and creating an estimated financial risk of $250,000. Which element of this scenario specifically constitutes the vulnerability?
An enterprise organization is establishing physical security measures to protect its central data center network hardware against unauthorized physical intrusion. Which TWO physical access controls should the network security team implement? (Select TWO.)
Select all that apply
A network administrator needs to establish an encrypted tunnel between two permanent branch office router gateways to securely interconnect their internal networks over the public Internet without installing client software on end-user devices. Which VPN deployment model best satisfies this requirement?
A network security administrator is designing a VPN architecture for an enterprise deployment. The primary requirement demands a persistent, gateway-to-gateway encrypted connection between two static data center locations to transparently transport subnets without requiring endpoint software. Additionally, the administrator must support mobile employees who need temporary, browser-based remote access to internal HTTPS web applications from unmanaged personal laptops without installing a dedicated VPN client software. Which combination of VPN deployment types and protocols best fulfills both architectural requirements?
A network administrator enables port security on a switch access port using the command switchport port-security mac-address sticky. Devices connect to the port, and their MAC addresses are dynamically added to the switch configuration. However, after a planned reload of the switch, the port loses all learned MAC addresses and fails to forward traffic for previously connected hosts. What is the primary cause of this issue?
During an emergency security assessment following a network breach attempt, a security analyst discovers that an edge router running legacy software contains an unpatched flaw allowing unauthorized remote privilege escalation. Although no functional malicious script has yet been executed against the system, the security team deploys an Access Control List (ACL) to restrict incoming management traffic. However, the ACL misconfiguration inadvertently causes a network outage because the engineer relied on traffic filtering without accounting for default drop behavior, while another technician misanalyzed the attack severity due to numeric logging inversions. Which term precisely classifies the unpatched software flaw itself, and what fundamental security principle explains the unintended blocking of legitimate traffic by the mitigation ACL?
A security assessment of an enterprise edge router reveals that while SSH access is enabled, administrative commands executed by engineers are logged under a single shared local account without individual accountability or granular command restriction. To eliminate this security risk and enforce centralized command-level authorization and per-user accounting, which solution should the network administrator implement?
A network administrator needs to prevent unauthorized individuals from physically entering a wiring closet containing core network switches and patch panels. Which mechanism directly serves as a physical access control for this facility?
An organization is implementing a remote access Virtual Private Network (VPN) solution to enable teleworkers to connect securely to corporate resources across the public internet. Which two operational characteristics are unique to remote access VPNs compared to site-to-site VPNs? (Select two.)
Select all that apply
An enterprise network administrator is configuring a remote access VPN client profile on a security appliance to support mobile remote workers. The administrator enables split-tunneling to optimize bandwidth usage on the corporate Internet connection. Which two statements accurately describe the operational characteristics of this split-tunneling configuration?
Select all that apply
An enterprise is configuring a remote access VPN solution for mobile employees using Cisco AnyConnect client software. The network engineering team wants to implement split-tunneling to conserve corporate Internet bandwidth while maintaining secure connectivity to internal resources. Which two statements describe the operational behavior of split-tunneling in this remote access VPN deployment? (Select TWO.)
Select all that apply
During an ongoing incident response investigation, a network analyst detects that an unauthorized host on an internal VLAN is transmitting spoofed Neighbor Discovery (ND) Router Advertisement messages to redirect host traffic through itself before forwarding it to the actual default gateway. Concurrently, the IT security department is seeking a control to prevent unauthorized account access resulting from compromised or stolen user passwords used across corporate endpoints. Which combination correctly identifies the active network attack vector and the most effective mitigation control against the password compromise risk?
A network security architect is reviewing threat vectors and host-level network attacks targeting a corporate access layer switch. The audit identifies that an attacker connected to an untrusted port successfully performed ARP poisoning to intercept traffic between local hosts and launched a rogue DHCP server to distribute malicious default gateway addresses to clients. Which two mitigation controls directly address these specific security vulnerabilities? (Select two.)
Select all that apply
Evaluate the following VPN deployment requirements and protocol operational mechanics. Pair each specific VPN design scenario on the left with its corresponding protocol behavior or cryptographic implementation on the right.
Click a left item, then click its matching right item
Items
Matches
Security controls in an enterprise network fall into physical access controls, user security awareness elements, or administrative policies. Which of the following correctly matches each security control to its corresponding security program element or physical control function?
Click a left item, then click its matching right item
Items
Matches
A network security administrator is tasked with hardening campus access switch ports against Layer 2 security threats, specifically rogue DHCP server responses and ARP poisoning attacks. Which two mitigations should be implemented to prevent these threats? (Select two.)
Select all that apply
A system administrator is configuring a client-based remote access VPN on company laptops. The configuration specifies that only traffic destined for internal corporate network ranges () should be directed through the encrypted VPN tunnel, while all unsecured internet traffic should go directly out the user's local internet connection. Which VPN feature is being implemented?