Font size
Worksheets105 10-13 Review
Total questions: 38
Worksheet time: 38mins
(Module 10)
When security is a concern, which OSI Layer is considered to be the weakest link in a network system?
Layer 2
Layer 3
Layer 4
Layer 7
Which Layer 2 attack will result in a switch flooding incoming frames to all ports?
ARP Poisoning
Spanning Tree Protocol Manipulation
MAC address overflow
IP address spoofing
In a server-based AAA implementation, which protocol will allow the router to successfully communicate with the AAA server?
RADIUS
SSH
802.1x
TACACS
Which Cisco solution helps prevent MAC and IP address spoofing attacks?
DHCP Snooping
Dynamic ARP Inspection
IP Source Gaurd
Port Security
What is the purpose of AAA accounting?
to collect and report application usage
to determine which resources the user can access
to prove users are who they say they are
to determine which operations the user can perform
Which Layer 2 attack will result in legitimate users not getting valid IP addresses?
DHCP starvation
IP address spoofing
MAC address flooding
ARP spoofing
What is involved in an IP address spoofing attack?
Bogus DHCPDISCOVER messages are sent to consume all the available IP addresses on a DHCP server.
A rogue node replies to an ARP request with its own MAC address indicated for the target IP address.
A legitimate network IP address is hijacked by a rogue node.
A rogue DHCP server provides false IP configuration parameters to legitimate DHCP clients.
What three services are provided by the AAA framework? (Choose three.)
Automation
Authentication
Authorization
Accounting
Assistance
Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this?
Authorization
Authentication
Auditing
Accessibility
(Module 11)
What is a recommended best practice when dealing with the native VLAN?
Turn off DTP
Assign the same VLAN number as the management VLAN
Assign it to an unused VLAN
Use port security
On what switch ports should PortFast be enabled to enhance STP stability?
only ports that attach to a neighboring switch
all end-user ports
only ports that are elected as designated ports
all trunk ports that are not root ports
Which command would be best to use on an unused switch port if a company adheres to the best practices as recommended by Cisco?
shutdown
switchport port-security mac-address sticky
switchport port-security violation shutdown
ip dhcp snooping
Which two features on a Cisco Catalyst switch can be used to mitigate DHCP starvation and DHCP spoofing attacks? (Choose two.)
port security
extended ACL
strong password on DHCP servers
DHCP snooping
DHCP server failover
What is the best way to prevent a VLAN hopping attack?
Use ISL encapsulation on all trunk links.
Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.
Disable STP on all nontrunk ports.
Use VLAN 1 as the native VLAN on trunk ports.
Which procedure is recommended to mitigate the chances of ARP spoofing?
Enable port security globally.
Enable IP Source Guard on trusted ports.
Enable DHCP snooping on selected VLANs.
Enable DAI on the management VLAN.
What are two types of switch ports that are used on Cisco switches as part of the defense against DHCP spoofing attacks? (Choose two.)
unknown port
trusted DHCP port
untrusted port
authorized DHCP port
unauthorized port
An administrator who is troubleshooting connectivity issues on a switch notices that a switch port configured for port security is in the err-disabled state. After verifying the cause of the violation, how should the administrator re-enable the port without disrupting network operation?
Reboot the switch.
Issue the shutdown command followed by the no shutdown command on the interface.
Issue the no switchport port-security violation shutdown command on the interface.
Issue the no switchport port-security violation shutdown command on the interface.
A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first?
ip dhcp snooping
ip dhcp snooping trust
ip dhcp snooping vlan
ip dhcp snooping limit rate
A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?
to check the destination MAC address in the Ethernet header against the target MAC address in the ARP body
to check the destination MAC address in the Ethernet header against the MAC address table
to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body
to check the destination MAC address in the Ethernet header against the user-configured ARP ACLs
What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?
ARP poisoning
VLAN hopping
ARP spoofing
DHCP spoofing
(Module 12)
In the context of mobile devices, what does the term tethering involve?
connecting a mobile device to a 4G cellular network
connecting a mobile device to a USB port on a computer in order to charge the mobile device
connecting a mobile device to a hands-free headset
connecting a mobile device to another mobile device or computer to share a network connection
Which method of wireless authentication is currently considered to be the strongest?
WEP
WPA
WPA2
Open
Which parameter is commonly used to identify a wireless network name when a home wireless AP is being configured?
SSID
ESS
ad hoc
BESS
Which characteristic describes a wireless client operating in active mode?
broadcasts probes that request the SSID
must be configured for security before attaching to an AP
must know the SSID to connect to an AP
ability to dynamically change channels
Which IEEE standard operates at wireless frequencies in both the 5 GHz and 2.4 GHz ranges?
802.11b
802.11n
802.11a
802.11g
Which statement describes an autonomous access point?
It is server-dependent.
It is a standalone access point.
It is used for networks that require a large number of access points.
It is managed by a WLAN controller.
Which two roles are typically performed by a wireless router that is used in a home or small business? (Choose two.)
access point
WLAN controller
Ethernet switch
RADIUS authentication server
repeater
Which type of telecommunication technology is used to provide Internet access to vessels at sea?
Ethernet
WiMax
Satellite
cellular
Which wireless network topology is being configured by a technician who is installing a keyboard, a mouse, and headphones, each of which uses Bluetooth?
ad hoc mode
infrastructure mode
mixed mode
hotspot
(Module 13)
A user is configuring a wireless access point and wants to prevent any neighbors from discovering the network. What action does the user need to take?
Configure DMZ settings
Disable SSID broadcast
Configure a DNS server
Enable WPA encryption
When a wireless network in a small office is being set up, which type of IP addressing is typically used on the networked devices?
private
wireless
public
network
A user has just purchased a generic home router and would like to secure it. What should be done to help secure the wireless home router?
Change the default admin password
set a private IPv4 network for the internal network
Allow only IPv6 traffic to enter the router
Change the default SSID
Which protocol could be used by a company to monitor devices such as a wireless LAN controller (WLC)?
PAT
SSH
SNMP
NTP
What is a DHCP scope as it relates to a WLAN configured on the WLC controller?
a pool of IP addresses for WLAN clients
security rules associated with DHCP for WLANs
a corporate plan for allocation of IP addresses for wireless clients
the distance allotted for wireless clients that can receive IP addressing info
Why would a technician configure a passphrase for a WLAN on a wireless router?
to protect someone from cabling directly to the router and accessing the router
to protect someone from changing the configuration
to protect the SSID from being changed
to configure wireless client authentication
What functionality is required on routers to provide remote workers with VoIP and videoconferencing capabilities?
PPPoE
IPsec
QoS
VPN
A wireless router is displaying the IP address of 192.168.0.1. What could this mean?
The wireless router has been configured to use the frequencies on channel 1.
Dynamic IP address allocation has been configured on the router and is functioning correctly.
The NAT function is not working on the wireless router.
The wireless router still has the factory default IP address.
In setting up a small office network, the network administrator decides to assign private IP addresses dynamically to workstations and mobile devices. Which feature must be enabled on the company router in order for office devices to access the internet?
MAC filtering
NAT
QoS
UPnP
