Network Security
427 questions
A network engineer is configuring stateless Access Control Lists (ACLs) on a Layer 3 switch to secure communication between an application tier subnet () and a database tier subnet (). The application servers must establish connection requests to MySQL database instances listening on TCP port . Because the filtering device is a stateless ACL rather than a stateful firewall, bidirectional rules must be defined explicitly. Which TWO of the following ACL entries must be configured on the database interface to allow this traffic flow while maintaining state awareness manually?
Select all that apply
Following an internal security audit of enterprise network infrastructure, a network engineer must remediate vulnerabilities on several Layer 3 switches. The audit report specifically highlighted risks associated with management plane traffic eavesdropping and VLAN hopping exploits on trunk links. Which of the following TWO device hardening measures should the engineer implement to directly address these findings? (Select TWO.)
Select all that apply
A network analyst inspecting a packet capture between a wireless access point and a centralized authentication server observes that while the user password field within the Access-Request frame is obscured, the username and assigned VLAN attributes are visible in cleartext. Which operational characteristic of the RADIUS protocol accounts for this observed behavior?
A network administrator is configuring a new wireless deployment for a corporate headquarters. The company's security policy requires each employee to authenticate using their individual domain credentials managed by a central RADIUS server, while ensuring robust encryption for all wireless traffic. Which wireless security configuration best fulfills these operational requirements?
During a routine security audit, a systems engineer notices that remote administration sessions to a core network switch transmit credentials in plaintext. Which administrative change should be implemented to secure interactive command-line access to the switch?
An organization is deploying a centralized AAA architecture, configuring RADIUS for 802.1X wireless access and TACACS+ for administration of network infrastructure devices. Which of the following operational characteristics accurately describe these protocols in this design? (Select TWO.)
Select all that apply
A network infrastructure team is deploying an edge micro data center enclosure on an active manufacturing floor to process real-time telemetry. Due to high physical traffic, ambient dust, and unauthorized personnel in the vicinity, the team must implement appropriate physical security access controls and environmental protection measures for the enclosure. Which TWO of the following controls should be deployed to address these specific access and environmental threats?
Select all that apply
A senior network security architect is designing physical and environmental defense controls for a tier-four enterprise data facility housing mission-critical financial databases. Match each physical or environmental control mechanism on the left with its primary security or environmental risk mitigation capability on the right.
Click a left item, then click its matching right item
Items
Matches
During an internal penetration test, an analyst connects a laptop to a standard user access port on a Managed Layer 2 switch. Without deploying double-encapsulated 802.1Q tags or compromising any credentials, the analyst crafts specific control frames that force the switch port into an active trunking state. This allows the laptop to send and receive traffic across multiple restricted VLANs. Which attack vector was exploited to breach VLAN isolation, and what is the primary mitigation step required to prevent it?
A network administrator is setting up a secure remote access VPN that uses Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec). Place the steps required to establish a fully functional L2TP/IPsec VPN connection in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network technician is configuring a new standalone wireless access point using WPA3-Personal for a small branch office that lacks a centralized AAA/RADIUS infrastructure. Which of the following technical features are native capabilities of WPA3-Personal that directly enhance security compared to WPA2-Personal? (Select TWO.)
Select all that apply
A network administrator is auditing the organization's wireless security baseline. Match each wireless security standard on the left with its corresponding primary encryption protocol or cryptographic suite on the right.
Click a left item, then click its matching right item
Items
Matches
A tier-2 Security Operations Center (SOC) analyst is analyzing threat intelligence logs and network packet captures from a recent enterprise security incident. Match each observed technical attack metric or anomalous protocol behavior to its corresponding network attack classification.
Click a left item, then click its matching right item
Items
Matches
A network technician is preparing a newly unboxed switch for deployment on a corporate network. Place the following administrative device hardening steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
A network security engineer is tasked with hardening the management plane of a newly installed enterprise edge router to ensure administrative traffic and network telemetry are fully protected against unauthorized access and packet inspection. Which set of configuration actions represents the best practice for hardening the device?
A network security administrator is deploying a core Layer 3 router into an enterprise environment. To establish secure administrative remote access, the administrator must configure the management plane from the local console port before exposing the device to the network. In what chronological order should the administrator perform the following hardening steps to correctly enable encrypted remote management?
Drag items to arrange them in the correct order
A network security administrator is aligning enterprise operational controls with fundamental security principles. Match each security mechanism or operational scenario to the core CIA Triad or security concept it primarily enforces.
Click a left item, then click its matching right item
Items
Matches
A network administrator is retrofitting an unmonitored Intermediate Distribution Frame (IDF) closet located directly beneath an active plumbing line in a satellite office. Facilities management raised concerns regarding potential unauthorized physical opening of the network enclosures during off-hours cleaning, as well as the risk of water condensation or plumbing leaks causing hardware damage.
Which TWO of the following physical and environmental controls should the network administrator deploy to directly mitigate these specific threats?
Select all that apply
A network security administrator is configuring a newly deployed wireless network for corporate headquarters. The organization's compliance policy specifies that every user must authenticate individually using their RADIUS credentials and that all management frames must be protected against spoofing attacks. Which of the following wireless security configurations fulfills these requirements?
An enterprise systems administrator discovers that an attacker gained access to a database server and modified audit log files to erase evidence of unauthorized database queries. The administrator needs to select a security control that specifically ensures log files cannot be altered or tampered with without detection. Which of the following core security controls best maintains this specific pillar of the CIA triad?