Network Security
427 questions
An enterprise network security team notices an unexpected influx of inbound UDP traffic targeted at the organization's public web server IP address. Packet captures reveal that the incoming traffic consists of large, unsolicited DNS response payloads originating from various external open resolver servers on UDP port 53. Further investigation indicates that the web server itself never initiated any corresponding DNS queries. Which of the following attack types and mechanisms is actively occurring?
A network security administrator is auditing packet captures of an IKEv2 remote access VPN connection. Place the stages of the IPsec IKEv2 session setup in the correct chronological order from initial connection attempt to payload data transmission.
Drag items to arrange them in the correct order
A principal network security architect is evaluating the control and management plane hardening profile for a cluster of core Layer 3 switches deployed in a zero-trust enterprise architecture. To comprehensively secure management communications against eavesdropping and protect inter-switch trunk connections from unauthorized traffic manipulation and VLAN exploitation, which of the following configuration practices must be implemented? (Select TWO.)
Select all that apply
During a routine audit, a system administrator discovers that an internal API service running on a web server had its configuration settings modified without authorization. While the service remained continuously reachable and no sensitive customer records were exposed or viewed by unauthorized parties, the altered configuration caused transaction logs to record invalid data. Which principle of the CIA triad was directly compromised in this scenario, and which security mechanism specifically protects against this type of breach?
A network technician is preparing to deploy a new switch into a production environment. Which TWO of the following security configuration steps represent essential device hardening best practices for securing administrative management access? (Select TWO.)
Select all that apply
A network security administrator is establishing data protection policies for automated router configuration backups stored on a remote server. Which TWO of the following technical controls directly safeguard the Integrity pillar of the CIA triad for these backup files?
Select all that apply
A network security team is designing physical and environmental security controls for a new high-security cryptographic key server enclosure located inside a multi-tenant facility. The facility audit identified two primary vulnerability vectors: potential physical access through shared drop-ceiling spaces into the server enclosure, and risk of electromagnetic eavesdropping (TEMPEST risks) on unshielded cryptographic hardware. Additionally, localized water pipe leakage under the raised floor must be detected immediately without placing electrical components at risk of direct contact with conductive standing water. Which of the following physical and environmental measures should the network security engineer implement to directly mitigate these identified risks? (Select TWO.)
Select all that apply
A network facility security officer is auditing physical defense mechanisms and environmental protection systems across an enterprise data center. Match each physical security or environmental vulnerability scenario on the left with the corresponding technical control on the right that provides appropriate mitigation.
Click a left item, then click its matching right item
Items
Matches
An infrastructure manager is auditing the environmental and life-safety controls of a newly built core network distribution facility. The server room relies on a total-flooding clean-agent gaseous fire suppression system to protect high-density switches and fiber interconnects. During a simulated system test, concern is raised regarding structural room integrity and agent containment when the high-pressure gas discharges. Which HVAC and airflow control procedure must be implemented upon fire suppression activation to ensure maximum suppression effectiveness while preventing structural damage?
An organization needs to grant remote workers secure access to corporate web applications from unmanaged personal devices. Corporate policy prohibits installing dedicated VPN software or administrative agents on these personal endpoints while requiring full encryption for all remote web traffic. Which protocol and transport layer configuration must be permitted on the perimeter firewall to support this clientless remote access design?
A network security administrator is configuring centralized access control for managing enterprise switch and router CLI sessions. The security policy mandates two key capabilities: full packet payload encryption for all authorization traffic, and granular per-command authorization for administrative roles. Which of the following operational characteristics of TACACS+ satisfy these requirements when compared to RADIUS? (Select TWO.)
Select all that apply
A network security administrator is transitioning a segment from a stateful firewall to a router utilizing stateless extended IPv4 Access Control Lists (ACLs). The administrator configures an inbound ACL on the interface connecting internal monitoring workstations () to allow diagnostic queries to a remote Syslog server () using UDP port . After applying the ACL, technicians report that while outbound query packets are sent successfully, return diagnostic responses from the Syslog server are blocked. Which statement accurately explains why this communication failure occurs?
An organization deploys a client-based IPsec VPN solution for remote system administrators. During initial deployment testing, users connecting from home networks behind Network Address Translation (NAT) devices experience immediate packet drops when using IPsec with Authentication Header (AH). However, changing the VPN configuration to use Encapsulating Security Payload (ESP) resolves the issue and allows full connectivity. Which of the following best explains why the AH configuration failed in this scenario?
A network security engineer is performing a physical security audit of a high-density transaction processing facility. The audit reveals three distinct vulnerabilities: confidential packet data is leaking via unintended electromagnetic emissions from server chassis, unauthorized employees are frequently tailgating through access doors during shift changes, and intruders could potentially bypass door access controls by crawling through the hollow space above the suspended drop ceiling. Which of the following combinations of physical security measures directly mitigates all three identified vulnerabilities?
During a security assessment of an enterprise LAN segment, a network technician observes that host traffic intended for the default gateway at IP address is being redirected through an unauthorized laptop at . Packet inspection reveals that host machines are continuously receiving unsolicited frame updates mapping to MAC address `00:11:22:AA:BB:CC`, which belongs to the laptop. Which network attack type is taking place, and what is its primary vector?
A network manager is reviewing a proposed upgrade plan for a corporate wireless network. The organization requires per-user authentication tied to Active Directory so that individual access can be revoked immediately upon employee termination. A technician suggests deploying WPA3-Personal with a complex 32-character passphrase to avoid configuring an 802.1X RADIUS infrastructure. Which of the following best explains why this recommendation fails to meet the organization's security requirements?
A network administrator is overseeing the construction of a new network closet situated directly adjacent to a light manufacturing area that produces significant airborne dust and debris. Which environmental control should be configured for the network closet's HVAC system to prevent dust from entering the room when personnel open the entry door?
A network technician is configuring remote administrative access on a newly installed network switch. Which protocol should be enabled to ensure that command-line interface (CLI) sessions and authentication credentials are encrypted across the network?
A security analyst is auditing a wireless network transition from WPA2-Personal to WPA3-Personal across several satellite offices. The goal is to support modern WPA3 security enhancements while maintaining temporary backward compatibility for legacy WPA2 devices. Which TWO of the following configuration settings or protocols are required to properly achieve this deployment? (Select TWO)
Select all that apply
A network security analyst is investigating logs from multiple enterprise security incidents across the network infrastructure. Match each observed attack symptom and mechanism to its corresponding network attack vector.
Click a left item, then click its matching right item
Items
Matches