Security Fundamentals
298 questions
A network administrator applies the following standard IPv4 access control list (ACL) inbound on a router interface:
`access-list 10 permit 192.168.1.0 0.0.0.255`
A host with the IPv4 address `192.168.2.50` attempts to send traffic through this interface. What action will the router take on this packet?
During a security assessment of a financial institution, a network administrator reviews the measures implemented to protect network infrastructure. The measures include installing biometric door locks on the main data center, deploying TACACS+ for switch administration authentication, implementing Port Security on access switches, and conducting quarterly user security awareness campaigns. Which of these measures is classified specifically as a physical access control?
A network technician configures port security on an access switch interface using the command `switchport port-security mac-address sticky`. Which TWO statements accurately describe how sticky MAC address learning operates on this interface?
Select all that apply
A network engineer must configure an IPv4 extended access control list (ACL 105) on a Cisco IOS router to enforce security policies for traffic originating from the internal subnet () destined for an application server at :
1. Allow host administrative SSH access (TCP port 22) to server .
2. Prevent all other hosts in the subnet from accessing server via SSH.
3. Allow all hosts in the subnet web access (TCP port 80) to server .
4. Explicitly block all remaining IP traffic from to server .
In what order should the network engineer place the ACL statements from top to bottom to ensure the policy is correctly enforced?
Drag items to arrange them in the correct order
A network administrator is reviewing the fundamental operation of standard IPv4 Access Control Lists (ACLs) on a Cisco IOS router. Which two statements correctly describe the operational characteristics of standard IPv4 ACLs?
Select all that apply
An enterprise network operations center is aligning its infrastructure security framework with Cisco security baseline recommendations. Match each security program element or access control type on the left to its corresponding operational implementation on the right.
Click a left item, then click its matching right item
Items
Matches
A network engineer is configuring digital certificate authentication for Cisco Identity Services Engine (ISE) and enterprise network infrastructure. To ensure proper certificate deployment and validation, the engineer must correctly identify the operational function of each Public Key Infrastructure (PKI) element. Match each PKI component on the left to its corresponding primary function on the right.
Click a left item, then click its matching right item
Items
Matches
A network administrator applies an extended IPv4 Access Control List (ACL) containing only a single rule to an interface: `access-list 100 permit tcp host 192.168.1.10 host 10.0.0.5 eq 80`. What happens when a host with IP address 192.168.1.11 attempts to send HTTP traffic to 10.0.0.5?
A network administrator configures the following IPv4 extended named Access Control List (ACL) on a Cisco IOS router to control access to an internal application server at IP address 192.168.50.10:
text
ip access-list extended APP_FILTER
10 permit tcp 10.10.20.0 0.0.0.255 host 192.168.50.10 eq 80
20 permit tcp 10.10.20.0 0.0.0.255 host 192.168.50.10 eq 443
30 deny ip 10.10.20.0 0.0.0.255 host 192.168.50.10
40 permit ip host 10.10.20.5 host 192.168.50.10
The ACL is applied outbound on GigabitEthernet0/1. An administrator attempts an SSH connection (TCP port 22) from management host 10.10.20.5 to the application server (192.168.50.10), while a user on host 10.10.20.100 attempts a web connection (TCP port 80) to the same server.
Which statement accurately describes how the router processes these two traffic flows?
A network security engineer is implementing multi-factor authentication (MFA) for administrative switch access using a centralized AAA server. When the primary RADIUS server is unreachable, the switch falls back to a locally configured emergency user account, allowing administrators to log in using only a local password without prompting for a dynamic one-time passcode (OTP). Which operational factor explains why multi-factor authentication is bypassed during this fallback scenario?
A network security administrator is configuring digital certificate services and Multi-Factor Authentication (MFA) to secure management sessions on enterprise network infrastructure. Which of the following statements accurately describe digital certificate verification and MFA factor rules? (Select TWO.)
