Security Fundamentals
298 soru
An enterprise organization is updating its Cisco Wireless Controller infrastructure to enforce WPA3-Enterprise 192-bit security mode across critical WLANs. During client validation, legacy 802.1X supplicants configured with AES-CCMP-128 encryption and EAP-TLS fail to associate with the SSID, whereas modern clients configured for 192-bit security connect successfully. Which technical requirement of WPA3-Enterprise 192-bit mode causes these legacy WPA2-Enterprise clients to fail association?
Match each wireless security protocol standard on the left with its defining cryptographic capability or key exchange mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A wireless network architect is reviewing enterprise security standards to align wireless LAN controller (WLC) profiles with IEEE 802.11 security specifications. Match each wireless security implementation on the left with its corresponding key exchange mechanism, cipher suite, or framing requirement on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise organization is updating its Cisco Wireless LAN Controller (WLC) security baseline to align with WPA3 specification standards across all branch locations. Which TWO architectural and security protocol enhancements are introduced when transitioning infrastructure from WPA2 to WPA3? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is upgrading a wireless deployment to implement the WPA3-Personal security standard. Which key exchange mechanism does WPA3-Personal introduce to protect against offline dictionary attacks?
A network administrator configures an extended IPv4 access control list (ACL 102) on a Cisco IOS router to restrict traffic from the internal LAN subnet to an external server at IP address . The administrator enters the following CLI commands:
`access-list 102 permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 80`
`access-list 102 permit tcp 172.16.10.0 0.0.0.255 host 192.168.50.10 eq 443`
After applying ACL 102 inbound on interface GigabitEthernet0/0, users report that HTTP and HTTPS access to works properly, but all DNS resolution queries to an internal server at and internet browsing to other hosts are failing. Which statement correctly explains why all other traffic originating from the internal subnet is being blocked?
A network engineering team requires strict per-command authorization and per-command audit logging for administrative CLI access on core Cisco switches. Every individual command entered by a logged-in administrator must be evaluated against central security policies before execution. Which protocol selection and architectural behavior correctly satisfies these operational requirements?
An administrator applies the following IPv4 extended named access control list (ACL) inbound on interface GigabitEthernet0/0/1 of a Cisco IOS router:
ip access-list extended FILTER_WEB
permit tcp 10.10.1.0 0.0.0.255 host 172.16.10.50 eq 80
permit tcp 10.10.1.0 0.0.0.255 host 172.16.10.50 eq 443
Which two statements accurately describe how traffic arriving on interface GigabitEthernet0/0/1 is evaluated by this ACL?
Geçerli olan tümünü seçin
A network security administrator needs to configure a local database user account named 'opsman' on a Cisco IOS XE router. The requirement specifies using PBKDF2 with SHA-256 hashing (Type 8 encryption) to securely store the plaintext password 'Secur3#Pass2026'. Which Cisco IOS global configuration command correctly satisfies this requirement?
Match each Cisco Layer 2 security feature or operational state on the left to its corresponding operational behavior on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network operations team is auditing access control protocols used across enterprise routers and switches. When comparing TACACS+ and RADIUS protocol implementations, which TWO functional characteristics belong specifically to TACACS+? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator configures a numbered standard IPv4 access control list on a Cisco IOS router to permit management access from the Network Operations Center (NOC) subnet while blocking all other hosts. The administrator enters the following commands:
text
Router(config)# access-list 15 permit 192.168.10.0 0.0.0.255
Router(config)# line vty 0 4
Router(config-line)# access-class 15 in
After applying this configuration, which traffic outcome occurs when an administrator at IP address attempts an SSH connection to the router's VTY interface, and why?
A network administrator needs to harden administrative access on a Cisco IOS XE router. The requirement specifies that users connecting via SSH must authenticate against the local device user database, and privileged EXEC mode access must be protected using Type 9 (scrypt) password hashing. Which two CLI configuration tasks must be performed to meet these security requirements? (Select two.)
Geçerli olan tümünü seçin
A network engineer must enforce a security policy requiring real-time validation of individual CLI commands executed during administrator sessions on enterprise switches. Additionally, the policy dictates that the entire communication payload between the switch and the AAA server must be encrypted. Which protocol and operational mechanism fulfill these security requirements?
A network administrator needs to configure an IPv4 extended named Access Control List (ACL) named SECURE_FLOW on a Cisco IOS router. The ACL must implement the following policy requirements in order:
1. Permit SSH access (TCP port 22) specifically from management host 10.20.1.15 to server 172.16.50.10.
2. Deny all other IP traffic originating from the 10.20.1.0/24 subnet targeted to server 172.16.50.10.
3. Permit all remaining IPv4 traffic originating from the 10.20.1.0/24 subnet to any destination.
4. Ensure all other IP traffic from any source not explicitly permitted is implicitly dropped.
Arrange the configuration command statements into the correct top-to-bottom sequential order to achieve this policy.
Öğeleri doğru sıraya koymak için sürükleyin
A network engineer observes the following partial running configuration on a Cisco IOS XE switch:
text
username netops privilege 15 secret Cisc0#2026!
!
line vty 0 4
password 7 094F471A1A0A
login
!
When administrators attempt to establish a remote SSH session to the switch, the prompt requests only a line password rather than asking for user credentials. Which command must be configured under line configuration mode to enforce authentication against the local user database?
An administrator applies the following extended IPv4 access control list outbound on interface GigabitEthernet0/0/1 to permit HTTP traffic from the Sales VLAN () to an internal Web Server ():
text
access-list 110 permit tcp 10.1.10.0 0.0.0.255 host 192.168.1.100 eq 80
After applying `ip access-group 110 out` on the interface, users in the Sales VLAN report that while HTTP access works, they can no longer send ICMP echo requests to the Web Server or access the corporate DNS server () located on the same subnet. Which condition is causing this traffic interruption?
A network engineer is implementing Layer 2 security controls across access switches in an enterprise network. The design requires deploying Dynamic ARP Inspection (DAI) alongside DHCP Snooping to mitigate ARP spoofing attacks. Which TWO statements correctly describe the operational interactions and interface trust requirements for these features?
Geçerli olan tümünü seçin
A network administrator is deploying a dual-compatibility wireless network on a Cisco Wireless LAN Controller (WLC) to support both modern WPA3-Personal endpoints and legacy WPA2-Personal devices under a single SSID. During initial validation, legacy WPA2 devices fail to complete the 802.11 association phase, while WPA3 devices connect successfully. Investigation reveals that the WLAN security profile is configured with Simultaneous Authentication of Equals (SAE) enabled, Protected Management Frames (PMF) set to "Required", and the encryption cipher suite restricted exclusively to GCMP-256. Which configuration modification on the WLC will enable legacy WPA2 clients to successfully associate while maintaining standard WPA3 Transition Mode operation?
A network security administrator is aligning enterprise network management requirements with AAA framework services and protocol architecture. Match each operational task or network access requirement on the left with its corresponding AAA component or protocol mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler