Network Security
427 soru
A network security engineer is designing a centralized AAA solution for administrative management access to core switches and firewalls. Organization security policies dictate that authentication and authorization functions must be decoupled to allow granular per-command authorization rules, the complete packet payload (including administrative commands) must be encrypted over the wire, and the protocol must use connection-oriented transport on standard port 49. Which protocol should the engineer select to meet all of these compliance requirements?
A security analyst needs to monitor critical database servers for unauthorized local file integrity modifications and zero-day memory exploits that lack known attack signatures. Which security solution best addresses these requirements?
A network security architect is reviewing the deployment of centralized authentication protocols across a global enterprise network infrastructure. The architecture requires separate handling for administrative access to network edge routers and user authentication for 802.1X wireless access. Which TWO of the following statements correctly evaluate the operational and security characteristics of RADIUS and TACACS+ in this deployment?
Geçerli olan tümünü seçin
A network security administrator is assessing the centralized access control deployment for an enterprise infrastructure. The administrator needs to evaluate the architectural and transport differences between RADIUS and TACACS+ protocols. Which of the following statements correctly distinguish TACACS+ from RADIUS? (Select TWO).
Geçerli olan tümünü seçin
A network security team is designing a monitoring strategy for a high-frequency trading subnetwork and a remote branch office. The trading network requires absolute zero added latency on active traffic paths while maintaining detection capability for novel, unknown protocol exploits. Meanwhile, the branch office needs comprehensive visibility into mirrored VLAN traffic captured by a switch SPAN port. Which of the following design choices correctly fulfill these architecture and detection requirements? (Select TWO)
Geçerli olan tümünü seçin
A network security administrator is deploying a dual centralized AAA architecture to support both network infrastructure management and 802.1X wireless user authentication. Which TWO of the following statements accurately distinguish the operational and transport properties of TACACS+ and RADIUS in this implementation?
Geçerli olan tümünü seçin
A network administrator needs to configure log retention to track user session durations and bytes transferred across remote access VPN connections for compliance auditing. Which pillar of the AAA framework directly delivers this tracking function?
A network security administrator is replacing legacy switch administration protocols across an enterprise. The administrator attempts to configure RADIUS to enforce per-command authorization for individual privileged shell commands executed by engineers during SSH sessions on core switches, attempting to replicate an existing TACACS+ feature set. However, command-line execution validation fails to inspect individual commands once the administrative session is established. Which of the following technical characteristics of RADIUS explains why it cannot provide real-time, granular per-command authorization during an active interactive session?
A network security administrator needs to deploy a security solution that sits directly in the traffic path to inspect incoming packets and actively block identified threats in real time before they reach internal hosts. Which of the following devices should the administrator implement?
A network engineer is inspecting packet captures during an audit of network management traffic. The captures show authentication and administration sessions between network switches and a central server communicating over TCP port 49, where the complete packet payload following the header is cryptographically encrypted. Which protocol is being observed, and which feature accurately reflects its architecture relative to RADIUS?
Match each AAA authentication protocol or access control framework to its defining operational and structural characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security engineer is analyzing a packet capture taken between a Network Access Server (NAS) and a centralized authentication server during a remote access connection attempt. The capture reveals that the authentication request is transmitted using UDP over port 1812. Further payload examination demonstrates that only the user password attribute within the packet is obfuscated using a shared secret and MD5 hashing, while the surrounding header information and username remain visible in plaintext. Based on these observed operational characteristics, which authentication protocol is in use, and what structural feature accounts for this payload exposure?
Match each intrusion detection or prevention concept with its corresponding operational characteristic.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a network security audit, an administrator discovers two major vulnerabilities on an enterprise network: internal administrative session credentials are being intercepted in cleartext by unauthorized packet sniffing, and stored database audit logs have been silently modified after an intrusion. To remediate these vulnerabilities and satisfy security compliance, the network engineering team must implement technical controls that explicitly protect the affected pillars of the CIA Triad. Which combination of security controls correctly restores confidentiality for administrative sessions while ensuring data integrity for the stored audit logs?
Match each Intrusion Detection/Prevention System (IDS/IPS) technology or deployment mode on the left with its corresponding operational characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each authentication protocol or access control framework to its defining operational and architectural characteristics.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network security architect is designing an enterprise monitoring and threat mitigation strategy. Match each intrusion detection/prevention deployment model on the left with its corresponding technical implementation characteristic on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator needs to centralize administrative access for network switches using an authentication protocol that encrypts the entire packet payload. Which protocol best satisfies this requirement?
A network administrator needs to deploy a network security device at the perimeter that sits directly in the traffic flow to inspect incoming packets and actively drop detected malicious traffic in real time. Which device should be placed inline to meet this objective?
Which of the following operational characteristics correctly distinguish TACACS+ from RADIUS when evaluating centralized network access controls? (Select TWO.)
Geçerli olan tümünü seçin