Network Security
427 soru
A network operations team is upgrading their device management infrastructure to implement centralized command-level access control on enterprise routers. They select TACACS+ over RADIUS to fulfill this security requirement. Which technical capability of TACACS+ directly supports restricting specific administrative commands on a per-user basis?
Match each Virtual Private Network (VPN) or remote access technology on the left with its core security or operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security administrator must configure an IPv4 Access Control List (ACL) on a router to enforce network security policies for the internal subnet . Place the following ACL rules in the correct top-to-bottom sequence so that host-specific restrictions are properly enforced without being shadowed by broader subnet rules.
Öğeleri doğru sıraya koymak için sürükleyin
A network security administrator needs to select a security control that specifically protects log files against unauthorized modification while stored at rest on a syslog server. Which of the following technical controls directly fulfills this Integrity requirement?
An IT security administrator needs to implement a full-tunnel remote access VPN solution for traveling employees. The primary constraint is that these employees frequently connect from restrictive public Wi-Fi networks and hotels where firewalls block non-standard outbound ports as well as native IPsec protocols (such as IKE UDP 500/4500 and ESP). The chosen protocol must provide complete network-layer access to internal IP subnets while seamlessly encapsulating traffic over standard HTTPS. Which of the following VPN technologies best fulfills these requirements?
A network engineer is configuring a remote access Virtual Private Network (VPN) solution using Layer 2 Tunneling Protocol over IPsec (L2TP/IPsec) for corporate users. Which of the following technical characteristics and operational requirements correctly apply to this deployment? (Select TWO.)
Geçerli olan tümünü seçin
An administrator notices that servers mounted in the middle of several server rack rows are experiencing thermal warnings during peak utilization. Environmental monitoring reveals that cool supply air from raised floor vents is mixing directly with hot exhaust air from adjacent equipment rows prior to entering server intake fans. Which physical infrastructure design change should the network administrator implement to prevent this air mixing?
A network security administrator is tasked with baseline hardening for a newly installed Layer 3 enterprise switch before connecting it to the production network. Corporate security compliance mandates that the configuration must mitigate double-tagging VLAN hopping attacks on trunk connections, prevent unauthorized access on unassigned physical ports, and protect administrative sessions from eavesdropping and tampering. Which set of device hardening measures best meets these requirements?
A network administrator is designing security controls for an enterprise application that transmits customer records across an untrusted network. The security policy dictates that the solution must prevent unauthorized eavesdropping on the payload content while also ensuring any unauthorized modifications to the data during transit are detected. Which TWO of the following security measures directly address these requirements?
Geçerli olan tümünü seçin
An IT manager is reviewing a proposed wireless network implementation for a corporate office. The security policy mandates individual user accountability through centralized 802.1X RADIUS authentication alongside mandatory Protected Management Frames. The installation team proposes deploying WPA3-Personal with a robust shared passphrase to streamline client onboarding. Which of the following statements best evaluates this proposal against the organization's requirements?
A system administrator notices that log events from the client subnet are not reaching the central Syslog server located at . An extended IPv4 Access Control List (ACL) applied inbound on the router interface serving the client subnet contains the following entries:
access-list 105 permit tcp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 514
access-list 105 permit udp 10.100.20.0 0.0.0.255 host 192.168.10.50 eq 161
access-list 105 deny ip any any
Which configuration error is preventing the log messages from reaching the Syslog server?
A network administrator is reviewing security logs for remote employees connecting to the corporate network via a client-based Remote Access Virtual Private Network (VPN). The administrator discovers that while remote users can access internal private servers, their web browsing traffic to external internet sites is being routed directly through their local home internet service providers rather than through the corporate firewall and web content filter. Which of the following configuration settings on the VPN concentrator or client profile should the administrator modify to ensure all network traffic from remote clients is routed through the secure tunnel?
An enterprise organization experiences a security incident where a system administrator denies executing a set of unauthorized configuration changes on a core network switch, claiming another user forged their session. The security team must implement a technical control that ensures administrative actions can be cryptographically traced to a specific individual who cannot later deny performing them. Which of the following security concepts best meets this operational requirement?
A network engineer is conducting a security baseline hardening exercise on a branch office router. The audit reveals that administrative management sessions and remote telemetry are currently using unencrypted legacy protocols. The engineer must secure the management plane so that all administrative command access and monitoring data are protected against eavesdropping and unauthorized modification. Which TWO configuration actions should the network engineer implement to meet these hardening requirements?
Geçerli olan tümünü seçin
A network administrator is deploying a WPA3-Enterprise wireless network for corporate headquarters to satisfy compliance mandates for individual user accountability and wireless management security. Which of the following components or protocol features are mandatory requirements when implementing WPA3-Enterprise? (Select TWO.)
Geçerli olan tümünü seçin
An organization is renovating a central server room that houses high-density rack servers and critical core switches. The facility team needs to install a fire suppression system that immediately extinguishes electrical fires without leaving residue, causing short circuits, or damaging sensitive electronic components. Which of the following fire suppression systems best meets these physical environmental requirements?
A network administrator is configuring inbound firewall rules on a perimeter security appliance for a web server located in a DMZ with IP address . Public users must be able to access the secure web application, and system administrators must be able to perform remote command-line administration from an authorized external management subnet (). Which of the following rule configurations are required to fulfill these security requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is implementing hardening controls on an enterprise core switch following a security audit. The audit report flagged two primary vulnerabilities: administrative monitoring data and CLI sessions are being transmitted without payload encryption, and untagged management traffic is exposed to potential VLAN hopping attacks across 802.1Q trunk lines. Which set of device hardening configurations directly remediates both identified security risks?
A network security architect is reviewing the organization's technical controls to ensure alignment with foundational security principles. Match each core security principle on the left with the technical control on the right that primarily enforces it.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security administrator is deploying a site-to-site Virtual Private Network (VPN) using Internet Key Exchange version 2 (IKEv2) and IPsec. Place the following operational phases and message exchanges in the correct chronological order from the first step to the final step during successful tunnel negotiation and data transfer.
Öğeleri doğru sıraya koymak için sürükleyin