Tüm alıştırma soruları
2237 soru
A corporate enterprise plans to deploy a new port security baseline across all access switches at branch office sites during an upcoming scheduled maintenance window. Which of the following components MUST be included within the formal Request for Change (RFC) document prior to submitting it for Change Advisory Board (CAB) review? (Select TWO.)
Geçerli olan tümünü seçin
Match each network security threat to its corresponding attack vector or operational mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each physical security control or environmental measure on the left with its primary protective function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is configuring centralized administration for network switches. The organization's security policy mandates that every CLI command executed by administrators must be individually authorized and audited, and all traffic between the switch and authentication server must be completely encrypted. Which authentication protocol should the administrator deploy to satisfy these requirements?
An enterprise implements Virtual Router Redundancy Protocol (VRRP) across two core switches to provide high availability for client devices on a production VLAN. During a scheduled test, the primary switch is powered down, and network logs confirm that the standby switch successfully transitions to the master role. However, workstations on the VLAN immediately lose external network connectivity and fail to recover. Diagnostics show that VRRP advertisement packets and virtual MAC transitions operated correctly. Which of the following host misconfigurations is the most likely cause of this connectivity failure?
A network technician is preparing to establish a secure management baseline on a newly unboxed switch prior to connecting it to the production network. Place the following administrative hardening steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is deploying a dual-protocol Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec) remote access VPN for mobile employees, integrated with a central RADIUS server for enterprise AAA. Which of the following technical requirements and protocol characteristics are accurate for this implementation? (Select TWO.)
Geçerli olan tümünü seçin
A network engineer installs dual redundant power distribution units (PDUs) and configures a dynamic link aggregation group (LAG) across two physically separate switch stacks for an enterprise storage cluster. Which core pillar of the CIA triad does this redundant architecture primarily support?
A network technician is investigating reports of intermittent dropouts and low data rates for mobile workstations in a newly renovated wing of a medical facility. The access point status indicates normal operational health, but a site measurement near the reinforced concrete walls shows a received signal strength indicator (RSSI) of -84 dBm compared to -52 dBm in the central hallway. Which of the following is the most likely cause of the degraded wireless performance?
A network security administrator is updating physical and environmental defense measures for a new enterprise data facility. Match each physical security or environmental risk on the left with its corresponding primary control measure on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is setting up a site-to-site IPsec VPN connection between a branch office router and the headquarters firewall. The branch office router is situated behind an ISP border device that performs Network Address Translation (NAT). During testing, the administrator notes that IPsec Encapsulating Security Payload (ESP) packets are dropped when traversing the NAT gateway because address translation alters packet headers and breaks cryptographic integrity checks. Which feature should be configured to encapsulate the IPsec traffic and allow successful traversal across the NAT device?
Users in an enterprise office report severe latency and high packet loss when connected to the 2.4 GHz Wi-Fi network near a central atrium. A spectral scan reveals several neighboring access points operating on channels 3, 4, and 5 with 40 MHz channel widths. Which TWO of the following actions should the network administrator take to resolve the wireless signal degradation? (Select TWO.)
Geçerli olan tümünü seçin
A network security engineer is creating an extended IPv4 Access Control List (ACL) on a perimeter router to regulate inbound traffic from an untrusted partner network () destined for an internal server subnet (). The security policy specifies the following administrative priorities:
1. All SSH policy enforcement (specific host access and subnet-wide restrictions) must be evaluated first.
2. Application database traffic must be permitted for the designated database host only.
3. All other unapproved traffic from the partner network to the internal subnet must be explicitly dropped at the end of the ACL.
Arrange the following ACL statements in the correct top-to-bottom sequence (from Line 10 to Line 40) to enforce this policy without rule shadowing or logic errors.
Öğeleri doğru sıraya koymak için sürükleyin
A network engineer is preparing a formal Request for Change (RFC) for an upcoming core router configuration update during a scheduled maintenance window. The Change Advisory Board (CAB) mandates that all high-impact RFCs include provisions to minimize operational downtime in case the update causes unforeseen service disruption. Which of the following components MUST be explicitly defined within the RFC to fulfill this mandatory requirement?
A network administrator is troubleshooting severe signal degradation and frequent disconnections reported by users working near large metal shelving units in a warehouse environment. A site survey reveals high signal attenuation and co-channel interference on the 2.4 GHz band. Which TWO of the following troubleshooting steps should the administrator perform to resolve these wireless connectivity issues?
Geçerli olan tümünü seçin
A network technician receives a service desk ticket regarding a user who has lost network connectivity. The technician gathers information from the user and formulates a probable cause that a loose Ethernet cable at the wall jack is causing the outage. According to the official CompTIA troubleshooting methodology, which step should the technician perform NEXT?
Following a maintenance check on a central data hall's environmental control system, telemetry logs indicate that the relative humidity () inside the facility has dropped to , while the ambient air temperature remains stable at (). Which of the following operational risks is most significantly increased by allowing this low humidity level to persist?
A network administrator notices that local endpoint traffic intended for the default gateway is being redirected to an unauthorized workstation. Packet captures reveal that the unauthorized workstation is repeatedly sending unsolicited gratuitous ARP replies associating the default gateway's IP address with its own MAC address. Which of the following attack types is occurring?
Users in a newly renovated office space report severe latency and frequent packet loss while connected to the wireless network. A network technician measures the Received Signal Strength Indicator (RSSI) on an affected client device and records a strong signal reading of . However, the Signal-to-Noise Ratio (SNR) is measured at only , leading to high retransmission rates. Which of the following is the most likely cause of this performance degradation?
A network engineer is configuring an IPsec site-to-site VPN connection across the Internet between a corporate headquarters router with a static public IP address and a branch office router situated behind a carrier-grade Network Address Translation (CGNAT) gateway. During initial deployment testing, IKEv2 Phase 1 negotiation completes successfully, but IPsec Phase 2 fails to pass encrypted data traffic across the tunnel, resulting in integrity check failure drops on the receiving router. Troubleshooting reveals that the security policy was configured using Authentication Header (AH) in transport mode. Which modification to the VPN configuration will resolve the transmission failure while ensuring payload encryption and data integrity across the NAT boundary?