Tüm alıştırma soruları
2237 soru
During a security audit of network infrastructure management practices, an auditor notes that switch management sessions rely on a protocol that encrypts only the password field within packet headers and combines authentication and authorization into a single service over UDP. To achieve full payload encryption, command-by-command authorization decoupling, and reliable connection-oriented transport on port 49, which protocol should be deployed?
A network operations engineer is investigating a routing failure following an unexpected failover between two redundant core routers. During the incident analysis, the engineer suspects that client workstations were incorrectly configured with the physical interface IP address of a single router rather than the shared Virtual IP (VIP) designated for the First Hop Redundancy Protocol (FHRP) group. To validate the authoritative VIP allocations, Layer 3 subnet boundaries, and associated VLAN identifiers without relying on live device configurations, which network documentation artifact should the engineer consult?
A network technician needs to establish an encrypted command-line management session with a core switch across the local subnet. Which protocol should the technician use to ensure administrative credentials are encrypted during transmission?
A network administrator configures an extended IPv4 Access Control List (ACL) on a router interface filtering inbound traffic toward an internal database subnet (). The ACL is designed to meet three requirements:
1. Allow secure administration from a jump host at via SSH (TCP 22).
2. Allow application servers on subnet to access the database server at on TCP port 5432.
3. Block all other traffic originating from subnet .
The administrator enters the following ACL entries in sequential order:
- Entry 10: `permit tcp host 10.50.1.15 10.50.10.0 0.0.0.255 eq 22`
- Entry 20: `deny ip 10.50.2.0 0.0.0.255 10.50.10.0 0.0.0.255`
- Entry 30: `permit tcp 10.50.2.0 0.0.0.255 host 10.50.10.100 eq 5432`
During testing, application servers on subnet are unable to establish database connections to . Which of the following best explains why this configuration fails?
A network technician discovers that queries sent to the local DNS server for a company intranet portal are resolving to an unauthorized external IP address due to corrupted cache entries. Which network attack vector does this scenario describe?
A security technician needs to configure an extended Access Control List (ACL) rule on a router to permit secure HTTPS web traffic from an internal subnet to an external web server. Which transport protocol and destination port combination must be specified in the ACL rule to correctly match this traffic?
A network administrator is auditing the physical and environmental security controls of a newly built enterprise data center. During inspection, the administrator notes that the HVAC system is maintaining ambient relative humidity at 15% inside the server room. Which of the following recommendations should the administrator make to address the primary risk caused by this environmental condition?
A network operations team is upgrading the enterprise monitoring architecture to address bandwidth degradation, security compliance, and service level agreement (SLA) tracking across site-to-site WAN links. Match each network performance monitoring technology or protocol on the left with the specific operational monitoring requirement it directly satisfies on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network engineer at a high-density regional hospital is upgrading the facility's wireless infrastructure to improve security and auditability. The security policy mandates that every medical staff member must authenticate to the corporate SSID using their unique Active Directory credentials, allowing central logging of user sessions via 802.1X RADIUS. During the deployment planning, a technician proposes configuring WPA3-Personal with Simultaneous Authentication of Equals (SAE) and distributing unique static passphrases to staff groups to avoid modifying existing RADIUS server certificate policies. Which of the following best explains why the technician's proposed solution fails to meet the corporate security mandate, and what configuration must be enforced instead?
A network administrator is configuring an extended IPv4 Access Control List (ACL) on a router interface to control traffic from the client workstation subnet () targeting the corporate server farm subnet (). The security policy specifies the following requirements for traffic destined for the database server () and the rest of the server farm:
1. SSH administrative access (TCP port 22) to host must be permitted ONLY from the primary administrator workstation at IP address .
2. All other SSH traffic (TCP port 22) to host originating from subnet must be explicitly blocked.
3. All non-SSH TCP traffic from subnet to host must be permitted.
4. Non-TCP IP traffic from subnet to host must be blocked.
5. All IP traffic from subnet to all other servers in subnet must be permitted.
In what top-to-bottom sequential order must the ACL entries be placed on the interface to enforce this security policy without rule shadowing?
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is designing security controls for transmitting sensitive corporate financial records between two remote office sites over an untrusted public network. The controls must ensure that unauthorized parties cannot intercept and read the data, and that any tampering during transit is immediately detected. Which TWO of the following technical mechanisms should the administrator implement to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network security engineer is deploying a remote access VPN solution using L2TP over IPsec (L2TP/IPsec) to support remote workers connecting from behind residential NAT routers. Authentication will be offloaded to a central enterprise AAA server. Which of the following port and protocol configurations must be permitted on the network firewalls and VPN gateway to ensure successful connection establishment and authentication? (Select TWO.)
Geçerli olan tümünü seçin
During a high-availability failover test on an enterprise subnet, client workstations lose all outbound network connectivity whenever the primary active router is powered off. Network logs confirm that the secondary router successfully assumes the active role within the First Hop Redundancy Protocol (FHRP) group and advertises the virtual MAC address. However, workstations fail to route traffic to external networks until the primary router is brought back online. Which of the following is the primary cause of this connectivity loss?
An organization is deploying an enterprise remote access VPN solution for mobile users who frequently operate behind Carrier-Grade NAT (CGNAT) and restrictive corporate firewalls. The network security team requires mutual certificate authentication, complete confidentiality of internal IP headers, and seamless NAT traversal without dropping integrity checks. Which of the following technical configurations and protocol mechanisms must be selected to satisfy these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator needs to construct an IPv4 extended Access Control List (ACL) to filter traffic originating from the internal subnet . The security policy requires the following requirements in order of processing:
1. Allow host to access web server using secure HTTPS (port 443).
2. Block all other hosts on the subnet from reaching server .
3. Permit all remaining outbound traffic from subnet to any other destination.
4. Catch and drop all remaining unspecified IP traffic.
In what order should these ACL statements be evaluated from top to bottom to satisfy the security policy without shadowing any rules?
Öğeleri doğru sıraya koymak için sürükleyin
A network engineer is configuring a centralized AAA server to support 802.1X port-based network access control across an enterprise wireless deployment. Which configuration parameters accurately specify the default transport protocol and port assignments required for standard RADIUS authentication and accounting services?
A system auditor observes that malicious encrypted TLS command-and-control (C2) traffic traversing an internal server VLAN went completely undetected by a newly installed Network Intrusion Detection System (NIDS) connected to a core switch SPAN port. The organization requires a security solution that can inspect host system calls, file integrity changes, and decrypted application memory buffers on critical servers without altering network physical cabling or introducing a single point of failure that causes latency on the switch hardware. Which solution should be implemented to fulfill these security and architectural requirements?
Following an emergency vendor security advisory regarding a remote code execution vulnerability in core routing hardware, an administrator is tasked with updating the operating system software. To minimize operational risk and strictly follow standardized patch management lifecycle procedures, which action should the administrator execute first prior to deploying the software update in the live environment?
A network administrator is configuring three adjacent 2.4 GHz wireless access points in an office floor plan. Which combination of channels should be assigned to these access points to prevent co-channel and adjacent-channel interference?
A network engineer is investigating intermittent packet loss and database session drops across a newly provisioned IPsec VPN tunnel between two enterprise data centers. After analyzing interface counters and running test ping sweeps with custom payload sizes, the engineer successfully proves that an MTU mismatch is causing packet fragmentation errors and confirms that lowering the tunnel interface MTU in a staging sandbox completely eliminates the drop count. According to the CompTIA troubleshooting methodology, which action should the engineer perform NEXT?