Tüm alıştırma soruları
2237 soru
A network administrator is designing a secure transport mechanism for automated database replication traffic sent between two geographically separated data centers over the public internet. The design must specifically ensure both the confidentiality of the database records and the integrity of the data while in transit. Which TWO of the following technical controls should the administrator implement to satisfy these core security objectives?
Geçerli olan tümünü seçin
A network administrator configures a clientless SSL/TLS VPN on the corporate gateway to allow remote contractors access to internal management applications. The contractors can successfully authenticate and access internal web portals using their web browsers. However, they report being unable to connect to internal servers using native SSH desktop applications. Which of the following best explains why native SSH sessions fail in this deployment?
A network security administrator is organizing the organization's access control architecture. Match each authentication protocol or framework to its correct operational characteristic and transport mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network technician is configuring a centralized authentication protocol for remote access VPN clients. Which protocol encrypts only the password within the packet payload and operates over UDP?
Match each authentication protocol or security standard to its core operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each network logging protocol, tool, or severity level on the left to its corresponding primary operational function or security characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each network logging and auditing protocol or concept on the left with its corresponding primary characteristic or function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to apply a firmware update to several enterprise network switches following standard operational procedures. In which sequential order should the administrator perform the steps of the patch management lifecycle?
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator implements cryptographic hashing algorithms to verify that transmitted configuration files are not altered or tampered with during transit. Which core pillar of the CIA triad is the administrator primarily protecting?
An enterprise organization is updating its security architecture to protect internal application servers. The solution must achieve two primary objectives: first, detect zero-day exploit attempts against server kernel processes that receive encrypted transport payloads; second, monitor network-wide bandwidth and protocol utilization patterns without introducing packet delivery latency or creating a single point of failure on the network link. Which of the following deployment choices will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network technician needs to upgrade the firmware on a campus access switch following standard IT service management practices. In what chronological order should the technician execute the steps of the change management lifecycle from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is preparing to perform a routine firmware update on enterprise network switches during a scheduled maintenance window. Which TWO of the following tasks should be completed prior to deploying the patch to the production environment? (Select TWO.)
Geçerli olan tümünü seçin
During a scheduled maintenance window, a network engineer deploys a critical configuration update to an edge router to enable new BGP routing policies. Immediately following the change, internal monitoring alerts show severe packet loss across multiple subnets, and remote sites lose connectivity to the primary datacenter. The engineer suspects a misconfigured route map but realizes that testing during the window ran out of time. According to standard change management procedures, which of the following is the MOST appropriate immediate action for the engineer to take?
A network administrator is upgrading device monitoring and logging protocols across the enterprise network to enforce strict encryption and data integrity standards during auditing. Which of the following configuration options fulfill these secure logging requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator deploys two Layer 3 switches (Switch-Alpha and Switch-Beta) using Hot Standby Router Protocol (HSRP) to provide default gateway redundancy for a server subnet (). Switch-Alpha is designated as the primary gateway with an HSRP priority of 120, while Switch-Beta is configured with the default priority of 100. Interface tracking is enabled on Switch-Alpha to decrement its priority by 30 if its uplink interface fails. During a simulated link failure on Switch-Alpha's uplink, its priority drops to 90, allowing Switch-Beta (priority 100) to assume the active gateway role. However, after the uplink link on Switch-Alpha is fully restored and its priority returns to 120, Switch-Beta remains the active gateway while Switch-Alpha stays in standby mode. Which of the following root causes best explains why Switch-Alpha failed to reclaim the active gateway role upon uplink restoration?
A network security administrator is evaluating an automated log collection architecture. Network routers and switches are configured to transmit syslog messages to a centralized syslog server over an encrypted TLS connection. However, the syslog server writes the received log streams directly to a disk volume without generating message digests, cryptographic hashes, or digital signatures. During a post-incident investigation, security analysts discover that an attacker compromised local host credentials on the log server and modified historic log entries to erase evidence of lateral movement. Which security pillar of the CIA triad was directly compromised due to the lack of log hashing or cryptographic validation?
A network engineer is configuring an extended IPv4 Access Control List (ACL) on a stateless router interface filtering outbound traffic leaving a DMZ subnet () toward an internal corporate LAN (). DMZ web servers (–) must respond to HTTPS client requests initiated from the internal LAN and send syslog telemetry to an internal monitoring server () over UDP port 514. Which of the following ACL configuration entries are required on this interface to satisfy these requirements while accounting for stateless filtering mechanics? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is evaluating central authentication services for an enterprise network to support both remote access users and administrative switch management. Which of the following characteristics accurately describe operational differences between the RADIUS and TACACS+ protocols? (Select TWO).
Geçerli olan tümünü seçin
An administrator is configuring 802.1X port-based authentication on an enterprise network switch. Which component in the 802.1X architecture refers to the client workstation or software requesting access to the network?
An enterprise security monitoring system generates an alert after detecting an unexpected surge in incoming UDP traffic targeted at a company's public-facing web server. Analysis of packet captures reveals thousands of external open recursive DNS servers sending large response payloads for ANY and TXT queries that were never initiated by the web server. The source IP address in the initial queries was forged to match the public IP address of the target server, causing severe link congestion. Which type of network attack is occurring?