wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

105 10-13 Review

Total questions: 38

Worksheet time: 38mins

Name
Class
Date
1.

(Module 10)

When security is a concern, which OSI Layer is considered to be the weakest link in a network system?​

a)

Layer 2

b)

Layer 3

c)

Layer 4

d)

Layer 7

2.

Which Layer 2 attack will result in a switch flooding incoming frames to all ports?

a)

ARP Poisoning

b)

Spanning Tree Protocol Manipulation

c)

MAC address overflow

d)

IP address spoofing

3.

In a server-based AAA implementation, which protocol will allow the router to successfully communicate with the AAA server?

a)

RADIUS

b)

SSH

c)

802.1x

d)

TACACS

4.

Which Cisco solution helps prevent MAC and IP address spoofing attacks?

a)

DHCP Snooping

b)

Dynamic ARP Inspection

c)

IP Source Gaurd

d)

Port Security

5.

What is the purpose of AAA accounting?

a)

to collect and report application usage

b)

to determine which resources the user can access

c)

to prove users are who they say they are

d)

to determine which operations the user can perform

6.

Which Layer 2 attack will result in legitimate users not getting valid IP addresses?

a)

DHCP starvation

b)

IP address spoofing

c)

MAC address flooding

d)

ARP spoofing

7.

What is involved in an IP address spoofing attack?

a)

Bogus DHCPDISCOVER messages are sent to consume all the available IP addresses on a DHCP server.

b)

A rogue node replies to an ARP request with its own MAC address indicated for the target IP address.

c)

A legitimate network IP address is hijacked by a rogue node.

d)

A rogue DHCP server provides false IP configuration parameters to legitimate DHCP clients.

8.

What three services are provided by the AAA framework? (Choose three.)

a)

Automation

b)

Authentication

c)

Authorization

d)

Accounting

e)

Assistance

9.

Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this?

a)

Authorization

b)

Authentication

c)

Auditing

d)

Accessibility

10.

(Module 11)

What is a recommended best practice when dealing with the native VLAN?

a)

Turn off DTP

b)

Assign the same VLAN number as the management VLAN

c)

Assign it to an unused VLAN

d)

Use port security

11.

On what switch ports should PortFast be enabled to enhance STP stability?

a)

only ports that attach to a neighboring switch

b)

all end-user ports

c)

only ports that are elected as designated ports

d)

all trunk ports that are not root ports

12.

Which command would be best to use on an unused switch port if a company adheres to the best practices as recommended by Cisco?

a)

shutdown

b)

switchport port-security mac-address sticky

c)

switchport port-security violation shutdown

d)

ip dhcp snooping

13.

Which two features on a Cisco Catalyst switch can be used to mitigate DHCP starvation and DHCP spoofing attacks? (Choose two.)

a)

port security

b)

extended ACL

c)

strong password on DHCP servers

d)

DHCP snooping

e)

DHCP server failover

14.

What is the best way to prevent a VLAN hopping attack?

a)

Use ISL encapsulation on all trunk links.

b)

Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.

c)

Disable STP on all nontrunk ports.

d)

Use VLAN 1 as the native VLAN on trunk ports.

15.

Which procedure is recommended to mitigate the chances of ARP spoofing?

a)

Enable port security globally.

b)

Enable IP Source Guard on trusted ports.

c)

Enable DHCP snooping on selected VLANs.

d)

Enable DAI on the management VLAN.

16.

What are two types of switch ports that are used on Cisco switches as part of the defense against DHCP spoofing attacks? (Choose two.)

a)

unknown port

b)

trusted DHCP port

c)

untrusted port

d)

authorized DHCP port

e)

unauthorized port

17.

An administrator who is troubleshooting connectivity issues on a switch notices that a switch port configured for port security is in the err-disabled state. After verifying the cause of the violation, how should the administrator re-enable the port without disrupting network operation?

a)

Reboot the switch.

b)

Issue the shutdown command followed by the no shutdown command on the interface.

c)

Issue the no switchport port-security violation shutdown command on the interface.

d)

Issue the no switchport port-security violation shutdown command on the interface.

18.

A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first?

a)

ip dhcp snooping

b)

ip dhcp snooping trust

c)

ip dhcp snooping vlan

d)

ip dhcp snooping limit rate

19.

