Font size
WorksheetsBlock 4 Thompson
Total questions: 116
Worksheet time: 58mins
TCP Port Number for File Transfer Protocol (FTP) data channel
25
23
22
21
20
TCP Port number for File Transfer Protocol (FTP) control channel
21
20
23
24
25
TCP Port number for Secure Shell (SSH)
21
22
23
24
20
TCP Port number for Telnet
23
25
22
21
20
TCP Port number for Simple Mail Transfer Protocol (SMTP)
23
24
25
26
21
TCP Port number for TACACS authentication service
48
46
47
49
50
TCP Port number for Hypertext Transfer Protocol (HTTP)
80
81
85
79
83
TCP Port for Post Office Protocol version 3 (POP3)
110
111
123
109
101
TCP Port for Network Basic Input/Output System (NetBIOS) session service
140
135
138
139
141
TCP Port for Internet Message Access Protocol version 4 (IMAPv4)
143
144
145
140
139
TCP Port for Lightweight Directory Access Protocol (LDAP)
389
388
398
397
386
TCP Port for HTTP-Secure (HTTPS)
433
443
423
432
434
TCP Port for Remote Desktop Protocol (RDP)
3381
3389
3390
3398
3397
UDP Port Number for Domain Name Service (DNS)
53
44
43
54
55
UDP Port number for Trivial File Transfer Protocol (TFTP)
698
64
96
68
69
UDP Port number for NetBIOS name service
138
135
137
139
UDP Port number for NetBIOS datagram service
138
137
135
140
134
UDP Port number for Simple Network Management Protocol (SNMP)
64 / 65
161 / 162
61 / 62
160 / 161
164 / 165
In regards to IPv4, what is the First Octet Range for a class B Address?
1-127
128-190
128-181
128-191
191-223
In regards to IPv4, what is the First Octet Range for a class C Address?
192-223
191-224
190-220
192-233
In regards to IPv4, what is the First Octet Range for a class A Address?
1-129
0-127
1-126
1-127
1-129
What are the two resolutions that must be in operation for a network to function properly?
Name, Network
Name, Data
Data, Network
Name, Address
Network, Address
What Institute established the specifications for any kind of communication device?
(IEEE) Insitute of Electrons and Electronical Economist
(IIEE) Institution of Innovation and Electronics Engineers
(IEEE) Institute of Electrical and Electronics Engineers
(PWW) Prestige World Wide
What are the three advantages of Wireless?
Innovation, Portfolios, and Economics`
Portfolios
Mobility, Ease of Installation and Lower Cost, and Scalability
Scalability, Portfolios, Mobility
What is Scalability?
Configuring Wireless LANS to form topologies to best achieve the needs of a specific application and installations.
Configuring Hardware to form ports
Configuring portfolios for innovation
Configuring Hardware to perform a TCP
What is the 3rd layer of the OSI model?
Network
Data Link
Physical
Session
What are the two disadvantages of using wireless?
Security, Rage
System, Oats
Security, Range
System, Range
What are the four key phases of designing a wireless network
Innovation, Portfolios, Economics, Real Estate
Location, Size, Parition, System
Planning, Data, Securing and Managment/support
Planning, Deployment, Securing, and Managment/support
Planning, Deployment, Security, and Portfolios
Data representation and code formatting are at this layer of the OSI Model
Layer 6, Presentation
Layer 5, Session
Layer 2, Data Link
Layer 1, Physical
This is the layer on which routing takes place on the OSI Model
Layer 3, Network
Layer 1, Physical`
Layer 2, Data Link
Layer 4, Transport
Layer 7, Application
Under deployment of the wireless design, what keyword is defined by "overlapping coverage"
Convergence
Coffee
Copper
Vigiliance
What does Dial-Up use?
(PSTN) Public Switch Teleport Network
(PSTN) Public Swap Technical Number
(PSTN) Public Switch Telephone Network
(PIR) Portfolios, Innovation, Real-Estate
Baseband uses
Tire-Duplex Multitude (TDM)
Time-Division Multiplexing (TDM)
Top-Division Multiplexing (TDM)
Time-Dividing Multiphasing (TDM)
Time-Day Multitude (TDM)
Name resolution translates ___ to ___ addresses via ___
FQDNs, IP, DNS
Yes
FQDNs, MAC, SND
FDQNs, IP, DNS
Address resolution translates logical ___ addresses to physical ___ address via ___.
