Network Security
427 soru
Match each network attack vector to its primary technical mechanism or observed network anomaly.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security technician is analyzing packet captures from an enterprise user segment after host traffic was unexpectedly intercepted. The packet capture shows multiple unsolicited ARP responses associating the default gateway's IP address with an unauthorized host's MAC address. Which of the following options correctly identify the mechanism behind this incident and an effective defense? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator investigating wireless network instability observes that corporate laptops are repeatedly disconnected from the primary access point after receiving spoofed 802.11 management frames. Immediately following these disconnections, several client devices automatically connect to a nearby unauthorized access point broadcasting the same Service Set Identifier (SSID). Which of the following attack types is primary driver behind this network disruption?
A network security engineer is configuring a central remote-access VPN gateway to integrate with an external authentication server. According to the organization's compliance policy, the selected authentication protocol must encrypt the entire packet payload during transit and strictly separate authentication from authorization duties. Which protocol should the engineer implement on the VPN gateway?
A financial firm is upgrading the wireless infrastructure across its corporate headquarters to comply with updated security policies. The engineering team must implement a wireless architecture that enforces centralized, individual user authentication against an existing RADIUS server and utilizes 256-bit Galois/Counter Mode Protocol (GCMP-256) for data confidentiality. Which wireless security deployment combination directly fulfills these mandate requirements?
A network security administrator is configuring an IPsec Remote Access VPN using IKEv1 Main Mode. Place the four primary operational steps of the IKE handshake process into the correct chronological sequence from start to finish.
Öğeleri doğru sıraya koymak için sürükleyin
A network security engineer configures a stateful firewall to protect an internal database server residing at that receives connections from an application server at over TCP port . An inbound rule permitting traffic from source IP to destination IP on TCP port is explicitly applied. Although no explicit outbound rule is created to permit return traffic from the database server back to the application server's ephemeral ports, communication functions normally without packet drops. Which of the following best explains why the return traffic is successfully permitted through the firewall?
A network administrator is designing a wireless infrastructure upgrade to implement WPA3-Enterprise across corporate headquarters. The design must ensure individual user accountability, centralized authentication, and protection against management frame spoofing attacks. Which of the following technical specifications and security mechanisms are required for this deployment? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is securing a newly deployed edge router at a remote facility. The organization requires central monitoring of system health over public networks while enforcing payload encryption and cryptographic user authentication. Additionally, legacy unencrypted protocols must be removed. Which configuration strategy best satisfies these hardening requirements for network monitoring?
A network technician is provisioning an isolated Wi-Fi network for temporary contractors at a branch office. The organization requires protection against offline dictionary attacks and passive eavesdropping, but explicitly wants to avoid the operational complexity of deploying an 802.1X RADIUS server or digital certificates. Which wireless security standard and authentication mechanism best meets these specifications?
A network administrator is configuring an extended IPv4 Access Control List (ACL) on a gateway router to secure a DMZ web server at IP address . The security policy requires allowing inbound web traffic (HTTPS) from any external source, and allowing remote administration (SSH) strictly from the internal network management subnet (). All other inbound traffic must be blocked. Which TWO of the following extended ACL statements must be included to satisfy these requirements? (Select TWO)
Geçerli olan tümünü seçin
A network security administrator is analyzing recorded security incident logs and anomaly reports across enterprise infrastructure. Match each observed security incident on the left to the corresponding network attack vector on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an internal security assessment, a system administrator is tasked with securing the administrative management plane of a core network switch against unauthorized remote access and brute-force authentication attacks. Which of the following hardening practices should the administrator implement on the device? (Select TWO.)
Geçerli olan tümünü seçin
Match each wireless security standard to its corresponding cryptographic cipher and integrity mechanism.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator configures a new extended IPv4 Access Control List (ACL) on a router interface serving an R&D subnet (). The administrator creates specific rules to permit hosts on this subnet to access an internal file server () via FTP. Immediately after applying the ACL inbound on the interface, users on the subnet report that they have lost connectivity to the internet and all other company subnets. What is the primary cause of this widespread connectivity failure?
During a routine network security audit, an administrator notices that internal workstation traffic destined for external web services is being redirected to an unauthorized local host on the same switch segment. An inspection of local workstation cache tables reveals that the default gateway's IP address has been mapped to the attacker's network interface card address, allowing the attacker to inspect and modify traffic prior to forwarding it. Which of the following attack types has occurred?
A network administrator is deploying a wireless network for standalone IoT inventory scanners in a logistics warehouse. Corporate security policies mandate protection against offline dictionary attacks through Simultaneous Authentication of Equals (SAE) without relying on a centralized RADIUS authentication server. Which wireless security standard should the administrator implement to fulfill these requirements?
During a post-incident audit at a branch office, a security analyst discovers that an unauthorized device successfully connected to the internal network by plugging into an unassigned Ethernet wall port. Further inspection reveals that all unassigned switchports remain administrative enabled in their default state on VLAN 1. Which of the following actions represents the best practice to harden these unassigned ports against unauthorized physical network access?
A network administrator needs to apply an inbound extended Access Control List (ACL) on a router interface connected to the user subnet to secure access to a server located at . The policy must enforce the following requirements:
1. Allow administrator workstation SSH access (TCP port 22) to the server.
2. Block host from accessing HTTP services (TCP port 80) on the server.
3. Allow all other hosts on the subnet to access HTTP services (TCP port 80) on the server.
4. Block all other unauthorized IP traffic.
Arrange the given ACL statements in the correct top-to-bottom processing sequence to enforce this security policy without rule shadowing.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise security Operations center detects two distinct anomalous network activities. First, an external threat actor transmits forged requests to public time servers, causing heavy response traffic to flood an internal web server's public IP interface. Second, an internal rogue host answers local broadcast Link-Local Multicast Name Resolution (LLMNR) queries to redirect workstations to a fake login portal. Which of the following attack types and vectors are present in this scenario? (Select TWO)
Geçerli olan tümünü seçin