All practice questions
2237 questions
A network administrator prepares a Request for Change (RFC) to perform a major firmware upgrade on the primary core switches of a enterprise network. The submitted RFC includes the technical rationale, a comprehensive risk impact analysis, results from pre-deployment sandbox testing, and a designated maintenance window schedule. During the Change Advisory Board (CAB) review, the committee defers approval due to an omitted required section. Which of the following critical elements was missing from the submitted RFC?
Match each out-of-band management operational requirement on the left with the most appropriate hardware management technology on the right.
Click a left item, then click its matching right item
Items
Matches
A network facility security officer is auditing physical defense mechanisms and environmental protection systems across an enterprise data center. Match each physical security or environmental vulnerability scenario on the left with the corresponding technical control on the right that provides appropriate mitigation.
Click a left item, then click its matching right item
Items
Matches
Match each enterprise high-availability mechanism or protocol on the left with its correct operational description on the right.
Click a left item, then click its matching right item
Items
Matches
An infrastructure manager is auditing the environmental and life-safety controls of a newly built core network distribution facility. The server room relies on a total-flooding clean-agent gaseous fire suppression system to protect high-density switches and fiber interconnects. During a simulated system test, concern is raised regarding structural room integrity and agent containment when the high-pressure gas discharges. Which HVAC and airflow control procedure must be implemented upon fire suppression activation to ensure maximum suppression effectiveness while preventing structural damage?
An organization needs to grant remote workers secure access to corporate web applications from unmanaged personal devices. Corporate policy prohibits installing dedicated VPN software or administrative agents on these personal endpoints while requiring full encryption for all remote web traffic. Which protocol and transport layer configuration must be permitted on the perimeter firewall to support this clientless remote access design?
During a scheduled high-availability failover test, a network administrator powers down Core Router A, which participates in a Virtual Router Redundancy Protocol (VRRP) group with Core Router B. Core Router A has a physical IP address of 10.1.10.2, Core Router B has a physical IP address of 10.1.10.3, and the VRRP virtual IP (VIP) is 10.1.10.1. Immediately following the shutdown, several workstations lose connection to remote networks. Troubleshooting reveals that these workstations have their default gateway statically configured as 10.1.10.2. What is the root cause of the connectivity failure?
A network security administrator is configuring centralized access control for managing enterprise switch and router CLI sessions. The security policy mandates two key capabilities: full packet payload encryption for all authorization traffic, and granular per-command authorization for administrative roles. Which of the following operational characteristics of TACACS+ satisfy these requirements when compared to RADIUS? (Select TWO.)
Select all that apply
A network security administrator is transitioning a segment from a stateful firewall to a router utilizing stateless extended IPv4 Access Control Lists (ACLs). The administrator configures an inbound ACL on the interface connecting internal monitoring workstations () to allow diagnostic queries to a remote Syslog server () using UDP port . After applying the ACL, technicians report that while outbound query packets are sent successfully, return diagnostic responses from the Syslog server are blocked. Which statement accurately explains why this communication failure occurs?
An organization deploys a client-based IPsec VPN solution for remote system administrators. During initial deployment testing, users connecting from home networks behind Network Address Translation (NAT) devices experience immediate packet drops when using IPsec with Authentication Header (AH). However, changing the VPN configuration to use Encapsulating Security Payload (ESP) resolves the issue and allows full connectivity. Which of the following best explains why the AH configuration failed in this scenario?
A network security engineer is performing a physical security audit of a high-density transaction processing facility. The audit reveals three distinct vulnerabilities: confidential packet data is leaking via unintended electromagnetic emissions from server chassis, unauthorized employees are frequently tailgating through access doors during shift changes, and intruders could potentially bypass door access controls by crawling through the hollow space above the suspended drop ceiling. Which of the following combinations of physical security measures directly mitigates all three identified vulnerabilities?
During a security assessment of an enterprise LAN segment, a network technician observes that host traffic intended for the default gateway at IP address is being redirected through an unauthorized laptop at . Packet inspection reveals that host machines are continuously receiving unsolicited frame updates mapping to MAC address `00:11:22:AA:BB:CC`, which belongs to the laptop. Which network attack type is taking place, and what is its primary vector?
A network manager is reviewing a proposed upgrade plan for a corporate wireless network. The organization requires per-user authentication tied to Active Directory so that individual access can be revoked immediately upon employee termination. A technician suggests deploying WPA3-Personal with a complex 32-character passphrase to avoid configuring an 802.1X RADIUS infrastructure. Which of the following best explains why this recommendation fails to meet the organization's security requirements?
A network administrator is overseeing the construction of a new network closet situated directly adjacent to a light manufacturing area that produces significant airborne dust and debris. Which environmental control should be configured for the network closet's HVAC system to prevent dust from entering the room when personnel open the entry door?
A network technician is configuring remote administrative access on a newly installed network switch. Which protocol should be enabled to ensure that command-line interface (CLI) sessions and authentication credentials are encrypted across the network?
A security analyst is auditing a wireless network transition from WPA2-Personal to WPA3-Personal across several satellite offices. The goal is to support modern WPA3 security enhancements while maintaining temporary backward compatibility for legacy WPA2 devices. Which TWO of the following configuration settings or protocols are required to properly achieve this deployment? (Select TWO)
Select all that apply
A network security analyst is investigating logs from multiple enterprise security incidents across the network infrastructure. Match each observed attack symptom and mechanism to its corresponding network attack vector.
Click a left item, then click its matching right item
Items
Matches
Match each wireless network symptom or issue to its corresponding root cause or scenario description.
Click a left item, then click its matching right item
Items
Matches
A network technician needs to establish direct administrative access to a network switch whose network interfaces are completely unreachable due to a network link failure. Which connection method provides dedicated out-of-band management to the command-line interface without relying on active network IP connectivity?
A network security engineer is establishing a hardened configuration baseline for a core switch cluster to mitigate internal eavesdropping and unauthorized access risks. A security audit highlights that device telemetry monitoring traffic exposes system OIDs and interface statistics in cleartext across the network, while unassigned access ports and default trunking settings present physical and logical intrusion risks. Which set of device hardening configurations correctly addresses all of these identified vulnerabilities according to industry best practices?