Tüm alıştırma soruları
2237 soru
A technician is deploying a wireless access point and needs to select security protocols that protect against offline dictionary password-guessing attacks while providing modern, high-strength data encryption. Which of the following wireless security standards or mechanisms fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
During a forensic analysis at a financial services organization, network engineers discover that an attacker executed a man-in-the-middle attack on an internal subnet between an application server and a SQL database. The attacker intercepted automated database queries and modified financial balances inside the packet payloads in transit without interrupting the TCP session or altering packet lengths. System uptime, server access, and network performance remained completely normal throughout the event. Which security principle of the CIA triad was directly violated, and which security control best mitigates this vulnerability?
An administrator is configuring a stateless extended IPv4 Access Control List (ACL) on a WAN edge router interface (GigabitEthernet0/1) to secure traffic between an internal database cluster () and a remote external cloud database server (). Internal hosts initiate outbound TCP connections to the external server on destination port .
To allow outbound traffic, the outbound ACL on GigabitEthernet0/1 contains the following rule:
`access-list 101 permit tcp 192.168.10.0 0.0.0.255 host 203.0.113.50 eq 5432`
Which entry must be added to the inbound ACL on GigabitEthernet0/1 to permit return traffic from the database server back to internal hosts while preventing unrequested inbound TCP connections from external sources?
A network administrator is deploying a performance monitoring solution to track switch CPU and memory utilization across a enterprise network. The solution must support encrypted management traffic and allow standard polling queries to pass through internal firewalls. Which of the following configurations and protocols should the administrator implement? (Select TWO)
Geçerli olan tümünü seçin
A network security engineer is designing an automated system to transmit high-value financial transaction logs between remote data centers across a public network. The security baseline specifies that the system must ensure data cannot be altered during transit without detection, while also cryptographically preventing the sending system from denying it originated the log transmission. Which of the following security mechanisms should the engineer implement to fulfill these specific security principles? (Select TWO.)
Geçerli olan tümünü seçin
A network engineer must implement a true out-of-band (OOB) remote management architecture for a critical enterprise data center. During a widespread core routing outage where the primary WAN connection and internal IP infrastructure are completely unreachable, the administrator needs direct console-level command-line access to reconfigure core switches. Which solution meets these out-of-band remote access and resilience requirements?
A network security administrator is evaluating centralized AAA protocols to manage enterprise infrastructure. The design requires implementing TACACS+ for device administration and RADIUS for network access control. Which TWO of the following characteristics accurately differentiate the operational behavior of TACACS+ from RADIUS? (Select TWO.)
Geçerli olan tümünü seçin
During an incident investigation on an enterprise dual-stack subnet, a network administrator observes that workstations are directing outbound traffic to an unauthorized device on the local segment. Packet captures indicate that while Dynamic ARP Inspection (DAI) and DHCP Snooping are active and successfully blocking rogue IPv4 gateway announcements, client dual-stack nodes have automatically updated their default gateway settings to a link-local IPv6 address transmitted via unsolicited ICMPv6 Type 134 messages from an unknown host. Which of the following attack vectors is occurring, and what is the primary Layer 2 mitigation required to block it?
A security engineer is tasked with monitoring a high-traffic enterprise network segment to identify zero-day attacks and unauthorized behavioral deviations. The organization requires that the monitoring solution must not introduce processing latency, drop legitimate packets during peak traffic hours, or create a single point of failure on the link. Which deployment architecture and detection method should the engineer implement?
During an automated compliance scan, a network operations team discovers that several edge firewalls have drifted from the approved baseline configuration due to unrecorded manual modifications made during a previous outage. To bring the firewalls back into compliance while adhering to strict change management protocols, which of the following actions MUST the team perform? (Select TWO.)
Geçerli olan tümünü seçin
A network security specialist is implementing an 802.1X Port-based Network Access Control architecture across an enterprise Ethernet infrastructure. In this deployment, network switches operate as authenticators that relay authentication requests from supplicants to a centralized backend server. Which TWO of the following statements accurately describe the operational and security characteristics of the RADIUS protocol in this AAA environment?
Geçerli olan tümünü seçin
A network administrator needs to allow remote employees to securely access internal web applications using only a standard web browser, without requiring any dedicated software installation on user endpoints. Which remote access VPN technology best satisfies this requirement?
A network operations engineer needs to apply a vendor-recommended firmware update to a stack of core network switches. To adhere to standard change management best practices and maintain high availability during the maintenance window, which TWO of the following tasks should be completed prior to deploying the patch into production?
Geçerli olan tümünü seçin
Match each wireless security standard on the left with its primary encryption cipher or key exchange protocol on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A system architect is upgrading a research organization's WLAN infrastructure to protect sensitive data transfers. The security policy mandates centralized per-user authentication integrated with an identity provider, mutual authentication between clients and RADIUS servers, and resistance against credential theft via offline dictionary attacks. Which of the following technical requirements and protocol implementations must be selected to satisfy this policy? (Select TWO.)
Geçerli olan tümünü seçin
A network security architect is evaluating security enforcement mechanisms across an enterprise infrastructure. Match each intrusion detection/prevention architecture and engine mechanism on the left to its distinct operational characteristic or structural limitation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a network audit, a systems engineer observes peak-hour throughput saturation on a primary WAN edge switch. The engineer must implement telemetry monitoring to track traffic volume by source/destination IP address pairs, protocols, and port numbers without capturing full packet payloads. Additionally, hardware health metrics must be polled securely across the management VLAN with requirements for cryptographic user authentication and data encryption. Which combination of monitoring technologies and security configurations meets all specified requirements?
A company is planning to modify the access control lists (ACLs) on its main gateway router to accommodate a new internal service. Before submitting the Request for Change (RFC) to the Change Advisory Board (CAB), which element is most critical to include in the proposal to minimize potential downtime if the modification causes unexpected network instability?
During a network performance check of a real-time audio application, an administrator notices that speech quality degrades due to irregular delivery times of audio packets. Which network performance metric specifically measures this variation in packet arrival times?
A network security administrator is tasked with deploying a wireless network across a financial organization's operations center. Executive policy mandates strict compliance with 192-bit cryptographic strength for all payload encryption, mandatory Protected Management Frames (PMF), and centralized identity validation through a RADIUS infrastructure using digital certificates. Which wireless security suite and cipher implementation must the administrator select to satisfy all organizational security mandates?