Font size
WorksheetsCisco3_Bridging_Practice1
Total questions: 12
Worksheet time: 7mins
What two protocols are supported on Cisco devices for AAA communications? (Choose two.)
VTP
LLDP
HSRP
RADIUS
TACACS+
Which service is enabled on a Cisco router by default that can reveal significant information about the router and potentially make it more vulnerable to attack?
HTTP
CDP
FTP
LLDP
When security is a concern, which OSI Layer is considered to be the weakest link in a network system?
Layer 4
Layer 2
Layer 3
Layer 7
Which Layer 2 attack will result in a switch flooding incoming frames to all ports?
ARP Poisoning
IP Address Spoofing
MAC Address Overflow
Spanning Tree Protocol Manipulation
Why is authentication with AAA preferred over a local database method?
It uses less network bandwidth
It requires login and password combination on the console, vty lines, and aux ports
It provides a fallback authentication method if the administrator forgets username and password
It specifies a different password for each line or port
In a server-based AAA implementation, which protocol will allow the router to successfully communicate with the AAA server?
SSH
RADIUS
TACACS
802.1x
Which Cisco solution helps prevent MAC and IP address spoofing attacks?
Port Security
DHCP Snooping
IP Source Guard
Dynamic ARP Inspection
What is the purpose of AAA accounting?
to collect and report application usage
to determine which resources the user can access
to prove users are who they say they are
to determine which operation the user can perform
Which Layer 2 attack will result in legitimate users not getting valid IP addresses?
ARP Spoofing
DHCP Starvation
IP Addressing Spoofing
MAC Address Flooding
Which three Cisco products focus on endpoint security solutions? (Choose three.)
IPS Sensor Appliance
Web Security Appliance
Email Security Appliance
SSL/IPsec VPN Appliance
NAC Appliance
Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this?
Accessibility
Authorization
Accounting
Auditing
Authentication
What mitigation plan is best for thwarting a DoS attack that is creating a MAC address table overflow?
Disable DTP
Disable STP
Enable Port Security
Place unused ports in an unused VLAN
