Network Security
427 soru
A network administrator is performing baseline security hardening on a newly installed Layer 3 switch before introducing it to the production network. Place the administrative hardening tasks into the correct sequential order from first step to last step.
Öğeleri doğru sıraya koymak için sürükleyin
A security analyst is reconfiguring the wireless network for a regional medical center's mobile workstation carts to meet stringent health data protection standards. The organization mandates upgrading to WPA3-Enterprise 192-bit mode. Which of the following requirements must be implemented to achieve this configuration? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is configuring a new wireless network for a corporate branch office. Company security policy mandates that every employee must authenticate using their individual domain accounts against a centralized RADIUS server, preventing the use of a shared network passphrase. Which WPA3 security mode and authentication mechanism should the administrator configure on the Wireless LAN Controller (WLC)?
A network engineer configures a stateless router Access Control List (ACL) to allow client workstations on subnet to access an internal web server at . The engineer applies the inbound rule `permit tcp 10.50.1.0 0.0.0.255 host 172.16.10.20 eq 80` on the interface facing the web server. Although initial packets reach the server, workstation browsers consistently time out when attempting to load web pages. Which configuration change will resolve this connection failure?
A network technician needs to isolate administrative access for core switches situated in an unstaffed facility. The security policy dictates that remote administrative management traffic must be completely separated from user data traffic so that compromised production host networks cannot reach the switch management interfaces. Which of the following strategies best fulfills this security requirement?
A network security analyst is updating incident classification guidelines for enterprise threat vectors. Match each network attack type on the left with its corresponding attack vector characteristics on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network engineer is configuring an extended Access Control List (ACL) on a stateless router interface. Client workstations on the internal subnet () can successfully transmit outgoing HTTPS requests ( port ) to external web servers, but return web traffic is blocked by the inbound ACL. Which of the following configuration adjustments will allow internal clients to receive return HTTPS traffic from external servers while maintaining stateless security controls? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is reviewing the management plane configuration of core campus switches during a security hardening initiative. The organization requires encrypted remote management and secure system monitoring. Which TWO configuration actions should the administrator implement to meet these hardening requirements?
Geçerli olan tümünü seçin
A network engineer configures an extended Access Control List (ACL) on an enterprise edge router to allow internal workstations on the subnet to perform domain name queries against an external DNS server at IP address . The engineer enters the following rule on the outbound interface:
`permit udp 10.100.4.0 0.0.0.255 host 8.8.8.8 eq 53`
Users report that basic DNS lookups succeed, but certain applications fail when DNS response payloads exceed bytes or when performing DNSSEC lookups that require switching transport protocols. Which modification to the ACL configuration will resolve this issue while adhering to the principle of least privilege?
A network technician is hardening an access switch installed in a publicly accessible building lobby. A vulnerability audit indicates that the switch port connected to the lobby Ethernet jack is transmitting detailed hardware specifications, system capabilities, and native device hostnames to connected client devices. Which of the following configuration changes should the technician implement on this interface to resolve the information disclosure vulnerability?
A network administrator observing traffic on a managed switch detects unauthorized Ethernet frames originating from a host on VLAN 10 arriving at a server isolated on VLAN 20 without passing through an intervening router. Packet analysis shows that the frames contain two 802.1Q headers: an outer tag corresponding to VLAN 10 (the native VLAN of the trunk link) and an inner tag specifying VLAN 20. Which of the following attack types is being executed?
A network administrator must configure a top-to-bottom sequence of rules in an extended IPv4 Access Control List (ACL) applied inbound on a router interface serving the internal user VLAN (). The ACL must enforce the following security policies for traffic destined to the DMZ web server ():
1. Host must be explicitly allowed HTTPS access ().
2. Host must be explicitly denied HTTP access ().
3. All other hosts on the subnet must be allowed HTTP access ().
4. All other traffic targeting the DMZ subnet () must be blocked.
Arrange the Access Control List (ACL) statements in the correct top-to-bottom evaluation sequence to ensure all rules execute as intended without rule shadowing.
Öğeleri doğru sıraya koymak için sürükleyin
A network security engineer is updating an organization's wireless security baseline to transition branch offices to WPA3-Enterprise. The baseline mandates individual user credential validation integrated with central directory services and protection against wireless management frame spoofing attacks. Which of the following technical requirements must be included in the WPA3-Enterprise specification? (Select TWO).
Geçerli olan tümünü seçin
A network security engineer is configuring secure management plane controls on a newly installed distribution switch before introducing it to the enterprise network. In what sequence should the engineer execute the baseline hardening steps to properly establish and secure SSH administrative access?
Öğeleri doğru sıraya koymak için sürükleyin
A security technician is investigating a multi-stage incident on an enterprise network segment. Packet logs reveal that an unauthorized internal host transmitted forged Gratuitous ARP messages to map the IP address of the default gateway to its own physical address. Simultaneously, internal users reported that entering legitimate domain names into their web browsers redirected them to a suspicious external IP address hosted on an unauthorized server. Which of the following attack types were executed during this incident? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is performing a baseline security hardening audit on core enterprise switches. The security report reveals that idle administrative sessions on virtual terminal (VTY) lines remain active indefinitely when left unattended, and remote management traffic lacks centralized command authorization and traffic encryption. Which set of configuration controls should the administrator implement to best address these findings?
A network technician configures an extended Access Control List (ACL) on a stateless router interface to allow workstations on subnet to access an external web application at over HTTPS (TCP port 443). The technician adds the following outbound rule on the internal interface:
`permit tcp 10.40.10.0 0.0.0.255 host 203.0.113.80 eq 443`
After applying this configuration, client computers cannot successfully connect to the web application. Network captures reveal that outbound TCP SYN packets leave the router, but return traffic is never delivered to the clients. Which of the following ACL modifications will resolve this connectivity issue?
A network administrator is deploying a wireless network for a corporate headquarters. Organization policy requires that every employee authenticate using their individual enterprise user credentials against a central authentication server, preventing the operational overhead and security risk of static pre-shared keys. Which wireless security standard and authentication mechanism should the administrator implement to fulfill these security requirements?
A network security analyst observes anomalous traffic on an internal enterprise subnet. When an end user accidentally mistypes an internal file server hostname, packet logs show an unauthorized host on the local broadcast domain immediately responding to the link-local multicast request before the DNS query completes, prompting the user's workstation to attempt authentication. Which of the following attack vectors is occurring?
A network administrator is securing a newly deployed Layer 3 access switch prior to production deployment. The security policy mandates encrypted remote monitoring, protection against unauthorized network infrastructure footprinting, and secure management protocol usage. Which of the following hardening configurations should the administrator apply to meet these security requirements? (Select TWO.)
Geçerli olan tümünü seçin