Network Security
427 soru
Match each network attack type on the left with its corresponding operational vector or network signature on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an infrastructure compliance audit, a network engineer must harden a Layer 2 access switch deployed in a branch office. The audit report identified two critical security findings: remote administration sessions transmit management credentials in cleartext, and unassigned physical switch ports remain active in the default VLAN. Which combination of hardening procedures should the engineer implement to remediate these specific vulnerabilities?
A network security administrator is configuring traffic filtering rules on a perimeter security appliance connecting an internal server zone () to an isolated database server (). The administrator configures explicit rules permitting TCP port 1433 traffic for database queries. However, administrative management scripts sending UDP status probes on port 1434 from the same subnet are silently dropped without generating an explicit block rule entry in the event log. Which of the following explains why the management script traffic is being blocked?
A network administrator is creating an inbound IPv4 extended Access Control List (ACL) on a router interface to filter traffic from the internal management subnet () heading toward a DMZ web server (). The policy requires allowing secure HTTPS access specifically for management workstation , allowing general HTTP traffic from the entire internal subnet to the web server, logging any other blocked attempts from the internal subnet to the DMZ subnet (), and relying on standard firewall drop behavior for remaining traffic. Arrange the following ACL entries in the correct top-to-bottom sequence to ensure proper evaluation without rule shadowing.
Öğeleri doğru sıraya koymak için sürükleyin
A network security administrator is configuring a newly installed enterprise edge router to establish a hardened management baseline. Place the administrative hardening tasks into the correct execution sequence, from initial authentication setup to physical port containment.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator at a branch office discovers that several newly connected workstation clients are receiving IP configuration parameters from an unauthorized scope outside the corporate network design. Analysis reveals that these clients were assigned a default gateway address belonging to an unknown laptop on the local segment, causing all outbound traffic from these clients to be intercepted. Which of the following attack types is being executed?
A network security administrator detects anomalous network activity where a switch is broadcasting unicast frames to all active switch ports, enabling an unauthorized user to capture sensitive network traffic. Investigation reveals that a connected device transmitted tens of thousands of frames with distinct, randomly generated source physical addresses within a few seconds. Which of the following statements accurately characterize the attack vector taking place and its primary mitigation method? (Select TWO)
Geçerli olan tümünü seçin
An organization operates a centralized logging infrastructure where internal servers on the subnet transmit log data to a Syslog server at . The network administrator configures an extended IPv4 Access Control List (ACL) with the rule `permit tcp 192.168.10.0 0.0.0.255 host 172.16.50.25 eq 514`. After applying this rule, no logs are received by the Syslog server. Which of the following modifications to the ACL will resolve the log transmission failure?
A network specialist is auditing and hardening newly deployed Layer 2 access switches at a branch office. To minimize the local physical attack surface and prevent VLAN hopping attacks across trunk connections, which TWO hardening practices should the specialist implement? (Select TWO.)
Geçerli olan tümünü seçin
A network engineer is configuring traffic filtering between a web application cluster in a DMZ () and a backend database subnet (). Web application servers must initiate queries to a database server listening on TCP port . The security architecture incorporates both a stateful inspection firewall and stateless router Access Control Lists (ACLs). Which TWO of the following statements correctly describe the filtering requirements and expected packet behavior for this deployment?
Geçerli olan tümünü seçin
During a bandwidth exhaustion incident, a network administrator inspects packet captures at the perimeter firewall. The logs show a massive influx of inbound UDP traffic on port 123 directed at an enterprise public IP address. The payload responses originate from third-party public time servers responding to spoofed commands that the target enterprise never initiated. Which of the following network attack types is being executed?
A network administrator is troubleshooting connectivity between internal network monitoring tools on subnet and an application server at . The administrator configured an inbound extended Access Control List (ACL) on the router interface facing the monitoring subnet with only the following active rules:
- `permit tcp 10.80.4.0 0.0.0.255 host 10.80.12.50 eq 80`
- `permit tcp 10.80.4.0 0.0.0.255 host 10.80.12.50 eq 443`
While HTTP and HTTPS traffic reach the server successfully, ICMP echo requests (ping) sent from the monitoring tools to fail. Which of the following best explains why the ICMP traffic is being dropped?
Match each common network attack type on the left with its corresponding operational mechanism or technical signature on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is configuring the management plane of an enterprise router to comply with baseline device hardening standards. The security policy mandates that all remote command-line management sessions use encrypted transport protocols, idle administrative sessions terminate automatically after minutes of inactivity, and VTY access be restricted strictly to hosts within the internal management subnet (). Which set of configuration commands on the virtual terminal (VTY) lines correctly enforces this hardening policy?
During a security audit, a network administrator discovers that an rogue laptop plugged into an unmanaged wall jack successfully established an 802.1Q trunking link with the local access switch by sending dynamic trunking negotiation messages. This enabled the device to capture and inject traffic across multiple internal VLANs. Which of the following network attack types did the rogue device execute?
A network technician is configuring an out-of-the-box managed network switch to establish a secure management baseline prior to production deployment. Arrange the implementation steps in the correct chronological order from first to last to properly configure hardened remote access.
Öğeleri doğru sıraya koymak için sürükleyin
A network engineer is deploying a stateless Access Control List (ACL) on a router WAN interface to allow internal hosts on subnet to access an external HTTPS web service hosted at . The engineer configures an outbound ACL rule permitting TCP traffic from source subnet to destination host on destination port . However, users report that connection attempts to the external web service continuously time out. Which of the following best explains why the connection fails and identifies the necessary solution?
An enterprise network security administrator discovers anomalous traffic on a switch interface where an attacker on VLAN 10 sent frames directly to a target server on VLAN 20 without passing through a router. Analysis of captured frames reveals two 802.1Q tags embedded within the Ethernet header. Which of the following conditions must be met for this double-tagging VLAN hopping attack to succeed? (Select TWO.)
Geçerli olan tümünü seçin
A security engineer is updating the baseline configuration of a remote branch router to comply with corporate security standards. The compliance mandate specifies two primary controls: preventing automated device discovery announcements from leaking network topology details to untrusted segments, and securing interactive management sessions against cleartext eavesdropping. Which set of configuration actions directly fulfills these security requirements?
A network administrator is implementing firewall policies on a stateful security appliance that protects internal servers on the subnet. The administrator needs to allow remote management via SSH from a trusted management workstation () to the internal servers while ensuring unapproved outbound connections from the servers to the Internet are blocked. Which of the following statements correctly describe how a stateful firewall processes traffic for this scenario? (Select TWO.)
Geçerli olan tümünü seçin