Tüm alıştırma soruları
2237 soru
An enterprise network operations team is analyzing complex performance anomalies and telemetry configurations across a hybrid WAN deployment. Match each observed network symptom or monitoring configuration requirement on the left with the correct network performance monitoring metric or protocol mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise deploys active inline Network Intrusion Prevention System (NIPS) appliances on two parallel border gateway links configured for active-active asymmetric routing. Shortly after deployment, users experience intermittent session terminations and dropped connections on legitimate TCP applications. Packet inspection reveals that outbound TCP SYN packets traverse Link 1 (monitored by NIPS 1), while the corresponding SYN-ACK return packets traverse Link 2 (monitored by NIPS 2), causing NIPS 2 to drop the return packets as invalid out-of-state traffic. Which of the following architectural adjustments will eliminate these session drops while maintaining active inline threat prevention across both links?
During a routine audit, a network engineer notices that multiple access-layer switches are running an outdated operating system version vulnerable to memory leaks under high traffic load. Before initiating the upgrade across the entire enterprise network during a scheduled window, which procedure should the engineer perform first to prevent unforeseen outages?
Match each core security principle on the left with its corresponding primary objective on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to configure centralized log forwarding from edge switches to a SIEM collector across an untrusted WAN connection. Corporate compliance mandates that log transmission must guarantee delivery confirmation to prevent log loss during congestion and secure event details against eavesdropping in transit. Which configuration best satisfies both requirements?
A network security auditor discovers that administrative session logs for network switches expose executed CLI command parameters in cleartext across the management network. Furthermore, the existing AAA deployment cannot restrict specific administrative commands per role because authentication and authorization are tightly coupled into a single transaction. Which AAA protocol implementation directly resolves both findings by encrypting the complete packet payload and decoupling authorization from authentication?
A network administrator configures a redundant gateway topology using a First Hop Redundancy Protocol (FHRP) to provide high availability for a corporate subnet. During a scheduled failover test, the primary router is powered off. Although logs confirm that the standby router successfully transitioned to the active role, all client workstations immediately lose outbound internet connectivity. Troubleshooting reveals that workstation traffic continues to be routed toward the MAC and IP addresses of the powered-off primary router interface. Which of the following configuration errors is the most likely cause of this issue?
An auditor notes that an organization's network monitoring traffic is transmitted without encryption and that critical log messages are lost during periods of high link utilization. The network administrator must reconfigure telemetry protocols on core switches to ensure reliable log transport, cryptographic confidentiality, and authenticated management querying. Which of the following implementations address the auditor's security and reliability findings? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator configures an Access Control List (ACL) with explicit permit statements for HTTP and HTTPS traffic on a router interface. However, users report that all other traffic attempting to pass through this interface is blocked, even though no deny statements were explicitly written. Which of the following features accounts for this behavior?
A network administrator needs to verify that downloaded firmware updates have not been corrupted or tampered with in transit, while also ensuring that administrative login sessions to core switches are strictly limited to authorized staff. Which TWO security concepts or mechanisms directly address these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is implementing TACACS+ for centralized management of network devices. Which TWO of the following operational characteristics accurately describe TACACS+? (Select TWO)
Geçerli olan tümünü seçin
A network security administrator configures full-disk encryption on all corporate laptops to ensure that sensitive files cannot be accessed if a laptop is lost or stolen. Which pillar of the CIA triad does this security control directly uphold?
A network administrator is setting up a wireless network for a business environment. The company policy mandates that each employee must authenticate with their own unique credentials using a central RADIUS server, rather than sharing a single password across the organization. Which of the following wireless security modes best fulfills this requirement?
A network administrator is configuring a local network segment using the prefix (subnet mask ). What is the maximum number of usable host IPv4 addresses that can be assigned to devices on this subnet?
A network engineer is configuring a centralized backend authentication server to support 802.1X port-based network access control across wireless access points in an enterprise network. The architecture requires a standard protocol to handle authentication and authorization requests forwarded by the wireless access points acting as authenticators. Which protocol and transport layer configuration correctly fulfills this network access control deployment?
Match each high-availability technology or operational mechanism on the left with its primary redundancy behavior on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is designing a wireless security architecture for an enterprise office. The organizational policy mandates centralized user authentication using 802.1X/RADIUS, individual credential accounting, and strict enterprise-grade encryption key management. A junior technician proposes implementing WPA3-Personal with Simultaneous Authentication of Equals (SAE) using a complex 30-character passphrase, arguing it avoids RADIUS server deployment while providing equal security. Which of the following best evaluates the junior technician's proposal?
A network administrator is executing a planned change during a maintenance window to implement new quality of service (QoS) dynamic bandwidth allocation rules on a primary distribution switch pair. Ten minutes into the post-implementation validation phase, automated network monitoring system alerts indicate that real-time telemetry traffic has breached defined latency and packet loss thresholds, failing the pre-established change success metrics. Which of the following is the most appropriate action for the administrator to take next?
A network technician is drafting a standard Request for Change (RFC) proposal to modify configuration parameters on a company's primary router. Which of the following key components must be included in the RFC document prior to submitting it for approval? (Select TWO.)
Geçerli olan tümünü seçin
An organization is enhancing its security monitoring architecture to detect zero-day exploits and analyze encrypted network application traffic. The network engineering team decides to deploy Host-based Intrusion Detection Systems (HIDS) across critical endpoints. Which of the following capabilities represent distinct operational advantages of a HIDS compared to a passive Network Intrusion Detection System (NIDS)? (Select TWO.)
Geçerli olan tümünü seçin