Network Security
427 soru
A network security administrator is evaluating network security monitoring appliances for an enterprise network segment that hosts time-sensitive industrial SCADA controllers. The team is deciding between installing an out-of-band passive Network Intrusion Detection System (NIDS) fed by a hardware network TAP versus an in-band inline Network Intrusion Prevention System (NIPS). Which of the following statements correctly identify operational trade-offs or characteristics of deploying the passive NIDS architecture over the inline NIPS architecture? (Select TWO.)
Geçerli olan tümünü seçin
A network security analyst is reviewing logs and architecture reports following a series of coordinated security incidents across an enterprise environment. Match each network attack type on the left with its corresponding operational vector or primary mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network technician is configuring environmental controls for a server room housing sensitive equipment. To minimize the risk of electrostatic discharge (ESD) damaging internal hardware components, which environmental measure should be maintained within standard recommended thresholds?
Engineers troubleshooting a remote access IPsec IKEv2 VPN deployment notice that clients can successfully complete initial IKE negotiations over UDP port 500 when assigned a public IPv4 address directly. However, when telecommuters attempt to connect from behind residential routers performing Port Address Translation (PAT), Phase 2 negotiation fails and no encrypted data passes through the tunnel because the intermediate PAT router drops IP Protocol 50 (ESP) packets. Which configuration modification on the VPN gateway will resolve this connection issue while preserving payload encryption for telecommuters?
A network administrator is configuring a remote access VPN for external contractors who need access to internal web-based applications. To comply with corporate security policies, the solution must allow access directly through a standard web browser over TCP port 443 without requiring the installation of dedicated endpoint client software on contractor devices. Which VPN technology should the administrator deploy?
A network administrator is configuring remote access VPN user authentication to forward requests to a central server using RADIUS. Which transport protocol and default destination port does RADIUS use for authentication traffic?
A network administrator is configuring a centralized authentication server to support remote access VPN clients using the RADIUS protocol. Security policies require creating specific firewall rules to permit authentication traffic from the VPN gateway to the backend RADIUS server. Which transport protocol and destination port combination must be allowed through the firewall for standard RADIUS authentication?
Match each network security threat to the primary mechanism or vector used to execute the attack.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network engineer is configuring a single Service Set Identifier (SSID) on an enterprise wireless access point to support both modern corporate laptops and legacy handheld scanners during a phased migration to WPA3. To achieve backward compatibility without establishing separate wireless networks, the engineer selects WPA3-Personal Transition Mode. Which TWO of the following technical requirements and configurations must be implemented on the access point for this deployment? (Select TWO.)
Geçerli olan tümünü seçin
A remote employee launches a client-based SSL/TLS VPN software application to connect to the corporate network over an untrusted internet connection. In what chronological order do the steps occur to establish the VPN session and enable secure data transfer?
Öğeleri doğru sıraya koymak için sürükleyin
Match each remote access protocol or security component with its primary technical characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security administrator needs to detect malicious process injections and file modifications on an internal application server that processes encrypted HTTPS traffic. The solution must inspect activity post-decryption without introducing network transmission latency or requiring payload decryption keys on network taps. Which detection system and deployment strategy best meets these requirements?
A network facility manager is reviewing physical security and environmental protection measures for a remote server room. Match each physical security control or environmental measure on the left with its primary operational purpose on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is configuring secure access for a newly installed network switch. The administrator needs to ensure that all web-based administrative traffic between the management workstation and the switch is encrypted to protect sensitive credentials from eavesdropping. Which protocol should be enabled on the switch to meet this requirement?
A network operations team needs to verify that log files sent from edge firewalls to a central monitoring server are not altered or tampered with during transmission. Which core security principle is the team primarily enforcing, and which technical mechanism achieves this goal?
A network security architect is defining wireless encryption and key negotiation baselines across multiple enterprise operating environments. Match each wireless security mode on the left with its corresponding mandatory cipher suite, authentication framework, and integrity mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An infrastructure engineer is designing physical access controls for a high-security data center hall. The facility security policy mandates a mechanism that strictly prevents tailgating (piggybacking) during employee entry. Additionally, in the event of a total facility power outage, exterior access doors must default to a locked state to maintain perimeter security against intruders, while personnel remaining inside the room must be able to exit safely without active electrical power. Which combination of physical access controls best satisfies all specified operational and safety requirements?
A network administrator needs to implement a physical security control for a data center entrance that prevents unauthorized individuals from following authorized personnel through a doorway (tailgating) by using a specialized room with two interlocking doors. Which physical security control should the administrator deploy?
A system administrator discovers an unauthorized wireless access point broadcasting the exact same network name (SSID) as the corporate Wi-Fi network, attempting to trick user devices into connecting to it. Which of the following network attack types best describes this scenario?
A network engineer is configuring a stateless Access Control List (ACL) on a router interface connecting an internal subnet () to an external gateway. To permit outbound DNS name resolution to a public DNS server (), the engineer applies the following outbound ACL entry on the router interface:
`permit udp 10.100.10.0 0.0.0.255 host 8.8.8.8 eq 53`
After applying this configuration, internal client hosts are still unable to resolve domain names. Packet captures confirm outbound DNS query packets are leaving the interface, but clients never receive answers. Which of the following best explains why the DNS resolution is failing?