All practice questions
2237 questions
Match each centralized authentication protocol or framework to its corresponding architectural design and operational characteristic.
Click a left item, then click its matching right item
Items
Matches
A network administrator needs to configure centralized log collection for core enterprise switches. Security policies require that all log messages sent across the network must be encrypted in transit. Which protocol and port combination should the administrator configure to securely transport Syslog data?
In enterprise network operations and security auditing, different logging protocols, severity levels, and monitoring frameworks fulfill distinct roles. Match each network auditing or logging component on the left with its correct operational description on the right.
Click a left item, then click its matching right item
Items
Matches
Match each high availability technology or redundancy concept on the left to its correct operational description on the right.
Click a left item, then click its matching right item
Items
Matches
A network security engineer is evaluating security monitoring controls and deployment topologies across an enterprise network. Match each intrusion detection or prevention architecture on the left with its defining operational characteristic or monitoring mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise network operations team needs to update the firmware across core network infrastructure following a vendor security disclosure. Place the standard operational steps of the patch management lifecycle in the correct order from first to last.
Drag items to arrange them in the correct order
Match each high availability or redundancy protocol/mechanism on the left with its precise operational characteristic or implementation detail on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise organization needs to mitigate a newly disclosed critical vulnerability affecting the operating system of its core infrastructure network devices. To ensure business continuity and adhere to standardized patch management governance, place the following operational steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network administrator is evaluating deployment topologies for intrusion security controls within a corporate network architecture. Which of the following statements accurately distinguish a passive Network Intrusion Detection System (NIDS) from an inline Network Intrusion Prevention System (NIPS)? (Select TWO.)
Select all that apply
A network engineer is configuring infrastructure devices to forward event logs to a centralized Security Information and Event Management (SIEM) server for auditing. Which TWO of the following configurations will ensure that log events are accurately correlated and securely transmitted across the network? (Select TWO.)
Select all that apply
A network security administrator is deploying a Network Intrusion Detection System (NIDS) connected to a hardware network TAP at the main datacenter perimeter. Which of the following operational characteristics and limitations apply specifically to this out-of-band NIDS architecture? (Select TWO).
Select all that apply
A network security team needs to implement intrusion monitoring across a high-throughput enterprise core switch link carrying latency-sensitive voice and transactional traffic. The security policy mandates that the monitoring deployment must not introduce latency, perform inline packet modification, or risk creating a single point of network failure if the monitoring service fails. Which deployment architecture and system type best meets these requirements?
A senior network security engineer is updating the centralized management architecture for core enterprise switches and firewalls. Enterprise compliance mandates that all administrative communications must completely separate authentication processes from command-by-command authorization rules, while encrypting the entire packet payload during transit across the management network. Which authentication protocol and transport configuration must the engineer deploy on the network access servers to satisfy all compliance parameters?
A network administrator implements a First Hop Redundancy Protocol (FHRP) across two core routers to maintain continuous gateway accessibility for end-user workstations. Which IP address must be assigned as the default gateway on the workstations to achieve seamless failover?
A network administrator is upgrading an enterprise monitoring infrastructure to comply with strict auditing standards. The current deployment experiences dropped log packets across congested WAN links and fails security audits due to cleartext management traffic across untrusted boundaries. Which protocol and transport configuration best satisfies the requirements for reliable, cryptographically protected log aggregation and secure device polling?
A network operations team is updating an organization's logging infrastructure across multiple branch office firewalls to meet strict compliance mandates. Currently, event log messages are transmitted across an untrusted WAN link using default unencrypted Syslog over UDP. The audit team requires that all remote log transmissions be encrypted to protect sensitive header and message contents, while also establishing a reliable, connection-oriented session. Which of the following transport configuration changes will meet these requirements?
A network security administrator is upgrading the centralized logging and management framework across core network switches to adhere to a strict zero-trust audit policy. The updated policy mandates that all forwarded event logs and SNMP polling queries must guarantee both cryptographic payload confidentiality (encryption) and data integrity/authentication during transit across administrative subnets. Which configuration combination should the network security administrator implement to meet all audit compliance requirements?
A network administrator receives a vendor security advisory requiring a critical operating system patch to be applied to perimeter firewalls. Before deploying this update to live production systems, which of the following operational practices represents the best approach to validate stability and prevent unplanned downtime?
An enterprise data center utilizes two edge routers, Edge-1 and Edge-2, configured with Hot Standby Router Protocol (HSRP) to provide default gateway redundancy for internal LAN clients. Edge-1 is configured with an HSRP priority of 120, while Edge-2 is configured with the default priority of 100. Both routers connect to downstream switches via their LAN interfaces and to separate ISP providers via their WAN interfaces. During a line cut on Edge-1's WAN circuit, internal LAN clients report a complete loss of internet connectivity. Network monitoring shows that Edge-1 remains the active HSRP router and continues accepting LAN traffic. Which of the following is the most likely cause of this failover failure?
Match each core component of the AAA security framework to its corresponding network security function.
Click a left item, then click its matching right item
Items
Matches