Tüm alıştırma soruları
2237 soru
A network administrator notices that an internal web server has suddenly stopped accepting new client connections. Analysis of packet captures shows thousands of incoming TCP packets with the SYN flag set coming from randomized source IP addresses, but none of these clients complete the three-way handshake with an ACK response. Which type of network attack is occurring?
Prior to performing a major routing protocol modification on an enterprise core network, an engineer must submit documentation detailing how to undo the modifications should performance degrade. Which of the following change management elements fulfills this requirement?
Match each secure remote access protocol or tunneling technology on the left to its corresponding architectural characteristic and operational port specification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each network attack type on the left with its corresponding vector or characteristic description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is troubleshooting intermittent quality degradation during corporate video conference calls across a site-to-site WAN link. While aggregate interface bandwidth utilization remains below capacity, users report packet arrival time variation (jitter) and video freezing. The administrator needs to analyze flow-level conversation statistics—specifically tracking source/destination IP addresses, port numbers, and byte counts—to pinpoint non-business application traffic consuming link resources. Which telemetry protocol and transport method should be implemented on the WAN edge router to export these flow statistics?
An enterprise security architect is specifying a centralized remote administration protocol to manage network switch and router configurations across the organization. The security policy strictly mandates granular authorization controls to restrict specific commands executed by administrators, as well as full-payload encryption for all packets transmitted between network hardware and the backend authentication server. Which authentication protocol should be implemented to meet these requirements?
A network administrator is configuring a IPv4 Access Control List (ACL) on a router interface to protect an internal server at IP address 10.0.0.5. The security requirement dictates that SSH management traffic (TCP port 22) to the server must be blocked from all sources, HTTPS web traffic (TCP port 443) must be allowed from the internal workstation subnet (192.168.1.0/24), all other general IP traffic from the internal workstation subnet to the server must be allowed, and all remaining traffic must be dropped. In what order, from top to bottom, should these ACL rules be placed to ensure proper filtering without rule shadowing?
Öğeleri doğru sıraya koymak için sürükleyin
A network security administrator is performing a compliance audit on an enterprise wireless infrastructure. Match each wireless security standard configuration on the left to its mandatory encryption algorithm and cryptographic authentication mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network engineering team is drafting a Request for Change (RFC) to deploy automated configuration management scripts across enterprise cloud interconnect routers. Which TWO of the following operational elements must be formally documented within the RFC prior to submitting it to the Change Advisory Board (CAB) for approval?
Geçerli olan tümünü seçin
Match each network performance metric with the operational measurement or network condition it directly quantifies.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is evaluating remote access solutions and decides to deploy Layer 2 Tunneling Protocol combined with IPsec (L2TP/IPsec) for remote employees. Which of the following statements correctly describe the functions and security characteristics of this combined VPN solution? (Select TWO.)
Geçerli olan tümünü seçin
Match each wireless security standard to its primary encryption algorithm or authentication mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise network engineer is configuring centralized event logging for perimeter switches sending data across a WAN connection. Security policy mandates that log messages must be delivered reliably to ensure no log loss during link congestion and that all log payloads must be cryptographically encrypted in transit. Which of the following transport protocols and port configurations best meets these compliance requirements?
To address an active security advisory affecting perimeter routing hardware, an engineer is tasked with implementing an urgent software patch. Before committing the patch package to primary operational equipment, which set of procedures best ensures network stability and recovery capability in accordance with standard maintenance practices?
A network administrator is migrating a corporate wireless network to WPA3-Enterprise to enhance access control and audit capabilities for individual staff members. During deployment, a junior technician suggests configuring Simultaneous Authentication of Equals (SAE) across the wireless access points to simplify onboarding without integrating the organization's existing RADIUS server. Which of the following best explains why this recommendation fails to meet the enterprise security requirement?
A network engineer is configuring a pair of redundant Layer 3 switches using Virtual Router Redundancy Protocol (VRRP) to provide default gateway high availability for an enterprise VLAN. The design requires that traffic automatically reroutes to the backup switch if the primary switch loses its connection to the core network, and that the primary switch resumes gateway duties once the core link is restored. Which TWO configuration settings must be implemented on the primary switch to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network technician observes that network traffic intended for the local default gateway is being intercepted by an unauthorized computer on the same subnet. Investigation reveals that the unauthorized computer sent spoofed Address Resolution Protocol messages to update the IP-to-MAC address resolution tables of neighboring hosts. Which of the following attack types is taking place?
A network administrator is tasked with setting up a high-performance network monitoring solution for an enterprise core switch. The monitoring system must collect flow-level traffic statistics to analyze bandwidth utilization by application, while also enabling secure management polling and alerting without exposing telemetry data or authentication credentials to eavesdropping on the management network. Which of the following protocol configurations and telemetry methods should the administrator implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An organization is deploying a secure remote access solution for traveling employees. The network security team specifies that the solution must encapsulate and encrypt all network-layer (Layer 3) IP traffic between host laptops and the central gateway, ensuring the original internal IP header is completely hidden while traversing the public Internet. Which protocol and deployment mode best satisfies these requirements?
After applying a newly defined Access Control List (ACL) containing only a single permit statement for a specific management host onto a router interface, a network technician notices that all traffic from other hosts on the network is immediately blocked. What default ACL behavior causes this traffic to be dropped?