Network Security
427 soru
A network security engineer is evaluating transport layer behavior and payload security differences between RADIUS and TACACS+ protocols during an infrastructure audit. Which of the following statements accurately describe characteristics of the TACACS+ protocol compared to RADIUS? (Select TWO).
Geçerli olan tümünü seçin
A network security team is transitioning from a passive out-of-band Network Intrusion Detection System (NIDS) TAP interface to an active in-band Network Intrusion Prevention System (NIPS) on an enterprise perimeter connection. Which of the following represent key operational advantages or trade-offs specific to deploying an inline NIPS compared to a passive NIDS? (Select TWO.)
Geçerli olan tümünü seçin
A network security administrator is configuring a stateful perimeter firewall and documenting how the device inspects incoming network traffic. When an initial TCP SYN packet initiating a new session arrives at the untrusted external interface destined for an internal server, the firewall executes specific operational phases to process the request. In what chronological order, from first to last, does the stateful firewall process this new incoming connection attempt?
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator is documenting the authentication sequence for remote users connecting to an enterprise network using an IKEv2 IPsec Virtual Private Network (VPN) with EAP authentication. Place the following phases and steps of the IKEv2 negotiation process in the correct chronological order from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
A network administrator receives security alerts from a passive Network Intrusion Detection System (NIDS) connected to a switch SPAN port, indicating that malicious payloads are reaching internal web servers. Although the NIDS successfully logs the suspicious traffic, it fails to stop the attacks. Which network security deployment modification would enable active packet dropping to prevent malicious traffic from reaching the servers?
A network technician discovers an unauthorized wireless router plugged into a corporate network switch port inside an unsecured conference room. The device is broadcasting a wireless network that mimics the legitimate company network to intercept employee credentials. Which of the following statements accurately describe this security threat? (Select TWO)
Geçerli olan tümünü seçin
Match each Virtual Private Network (VPN) protocol to its primary operational characteristic or protocol specification.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise is upgrading its remote access infrastructure for network administrators who connect via remote VPN sessions to manage core routers and firewalls. The security policy mandates a central AAA authentication service that encrypts the entire packet payload during communication between the VPN gateway and the authentication server, while also supporting granular, command-level authorization. Which protocol should the network engineer configure on the VPN gateway to meet these security requirements?
A network administrator is upgrading a small office wireless access point from WPA2-Personal to WPA3-Personal. Which TWO of the following capabilities are standard security enhancements introduced by WPA3-Personal?
Geçerli olan tümünü seçin
A network security architect is designing a wireless infrastructure for a regional corporate facility. Organizational compliance rules require that every employee authenticate using individual Active Directory domain credentials managed through a centralized authentication server, while simultaneously utilizing modern AES-based cipher suites for confidentiality. Which wireless security standard and authentication mechanism combination fulfills all compliance requirements?
A network engineer is troubleshooting a remote access VPN deployment. Remote workers connecting via an IPsec IKEv2 client can successfully establish Phase 1 and Phase 2 Security Associations and access internal servers by IP address. However, when users attempt to connect to internal resources using hostnames such as `server1.corp.internal`, the lookup fails or resolves to public internet addresses. The engineer needs internal hostnames to be resolved by the corporate DNS server across the tunnel while preventing general internet web traffic from being redirected through the corporate network. Which of the following configuration changes should the engineer implement on the VPN gateway profile?
During a security incident investigation, a network analyst reviews packet captures from an ongoing Distributed Denial of Service (DDoS) event targeting an enterprise's web server. The logs reveal a high volume of inbound UDP traffic originating from standard network management servers on external networks. The attacker initiated this traffic by transmitting small query packets with a forged source IP address matching the victim's public server, inducing the external servers to transmit significantly larger response payloads back to the victim. Which of the following attack vectors is being executed in this scenario?
An organization is deploying a remote access VPN solution and requires integration with a central AAA server for network administration access control. The security requirements dictate that authentication and authorization functions must be decoupled into separate processes, and the entire payload of each AAA transmission must be encrypted. Which protocol should the network administrator select?
A network administrator notices that an internal web server has suddenly stopped accepting new client connections. Analysis of packet captures shows thousands of incoming TCP packets with the SYN flag set coming from randomized source IP addresses, but none of these clients complete the three-way handshake with an ACK response. Which type of network attack is occurring?
Match each secure remote access protocol or tunneling technology on the left to its corresponding architectural characteristic and operational port specification on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each network attack type on the left with its corresponding vector or characteristic description on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise security architect is specifying a centralized remote administration protocol to manage network switch and router configurations across the organization. The security policy strictly mandates granular authorization controls to restrict specific commands executed by administrators, as well as full-payload encryption for all packets transmitted between network hardware and the backend authentication server. Which authentication protocol should be implemented to meet these requirements?
A network administrator is configuring a IPv4 Access Control List (ACL) on a router interface to protect an internal server at IP address 10.0.0.5. The security requirement dictates that SSH management traffic (TCP port 22) to the server must be blocked from all sources, HTTPS web traffic (TCP port 443) must be allowed from the internal workstation subnet (192.168.1.0/24), all other general IP traffic from the internal workstation subnet to the server must be allowed, and all remaining traffic must be dropped. In what order, from top to bottom, should these ACL rules be placed to ensure proper filtering without rule shadowing?
Öğeleri doğru sıraya koymak için sürükleyin
A network security administrator is performing a compliance audit on an enterprise wireless infrastructure. Match each wireless security standard configuration on the left to its mandatory encryption algorithm and cryptographic authentication mechanism on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A network administrator is evaluating remote access solutions and decides to deploy Layer 2 Tunneling Protocol combined with IPsec (L2TP/IPsec) for remote employees. Which of the following statements correctly describe the functions and security characteristics of this combined VPN solution? (Select TWO.)
Geçerli olan tümünü seçin