All practice questions
2237 questions
A network technician is configuring an Access Control List (ACL) on a router interface to allow web traffic to an internal web server at 192.168.1.50 via HTTPS (TCP port 443). The technician adds an explicit rule permitting this traffic. However, after applying the ACL, all other network traffic passing through the interface is immediately blocked, despite no explicit deny rules being added to the configuration. Which fundamental ACL feature causes this automatic blocking behavior?
A network security engineer is evaluating transport layer behavior and payload security differences between RADIUS and TACACS+ protocols during an infrastructure audit. Which of the following statements accurately describe characteristics of the TACACS+ protocol compared to RADIUS? (Select TWO).
Select all that apply
A network security team is transitioning from a passive out-of-band Network Intrusion Detection System (NIDS) TAP interface to an active in-band Network Intrusion Prevention System (NIPS) on an enterprise perimeter connection. Which of the following represent key operational advantages or trade-offs specific to deploying an inline NIPS compared to a passive NIDS? (Select TWO.)
Select all that apply
A network engineering team needs to upgrade the firmware and security policy configuration on a mission-critical, active/passive high-availability (HA) firewall pair. To adhere to enterprise change management best practices while ensuring minimal risk of unapproved downtime, in what sequence should the engineer execute these implementation steps?
Drag items to arrange them in the correct order
A network security administrator is configuring a stateful perimeter firewall and documenting how the device inspects incoming network traffic. When an initial TCP SYN packet initiating a new session arrives at the untrusted external interface destined for an internal server, the firewall executes specific operational phases to process the request. In what chronological order, from first to last, does the stateful firewall process this new incoming connection attempt?
Drag items to arrange them in the correct order
A network administrator is documenting the authentication sequence for remote users connecting to an enterprise network using an IKEv2 IPsec Virtual Private Network (VPN) with EAP authentication. Place the following phases and steps of the IKEv2 negotiation process in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network administrator receives security alerts from a passive Network Intrusion Detection System (NIDS) connected to a switch SPAN port, indicating that malicious payloads are reaching internal web servers. Although the NIDS successfully logs the suspicious traffic, it fails to stop the attacks. Which network security deployment modification would enable active packet dropping to prevent malicious traffic from reaching the servers?
A network technician discovers an unauthorized wireless router plugged into a corporate network switch port inside an unsecured conference room. The device is broadcasting a wireless network that mimics the legitimate company network to intercept employee credentials. Which of the following statements accurately describe this security threat? (Select TWO)
Select all that apply
Match each Virtual Private Network (VPN) protocol to its primary operational characteristic or protocol specification.
Click a left item, then click its matching right item
Items
Matches
Match each high-availability concept or operational mechanism on the left with its corresponding description on the right.
Click a left item, then click its matching right item
Items
Matches
An enterprise is upgrading its remote access infrastructure for network administrators who connect via remote VPN sessions to manage core routers and firewalls. The security policy mandates a central AAA authentication service that encrypts the entire packet payload during communication between the VPN gateway and the authentication server, while also supporting granular, command-level authorization. Which protocol should the network engineer configure on the VPN gateway to meet these security requirements?
During a routine audit of core network operations, a security analyst discovers that event logs generated by perimeter firewalls are occasionally dropped during bandwidth spikes. Additionally, network packet captures reveal that log messages are transmitted across the internal network in unencrypted text. Which configuration update will resolve log delivery failures while ensuring log confidentiality during transit?
A network administrator is upgrading a small office wireless access point from WPA2-Personal to WPA3-Personal. Which TWO of the following capabilities are standard security enhancements introduced by WPA3-Personal?
Select all that apply
A network security architect is designing a wireless infrastructure for a regional corporate facility. Organizational compliance rules require that every employee authenticate using individual Active Directory domain credentials managed through a centralized authentication server, while simultaneously utilizing modern AES-based cipher suites for confidentiality. Which wireless security standard and authentication mechanism combination fulfills all compliance requirements?
A network engineer is troubleshooting a remote access VPN deployment. Remote workers connecting via an IPsec IKEv2 client can successfully establish Phase 1 and Phase 2 Security Associations and access internal servers by IP address. However, when users attempt to connect to internal resources using hostnames such as `server1.corp.internal`, the lookup fails or resolves to public internet addresses. The engineer needs internal hostnames to be resolved by the corporate DNS server across the tunnel while preventing general internet web traffic from being redirected through the corporate network. Which of the following configuration changes should the engineer implement on the VPN gateway profile?
During a security incident investigation, a network analyst reviews packet captures from an ongoing Distributed Denial of Service (DDoS) event targeting an enterprise's web server. The logs reveal a high volume of inbound UDP traffic originating from standard network management servers on external networks. The attacker initiated this traffic by transmitting small query packets with a forged source IP address matching the victim's public server, inducing the external servers to transmit significantly larger response payloads back to the victim. Which of the following attack vectors is being executed in this scenario?
A network technician is establishing standard configuration baseline documentation for newly installed branch switches. Which of the following elements should be included as key components of an enterprise configuration baseline? (Select TWO.)
Select all that apply
An enterprise network engineer is designing a comprehensive network performance monitoring architecture. Match each telemetry protocol or monitoring technique on the left with its appropriate operational deployment objective on the right.
Click a left item, then click its matching right item
Items
Matches
A network infrastructure team is preparing a complex change to transition an enterprise data center's core routing infrastructure from a static routing model to an internal BGP (iBGP) topology. The proposed configuration updates have already been tested in a isolated sandbox environment and reviewed by the Change Advisory Board (CAB). Which of the following components must be formally documented within the final Request for Change (RFC) before the maintenance window is approved for execution?
An organization is deploying a remote access VPN solution and requires integration with a central AAA server for network administration access control. The security requirements dictate that authentication and authorization functions must be decoupled into separate processes, and the entire payload of each AAA transmission must be encrypted. Which protocol should the network administrator select?