Security Fundamentals

298 questions

Question 101Question

An enterprise organization is updating its Cisco Wireless Controller infrastructure to enforce WPA3-Enterprise 192-bit security mode across critical WLANs. During client validation, legacy 802.1X supplicants configured with AES-CCMP-128 encryption and EAP-TLS fail to associate with the SSID, whereas modern clients configured for 192-bit security connect successfully. Which technical requirement of WPA3-Enterprise 192-bit mode causes these legacy WPA2-Enterprise clients to fail association?

Show answer & explanation

Answer: WPA3-Enterprise 192-bit mode mandates GCMP-256 encryption and required Protected Management Frames (PMF), making CCMP-128 client suites incompatible.

Answer

WPA3-Enterprise 192-bit mode mandates GCMP-256 encryption and required Protected Management Frames (PMF), making CCMP-128 client suites incompatible.
WPA3-Enterprise 192-bit mode enforces a strict suite of cryptographic algorithms defined in CNSA (Commercial National Security Algorithm) guidelines. This requires Galois/Counter Mode Protocol with a 256-bit key (GCMP-256), HMAC-SHA384 key derivation, and mandatory Protected Management Frames (PMF) using BIP-GMAC-256. Clients offering legacy AES-CCMP-128 cannot satisfy these stringent RSN security capabilities and are rejected during association.

Step-by-Step Solution

1
Analyze WPA3-Enterprise 192-bit security requirements.
Identified that WPA3-Enterprise 192-bit mode requires specific robust cryptographic primitives: GCMP-256 for data confidentiality, HMAC-SHA384 for key derivation, and mandatory Protected Management Frames (PMF / IEEE 802.11w) with BIP-GMAC-256.
Security mandates for high-security deployment profiles require replacing 128-bit ciphers with 256-bit ciphers.
2
Compare legacy client configuration against WPA3-Enterprise 192-bit parameters.
Legacy clients attempting to associate with AES-CCMP-128 do not meet the minimum cipher requirements (GCMP-256) enforced by the WPA3-Enterprise 192-bit WLAN profile.
WLCs operating in 192-bit mode reject Robust Security Network (RSN) Capabilities IE proposals that offer lower-tier 128-bit ciphers.
3
Formulate the exact failure root cause.
The failure occurs due to mismatched cipher suites (CCMP-128 vs GCMP-256) and mandatory PMF requirements.
Both GCMP-256 and PMF enforcement are mandatory under 192-bit mode specification.

Key Concept

WPA3-Enterprise 192-bit Cryptographic Requirements and PMF Enforcement
Question 102Question

Match each wireless security protocol standard on the left with its defining cryptographic capability or key exchange mechanism on the right.

Click a left item, then click its matching right item

Items

WPA (Legacy)
WPA2-Personal
WPA3-Personal
WPA3-Enterprise

Matches

Show answer & explanation

Answer

WPA (Legacy) pairs with TKIP/RC4 cipher suite; WPA2-Personal pairs with AES-CCMP and PSK 4-way handshake; WPA3-Personal pairs with SAE key exchange; WPA3-Enterprise pairs with mandatory PMF and optional 192-bit security mode.
Each wireless security protocol standard corresponds directly to its cryptographic cipher suite and authentication mechanism: legacy WPA uses TKIP/RC4, WPA2-Personal uses AES-CCMP with PSK authentication, WPA3-Personal uses SAE to defend against dictionary attacks, and WPA3-Enterprise enforces Protected Management Frames (PMF) alongside an optional 192-bit encryption suite.

Step-by-Step Solution

1
Identify the legacy WPA mechanism
WPA relies on TKIP and RC4 encryption.
Original WPA was created as an interim standard to improve WEP security without replacing hardware.
2
Identify WPA2-Personal standard features
WPA2-Personal standardizes AES-CCMP encryption with PSK authentication using a 4-way handshake.
IEEE 802.11i compliance mandated AES encryption for strong baseline confidentiality.
3
Identify WPA3-Personal enhancements
WPA3-Personal uses SAE (Simultaneous Authentication of Equals) instead of PSK.
SAE provides forward secrecy and protects against passive eavesdropping and offline dictionary attacks.
4
Identify WPA3-Enterprise features
WPA3-Enterprise mandates Protected Management Frames (PMF) and supports optional 192-bit encryption.
PMF protects management traffic against spoofing, while 192-bit mode supports high-security environments.

Key Concept

Wireless Security Protocols (WPA, WPA2, WPA3)
Question 103Question

A wireless network architect is reviewing enterprise security standards to align wireless LAN controller (WLC) profiles with IEEE 802.11 security specifications. Match each wireless security implementation on the left with its corresponding key exchange mechanism, cipher suite, or framing requirement on the right.

Click a left item, then click its matching right item

Items

WPA2-Personal Key Exchange
WPA3-Personal Key Exchange
WPA3-Enterprise 192-bit Security Mode
WPA2-Enterprise Core Architecture

Matches

Show answer & explanation

Answer

WPA2-Personal Key Exchange matches the standard 4-Way Handshake utilizing a static Pre-Shared Key (PSK); WPA3-Personal Key Exchange matches Simultaneous Authentication of Equals (SAE) via Dragonfly handshake; WPA3-Enterprise 192-bit Security Mode matches GCMP-256 with mandatory BIP-GMAC-256 Protected Management Frames; WPA2-Enterprise Core Architecture matches IEEE 802.1X framework with dynamic EAP/RADIUS authentication.
Each wireless security protocol implementation correctly pairs with its key exchange protocol, authentication framework, and cipher suite requirements according to IEEE 802.11i and 802.11ax standards.

