Network Security
427 soru
Match each wireless security standard to its primary encryption algorithm or authentication mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is migrating a corporate wireless network to WPA3-Enterprise to enhance access control and audit capabilities for individual staff members. During deployment, a junior technician suggests configuring Simultaneous Authentication of Equals (SAE) across the wireless access points to simplify onboarding without integrating the organization's existing RADIUS server. Which of the following best explains why this recommendation fails to meet the enterprise security requirement?
A network technician observes that network traffic intended for the local default gateway is being intercepted by an unauthorized computer on the same subnet. Investigation reveals that the unauthorized computer sent spoofed Address Resolution Protocol messages to update the IP-to-MAC address resolution tables of neighboring hosts. Which of the following attack types is taking place?
An organization is deploying a secure remote access solution for traveling employees. The network security team specifies that the solution must encapsulate and encrypt all network-layer (Layer 3) IP traffic between host laptops and the central gateway, ensuring the original internal IP header is completely hidden while traversing the public Internet. Which protocol and deployment mode best satisfies these requirements?
After applying a newly defined Access Control List (ACL) containing only a single permit statement for a specific management host onto a router interface, a network technician notices that all traffic from other hosts on the network is immediately blocked. What default ACL behavior causes this traffic to be dropped?
A network security architect at a high-security research institution is deploying a new wireless network to comply with National Security Agency (NSA) Commercial National Security Algorithm (CNSA) Suite standards. The compliance mandate specifies that all wireless communications must use 192-bit cryptographic strength for both data confidentiality and integrity, paired with centralized identity management. Which configuration combination on the wireless LAN controller (WLC) and authentication server satisfies all aspects of this security mandate?
Match each intrusion detection or prevention system (IDS/IPS) architecture and mechanism on the left to its corresponding operational scenario on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is deploying a wireless network for an enterprise office. Management requires each employee to authenticate individually using their corporate domain credentials via an IEEE 802.1X RADIUS server, rather than relying on a shared passphrase. Which wireless security mode should the administrator configure?
A network technician applies an Access Control List (ACL) to a router interface containing a single entry that permits outbound HTTP traffic from an internal subnet. Immediately after applying the rule, users report that all non-HTTP network traffic originating from that subnet is blocked. Which fundamental ACL rule mechanism causes traffic not explicitly allowed to be dropped automatically?
Match each remote access security technology or VPN architectural mechanism on the left to its corresponding operational characteristic and protocol specification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security consultant is conducting an audit of an organization's multi-generational wireless network infrastructure. Match each wireless security requirement or vulnerability scenario to its corresponding cryptographic protocol or mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is evaluating remote access and tunneling configurations to meet specific enterprise connectivity requirements. Match each secure tunneling protocol or configuration mode on the left with its defining operational characteristic or protocol constraint on the right. Which pairs correctly match each remote access security technology to its technical behavior?
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security analyst is reviewing a remote access VPN architecture that combines Layer 2 Tunneling Protocol (L2TP) with IPsec alongside a centralized AAA server infrastructure. Which of the following statements correctly describe the technical protocol characteristics and operational requirements of this solution? (Select TWO.)
Geçerli olan tümünü seçin
An organization is updating its perimeter defenses to protect a cluster of public-facing web servers from known exploit signatures. The security policy mandates that malicious traffic must be actively blocked in real time before reaching the internal network segment, while ensuring zero processing load added to the web servers' host operating systems. Which deployment architecture best fulfills these requirements?
A network technician captures packet traces while troubleshooting administrative access logs on core routers. The trace analysis reveals that the authentication protocol operates over UDP, encrypts only the password field within packets, and combines authentication and authorization procedures into single exchange pairs. Which security protocol is actively in use for this centralized access control system?
A network administrator discovers that hosts on a local subnet are directing default gateway traffic to an unauthorized computer's MAC address. An inspection reveals that the ARP caches on the affected hosts associate the default gateway's IP address with the attacker's MAC address. Which of the following statements correctly describe the mechanisms or impact of this network security attack? (Select TWO)
Geçerli olan tümünü seçin
A network administrator is reviewing basic firewall operations and Access Control List (ACL) filtering rules. Which of the following statements correctly describe how these security mechanisms function? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is setting up an IPsec remote access VPN tunnel for mobile workers. Place the steps of the Internet Key Exchange (IKE) negotiation process in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network security administrator is configuring wireless security policies for remote retail branches that lack 802.1X/RADIUS authentication infrastructure. The new security baseline requires protecting modern client connections against offline dictionary attacks and wireless deauthentication frame spoofing. However, legacy Wi-Fi 5 point-of-sale terminals that only support WPA2-Personal (AES-CCMP) and do not support 802.11w Protected Management Frames (PMF) must continue operating on the same SSID until phase-out. Which of the following security settings must the administrator configure on the wireless controllers to meet all operational and security criteria? (Select TWO)
Geçerli olan tümünü seçin
A network security technician is configuring a secure wireless deployment for a financial institution's regional office. Organization policy requires individual user accounting and authentication against a central Active Directory infrastructure via a RADIUS server, along with enforced protection against deauthentication and management frame spoofing attacks. Which wireless security deployment standard and authentication combination fully satisfies these organization requirements?