Tüm alıştırma soruları
2237 soru
A network administrator configures a pair of routers using a First Hop Redundancy Protocol (FHRP) to ensure high availability for a subnet. During scheduled maintenance on the primary router, the secondary router successfully assumes the active role according to the system logs. However, workstations on the subnet immediately lose access to external networks. Which of the following is the most likely cause of this connectivity failure?
A network engineer observes anomalous latency spikes on a critical web application server following a recent security upgrade. Upon investigation, the engineer discovers that security software deployed directly on the web server is performing deep packet inspection on all local system calls and application memory buffers, creating processing overhead under high traffic load. Which security control is actively causing this host-level performance degradation?
During a scheduled maintenance window, a network technician updates the operating system of a primary enterprise router. Immediately after the device reboots with the newly installed firmware image, all recent ACL modifications and custom static routes disappear, causing routing failures across multiple subnets. An audit reveals that recent configuration changes resided solely in volatile memory when the firmware installer triggered the system reload. Which critical pre-patch maintenance procedure was omitted prior to executing the software update?
Following an emergency vulnerability disclosure, a network engineering team must apply a critical operating system patch to a high-availability core switch cluster without causing network downtime. Which of the following procedures should the team execute to ensure continuous service availability and full recovery capability during this maintenance operation? (Select TWO).
Geçerli olan tümünü seçin
Match each AAA authentication protocol or access control framework to its defining operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security engineer is designing a centralized AAA solution for administrative management access to core switches and firewalls. Organization security policies dictate that authentication and authorization functions must be decoupled to allow granular per-command authorization rules, the complete packet payload (including administrative commands) must be encrypted over the wire, and the protocol must use connection-oriented transport on standard port 49. Which protocol should the engineer select to meet all of these compliance requirements?
During a post-incident audit of a multi-tier data center environment, an engineer discovers that inter-VLAN routing failure and unexpected high-availability failovers occurred because secondary database nodes were improperly connected to trunk ports missing native VLAN tags, while hosts were statically configured with individual physical interface IP addresses rather than shared gateway abstractions. Additionally, technicians were unable to physically locate the corresponding patch panel switchports during the outage due to missing physical layout records. Which of the following documentation components and procedural updates must be corrected and updated to fully remediate this environment? (Select TWO.)
Geçerli olan tümünü seçin
A network operations team is auditing the event management and polling security parameters on core routers to meet strict regulatory compliance mandates. The regulatory framework requires two key controls: all remote system logging messages must be delivered using a connection-oriented protocol that guarantees transport-layer encryption, and all telemetry polling performed by network management stations must enforce both cryptographic user authentication and packet payload encryption.
Which of the following configuration steps must the administrator perform to satisfy these auditing mandates? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise deployment connects dual-homed application servers to two separate top-of-rack access switches using LACP (IEEE 802.3ad) NIC teaming for link redundancy, while two core routers run Virtual Router Redundancy Protocol (VRRP) to provide default gateway resiliency. Following a network migration, users report intermittent traffic loss during router failover tests, and LACP bundles on the servers fail to form properly. Which TWO of the following technical misconfigurations or architectural oversights are the primary causes of these issues?
Geçerli olan tümünü seçin
A security analyst needs to monitor critical database servers for unauthorized local file integrity modifications and zero-day memory exploits that lack known attack signatures. Which security solution best addresses these requirements?
A network security architect is reviewing the deployment of centralized authentication protocols across a global enterprise network infrastructure. The architecture requires separate handling for administrative access to network edge routers and user authentication for 802.1X wireless access. Which TWO of the following statements correctly evaluate the operational and security characteristics of RADIUS and TACACS+ in this deployment?
Geçerli olan tümünü seçin
A network engineer is upgrading an enterprise log auditing and monitoring infrastructure. Corporate compliance policies require that all network event logs sent to the central server, as well as SNMP polling traffic, provide confidentiality and integrity verification in transit. Which of the following configuration choices should the engineer implement to fulfill these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network technician is preparing to update the operating system firmware on several enterprise switches. Which of the following actions should the technician take prior to applying the update in the production environment? (Select TWO.)
Geçerli olan tümünü seçin
A network technician is deploying high availability for enterprise servers connected to redundant access switches. Which TWO of the following technologies or mechanisms directly provide link aggregation and adapter redundancy at Layer 2?
Geçerli olan tümünü seçin
A network security administrator is assessing the centralized access control deployment for an enterprise infrastructure. The administrator needs to evaluate the architectural and transport differences between RADIUS and TACACS+ protocols. Which of the following statements correctly distinguish TACACS+ from RADIUS? (Select TWO).
Geçerli olan tümünü seçin
A network security team is designing a monitoring strategy for a high-frequency trading subnetwork and a remote branch office. The trading network requires absolute zero added latency on active traffic paths while maintaining detection capability for novel, unknown protocol exploits. Meanwhile, the branch office needs comprehensive visibility into mirrored VLAN traffic captured by a switch SPAN port. Which of the following design choices correctly fulfill these architecture and detection requirements? (Select TWO)
Geçerli olan tümünü seçin
A network security administrator is deploying a dual centralized AAA architecture to support both network infrastructure management and 802.1X wireless user authentication. Which TWO of the following statements accurately distinguish the operational and transport properties of TACACS+ and RADIUS in this implementation?
Geçerli olan tümünü seçin
A network administrator is designing a high-availability infrastructure for a datacenter rack connected to dual switches and redundant edge routers. The design must support link aggregation across physical network interfaces on dual-homed servers while also ensuring rapid Layer 3 gateway failover if an upstream WAN link drops. Which TWO of the following technical configurations should the administrator implement to meet these requirements?
Geçerli olan tümünü seçin
An enterprise network engineering team is designing a high-security log forwarding and auditing infrastructure across multi-site edge routers. The compliance policy mandates that event log forwarding to the centralized SIEM must guarantee transport reliability and payload encryption, while active remote device telemetry queries must enforce both cryptographic user authentication and data payload privacy encryption. Which of the following configuration choices and protocols satisfy these requirement criteria? (Select TWO.)
Geçerli olan tümünü seçin
A network team is preparing a maintenance window to perform a software operating system update on a high-availability core switch cluster operating in an active/standby state. Which TWO actions must the engineers execute to maintain service continuity and ensure rapid recovery if an issue arises?
Geçerli olan tümünü seçin