Step-by-Step Solution

1
Analyze WPA2-Personal authentication and encryption mechanics.
Identify that WPA2-Personal relies on a Pre-Shared Key (PSK) converted via PBKDF2 into a static PMK, which undergoes a 4-Way Handshake to establish the PTK.
Understanding the vulnerability of WPA2-Personal to passive capture and offline dictionary cracking helps distinguish it from SAE.
2
Analyze WPA3-Personal key exchange enhancements over WPA2.
Identify that WPA3-Personal introduces Simultaneous Authentication of Equals (SAE) using the Dragonfly key exchange protocol.
SAE prevents dictionary attacks by requiring interactive proof of password knowledge without transmitting password derivatives directly usable in offline calculation.
3
Evaluate WPA3-Enterprise 192-bit mode cryptographic primitives.
Confirm requirement of 256-bit symmetric encryption using GCMP-256 and BIP-GMAC-256 for management frame protection.
192-bit mode aligns with NSA Commercial National Security Algorithm (CNSA) suite specifications, upgrading from CCMP-128.
4
Differentiate Enterprise authentication models from Personal authentication models.
Associate 802.1X, EAP types (PEAP, EAP-TLS, EAP-FAST), and RADIUS integration with enterprise mode.
Enterprise implementations utilize centralized identity stores and dynamic key generation rather than shared static credentials.

Key Concept

Wireless Security Protocols, Authentication Frameworks, and Cipher Suites (WPA2/WPA3 Personal vs Enterprise)
Question 104Question

An enterprise organization is updating its Cisco Wireless LAN Controller (WLC) security baseline to align with WPA3 specification standards across all branch locations. Which TWO architectural and security protocol enhancements are introduced when transitioning infrastructure from WPA2 to WPA3? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: WPA3-Personal replaces the PSK 4-way handshake with Simultaneous Authentication of Equals (SAE) to provide forward secrecy and mitigate offline dictionary attacks.; WPA3 mandates the implementation of Protected Management Frames (PMF / IEEE 802.11w) for all client connections to protect unicast and multicast management actions against spoofing.

Answer

WPA3 introduces key cryptographic enhancements: WPA3-Personal replaces standard PSK handshakes with Simultaneous Authentication of Equals (SAE) to guard against offline brute-force attacks, and WPA3 mandates Protected Management Frames (PMF/802.11w) to stop management frame spoofing.
WPA3 enhances wireless network security by introducing Simultaneous Authentication of Equals (SAE) for Personal modes to defend against offline dictionary attacks and enforcing Protected Management Frames (PMF / IEEE 802.11w) to stop deauthentication attacks.

Step-by-Step Solution

1
Analyze WPA3-Personal authentication improvements over WPA2-PSK.
Identified that WPA3-Personal replaces the 4-way PSK handshake with Simultaneous Authentication of Equals (SAE), preventing offline dictionary attacks even with weak passwords.
SAE uses Dragonfly key exchange providing forward secrecy.
2
Evaluate Management Frame Protection requirements in WPA3.
Identified that IEEE 802.11w (PMF) is mandatory for WPA3 connections.
PMF prevents attackers from forging deauthentication or disassociation frames to cause denial of service.
3
Evaluate cipher suite and enterprise authentication claims.
Disqualified TKIP as legacy/insecure and verified that 802.1X authentication remains a requirement for enterprise mode.
WPA3 mandates strong ciphers (CCMP/GCMP) and standard RADIUS/802.1X for WPA3-Enterprise.

Key Concept

WPA3 Wireless Security Enhancements (SAE and PMF)
Estimated Time:1m 30s
Question 105Question

A network administrator is upgrading a wireless deployment to implement the WPA3-Personal security standard. Which key exchange mechanism does WPA3-Personal introduce to protect against offline dictionary attacks?

Show answer & explanation

Answer: Simultaneous Authentication of Equals (SAE)

Answer

Simultaneous Authentication of Equals (SAE)
Simultaneous Authentication of Equals (SAE) is the mandatory replacement for Pre-Shared Key (PSK) authentication in WPA3-Personal. SAE utilizes the Dragonfly handshake protocol, which prevents attackers from performing offline dictionary attacks against captured wireless handshakes.

Step-by-Step Solution

1
Identify the key security enhancement introduced specifically in WPA3-Personal over WPA2-Personal.
WPA3-Personal replaces the standard PSK 4-way handshake with a key exchange protocol resistant to password guessing attacks.
WPA2-Personal relied on a pre-shared key (PSK) 4-way handshake that was susceptible to offline dictionary attacks if an attacker captured the initial handshake frames.
2
Match the protocol mechanism name with its function in WPA3.
Simultaneous Authentication of Equals (SAE) is the Dragonfly-based key exchange mechanism that fulfills this requirement.
SAE provides forward secrecy and prevents brute-force passive offline dictionary cracking attempts even when weak passphrases are used.

Key Concept

WPA3-Personal SAE Key Exchange Mechanism
Question 106Question

A network administrator configures an extended IPv4 access control list (ACL 102) on a Cisco IOS router to restrict traffic from the internal LAN subnet 172.16.10.0/24172.16.10.0/24 to an external server at IP address 192.168.50.10192.168.50.10. The administrator enters the following CLI commands:

`access-list 102 permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 80`
`access-list 102 permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 443`

After applying ACL 102 inbound on interface GigabitEthernet0/0, users report that HTTP and HTTPS access to 192.168.50.10192.168.50.10 works properly, but all DNS resolution queries to an internal server at 172.16.10.2172.16.10.2 and internet browsing to other hosts are failing. Which statement correctly explains why all other traffic originating from the internal subnet is being blocked?

Show answer & explanation

Answer: The router processes traffic sequentially and drops all unlisted traffic due to the implicit deny clause located at the end of the access control list.

Answer

The router evaluates traffic against ACL 102 sequentially from top to bottom and drops all unlisted packets because of the invisible implicit deny clause ('deny ip any any') appended at the end of every IPv4 ACL.
In Cisco IOS networking, all standard and extended IPv4 Access Control Lists end with an invisible 'implicit deny' statement (conceptually `deny ip any any`). Packets entering an interface with an applied ACL are compared against statements top-down. Because ACL 102 only explicitly permits TCP ports 80 and 443 to host 192.168.50.10192.168.50.10, all other traffic—including DNS (UDP port 53) and traffic destined for other IP addresses—reaches the end of the ACL and is dropped by the implicit deny rule.

Step-by-Step Solution

1
Analyze the configured access list statements
ACL 102 explicitly permits only TCP destination port 80 (HTTP) and TCP destination port 443 (HTTPS) traffic from source 172.16.10.0/24172.16.10.0/24 to destination 192.168.50.10192.168.50.10.
Top-down ACL evaluation checks each incoming packet against these two rules first.
2
Evaluate how non-HTTP/HTTPS traffic is handled
DNS queries (UDP/TCP port 53) and general IP traffic destined for other IP addresses do not match either of the explicit permit statements.
When no explicit permit statement matches a packet, processing reaches the end of the access list.
3
Apply Cisco IOS default ACL behavior
All non-matching traffic is dropped by the unwritten implicit deny clause ('deny ip any any').
To allow other traffic, explicit permit statements (such as 'permit ip any any' or specific service permits) must be configured.

Key Concept

Implicit Deny Clause in IPv4 ACLs
Estimated Time:1m 30s
Question 107Question

A network engineering team requires strict per-command authorization and per-command audit logging for administrative CLI access on core Cisco switches. Every individual command entered by a logged-in administrator must be evaluated against central security policies before execution. Which protocol selection and architectural behavior correctly satisfies these operational requirements?

Show answer & explanation

Answer: TACACS+, because its modular AAA architecture separates authentication and authorization, sending distinct TCP-based authorization requests for each individual command entered.

Answer

TACACS+, because its modular AAA architecture separates authentication and authorization, sending distinct TCP-based authorization requests for each individual command entered.
The correct selection identifies TACACS+ as the protocol that decouples authentication and authorization over TCP port 49 with full-packet payload encryption. This modular separation enables network devices to send an authorization request for every CLI command entered by an administrator.

Step-by-Step Solution

1
Analyze the functional access control requirement.
The requirement calls for per-command administrative authorization and CLI logging on network infrastructure devices.
Device administration requires fine-grained control over CLI commands, which is supported natively by TACACS+.
2
Compare protocol separation mechanics between TACACS+ and RADIUS.
TACACS+ completely decouples Authentication, Authorization, and Accounting (AAA), whereas RADIUS combines Authentication and Authorization into single protocol exchanges.
Decoupling authorization allows a NAS (network access server) to request explicit permission for individual CLI commands after a user has already authenticated.
3
Evaluate transport and security mechanisms for TACACS+ vs RADIUS.
TACACS+ uses TCP port 49 and encrypts the entire packet payload (body). RADIUS uses UDP ports 1812/1813 and encrypts only the password attribute.
TCP guarantees reliable delivery for per-command authorization packets, and full-payload encryption protects command strings and output sent across the network.

Key Concept

TACACS+ vs RADIUS Protocol Architecture and AAA Function Separation
Question 108Question

An administrator applies the following IPv4 extended named access control list (ACL) inbound on interface GigabitEthernet0/0/1 of a Cisco IOS router:

ip access-list extended FILTER_WEB
permit tcp 10.10.1.0 0.0.0.255 host 172.16.10.50 eq 80
permit tcp 10.10.1.0 0.0.0.255 host 172.16.10.50 eq 443

Which two statements accurately describe how traffic arriving on interface GigabitEthernet0/0/1 is evaluated by this ACL?

Select all that apply

Show answer & explanation

Answer: HTTP traffic originating from host 10.10.1.25 and destined for server 172.16.10.50 on port 80 is permitted.; ICMP echo requests sent from host 10.10.1.25 to destination server 172.16.10.50 are dropped by the router.

