Network Security
427 soru
Match each network attack type on the left with its corresponding technical mechanism or operational signature on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security administrator is selecting a centralized AAA protocol for managing corporate switches and firewalls. Organization security policies dictate that administrative sessions must use a connection-oriented transport protocol and encrypt the complete packet payload, including the header and body. Which protocol meets all specified requirements?
A network security administrator is tasked with deploying a solution to protect internal web servers from malicious payload attacks. The deployment requirements specify that the device must inspect passing packet payloads in real time and actively drop malicious packets before they reach the destination hosts. Which of the following system types and deployment modes should the administrator implement?
A network administrator is designing a centralized access control solution for managing network infrastructure devices, such as switches and routers. The security policy requires that the authorization component must be completely decoupled from authentication, allowing custom command-level access privileges per user group. Additionally, the entire protocol payload, including all administrative commands transmitted during interactive sessions, must be encrypted over a reliable connection. Which protocol best satisfies all of these requirements?
A network administrator is tasked with deploying a centralized AAA solution specifically for administrative CLI access to enterprise network switches. The security baseline mandates that all administrative command authorization details and session logs transmitted between the switches and the AAA server must have their entire packet payloads encrypted. Additionally, the authentication service must operate over a connection-oriented transport protocol to guarantee packet delivery. Which protocol and default port configuration should the administrator implement to meet these requirements?
A network administrator is implementing TACACS+ for centralized administration of network routers and switches. Which TWO of the following are distinct operational characteristics of the TACACS+ protocol?
Geçerli olan tümünü seçin
A network administrator needs to implement a network security control in front of a critical database cluster. The security policy mandates that known exploit payloads must be actively blocked in real time before reaching internal targets, and any hardware or software failure of the security device must not disrupt legitimate network traffic flow. Which deployment topology and detection mechanism best satisfies all of these requirements?
Match each Intrusion Detection and Prevention System (IDS/IPS) detection logic or deployment mode on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to deploy a security control that inspects live network traffic and actively drops malicious packets in real time before they reach internal network resources. Which of the following devices or deployments best fulfills this requirement?
A network technician is configuring centralized authentication for a remote access VPN solution. The organization's security guidelines mandate using an open-standard protocol that encrypts only the password attribute inside access-request packets, leaving the remaining header information unencrypted. Which authentication protocol meets these specific requirements?
A network security administrator is reviewing different deployment architectures and detection logic for intrusion monitoring. Match each intrusion detection or prevention mechanism on the left with its corresponding operational description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each centralized authentication protocol or framework to its corresponding architectural design and operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security engineer is evaluating security monitoring controls and deployment topologies across an enterprise network. Match each intrusion detection or prevention architecture on the left with its defining operational characteristic or monitoring mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is evaluating deployment topologies for intrusion security controls within a corporate network architecture. Which of the following statements accurately distinguish a passive Network Intrusion Detection System (NIDS) from an inline Network Intrusion Prevention System (NIPS)? (Select TWO.)
Geçerli olan tümünü seçin
A network security administrator is deploying a Network Intrusion Detection System (NIDS) connected to a hardware network TAP at the main datacenter perimeter. Which of the following operational characteristics and limitations apply specifically to this out-of-band NIDS architecture? (Select TWO).
Geçerli olan tümünü seçin
A network security team needs to implement intrusion monitoring across a high-throughput enterprise core switch link carrying latency-sensitive voice and transactional traffic. The security policy mandates that the monitoring deployment must not introduce latency, perform inline packet modification, or risk creating a single point of network failure if the monitoring service fails. Which deployment architecture and system type best meets these requirements?
A senior network security engineer is updating the centralized management architecture for core enterprise switches and firewalls. Enterprise compliance mandates that all administrative communications must completely separate authentication processes from command-by-command authorization rules, while encrypting the entire packet payload during transit across the management network. Which authentication protocol and transport configuration must the engineer deploy on the network access servers to satisfy all compliance parameters?
Match each core component of the AAA security framework to its corresponding network security function.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network engineer observes anomalous latency spikes on a critical web application server following a recent security upgrade. Upon investigation, the engineer discovers that security software deployed directly on the web server is performing deep packet inspection on all local system calls and application memory buffers, creating processing overhead under high traffic load. Which security control is actively causing this host-level performance degradation?
Match each AAA authentication protocol or access control framework to its defining operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler