Network Security
427 questions
A network technician is configuring a newly established small office location. The security baseline mandates protection against offline dictionary password-cracking attacks while utilizing a shared secret for authentication, as well as requiring Protected Management Frames (PMF) to safeguard against wireless deauthentication attacks. Which wireless security deployment best fulfills these requirements?
A network security administrator needs to restrict hosts in the Finance VLAN () from accessing an internal accounting web server () over port 80 (HTTP), while allowing all other network traffic between the subnets. The administrator configures a standard IPv4 Access Control List (`access-list 10 deny 10.50.10.0 0.0.0.255`) and applies it inbound on the router interface servicing the Finance VLAN.
Which statement best describes the outcome of this deployment?
A network administrator is configuring remote monitoring across an untrusted WAN link to collect system metrics and notifications from branch office switches. The administrator must implement a security solution that ensures monitoring credentials and packet payloads remain encrypted for confidentiality, while also verifying packet integrity and authenticating the transmitting switch. Which of the following protocol configurations best satisfies these security requirements?
A network security engineer is performing baseline administrative hardening on a newly deployed edge router to secure its management plane before production deployment. In what correct operational sequence should the engineer execute the following administrative hardening steps to establish secure remote management and enforce network access controls?
Drag items to arrange them in the correct order
A network administrator is documenting the cryptographic baselines for wireless security standards across company facilities. Match each wireless security protocol standard on the left with its primary encryption protocol and integrity mechanism on the right.
Click a left item, then click its matching right item
Items
Matches
A network administrator is deploying security controls on a Layer 3 switch interface connecting a workstation VLAN () to an internal Voice over IP (VoIP) server (). The policy requires allowing standard SIP call signaling and RTP media streams while restricting all other communication from the workstation subnet to the VoIP server. Which of the following statements correctly describe the requirements for this Access Control List (ACL) deployment? (Select TWO.)
Select all that apply
A network administrator is designing a wireless deployment for a corporate branch office. Security policy mandates individual user accountability, centralized credential management using an existing 802.1X RADIUS infrastructure, and enterprise-grade encryption. A junior technician proposes deploying WPA3-Personal with Simultaneous Authentication of Equals (SAE) to avoid the administrative overhead of deploying and managing digital certificates on client devices. Which of the following best explains why the technician's proposal fails to satisfy the organizational security compliance baseline?
A network administrator needs to grant third-party auditors access to an internal web-based financial dashboard. The security policy dictates that remote users must not be required to install dedicated client software or agent applications on their unmanaged personal endpoints, yet all session traffic must remain encrypted over the internet. Which remote access technology best meets these requirements?
A network security administrator must configure an IPv4 Access Control List (ACL) on a router to enforce access policies for the internal host network () communicating with a database server (). The policy requires that host is allowed HTTP access to the server, while all other hosts in are denied HTTP access. However, all hosts in must be allowed all other IP traffic to the server, and all remaining traffic from any other network must be dropped. Place the ACL statements in the correct top-to-bottom execution order to enforce this security policy without rule shadowing.
Drag items to arrange them in the correct order
An enterprise organization is mitigating two distinct security concerns regarding its web services: unauthorized tampering of REST API transactional data in transit, and frequent web server unresponsiveness caused by TCP SYN flood attacks. Which TWO of the following security mechanisms directly address the Integrity and Availability pillars of the CIA triad to mitigate these specific issues? (Select TWO)
Select all that apply
A security engineer is updating an organization's wireless baseline documentation to prepare for a migration from legacy Wi-Fi security protocols to WPA3-Enterprise across all corporate facilities. Which of the following technical features and requirements specifically apply when implementing WPA3-Enterprise? (Select TWO)
Select all that apply
Match each Virtual Private Network (VPN) protocol or header component to its corresponding operational characteristics and transport specifications.
Click a left item, then click its matching right item
Items
Matches
A network administrator applies the following IPv4 extended Access Control List (ACL) inbound on interface GigabitEthernet0/0 to control outbound internet access for internal clients on the network:
text
access-list 102 permit udp 172.16.40.0 0.0.0.255 any eq 53
access-list 102 permit tcp 172.16.40.0 0.0.0.255 eq 443 any
Users report that domain name resolution functions properly, but secure web browsing to external websites fails. Which of the following configuration errors in the ACL is causing the HTTPS traffic to be dropped?
A network security administrator is troubleshooting a remote access IPsec VPN deployment across a router performing Network Address Translation (NAT). During testing, site-to-client connections configured to use IPsec Authentication Header (AH) fail to establish, whereas connections configured to use Encapsulating Security Payload (ESP) succeed. Which of the following best explains why IPsec AH fails when passing through a NAT device?
A network security administrator reviews authentication logs for a corporate Remote Access VPN gateway and notices a pattern of authentication failures across over 500 distinct employee accounts within a short timeframe. Further inspection shows that each individual account experienced only two failed login attempts per hour, avoiding account lockout thresholds. Which of the following attack types is most likely occurring?
A network administrator is provisioning a wireless network for a medical clinic. To fulfill regulatory compliance mandates, the deployment requires centralized user authentication integrated with an 802.1X RADIUS server and 192-bit cryptographic strength for payload confidentiality. Which wireless security deployment mode and encryption suite best satisfies these requirements?
A network administrator needs to construct an inbound IPv4 extended Access Control List (ACL) on a gateway router to secure an internal server subnet (). The security policy requires allowing administrative SSH access from host , allowing web HTTPS traffic from the internal workstation subnet (), blocking all other traffic originating from subnet , and permitting traffic from all other internal subnets. Place the following ACL statement descriptions in the correct sequence from top to bottom (first matching rule to last).
Drag items to arrange them in the correct order
An organization is implementing a client-based Remote Access VPN using L2TP/IPsec to provide secure connectivity for remote workers through perimeter firewalls and Network Address Translation (NAT) gateways. Which of the following protocol requirements and firewall rules are necessary to establish and maintain this VPN connection? (Select TWO.)
Select all that apply
A network administrator is configuring an extended IPv4 Access Control List (ACL) on a core router to permit administrator workstations on subnet to manage remote servers on subnet using Remote Desktop Protocol (RDP). The administrator configures the following ACL entry inbound on the router interface connected to the administrator subnet:
`access-list 110 permit tcp 172.20.10.0 0.0.0.255 eq 3389 10.30.50.0 0.0.0.255`
`access-list 110 deny ip any any`
After applying the ACL, administrators report that RDP connection attempts to the servers time out. Which of the following identifies the configuration error in the ACL entry?
A network audit requires verifying that wireless security standards across company facilities are aligned with their correct cryptographic algorithms and integrity controls. Match each wireless security protocol on the left with its corresponding encryption cipher and integrity mechanism on the right.
Click a left item, then click its matching right item
Items
Matches