Answer

HTTP traffic on port 80 from subnet 10.10.1.0/24 to 172.16.10.50 is permitted by the first ACL entry, while ICMP traffic is dropped due to the implicit deny at the end of the access list.
The extended ACL explicitly allows TCP traffic on port 80 from the 10.10.1.0/24 network to destination host 172.16.10.50. Any protocol or traffic type not explicitly permitted—such as ICMP or UDP traffic—matches the implicit deny clause at the end of the ACL and is dropped by the router.

Step-by-Step Solution

1
Evaluate the explicit permit statements in the ACL configuration sequentially from top to bottom.
Rule 1 permits TCP traffic from 10.10.1.0/24 to host 172.16.10.50 on port 80. Rule 2 permits TCP traffic from 10.10.1.0/24 to host 172.16.10.50 on port 443.
Top-down sequential matching permits HTTP and HTTPS traffic matching the specified source subnet and destination host IP.
2
Evaluate non-matching traffic types (such as ICMP and UDP) against the ACL end condition.
Traffic types not matched by explicit permit statements fall through to the default implicit deny clause (deny ip any any).
All Cisco IOS ACLs end with an implicit deny all statement that drops any packet not explicitly permitted.

Key Concept

Extended IPv4 Access Control List Sequential Processing and Implicit Deny Behavior
Question 109Question

A network security administrator needs to configure a local database user account named 'opsman' on a Cisco IOS XE router. The requirement specifies using PBKDF2 with SHA-256 hashing (Type 8 encryption) to securely store the plaintext password 'Secur3#Pass2026'. Which Cisco IOS global configuration command correctly satisfies this requirement?

Show answer & explanation

Answer: username opsman secret algorithm-type pbkdf2 Secur3#Pass2026

Answer

The command 'username opsman secret algorithm-type pbkdf2 Secur3#Pass2026' correctly configures the local account with PBKDF2 (Type 8) password hashing.
In Cisco IOS XE, creating a local database user account with PBKDF2 hashing (Type 8) from a cleartext string requires the syntax 'username <name> secret algorithm-type pbkdf2 <plaintext_password>'. The router automatically computes the SHA-256 PBKDF2 hash and stores it in the running configuration as a Type 8 secret.

Step-by-Step Solution

1
Identify the target requirement
The goal is to configure a local user secret using PBKDF2 (Type 8 encryption) from a cleartext input password on Cisco IOS XE.
Cisco IOS XE supports enhanced password hashing algorithms via the 'secret' command branch.
2
Evaluate Cisco IOS XE syntax rules for local user database creation
The 'username <name> secret algorithm-type <type> <password>' syntax is used to define cleartext passwords hashed with specific algorithms such as pbkdf2 or scrypt.
Using 'secret algorithm-type pbkdf2' specifies Type 8 SHA-256 PBKDF2 hashing.
3
Differentiate from incorrect options
The 'password' keyword cannot take hashing algorithms, the literal number '8' expects an already computed hash string, and 'service password-encryption' is a global command for legacy Type 7 encryption.
Syntax elements must match the command state and input format expected by IOS XE.

Key Concept

Local database user authentication and password hashing algorithms (Type 5 MD5, Type 8 PBKDF2, Type 9 scrypt, Type 7 service password-encryption).
Question 110Question

Match each Cisco Layer 2 security feature or operational state on the left to its corresponding operational behavior on the right.

Click a left item, then click its matching right item

Items

Port Security (Restrict Mode)
DHCP Snooping Untrusted Interface
Dynamic ARP Inspection (DAI)
Port Security (Sticky MAC)

Matches

Show answer & explanation

Answer

Port Security (Restrict Mode) matches with dropping unauthorized frames, incrementing the violation counter, and logging without shutting the interface down. DHCP Snooping Untrusted Interface matches with blocking incoming DHCP server responses and building the binding table from client traffic. Dynamic ARP Inspection (DAI) matches with intercepting and validating ARP packets against the binding database. Port Security (Sticky MAC) matches with dynamically adding learned MAC addresses as secure entries in the running configuration.
Each feature maps to its exact Cisco IOS operational behavior: Restrict mode logs and drops without disabling the port; DHCP Snooping untrusted ports drop server responses; DAI validates ARP frames against the DHCP binding table; and Sticky MAC converts dynamically learned addresses into running-config entries.

Step-by-Step Solution

1
Analyze Port Security violation modes
Identify that 'restrict' drops traffic, logs a message, and increments counters without disabling the port (unlike 'shutdown' mode which err-disables the interface).
Differentiating between protect, restrict, and shutdown modes is essential for Layer 2 access control.
2
Analyze DHCP Snooping interface roles
Recognize that untrusted ports drop DHCP server response packets (DHCPOFFER, DHCPACK) to prevent rogue DHCP server attacks.
DHCP Snooping enforces trust boundaries between user access ports (untrusted) and legitimate DHCP server ports (trusted).
3
Analyze Dynamic ARP Inspection mechanics
Confirm DAI checks incoming ARP packets on untrusted interfaces against the DHCP Snooping IP-to-MAC binding database.
DAI depends on the integrity of the DHCP Snooping binding table to mitigate man-in-the-middle ARP spoofing.
4
Analyze Sticky MAC address persistence
Verify that sticky MAC learning places dynamically discovered MAC addresses directly into the active running configuration.
Sticky MAC addresses persist in memory until saved to startup-config via copy running-config startup-config.