Select all that apply
A network engineer configures the following IPv4 extended named access control list (ACL) on a Cisco IOS router interface to filter traffic between host and web server :
text
ip access-list extended SECURE_VLAN
deny icmp host 10.20.5.15 host 192.168.100.50
permit tcp host 10.20.5.15 host 192.168.100.50 eq 80
permit tcp host 10.20.5.15 host 192.168.100.50 eq 443
Which two statements accurately describe the traffic filtering behavior enforced by this ACL? (Choose two.)
Select all that apply
A network administrator configures Dynamic ARP Inspection (DAI) on VLAN 10 of a Cisco Catalyst switch to prevent ARP spoofing. DHCP snooping is enabled and functioning properly. However, several servers connected to untrusted access ports use statically assigned IP addresses, causing DAI to drop their legitimate ARP requests because they lack entries in the DHCP snooping binding database. Which configuration action should the administrator perform to permit ARP traffic from these static servers while maintaining DAI protection on VLAN 10?
A network administrator is creating an IPv4 extended Access Control List (ACL 105) to allow HTTPS access from host 192.168.10.5 to web server 10.0.0.5, block all other TCP traffic from the 192.168.10.0/24 subnet to the 10.0.0.0/8 network, and permit all remaining traffic. In what sequential order from top to bottom should these ACL statements be configured to enforce the intended policy correctly?
Drag items to arrange them in the correct order
A network administrator is configuring an extended IPv4 access control list (ACL) named `FILTER_INTERNAL` on GigabitEthernet0/0/0 (inbound) on a Cisco IOS router. The objective is to enforce the following security policy for internal users on network :
1. Allow HTTPS traffic (TCP port 443) to the DMZ web server at .
2. Allow DNS domain queries (UDP port 53) to the DMZ DNS server at .
3. Explicitly drop and log all other traffic from directed to any host in the DMZ subnet ().
4. Permit all remaining traffic originating from destined to other corporate subnets or the Internet.
Which two configuration statements or operational logic requirements must be included in the ACL design to satisfy these requirements without blocking non-DMZ traffic?
Select all that apply
A network administrator wants to restrict access on a switch port to an authorized end device. If an unauthorized MAC address sends traffic to the port, the interface must drop the frames, avoid incrementing the security violation counter, and avoid disabling the port. Which port security violation mode meets this requirement?
An enterprise network administrator configures Dynamic ARP Inspection (DAI) on VLAN 10 using the command `ip arp inspection vlan 10`. Host devices dynamically receiving IPv4 configuration via DHCP operate without issue. However, a critical server connected to access switchport GigabitEthernet0/2 in VLAN 10 is configured with a static IPv4 address () and MAC address (). Network telemetry indicates that all network traffic from this server is dropped because DAI marks its ARP packets as invalid. Which configuration step correctly resolves the ARP packet drop for this static host while maintaining active DAI protection on VLAN 10?
Match each Layer 2 security mechanism or feature component on the left with its corresponding operational behavior on the right.
Click a left item, then click its matching right item
Items
Matches
A network administrator is implementing administrative security controls for enterprise network switches and configuring Public Key Infrastructure (PKI) certificate validation for HTTPS management access. When evaluating multi-factor authentication (MFA) factor categories and PKI digital certificate validation mechanics, which two statements are correct?
Select all that apply
An network administrator is troubleshooting traffic drops on switch port GigabitEthernet1/0/10. The interface is configured with Layer 2 security features including DHCP Snooping, Dynamic ARP Inspection (DAI), and Port Security in restrict mode. The output of `show ip dhcp snooping binding` displays a valid IP-to-MAC entry for the connected client on GigabitEthernet1/0/10. However, executing `show port-security interface g1/0/10` shows that the `SecurityViolation` counter is actively incrementing every time the host attempts to transmit data, while the port status remains operational (`secure-up`). Which scenario accounts for these symptoms?