DNS, IP, ARC
IP, DNS, ARP
IP, MAC, ARP
Speed and frequency for 802.11a
2.4 Ghz; 54 Mbps
5 Ghz; 55 Mbps
6 Ghz; 55 Mbps
5 Ghz; 54 Mbps
Speed and frequency for 802.11b
2.4 GHz; 51 Mbps
2.4 GHz; 11 Mbps
2.4 GHz; 21 Mbps
2.4 GHz; 54 Mbps
Speed and frequency for 802.11g
2.4 GHz; 54 Mbps
2.4 GHz; 55 Mbps
5.4 GHz; 54 Mbps
5 GHz; 54 Mbps
Speed and frequency for 802.11n
5 GHz & 5 GHz; 10 Mbps
2.4 GHz & 5 GHz; 1000 Mbps
5 GHz & 5 GHz; 100 Mbps
2.4 GHz & 5 GHz; 100 Mbps
Speed and frequency for 802.11ac
5 GHz & 5 GHz; 500 Mbps
2.4 GHz & 5 GHz; 500 Mbps
5.4 GHz & 5 GHz; 50 Mbps
5.4 GHz & 5 GHz; 500 Mbps
When developing a wireless solution, you should pay close attention to _____ and ____
Data security and integrity
Data Surety and integrity
Data link and integrity
When installing access points, remember to consider [a] limitations and re-adjust access point locations to allow for [b].
Range & Convergence
Rage & Coffee
Range & Security
Range & Cost
Worked on only one frequency and had a range of 150 feet.
802.11g
802.11a
802.11ac
802.11n
The first standard to become universal.
802.11n
802.11b
802.11g
802.11ac
The first standard to offer backwards compatibility with 802.11b.
802.11a
802.11ac
802.11n
802.11g
The first standard to operate on both frequencies.
802.11a
802.11g
802.11n
802.11ac
The most recent standard developed.
802.11ac
802.11a
802.11n
802.11g
Delivers data frames between devices on a LAN
•Upper Sublayer: Logical Link control
-Provides addressing and control of the data link
•Lower Sublayer: Media Access Control
-Determines what is allowed to access the physical media at any given time.
Layer 1 : Physical
Layer 3 : Network
Layer 6 : Presentation
Layer 2 : Data Link
Layer 7 : Application
•This is the layer on which routing takes place.
•Defines the structure and use of logical addressing, as well as the processes used to route packets
Layer 4 : Transport
Layer 2: Data Link
Layer 3 : Network
Layer 1 : Physical
The functions defined in this layer provide for the reliable transmission of data segments, as well as the disassembly and assembly of the data before and after transmission.
Layer 4 : Transport
Layer 3 : Network
Layer 2 : Data Link
A connection-oriented protocol
TCP Transmission Control Protocol
UDP
TCP Timing Control Protocol
____ creates data segments with addresses from IP
UDP
TCP
MAC
IP
What helps to reduce congestion by allowing multiple nodes to share a single public IP address
Network Application Translation (NAT)
Network Adding Transport (NAT)
Network Address Transport (NAT)
Network Address Translation (NAT)
Class A Ipv4 private addresses
10.0.0.0 –10.254.254.254
10.0.0.0 –10.255.255.255
10.0.0.2 –10.255.255.255
Class B Ipv4 private addresses
172.16.0.0 –172.31.255.255
172.16.0.0 –172.31.254.254
174.16.0.0 –174.31.255.255
Class c Ipv4 private addresses
192.168.0.0 –192.168.254.254
192.168.0.0 –192.168.255.255
193.168.0.0 –193.168.255.255
________________ is a process of subdividing a network to provide logical distinctions between hosts
scalability
Convergence
Subnetting
MAC
_________________ provides the translation between IP and MAC
Address Resolution Protocol (ARP)
Fully Qualified Domain Name (FQDNS)
MAC
Convergence
The simplicity behind baseband signaling is that only three signal states need to be distinguished, __, __, and __.
one, zero and idle.
one, zero and two
one, zero and MAC
All these methods provide bandwidth in excess of 300Kbps; current implementations are two-way services, permitting you to use your telephone while accessing the internet.
Baseband
Broadband
The user's _____ or router uses an attached modem connected to a telephone line to dial into an Internet Service Provider's (ISP) telecom node to establish a _____ -to- ______link.
Computer, peer, peer
Client, peer, modem
Computer, modem, modem
Client, peer, peer
Only one signal can be transmitted at a time through baseband transmission lines.