Key Concept

Layer 2 security mitigations (Port Security violation modes, DHCP Snooping trust roles, and Dynamic ARP Inspection validation mechanics).
Question 111Question

A network operations team is auditing access control protocols used across enterprise routers and switches. When comparing TACACS+ and RADIUS protocol implementations, which TWO functional characteristics belong specifically to TACACS+? (Select TWO.)

Select all that apply

Show answer & explanation

Answer: It utilizes TCP port 49 and encrypts the entire payload of the packet.; It completely separates authentication and authorization into independent operational processes.

Answer

The two correct functional characteristics of TACACS+ are that it utilizes TCP port 49 while encrypting the entire packet payload, and it completely separates authentication and authorization into independent operational processes.
TACACS+ is primarily engineered for administrative device access control. It uses TCP port 49 and provides full-packet payload encryption. Furthermore, TACACS+ strictly separates the authentication, authorization, and accounting functions, which permits network administrators to implement granular command-level authorization policies independently of user authentication.

Step-by-Step Solution

1
Analyze transport layer behavior and security mechanics for TACACS+.
TACACS+ uses TCP port 49 and encrypts the entire payload.
TACACS+ relies on connection-oriented TCP for reliable communication and encrypts all packet payload data beyond the header.
2
Evaluate functional separation within the AAA architecture for TACACS+.
TACACS+ decouples authentication, authorization, and accounting.
Separating authorization from authentication enables precise, per-command CLI access control during device administration sessions.

Key Concept

TACACS+ vs RADIUS Protocol Architecture and Operational Mechanics
Estimated Time:2m 0s
Question 112Question

A network administrator configures a numbered standard IPv4 access control list on a Cisco IOS router to permit management access from the Network Operations Center (NOC) subnet 192.168.10.0/24192.168.10.0/24 while blocking all other hosts. The administrator enters the following commands:

text
Router(config)# access-list 15 permit 192.168.10.0 0.0.0.255
Router(config)# line vty 0 4
Router(config-line)# access-class 15 in

After applying this configuration, which traffic outcome occurs when an administrator at IP address 192.168.10.45192.168.10.45 attempts an SSH connection to the router's VTY interface, and why?

Show answer & explanation

Answer: The SSH session is permitted because the source IP address matches the permit entry in ACL 15.

Answer

The SSH connection attempt from IP address 192.168.10.45 is permitted because it matches the permit statement for network 192.168.10.0 with wildcard mask 0.0.0.255 in access-list 15.
The incoming SSH connection attempt originates from 192.168.10.45, which falls inside the 192.168.10.0/24 IP network range matched by wildcard mask 0.0.0.255. When the packet is checked against access-list 15 applied inbound on the VTY lines via the access-class command, it hits the first rule, matches, and is permitted.

Step-by-Step Solution

1
Analyze the ACL entry network range and wildcard mask
Network 192.168.10.0 with wildcard mask 0.0.0.255 matches source IP addresses in the range 192.168.10.0 to 192.168.10.255.
Wildcard mask bits of 0 require exact matching of octet values, while 255 allows any value in the fourth octet.
2
Evaluate the incoming SSH source IP address against ACL 15 sequentially
IP address 192.168.10.45 matches the first statement: access-list 15 permit 192.168.10.0 0.0.0.255.
ACL processing evaluates statements top-down until a match is found.
3
Determine line VTY access policy application
Traffic matching a permit line in an access-class in ACL applied to line vty is allowed through to establish the administrative management connection.
Once a permit match occurs, ACL evaluation terminates and the action specified in the matched statement (permit) is executed.

Key Concept

Standard IPv4 ACL Evaluation and VTY Line Application
Question 113Question

A network administrator needs to harden administrative access on a Cisco IOS XE router. The requirement specifies that users connecting via SSH must authenticate against the local device user database, and privileged EXEC mode access must be protected using Type 9 (scrypt) password hashing. Which two CLI configuration tasks must be performed to meet these security requirements? (Select two.)

Select all that apply

Show answer & explanation

Answer: Configure enable secret algorithm-type scrypt <password> in global configuration mode.; Execute the login local command under line vty configuration mode.

Answer

The two required CLI configuration tasks are configuring enable secret algorithm-type scrypt <password> in global configuration mode and executing login local under line vty configuration mode.
Configuring enable secret with the algorithm-type scrypt option enforces strong Type 9 hashing for privileged EXEC access, and issuing login local under line vty mode forces VTY remote access to validate credentials against local user database accounts.

Step-by-Step Solution

1
Identify the command required to enforce strong Type 9 privileged EXEC password protection.
Executing enable secret algorithm-type scrypt <password> creates a Type 9 password hash using the scrypt key derivation function for privileged EXEC mode.
Cisco IOS XE supports Type 9 scrypt encryption, which provides significantly stronger protection than standard Type 5 MD5 or Type 7 obfuscation.
2
Identify the line configuration command required for local user database authentication on VTY lines.
Navigating to line vty configuration mode and executing login local configures VTY sessions to authenticate incoming connections against accounts created in the local database.
Using the standalone login command checks only a line-level password, whereas login local directs authentication to the local username database.

