Network Security
427 soru
A network security engineer is establishing a hardened configuration baseline for a core switch cluster to mitigate internal eavesdropping and unauthorized access risks. A security audit highlights that device telemetry monitoring traffic exposes system OIDs and interface statistics in cleartext across the network, while unassigned access ports and default trunking settings present physical and logical intrusion risks. Which set of device hardening configurations correctly addresses all of these identified vulnerabilities according to industry best practices?
Match each network security threat to its corresponding attack vector or operational mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each physical security control or environmental measure on the left with its primary protective function on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is configuring centralized administration for network switches. The organization's security policy mandates that every CLI command executed by administrators must be individually authorized and audited, and all traffic between the switch and authentication server must be completely encrypted. Which authentication protocol should the administrator deploy to satisfy these requirements?
A network technician is preparing to establish a secure management baseline on a newly unboxed switch prior to connecting it to the production network. Place the following administrative hardening steps in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is deploying a dual-protocol Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec) remote access VPN for mobile employees, integrated with a central RADIUS server for enterprise AAA. Which of the following technical requirements and protocol characteristics are accurate for this implementation? (Select TWO.)
Geçerli olan tümünü seçin
A network engineer installs dual redundant power distribution units (PDUs) and configures a dynamic link aggregation group (LAG) across two physically separate switch stacks for an enterprise storage cluster. Which core pillar of the CIA triad does this redundant architecture primarily support?
A network security administrator is updating physical and environmental defense measures for a new enterprise data facility. Match each physical security or environmental risk on the left with its corresponding primary control measure on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is setting up a site-to-site IPsec VPN connection between a branch office router and the headquarters firewall. The branch office router is situated behind an ISP border device that performs Network Address Translation (NAT). During testing, the administrator notes that IPsec Encapsulating Security Payload (ESP) packets are dropped when traversing the NAT gateway because address translation alters packet headers and breaks cryptographic integrity checks. Which feature should be configured to encapsulate the IPsec traffic and allow successful traversal across the NAT device?
A network security engineer is creating an extended IPv4 Access Control List (ACL) on a perimeter router to regulate inbound traffic from an untrusted partner network () destined for an internal server subnet (). The security policy specifies the following administrative priorities:
1. All SSH policy enforcement (specific host access and subnet-wide restrictions) must be evaluated first.
2. Application database traffic must be permitted for the designated database host only.
3. All other unapproved traffic from the partner network to the internal subnet must be explicitly dropped at the end of the ACL.
Arrange the following ACL statements in the correct top-to-bottom sequence (from Line 10 to Line 40) to enforce this policy without rule shadowing or logic errors.
Öğeleri doğru sıraya koymak için sürükleyin
Following a maintenance check on a central data hall's environmental control system, telemetry logs indicate that the relative humidity () inside the facility has dropped to , while the ambient air temperature remains stable at (). Which of the following operational risks is most significantly increased by allowing this low humidity level to persist?
A network administrator notices that local endpoint traffic intended for the default gateway is being redirected to an unauthorized workstation. Packet captures reveal that the unauthorized workstation is repeatedly sending unsolicited gratuitous ARP replies associating the default gateway's IP address with its own MAC address. Which of the following attack types is occurring?
A network engineer is configuring an IPsec site-to-site VPN connection across the Internet between a corporate headquarters router with a static public IP address and a branch office router situated behind a carrier-grade Network Address Translation (CGNAT) gateway. During initial deployment testing, IKEv2 Phase 1 negotiation completes successfully, but IPsec Phase 2 fails to pass encrypted data traffic across the tunnel, resulting in integrity check failure drops on the receiving router. Troubleshooting reveals that the security policy was configured using Authentication Header (AH) in transport mode. Which modification to the VPN configuration will resolve the transmission failure while ensuring payload encryption and data integrity across the NAT boundary?
A network security administrator applies a new stateless extended IPv4 Access Control List (ACL) to interface in the inbound direction on a perimeter router. The interface serves an internal management VLAN on subnet . The objective of the configuration is to permit local network devices to send SNMP trap notifications to an off-site monitoring server at IP address listening on UDP port 162.
The technician configures a single rule entry:
`access-list 102 permit udp 192.168.4.0 0.0.0.255 host 198.51.100.45 eq 162`
Immediately after applying the ACL with `ip access-group 102 in`, users on the subnet report a complete loss of web access (TCP ports 80/443) and DNS name resolution (UDP port 53) to all external destinations.
Which of the following identifies the root cause of this network outage?
A network administrator is establishing a baseline hardening configuration on a newly deployed edge switch. Which of the following administrative practices should be implemented to secure the management plane of the device? (Select TWO.)
Geçerli olan tümünü seçin
A network security team is updating its enterprise defense framework to align existing technical controls with core security principles. Match each core security principle on the left with its corresponding technical control implementation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise network engineer is designing a physical connectivity architecture between two secure server rooms located on separate floors of a shared multi-tenant commercial facility. High-throughput fiber optic cabling must pass through unmonitored building maintenance risers accessible to third-party facility personnel. The security policy requires real-time automated alerts if physical tampering, unauthorized bending, or physical tapping of the conduit pathway occurs. Which physical security control should the engineer implement to meet this requirement?
An IT technician working in a newly commissioned remote network facility reports experiencing frequent static electric shocks when touching metallic server racks. Subsequent monitoring reveals that the temperature is maintained at , but relative humidity levels inside the room have dropped to . Which of the following environmental security controls should be adjusted to minimize electrostatic discharge (ESD) risks to sensitive network hardware?
A network security administrator is documenting legacy and modern wireless security protocols for a corporate compliance audit. Match each wireless security standard on the left with its corresponding encryption cipher and integrity mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security team investigates an incident where employees on a corporate LAN segment report intermittent connectivity drops and redirection to an untrusted portal. Network packet captures reveal two distinct anomalous activities: a rapid influx of DHCP DISCOVER frames generated using spoofed source MAC addresses to exhaust available IP pool leases, followed by unauthorized DHCP ACK messages directing hosts to use an attacker-controlled default gateway. Which TWO of the following attack types were executed during this incident?
Geçerli olan tümünü seçin