True
False
How many signals can be simultaneously transmitted over a baseband cable?
1
2
0
To better identify what kind of attack has occurred, the National Security Agency (NSA) Information Assurance Technical Framework (IATF) has identified five distinct classes of network attack, what are they?
Active, Close-Off, Distribution, Insider & Passive
Application, Close-In, Distribution, Insider & Passive
Activity, Close-In, DNS, Inside & Passive
Active, Close-In, Distribution, Insider & Passive
_______ attacks include traffic analysis, monitoring of unprotected communications, decrypting weakly encrypted traffic, and capture of authentication information (e.g., passwords). ______ intercept of network operations can give adversaries indications and warnings of impending actions. ________ attacks can result in disclosure of information or data files to an attacker without the consent or knowledge of the user. Examples include the disclosure of personal information such as credit card numbers and medical files.
Active
Passive
Close-In
Distribution
_____ attacks can result in the disclosure or dissemination of data files, denial of service, or modification of data.
Passive
Active
Distribution
Close-In
______ attacks include attempts to circumvent or break protection features, introduce malicious code, or steal or modify information. These attacks may be mounted against a network backbone, exploit information in transit, electronically penetrate an enclave, or attack an authorized remote user during an attempt to connect to an enclave
Active
Close-In
Passive
Distribution
________ attacks is where an unauthorized individual is in physical close proximity to networks, systems, or facilities for the purpose of modifying, gathering, or denying access to information
Active
Passive
Close-In
Distribution
Insider
_____ attacks can be malicious or non-malicious. Malicious ______ intentionally eavesdrop, steal or damage information, use information in a fraudulent manner, or deny access to other authorized users.
Close-In
Insider
Passive
Distribution
________ attacks focus on the malicious modification of hardware or software at the factory or during distribution. These attacks can introduce malicious code into a product, such as a back door to gain unauthorized access to information or a system function at a later date.
Insider
Distribution
Close-In
Active
Group inside a group, basically adding a group inside another group
Group Domain
Group Nesting
Group Inception
Group Network
_____________ of a hard drive is the information that tells a machine how to turn on and load an operating system. A virus that infects this _________ can replace the legitimate boot-up instructions with viral code. Because the virus will load into memory ahead of any operating system instructions, no system-level antivirus software can remove it.
Macro Viruses
Worm
Boot Sector Virus
File-Fector-Viruses
A ______ is a set of user-generated list of computer instructions which can be executed at any time by the user
Macro Viruses
Boot Sector Virus
Worm
File-Infector Virus
______ viruses attach themselves to executable files (.exe, .com, .sys, etc.) and copy themselves into memory whenever the host file is run. From memory, the virus attaches itself to other executable files. This process continues on and on, and can wind up infecting thousands of files on users’ hard drives. As if the rampant copying of viral code wasn’t enough, these viruses often contain instructions to permanently erase or overwrite data.
File-Infector Viruses
Worms
Boot Sector Virus
Macro Virus
The destruction caused by worms is usually dealt in two methods: _______, and _________
denial of service, and viral security
denial of service, and viral application
denial of service, and viral payloads
denial of service, and data integrity
__________are not technically viruses; rather, they are programs that run independently of users and travel between computers and across networks.
Worms
Malware
File-Infector Virus
Macro Virus
Like a worm, a _____________ is also not technically a virus; instead, it is a program that disguises itself as something useful but actually harms your system.
Boot Sector Virus
File-Infector Virus
Malware
Trojan horse
To close off avenues of attack is to eliminate vulnerabilities and reduce your overall risk. This concept is known as “_________” a system
Shielding
Hardening
Defending
Protecting
______________ software is essential for all computer hosts; the software must remain updated and current in its virus definitions. With the rise of mobile computing, a strong MDM anti-virus policy is also vital to ensuring mobile availability
BroadBand-Frequency Division Multiplexing
Anti-Spyware/Anti-Malware
Firewall
Anti-Virus/Anti-Malware
Both hardware- and software-based _________ are critical to filtering incoming and outgoing network traffic.
Anti-Virus
Firewalls
Encryption
Account Lockout Policy
A type of hardening - Keeping an unnecessary service enabled on a computer is like keeping your back door open because you think no burglar will ever look there. Guess what? The burglar will find your open door, and hackers will find your open network ports. It’s only a matter of time. Remove any software that isn’t mission-oriented, and disable any services that aren’t needed.