Key Concept

Cisco IOS Local User Authentication and Password Hashing Types
Question 114Question

A network engineer must enforce a security policy requiring real-time validation of individual CLI commands executed during administrator sessions on enterprise switches. Additionally, the policy dictates that the entire communication payload between the switch and the AAA server must be encrypted. Which protocol and operational mechanism fulfill these security requirements?

Show answer & explanation

Answer: TACACS+, because it operates over TCP and decouples authorization from authentication, allowing per-command validation while encrypting the entire packet payload.

Answer

TACACS+ is the correct choice because it uses TCP transport, decouples AAA functions to enable individual command authorization, and encrypts the entire packet payload.
TACACS+ separates the AAA pillars into discrete operations, allowing an administrator to configure per-command authorization on network devices. Furthermore, TACACS+ runs over TCP port 49 and encrypts the entire packet body beyond the 12-byte header, satisfying all requirements specified in the scenario.

Step-by-Step Solution

1
Evaluate transport protocol and encryption characteristics
TACACS+ uses TCP port 49 and encrypts the entire packet payload (everything after the standard TACACS+ header). RADIUS uses UDP ports 1812/1813 and encrypts only the password field within Access-Request packets.
Security requirements call for full packet payload encryption.
2
Evaluate AAA functional separation for command-level authorization
TACACS+ fully separates Authentication, Authorization, and Accounting into distinct modular services, enabling per-command authorization checks before execution. RADIUS combines authentication and authorization in unified exchange messages.
Administrative command validation requires standalone authorization requests per CLI command.
3
Select the protocol that satisfies both requirements
Only TACACS+ satisfies both full packet payload encryption and decoupled per-command authorization.
Matching all technical and policy constraints leads directly to TACACS+.

Key Concept

TACACS+ vs RADIUS Protocol Capabilities and AAA Functional Separation
Question 115Question

A network administrator needs to configure an IPv4 extended named Access Control List (ACL) named SECURE_FLOW on a Cisco IOS router. The ACL must implement the following policy requirements in order:
1. Permit SSH access (TCP port 22) specifically from management host 10.20.1.15 to server 172.16.50.10.
2. Deny all other IP traffic originating from the 10.20.1.0/24 subnet targeted to server 172.16.50.10.
3. Permit all remaining IPv4 traffic originating from the 10.20.1.0/24 subnet to any destination.
4. Ensure all other IP traffic from any source not explicitly permitted is implicitly dropped.

Arrange the configuration command statements into the correct top-to-bottom sequential order to achieve this policy.

Drag items to arrange them in the correct order

Show answer & explanation

Answer

The correct sequence starts by entering named extended ACL configuration mode ('ip access-list extended SECURE_FLOW'), followed by the specific SSH permit statement ('permit tcp host 10.20.1.15 host 172.16.50.10 eq 22'), then the broader subnet server deny statement ('deny ip 10.20.1.0 0.0.0.255 host 172.16.50.10'), and finally the general subnet permit statement ('permit ip 10.20.1.0 0.0.0.255 any').
Cisco ACLs process rules sequentially from top to bottom and stop evaluating as soon as a packet matches an entry. Therefore, specific host exceptions must precede broader subnet rules. Entering named ACL configuration mode ('ip access-list extended SECURE_FLOW') is required first. Next, permitting SSH from host 10.20.1.15 to server 172.16.50.10 must come before denying the entire 10.20.1.0/24 subnet to host 172.16.50.10; otherwise, 10.20.1.15 would match the subnet deny rule and be blocked. Permitting 10.20.1.0/24 to any destination must come after the specific server block so other outbound traffic is allowed before hitting the implicit deny any.

Step-by-Step Solution

1
Define the ACL header
Enter configuration mode for named extended ACL 'SECURE_FLOW'
Cisco IOS requires defining the ACL scope before adding sequential filtering statements.
2
Place the most specific exception statement at the top
Add 'permit tcp host 10.20.1.15 host 172.16.50.10 eq 22'
Cisco ACL processing evaluates entries sequentially top-to-bottom and stops at the first match. The specific host-to-host SSH permit must be evaluated before any broader block rule.
3
Place the restrictive subnet-to-server block rule next
Add 'deny ip 10.20.1.0 0.0.0.255 host 172.16.50.10'
This blocks all remaining hosts on 10.20.1.0/24 from reaching server 172.16.50.10 while allowing host 10.20.1.15's SSH traffic already permitted in step 2.
4
Place the general subnet permit rule last among explicit statements
Add 'permit ip 10.20.1.0 0.0.0.255 any'
This allows the 10.20.1.0/24 subnet to reach all other destinations while relying on the built-in implicit deny at the bottom to drop any unmentioned traffic.

Key Concept

Cisco IOS Access Control Lists evaluate matching statements in sequential top-down order, terminating evaluation immediately upon finding the first match.
Question 116Question

A network engineer observes the following partial running configuration on a Cisco IOS XE switch:

text
username netops privilege 15 secret Cisc0#2026!
!
line vty 0 4
password 7 094F471A1A0A
login
!

