Network Security
427 soru
Match each authentication protocol or security standard to its core operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator implements cryptographic hashing algorithms to verify that transmitted configuration files are not altered or tampered with during transit. Which core pillar of the CIA triad is the administrator primarily protecting?
An enterprise organization is updating its security architecture to protect internal application servers. The solution must achieve two primary objectives: first, detect zero-day exploit attempts against server kernel processes that receive encrypted transport payloads; second, monitor network-wide bandwidth and protocol utilization patterns without introducing packet delivery latency or creating a single point of failure on the network link. Which of the following deployment choices will meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network security administrator is evaluating an automated log collection architecture. Network routers and switches are configured to transmit syslog messages to a centralized syslog server over an encrypted TLS connection. However, the syslog server writes the received log streams directly to a disk volume without generating message digests, cryptographic hashes, or digital signatures. During a post-incident investigation, security analysts discover that an attacker compromised local host credentials on the log server and modified historic log entries to erase evidence of lateral movement. Which security pillar of the CIA triad was directly compromised due to the lack of log hashing or cryptographic validation?
A network engineer is configuring an extended IPv4 Access Control List (ACL) on a stateless router interface filtering outbound traffic leaving a DMZ subnet () toward an internal corporate LAN (). DMZ web servers (–) must respond to HTTPS client requests initiated from the internal LAN and send syslog telemetry to an internal monitoring server () over UDP port 514. Which of the following ACL configuration entries are required on this interface to satisfy these requirements while accounting for stateless filtering mechanics? (Select TWO.)
Geçerli olan tümünü seçin
A network administrator is evaluating central authentication services for an enterprise network to support both remote access users and administrative switch management. Which of the following characteristics accurately describe operational differences between the RADIUS and TACACS+ protocols? (Select TWO).
Geçerli olan tümünü seçin
An administrator is configuring 802.1X port-based authentication on an enterprise network switch. Which component in the 802.1X architecture refers to the client workstation or software requesting access to the network?
An enterprise security monitoring system generates an alert after detecting an unexpected surge in incoming UDP traffic targeted at a company's public-facing web server. Analysis of packet captures reveals thousands of external open recursive DNS servers sending large response payloads for ANY and TXT queries that were never initiated by the web server. The source IP address in the initial queries was forged to match the public IP address of the target server, causing severe link congestion. Which type of network attack is occurring?
Match each authentication and access control protocol with its corresponding transport and security characteristics.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A security operations team requires a centralized AAA solution for managing network device administrative sessions. The requirements specify that authentication and authorization functions must be separated to allow granular command-level authorization, and the entire packet payload between the switch and AAA server must be encrypted. Which protocol and transport layer combination meets these security requirements?
A security engineer is configuring a site-to-site Virtual Private Network (VPN) between two gateway routers across an untrusted public network. The mandate requires that the entire original IP packet—including both its header and payload—must be fully encrypted and encapsulated within a new outer IP header for gateway-to-gateway transit. Which IPsec operational mode and protocol combination must be deployed to satisfy these requirements?
A network administrator observes a flood of incoming ICMP Echo Reply packets targeting a key internal server. Investigation reveals that an external attacker sent ICMP Echo Requests to a network broadcast address with the source IP address spoofed to match the target server's IP address. Which type of network attack is taking place?
A network security team investigates an incident where an internal server crashed due to an IP fragmentation reassembly attack (Teardrop attack). Although an out-of-band Network Intrusion Detection System (NIDS) was actively monitoring traffic via a switch SPAN port with up-to-date threat signatures, it generated no alerts during the attack. Subsequent packet capture analysis reveals that the attacker intentionally transmitted overlapping IPv4 fragments with inconsistent offset values. Which of the following statements correctly explain why the passive NIDS failed to trigger an alert, and which architectural adjustment would directly prevent this evasion technique? (Select TWO)
Geçerli olan tümünü seçin
A network administrator is reviewing filtering methods for perimeter security devices. Which of the following statements accurately describe the operational behavior of stateless firewalls and standard packet filters? (Select TWO)
Geçerli olan tümünü seçin
A security analyst is auditing an edge router configured with stateless Access Control Lists (ACLs) to filter traffic between an internal management subnet () and a cloud monitoring cluster (). The analyst notes that SNMP monitoring requests sent over UDP port 161 from the cloud cluster to internal endpoints pass successfully, but the response packets generated by the internal endpoints fail to reach the monitoring cluster.
Which TWO of the following statements correctly explain why this issue occurs and identify an appropriate resolution?
Geçerli olan tümünü seçin
During a security audit, a network analyst discovers that a host connected to an access port on VLAN 10 successfully transmitted unauthorized frames directly to a critical server on VLAN 30 without passing through an inter-VLAN routing firewall. The two hosts reside on separate switches connected by an 802.1Q trunk link, where VLAN 10 is designated as the native VLAN. Which of the following statements correctly identify the mechanism behind this security breach and the appropriate remediation step? (Select TWO.)
Geçerli olan tümünü seçin
Match each wireless security standard on the left with its corresponding primary cryptographic cipher and authentication mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each AAA protocol or network authentication framework to its corresponding operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to enable centralized remote monitoring on core network switches. The corporate security baseline mandates that management traffic must enforce both cryptographic user authentication and encryption (privacy) of transmitted payload data across the management network. Which SNMP configuration should the administrator implement to satisfy these security requirements?
During an incident response investigation, a network security analyst discovers that internal users attempting to connect to a partner organization's remote server were redirected to an untrusted external host. Analysis reveals that client workstations issued standard domain name lookup requests, but the enterprise's recursive resolver returned forged IP address records that had been injected into its local cache. Which of the following attack types best describes this security incident?