Disabling firewalls
Disabling unnecessary software/services
Enycrption
Disabiling necessary protocols
Enforce WPA2- Enterprise on your corporate wireless networks. Enforce mandatory HTTPS through modern Transport Layer Security (TLS) on all internal web servers. Enforce data-at-rest and data-inmotion encryption for all sensitive files.
Firewall -An example of hardening
Enycrption -An example of hardening
Anti-virus/anti-malware -An example of hardening
Disabling unnecessary software/services: -An example of hardening
Password policy -An example of hardening
To prevent brute force password attacks against user accounts, force a lockout status after a pre-set number of invalid login attempts.
Account lockout policy- An example of hardening
Disabling unused accounts -An example of hardening
Disabling guest accounts -An example of hardening
Encryption: -An example of hardening
Disabling unnecessary software/services: -An example of hardening
Unused accounts have no place on a network. They could be taken over by attackers with malicious intent. Disable network accounts that have not been accessed for 30 days, and plan to delete them soon thereafter.
Enycrption - - An example of hardening
Firewall - - An example of hardening
Disabling unused accounts: - An example of hardening
Disabling unnecessary software/services - An example of hardening
Anti-virus/anti-malware - An example of hardening
You should disable _____ accounts, they have no place on a enterprise network. There's no way to trace who is on a ____ account, and it's hard to hold them accountable. Never ever have ____ accounts enable. This is a type of hardening by disabling ____ accounts.
User (Disabling Unused Accounts)
Guest (Disabling Guest Accounts)
A type of hardening- _________ is an OS which has been thoroughly evaluated, vetted, and ranked into one of seven Evaluation Assurance Levels (EALs) according to the Common Criteria for Information Technology Security Evaluation defined in ISO 15408.
Trusted Operating Systems (TOSs)
Only download
TOS
For hardening
The first wireless networks were based off of Packet Radio transmissions between ___ and __ radio base stations, and were not protected at all
VHF, HF
VHS, HF
MAC, IP
DNS, IP
The ____ is the broadcasted name of a wireless network
(SSID) - Service Set Identifier
(SSID) - Service Setup Identify
(SSID) - Startup Setup
MAC
A WAP is a loudspeaker, constantly shouting to anyone who can listen. Increase security by decreasing your WAP’s _______, in effect, by reducing the volume on your loudspeaker. There’s no reason to broadcast at maximum power when all wireless clients are within 20 feet.
Power Level - A type of WIRELESS NETWORKS SECURITY
MAC Address Filtering - A type of WIRELESS NETWORKS SECURITY
Captive Portals - A type of WIRELESS NETWORKS SECURITY
Antenna Placement - A type of WIRELESS NETWORKS SECURITY
Public WLANs often use a _____ ______ technology to force all incoming users to a one-time “landing page” or Portal to assure that users are aware of terms and conditions of use. Users will acknowledge the rules, and then have access to the network. This is an administrator’s way of saying, “Hey, I’m watching you!” and forcing all users to register their consent.
Antenna Placement- A type of WIRELESS NETWORKS SECURITY
Captive Portal - A type of WIRELESS NETWORKS SECURITY
VPN over open WiFi- A type of WIRELESS NETWORKS SECURITY
MAC Address Filtering- A type of WIRELESS NETWORKS SECURITY
Keep your WAP antennas centralized to prevent eavesdropping. Additionally, be aware of common sources of interference. WAPs that utilize the 2.4GHz spectrum (802.11b/g) are especially vulnerable to interference from such appliances as microwave ovens, generators, and baby monitors.
Service Set Identifier (SSID) - A type of WIRELESS NETWORKS SECURITY
Antenna Placement - A type of WIRELESS NETWORKS SECURITY
MAC Address Filtering- A type of WIRELESS NETWORKS SECURITY
Captive Portals- A type of WIRELESS NETWORKS SECURITY
WAPs that utilize the 2.4GHz spectrum ____ and _____ are especially vulnerable to interference from such appliances as microwave ovens, generators, and baby monitors.
802.11b and 802.11g
802.11a and 802.11b
802.11g and 802.11n
802.11ac and 802.11n
If a wireless network must remain unencrypted for matters of user convenience or connectivity, consider enforcing a VPN policy. Virtual Private Networks create encrypted “tunnels” through the internet from endpoint to endpoint, preventing even determined sniffers from reading data or metadata. T
A type of WIRELESS NETWORKS SECURITY
VPN over open WiFi
___ encrypts all data packets using a stream cipher called RC4, which relies on a 40-bit key plus a 24-bit Initialization Vector (IV).