When administrators attempt to establish a remote SSH session to the switch, the prompt requests only a line password rather than asking for user credentials. Which command must be configured under line configuration mode to enforce authentication against the local user database?

Show answer & explanation

Answer: login local

Answer

The command 'login local' must be configured under line configuration mode to require local database authentication.
Configuring 'login local' under line configuration mode instructs Cisco IOS to authenticate incoming VTY session users using usernames and passwords stored in the router's local user database.

Step-by-Step Solution

1
Analyze current line configuration
The current line configuration contains the keyword 'login', which only checks the line password specified by 'password 7 094F471A1A0A'.
The standard 'login' keyword directs Cisco IOS to validate against line-specific passwords rather than individual user accounts.
2
Determine the required authentication behavior
Local user account 'netops' exists in global configuration, requiring VTY lines to perform local database lookups.
Security best practices demand individual accountability using local database credentials instead of shared line passwords.
3
Select the correct CLI command for line configuration mode
Configuring 'login local' under 'line vty 0 4' replaces line password authentication with local database authentication.
The 'local' parameter appended to 'login' explicitly directs the line interface to consult the device local account database for login verification.

Key Concept

Local Database Authentication on Cisco IOS Lines
Estimated Time:1m 0s
Question 117Question

An administrator applies the following extended IPv4 access control list outbound on interface GigabitEthernet0/0/1 to permit HTTP traffic from the Sales VLAN (10.1.10.0/2410.1.10.0/24) to an internal Web Server (192.168.1.100192.168.1.100):

text
access-list 110 permit tcp 10.1.10.0 0.0.0.255 host 192.168.1.100 eq 80

After applying `ip access-group 110 out` on the interface, users in the Sales VLAN report that while HTTP access works, they can no longer send ICMP echo requests to the Web Server or access the corporate DNS server (192.168.1.2192.168.1.2) located on the same subnet. Which condition is causing this traffic interruption?

Show answer & explanation

Answer: The unwritten implicit deny clause at the end of the ACL drops all IP traffic that does not explicitly match the permit statement.

Answer

The implicit deny statement at the end of the ACL drops all IP traffic that does not explicitly match the single permit entry.
Every Cisco IPv4 Access Control List includes an invisible implicit deny statement at the end (`deny ip any any`). Because ACL 110 only explicitly permits TCP traffic to port 80 on host 192.168.1.100, all other IP traffic—including ICMP ping requests and UDP DNS traffic to 192.168.1.2—is dropped by the implicit deny clause.

Step-by-Step Solution

1
Analyze the applied ACL configuration
ACL 110 contains only one line permitting TCP traffic from 10.1.10.0/24 to host 192.168.1.100 on port 80.
Identify what traffic is explicitly allowed by the configured rules.
2
Evaluate non-matching traffic behavior
ICMP (ping) and UDP port 53 (DNS) traffic do not match the TCP port 80 rule.
Traffic that fails to match any explicit ACL rule falls through to the implicit deny at the end of the list (`deny ip any any`).
3
Determine the solution to restore required connectivity
Additional permit statements (such as permitting ICMP or DNS, or a trailing `permit ip any any` if general traffic is allowed) must be appended to the ACL.
Explicit permit entries are required to prevent unintended traffic drops caused by the implicit deny.

Key Concept

ACL Implicit Deny Any behavior and extended IPv4 statement evaluation order
Question 118Question

A network engineer is implementing Layer 2 security controls across access switches in an enterprise network. The design requires deploying Dynamic ARP Inspection (DAI) alongside DHCP Snooping to mitigate ARP spoofing attacks. Which TWO statements correctly describe the operational interactions and interface trust requirements for these features?

Select all that apply

Show answer & explanation

Answer: DAI inspects incoming ARP requests and responses on untrusted interfaces by validating the IP-to-MAC mapping against the DHCP snooping binding database.; Access ports connected to end-user host workstations should be configured as untrusted for both DHCP Snooping and Dynamic ARP Inspection.

Answer

The correct statements are that DAI inspects incoming ARP packets on untrusted interfaces against the DHCP snooping binding database, and that user-facing access ports must be set as untrusted for both security features.
Dynamic ARP Inspection (DAI) relies directly on the binding table populated by DHCP Snooping to validate ARP packets received on untrusted ports. In standard Layer 2 security deployments, host-facing access ports are designated as untrusted for both DHCP Snooping (blocking rogue DHCP server offers) and DAI (blocking spoofed ARP announcements).

Step-by-Step Solution

1
Analyze how Dynamic ARP Inspection (DAI) operates on untrusted interfaces.
DAI intercepts all ARP requests and responses on untrusted ports and verifies their IP-to-MAC bindings using the DHCP snooping binding database or static ARP ACLs.
This mechanism prevents man-in-the-middle ARP poisoning attacks on the local switch segment.
2
Evaluate port trust configurations for host-facing interfaces.
Access ports connecting client endpoints must remain untrusted for both DHCP Snooping and DAI.
Untrusted ports are subjected to rate limiting and packet validation checks to block unauthorized DHCP responses and spoofed ARP replies.
3
Evaluate misconceptions regarding database persistence and trunk VLAN mismatches.
Dynamic bindings are stored in RAM and not automatically written to startup-config. Furthermore, native VLAN mismatches affect trunking semantics but do not disable DAI filtering.
Understanding feature isolation prevents incorrect troubleshooting assumptions regarding switch state saving and multi-vlan trunking errors.