A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?

a)

to check the destination MAC address in the Ethernet header against the target MAC address in the ARP body

b)

to check the destination MAC address in the Ethernet header against the MAC address table

c)

to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body

d)

to check the destination MAC address in the Ethernet header against the user-configured ARP ACLs

20.

What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?

a)

ARP poisoning

b)

VLAN hopping

c)

ARP spoofing

d)

DHCP spoofing

21.

(Module 12)

In the context of mobile devices, what does the term tethering involve?

a)

connecting a mobile device to a 4G cellular network

b)

connecting a mobile device to a USB port on a computer in order to charge the mobile device

c)

connecting a mobile device to a hands-free headset

d)

connecting a mobile device to another mobile device or computer to share a network connection

22.

Which method of wireless authentication is currently considered to be the strongest?

a)

WEP

b)

WPA

c)

WPA2

d)

Open

23.

Which parameter is commonly used to identify a wireless network name when a home wireless AP is being configured?

a)

SSID

b)

ESS

c)

ad hoc

d)

BESS

24.

Which characteristic describes a wireless client operating in active mode?

a)

broadcasts probes that request the SSID

b)

must be configured for security before attaching to an AP

c)

must know the SSID to connect to an AP

d)

ability to dynamically change channels

25.

Which IEEE standard operates at wireless frequencies in both the 5 GHz and 2.4 GHz ranges?

a)

802.11b

b)

802.11n

c)

802.11a

d)

802.11g

26.

Which statement describes an autonomous access point?

a)

It is server-dependent.

b)

It is a standalone access point.

c)

It is used for networks that require a large number of access points.

d)

It is managed by a WLAN controller.

27.

Which two roles are typically performed by a wireless router that is used in a home or small business? (Choose two.)

a)

access point

b)

WLAN controller

c)

Ethernet switch

d)

RADIUS authentication server

e)

repeater

28.

Which type of telecommunication technology is used to provide Internet access to vessels at sea?

a)

Ethernet

b)

WiMax

c)

Satellite

d)

cellular

29.

Which wireless network topology is being configured by a technician who is installing a keyboard, a mouse, and headphones, each of which uses Bluetooth?

a)

ad hoc mode

b)

infrastructure mode

c)

mixed mode

d)

hotspot

30.

(Module 13)

A user is configuring a wireless access point and wants to prevent any neighbors from discovering the network. What action does the user need to take?

a)

Configure DMZ settings

b)

Disable SSID broadcast

c)

Configure a DNS server

d)

Enable WPA encryption

31.

When a wireless network in a small office is being set up, which type of IP addressing is typically used on the networked devices?

a)

private

b)

wireless

c)

public

d)

network

32.

A user has just purchased a generic home router and would like to secure it. What should be done to help secure the wireless home router?

a)

Change the default admin password

b)

set a private IPv4 network for the internal network

c)

Allow only IPv6 traffic to enter the router

d)

Change the default SSID

33.

Which protocol could be used by a company to monitor devices such as a wireless LAN controller (WLC)?

a)

PAT

b)

SSH

c)

SNMP

d)

NTP

34.

What is a DHCP scope as it relates to a WLAN configured on the WLC controller?

a)

a pool of IP addresses for WLAN clients

b)

security rules associated with DHCP for WLANs

c)

a corporate plan for allocation of IP addresses for wireless clients

d)

the distance allotted for wireless clients that can receive IP addressing info

35.

Why would a technician configure a passphrase for a WLAN on a wireless router?

a)

to protect someone from cabling directly to the router and accessing the router

b)

to protect someone from changing the configuration

c)

to protect the SSID from being changed

d)

to configure wireless client authentication

36.

What functionality is required on routers to provide remote workers with VoIP and videoconferencing capabilities?

a)

PPPoE

b)

IPsec

c)

QoS

d)

VPN

37.

A wireless router is displaying the IP address of 192.168.0.1. What could this mean?

a)

The wireless router has been configured to use the frequencies on channel 1.

b)

Dynamic IP address allocation has been configured on the router and is functioning correctly.

c)

The NAT function is not working on the wireless router.

d)

The wireless router still has the factory default IP address.

38.

In setting up a small office network, the network administrator decides to assign private IP addresses dynamically to workstations and mobile devices. Which feature must be enabled on the company router in order for office devices to access the internet?

a)

MAC filtering

b)

NAT

c)

QoS

d)

UPnP