Network Security
427 questions
A network administrator is performing baseline security hardening on a newly deployed Layer 2 switch in a corporate network environment. To secure the device against unauthorized physical connection and Layer 2 traffic interception, which TWO of the following switch hardening practices should the administrator implement?
Select all that apply
A network security administrator is organizing a training module to help tier-1 analysts identify malicious activity across different network layers. Match each network attack type on the left with its corresponding operational mechanism or technical signature on the right.
Click a left item, then click its matching right item
Items
Matches
A network technician is hardening remote administrative access on a core router deployed at an enterprise edge site. To comply with security baseline requirements, all remote management sessions must use strong payload encryption, and inactive administrative sessions must automatically terminate after five minutes. Which configuration strategy correctly fulfills these hardening requirements?
During a security assessment on an enterprise network segment, a SOC analyst observes that users attempting to establish encrypted HTTPS connections to an external server are transparently modified in transit by an adversary on the local network segment. The adversary intercepts initial connection requests and converts HTTPS links into unencrypted HTTP links, forcing client browsers to transmit credentials in plaintext over port 80 while maintaining a separate secure session with the target server. Which of the following network attack types is being executed?
A network security administrator is configuring a top-to-bottom IPv4 extended Access Control List (ACL) on a gateway router interface. The ACL must enforce the following security policy objectives:
1. Allow administrative host SSH access ( port 22) to management server .
2. Block all other traffic from internal subnet destined to management server .
3. Allow all hosts on subnet HTTP access ( port 80) to any destination.
4. Explicitly block all remaining IP traffic.
Arrange the ACL rules in the correct top-to-bottom processing order to satisfy these security requirements without shadowing any rules.
Drag items to arrange them in the correct order
During an internal security investigation, network administrators notice that whenever client workstations experience a failure resolving internal hostnames via the primary DNS server, an unauthorized endpoint on the same broadcast domain immediately responds to Link-Local Multicast Name Resolution (LLMNR) and NetBIOS Name Service (NBT-NS) queries. The rogue system provides its own IP address, tricking victim computers into sending authentication hashes when trying to access network shares.
Which of the following correctly identify the attack vector taking place and the primary security risk established by this activity? (Select TWO.)
Select all that apply
A network administrator needs to restrict administrative access to a managed switch located at IP address . Only the administrator's workstation at IP address must be allowed to establish Secure Shell (SSH) management sessions with the switch. All other SSH attempts to the switch must be blocked, while all other non-SSH IP traffic across the subnet must continue to traverse the interface uninhibited.
Which set of extended IPv4 Access Control List (ACL) statements correctly fulfills this security requirement?
statement 2: deny udp any host 10.20.30.2 eq 22
statement 3: permit ip any any
statement 2: deny tcp any host 10.20.30.2 eq 22
statement 3: permit ip any any
statement 2: deny tcp any host 10.20.30.2 eq 23
statement 3: permit ip any any
statement 2: deny tcp any host 10.20.30.2 eq 22
A network administrator discovers that a managed switch has begun flooding unicast frames out of all physical ports within a specific VLAN, causing the switch to degrade to hub-like behavior. Packet captures reveal a high volume of traffic originating from a single host port, containing randomized, rapidly changing source MAC addresses that exhaust the switch's Content Addressable Memory (CAM) table capacity. Which of the following attack types is taking place?
Match each network attack type to the technical indicator or mechanism that best characterizes its execution.
Click a left item, then click its matching right item
Items
Matches
During a network incident investigation, a technician notices that several workstations on a local subnet received IP configuration settings within the network range instead of the standard internal range. Further inspection reveals that a malicious host flooded the network with forged requests to exhaust the legitimate pool of IP addresses and then responded to client broadcasts with its own default gateway settings. Which of the following attack types has taken place?
Match each common network attack type on the left with the primary mechanism or technical indicator that best characterizes its execution on the right.
Click a left item, then click its matching right item
Items
Matches
An organization's security policy mandates centralized access control for managing network hardware via CLI. The policy specifically requires that individual commands executed during an administrative session must be authorized separately on a per-user basis, and that all payload data exchanged between the network switches and the AAA server must be fully encrypted. Which security protocol should the administrator implement to meet these requirements?
An enterprise network security engineer is evaluating the deployment of a passive Network Intrusion Detection System (NIDS) connected via a switch SPAN port versus an inline Network Intrusion Prevention System (NIPS) placed at the perimeter firewall interface. Which of the following statements accurately describe the operational trade-offs and functional behaviors of these two implementations? (Select TWO.)
Select all that apply
A security team is evaluating the operational differences between placing a Network Intrusion Detection System (NIDS) passively via a switch SPAN port versus deploying a Network Intrusion Prevention System (NIPS) inline. Which of the following statements accurately describe these deployment models? (Select TWO.)
Select all that apply
A network administrator is implementing Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) for corporate wireless client authentication. Which of the following components are required to successfully establish mutual authentication using EAP-TLS? (Select TWO)
Select all that apply
An enterprise network administrator is deploying a site-to-site IPsec VPN between a corporate headquarters and a remote branch office. The branch office router is positioned behind a service provider gateway performing Port Address Translation (PAT). Diagnostic logs confirm that Phase 1 (IKE) authentication succeeds over UDP port 500. However, Phase 2 fails to establish a functional data tunnel. Further analysis reveals that the security policy is configured to use IPsec Authentication Header (AH) in tunnel mode. Which of the following root causes best explains why the IPsec VPN tunnel fails to operate across the PAT gateway?
A network security team is deploying an 802.1X port-based network access control framework across enterprise Ethernet switches. Which of the following statements accurately describe the operational roles and protocol encapsulation methods defined in this framework? (Select TWO)
Select all that apply
An enterprise network analyst observes that unicast frames intended exclusively for a secure file server are suddenly being received by all host interfaces connected to the same switch module. A review of the switch diagnostics reveals that the switch's MAC address table is entirely saturated with thousands of randomized, fake source MAC addresses. As a result, new frame forwarding defaults to broadcasting across all ports within the VLAN. Which of the following attack types has occurred, and what is its operational objective?
Match each physical security or environmental control mechanism to its primary function in a network facility.
Click a left item, then click its matching right item
Items
Matches
A network engineer is establishing physical and environmental controls for a newly constructed remote edge data facility. To prevent hardware failure from static accumulation, moisture buildup, and inefficient thermal distribution, which TWO of the following environmental deployment strategies should be implemented? (Select TWO.)
Select all that apply