Key Concept

Dynamic ARP Inspection (DAI) and DHCP Snooping Integration and Port Trust States
Question 119Question

A network administrator is deploying a dual-compatibility wireless network on a Cisco Wireless LAN Controller (WLC) to support both modern WPA3-Personal endpoints and legacy WPA2-Personal devices under a single SSID. During initial validation, legacy WPA2 devices fail to complete the 802.11 association phase, while WPA3 devices connect successfully. Investigation reveals that the WLAN security profile is configured with Simultaneous Authentication of Equals (SAE) enabled, Protected Management Frames (PMF) set to "Required", and the encryption cipher suite restricted exclusively to GCMP-256. Which configuration modification on the WLC will enable legacy WPA2 clients to successfully associate while maintaining standard WPA3 Transition Mode operation?

Show answer & explanation

Answer: Configure PMF to "Optional" (Capable) and add AES-CCMP128 to the supported cipher suites alongside SAE and PSK authentication.

Answer

Configure PMF to "Optional" (Capable) and add AES-CCMP128 to the supported cipher suites alongside SAE and PSK authentication.
WPA3 Transition Mode allows a single SSID to service both WPA2-Personal and WPA3-Personal clients. WPA3 mandates Protected Management Frames (PMF/802.11w) and SAE key exchange. However, legacy WPA2 devices frequently do not support PMF or GCMP-256 ciphers. Configuring PMF to 'Optional' (Capable) and adding AES-CCMP128 cipher support permits legacy WPA2 devices to associate using standard PSK/CCMP-128 while allowing modern devices to connect using WPA3 SAE and mandatory PMF.

Step-by-Step Solution

1
Analyze WPA3-Personal requirements vs WPA2-Personal legacy compatibility.
WPA3 mandates Simultaneous Authentication of Equals (SAE) and Protected Management Frames (PMF / IEEE 802.11w). WPA2-Personal uses Pre-Shared Key (PSK) and optional PMF with AES-CCMP128.
Legacy devices fail association when PMF is set to 'Required' or when supported WPA2 ciphers (AES-CCMP128) are disabled.
2
Determine WPA3 Transition Mode configuration parameters on Cisco WLC.
PMF must be configured as 'Optional' (or 'Capable') rather than 'Required'. Both SAE and PSK must be enabled for Key Management, and AES-CCMP128 must be allowed as a cipher.
Setting PMF to Optional permits legacy WPA2 clients that lack 802.11w support to connect without PMF, while WPA3-capable clients are required to negotiate PMF and SAE.

Key Concept

WPA3 Transition Mode and Protected Management Frames (PMF/802.11w) Coexistence
Question 120Question

A network security administrator is aligning enterprise network management requirements with AAA framework services and protocol architecture. Match each operational task or network access requirement on the left with its corresponding AAA component or protocol mechanism on the right.

Click a left item, then click its matching right item

Items

Validating user credentials against a centralized directory server during an initial 802.1X supplicant connection
Restricting an authenticated operator from executing specific privilege level configuration commands on a router
Logging start and stop timestamps, user identity, and session byte counts for administrative sessions to a central database
Encrypting the complete body of transmission packets over connection-oriented TCP port 49 during administrative sessions

Matches

Show answer & explanation

Answer

Validating credentials maps to Authentication; restricting command execution maps to Authorization; logging timestamps and session data maps to Accounting; encrypting full packet bodies over TCP port 49 maps to TACACS+ Protocol Mechanics.
Each operational requirement directly corresponds to a fundamental pillar of the AAA framework or a specific protocol implementation detail: Authentication handles identity verification, Authorization enforces command and resource access rights, Accounting logs session and audit data, and TACACS+ provides full-payload encryption over TCP port 49.

Step-by-Step Solution

1
Identify the AAA pillar responsible for identity verification.
Validating user credentials against a central directory service establishes identity, which is the core function of Authentication.
Authentication answers the question 'Who are you?' by checking credentials.
2
Identify the AAA pillar responsible for enforcing permissions and command restrictions.
Controlling command access and restricting operational privileges maps to Authorization.
Authorization answers the question 'What are you allowed to do?' after identity has been established.
3
Identify the AAA pillar responsible for audit trailing and session metrics.
Recording timestamps, session statistics, and user activities maps to Accounting.
Accounting answers the question 'What did you do and for how long?' for compliance auditing.
4
Identify the security protocol characteristic involving full packet body encryption over TCP 49.
TCP port 49 transport with complete payload encryption is a defining feature of TACACS+.
Unlike RADIUS, which uses UDP and encrypts only the password field, TACACS+ encrypts the entire payload over TCP.

Key Concept

AAA Framework Functional Separation & TACACS+ vs RADIUS Architecture
PreviousPage 6 / 15Next
Security Fundamentals Practice Questions — Cisco CCNA — Page 6 | Examkin