WEP
WPA
EAP
___ is not considered strong enough for modern use, and has been entirely superceded by newer security methods.
WPA - Wi-Fi Protected Access
WEP - Wired Equivalent Privacy
EAP - Extensible Authentication Protocol
Rather than a specific protocol in its own right, ___ is an authentication framework that defines methods and mechanisms to verify the identity of users connecting to wired or wireless networks.
Extensible Authentication Protocol (EAP)
Extensible Application Protocol (EAP)
Extensible Authentication Physical (EAP)
Exponent Authentication Protocol (EAP)
Extensible Authentication Protocol (EAP) defines three specific functions for user verification.
- ___
- ___
- ____
(Protecting a Wireless Network through Encryption)
Supplicant (the user requesting access)
Authenticator (the WAP or switch to which the user’s device is connecting)Authentication Server (Usually RADIUS, Diameter, or something similar)
Supplicant (the user requesting access)
Application (the WAP or switch to which the user’s device is connecting)Authentication System (Usually RADIUS, Diameter, or something similar)
Systemt (the user requesting access)
Application (the WAP or switch to which the user’s device is connecting)Authentication Server (Usually RADIUS, Diameter, or something similar)
Because ___ was originally designed for physical, wired networks (Wi-Fi hadn’t been invented yet), there is no requirement for packet encryption.
Extensible Authentication Protocol (EAP)
Wired Equivalent Privacy (WEP)
__________ is a standard that defines how EAP should be applied across all IEEE 802 networks.
Lightweight EAP (LEAP)
Protected EAP (PEAP)
IEEE 802.1X
_______________ is a Cisco-proprietary method of EAP implementation that was designed to address the authentication flaws of WEP. As such, _______ is not a fullyformed security method.
IEEE 802.1X
Lightweight EAP (LEAP)
Protected EAP (PEAP)
________ is a method of encapsulating specific EAP methods within a securely encrypted TLS end-to-end tunnel. It does not define the use of SW E3AQR3D131 01AA 26 the authentication mechanisms, but rather provides the encrypted tunnel within which to send them. _____ is a strongly recommended, more modern alternative to LEAP.
Lightweight EAP (LEAP)
Protected EAP (PEAP)
IEEE 802.1X
WPA implements _________ to further scramble the root key and IV before being handled by RC4 during the data encryption process
Temporary Key Integrity Protocol (TKIP)
Temporal Key Integrity Protocol (TKIP)
Temporal Key Integrity Physical(TKIP)
Temporary Key Input Protocol (TKIP)
___ is not secure, and has been replaced by the current standard, WPA2
WPA
WAZ
A user is able to listen into weakly encrypted traffic.
Active
Passive
Close-In
Insider
A user is able to penetrate a firewall in order to force into the network through a denial of service attack.
Active
Passive
Close-In
Insider
A user captures wireless signal broadcasting outside the building and is able to gather information.
Active
Passive
Close-In
Insider
Replaces the legitimate boot-up instructions with viral code.
Macro Virus
Trojan Horse
Boot Sector Virus
Worms
Replaces a set of user-generated list of computer instructions with viral code.
Boot Sector Virus
File-Infector Virus
Macro Virus
Trojan Horse
Attached to .exe, .com, .sys, or other executable files and can replicate very quickly.
Macro Virus
File-Infector Virus
Boot Sector Virus
Worms
Doesn't require activation by the user. Main goal is denial of service rather than data destruction.
Boot Sector Virus
Macro Virus
File-Infector Virus
Worms
This is the Air Force’s primary web-basedtool for CST administration of an Active Directory domain
Directory and Resource Administrator (DRA)
Active Directory Users and Computers (ADUC
CSTs primarily use two tools to manage Active Directory
(EAP)
Directory and Resource Administrator (DRA)
Active Directory Users and Computers (ADUC)
Only one object is manipulated at a time
Active Directory Users and Computers (ADUC)
Directory and Resource Administrator (DRA)
Lightweight Directory Access Protocol (LDAP)
There are many directory systems in use for internetworking, and the original is the International Telecommunication Union’s ____ directory standard
DRA
LDAP
X.500
What is the name for Microsoft’s implementation of a directory service?
Active Directory
Directory and Resource Administrator
X.500
LDAP
What is the central authentication service implemented within MS Active Directory?
TACACS
Kerberos
DIAMETER
RADIUS
