All practice questions
2237 questions
A network security engineer is analyzing a packet capture taken between a Network Access Server (NAS) and a centralized authentication server during a remote access connection attempt. The capture reveals that the authentication request is transmitted using UDP over port 1812. Further payload examination demonstrates that only the user password attribute within the packet is obfuscated using a shared secret and MD5 hashing, while the surrounding header information and username remain visible in plaintext. Based on these observed operational characteristics, which authentication protocol is in use, and what structural feature accounts for this payload exposure?
During a compliance audit of an organization's network monitoring infrastructure, an auditor notes that event log messages and SNMP telemetry are vulnerable to packet loss, eavesdropping, and tampering across WAN links. To remediate these findings, the security engineer must ensure that centralized log forwarding to the SIEM appliance guarantees delivery acknowledgment, encrypts message traffic over standard secure ports, and that SNMP polling enforces cryptographic user authentication along with payload privacy. Which of the following configuration sets correctly fulfills all specified requirements?
Match each intrusion detection or prevention concept with its corresponding operational characteristic.
Click a left item, then click its matching right item
Items
Matches
A network architecture team is updating its operational repository to streamline disaster recovery, infrastructure auditing, and physical capacity management workflows across a hybrid enterprise data center. Match each specialized network documentation artifact to its primary operational or troubleshooting application.
Click a left item, then click its matching right item
Items
Matches
A network administrator is establishing a standard patch management procedure for enterprise routers. Place the following steps of the software patch management lifecycle in the correct order from first to last.
Drag items to arrange them in the correct order
During a network security audit, an administrator discovers two major vulnerabilities on an enterprise network: internal administrative session credentials are being intercepted in cleartext by unauthorized packet sniffing, and stored database audit logs have been silently modified after an intrusion. To remediate these vulnerabilities and satisfy security compliance, the network engineering team must implement technical controls that explicitly protect the affected pillars of the CIA Triad. Which combination of security controls correctly restores confidentiality for administrative sessions while ensuring data integrity for the stored audit logs?
Match each Intrusion Detection/Prevention System (IDS/IPS) technology or deployment mode on the left with its corresponding operational characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
Match each authentication protocol or access control framework to its defining operational and architectural characteristics.
Click a left item, then click its matching right item
Items
Matches
Match each network logging and auditing component on the left with its corresponding primary function on the right.
Click a left item, then click its matching right item
Items
Matches
A network engineer configures two Layer 3 switches, Switch-1 and Switch-2, with Virtual Router Redundancy Protocol (VRRP) to provide default gateway redundancy for a server VLAN (). Switch-1 is configured with a VRRP priority of 110 and a physical SVI address of . Switch-2 has a priority of 100 and a physical SVI address of . The VRRP Virtual IP (VIP) is assigned as . After a network maintenance reboot, end-user servers lose connectivity to external subnets whenever Switch-1 undergoes maintenance, despite Switch-2 being fully operational. Troubleshooting reveals that all servers were manually statically configured with as their default gateway. Which of the following best explains why gateway redundancy failed and identifies the correct solution?
Match each Syslog severity level to its corresponding event description based on standard network auditing and logging specifications.
Click a left item, then click its matching right item
Items
Matches
A network engineering team must mitigate a critical zero-day privilege escalation vulnerability affecting core infrastructure routers. Which of the following represents the correct sequence of administrative and technical steps required to safely implement this software update according to standardized network maintenance procedures?
Drag items to arrange them in the correct order
Match each high availability and redundancy mechanism to its corresponding operational characteristics within an enterprise network design.
Click a left item, then click its matching right item
Items
Matches
A network security architect is designing an enterprise monitoring and threat mitigation strategy. Match each intrusion detection/prevention deployment model on the left with its corresponding technical implementation characteristic on the right.
Click a left item, then click its matching right item
Items
Matches
A senior network engineer is leading a major infrastructure upgrade to implement multi-chassis link aggregation and new VLAN topologies across an enterprise datacenter. To satisfy compliance and ensure minimal service disruption, the organization enforces a strict ITIL-aligned change control policy. Place the following phases of the change management lifecycle in the correct sequential order from first to last.
Drag items to arrange them in the correct order
A network administrator must remediate a critical software vulnerability discovered on an enterprise edge router. Arrange the standard patch management lifecycle procedures in the correct sequence from first to last.
Drag items to arrange them in the correct order
A network administrator needs to centralize administrative access for network switches using an authentication protocol that encrypts the entire packet payload. Which protocol best satisfies this requirement?
A network administrator needs to deploy a network security device at the perimeter that sits directly in the traffic flow to inspect incoming packets and actively drop detected malicious traffic in real time. Which device should be placed inline to meet this objective?
Which of the following operational characteristics correctly distinguish TACACS+ from RADIUS when evaluating centralized network access controls? (Select TWO.)
Select all that apply
An enterprise network uses two routers, Router-A and Router-B, to provide default gateway redundancy for the subnet using Hot Standby Router Protocol (HSRP). Router-A has a physical interface IP address of , Router-B has a physical interface IP address of , and the configured HSRP virtual IP (VIP) is . During scheduled maintenance, Router-A is rebooted, causing Router-B to successfully transition from Standby to Active status. However, hosts on the subnet immediately lose all outbound network access. Which of the following is the most likely cause of this issue?