Tüm alıştırma soruları
1987 soru
A network administrator configures a dual-mode WLAN on a Cisco Wireless LAN Controller (WLC) intended to support both modern WPA3-Personal devices and legacy WPA2-Personal client hardware during a corporate migration. WPA3-capable endpoints connect seamlessly; however, older WPA2-only devices consistently fail during the 802.11 association phase and cannot establish network connectivity. Frame captures reveal that the legacy stations receive association responses containing mandatory Protected Management Frames (PMF/802.11w) requirements. Which WLC configuration modification resolves this association failure for legacy endpoints while continuing to support WPA3-Personal clients?
A network administrator configures port security on access interface GigabitEthernet0/1 of a Cisco Catalyst switch by executing `switchport port-security` and `switchport port-security mac-address sticky`. Hosts connect successfully and their MAC addresses are dynamically learned by the switch. However, after an unscheduled switch reboot, the administrator discovers that the dynamically learned MAC addresses were removed and hosts must re-trigger learning. Which operational step was omitted prior to the switch restart?
A network security engineer is configuring digital certificate enrollment on a Cisco IOS router to establish secure IPsec VPN tunnels. Before submitting a Certificate Signing Request (CSR) to an enterprise Certificate Authority (CA), which item must be generated directly on the local router?
A security policy requires that all locally configured administrative accounts on Cisco network devices store passwords using strong one-way cryptographic hashing instead of reversible encryption. During an audit, an engineer inspects a switch configuration and discovers the command `username netadmin password 7 0822455D0A16`. Which action must the engineer take to bring this account configuration into compliance with the security policy?
A network administrator configures an IPv4 standard access control list on a Cisco router and applies it inbound on interface GigabitEthernet0/1:
text
access-list 15 permit host 172.16.20.50
access-list 15 permit 172.16.30.0 0.0.0.255
A technician attempts to send traffic through interface GigabitEthernet0/1 from host 172.16.20.51 destined for a server on an internal network. The traffic is dropped by the router. Which statement accurately explains why traffic from host 172.16.20.51 is dropped?
A network engineer is selecting a protocol to manage administrative CLI access to enterprise routers. The security policy mandates two key capabilities: full-packet payload encryption for all AAA transactions and the independent authorization of individual executive commands after initial login authentication. Which protocol fulfills these requirements?
A network technician is inspecting authentication behavior on a newly deployed Wi-Fi network configured for personal use. The security policy mandates protection against passive eavesdropping and offline password-dictionary attacks by utilizing a Dragonfly Key Exchange during association. Which wireless security protocol mechanism provides this specific key exchange functionality?