Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cisco_Sem2_Mod10+11

Total questions: 34

Worksheet time: 17mins

Name
Class
Date
1.

True or False, For about 16 years (from 1962 to 1977), the computer controlled launch code for the US nuclear missiles was 00000000

a)

True

b)

False

2.

What is a Distributed Denial of Service (DDoS) attack?

a)

This is an attack in which an organization’s data servers or hosts are compromised to steal confidential information

b)

This is an attack in which an organization’s hosts are infected with malicious software that cause a variety of problems

c)

This is an attack using a Trojan Horse

d)

This is a coordinated attack from many devices, called zombies, with the intention of degrading or halting public access to an organization’s website and resources

3.

Various network security devices are required to protect the network perimeter from outside access, select All of the devices

a)

Virtual Private Network (VPN) enabled router

b)

Next-Generation Firewall (NGFW)

c)

Network Access Control (NAC)

d)

Network Internet Control (NIC)

4.

True or False, endpoints are particularly susceptible to malware-related attacks that originate through email or web browsing. ​

a)

True

b)

False

5.

What does SMTP stand for?

a)

Simple Male Transfer Protocol

b)

Simple Map Transfer Protocol

c)

Simple Mail Transfiguration Protocol

d)

Simple Mail Transfer Protocol

6.

True or False, the Cisco Web Security Appliance (WSA) is a mitigation technology for web-based threats

a)

True

b)

False

7.

AAA stands for?

a)

Alteration, Authorization, and Accounting

b)

Authentication, Authorization, and Accounting

c)

Authentication, Alteration, and Accounting

d)

Authentication, Authorization, and Alteration

8.

True or False, AAA is a way to control who is permitted to access a network (authenticate), what they can do while they are there (authorize), and to audit what actions they performed while accessing the network (accounting)

a)

True

b)

False

9.

Select the TWO common methods of implementing AAA authentication

a)

​


Local AAA Authentication

b)

​


Local AAA Alteration

c)

Server-Based AAA Authentication

d)

Server-Based AAA Alteration

10.

True or False, a primary use of accounting is to combine it with AAA authentication

a)

True

b)

False

11.

This protocol restricts unauthorized workstations from connecting to a LAN through publicly accessible switch ports

a)

802.2X

b)

802.3X

c)

802.1X

d)

802.4X

12.

Select ALL the Switch Attack Categories

a)

MAC Table Attacks

b)

VLAN Attacks

c)

DHCP Attacks

d)

ARP Attacks

e)

STP Attacks

13.

Select ALL the Switch Attack Mitigation Techniques

a)

Port Security

b)

DHCP Snooping

c)

Dynamic ARP Inspection (DAI)

d)

IP Source Guard (IPSG)

e)

DNS Security

14.

True or False, A VLAN hopping attack enables traffic from one VLAN to be seen by another VLAN without the aid of a router

a)

True

b)

False

15.

Select ALL the VLAN Attack Mitigation techniques

a)

Disable trunking on all access ports

b)

Disable auto trunking on trunk links so that trunks must be manually enabled

c)

Be sure that the native VLAN is only used for trunk links

d)

Disable all Access ports

16.

What do DHCP servers dynamically provide?, select ALL correct options

a)

IP address

b)

subnet mask

c)

default gateway

d)

DNS servers

17.

True or False, a DHCP Starvation Attack occurs when a rogue DHCP server is connected to the network and provides false IP configuration parameters to legitimate clients. A rogue server can provide a variety of misleading information

a)

True

b)

False

18.

In a typical attack, a threat actor sends unsolicited ARP Replies to other hosts on the subnet with the MAC Address of the threat actor and the IP address of the default gateway, effectively setting up a ___-__-___-______ attack

(a)  

19.

True or False, IP address spoofing is when a threat actor hijacks a valid IP address of another device on the subnet or uses a random IP address

a)

True

b)

False

20.

True or False, Cisco Discovery Protocol (CDP) information is sent out CDP-enabled ports in periodic, unencrypted, unauthenticated broadcasts. CDP information includes the IP address of the device, IOS software version, platform, capabilities, and the native VLAN

a)

True

b)

False

21.

True or False, the first hard disk of 1 GB capacity was developed in 1980. It weighed 249kg and its cost was $40,000 at that time

a)

True

b)

False

22.

True or False, A simple method that many administrators use to help secure the network from unauthorized access is to enable all unused ports on a switch

a)

True

b)

False

23.

True or False, The simplest and most effective method to prevent MAC address table overflow attacks is to disable port security

a)

True

b)

False

24.

True or False, Port security is enabled with the switchport port-security interface configuration command

a)

True

b)

False

25.

True or False, If an active port is configured with the switchport port-security command and more than one device is connected to that port, the port will transition to the error-disabled state

a)

True

b)

False

26.

A switch can be configured to learn about MAC addresses on a secure port in one of three ways, select ALL three

a)

Manually Configured

b)

Dynamically Configured

c)

Dynamically Learned – Sticky

d)

Dynamically Learned

27.

True or False, when introducing a rogue switch and enabling trunking. An attacker can then access all the VLANs on the victim switch from the rogue switch

a)

True

b)

False

28.

True or False, The goal of a DHCP starvation attack is to create a Denial of Service (DoS) for connecting clients

a)

True

b)

False

29.

True or False, In a typical ARP attack, a threat actor can send unsolicited ARP replies to other hosts on the subnet with the MAC Address of the threat actor and the IP address of the default gateway

a)

True

b)

False

30.

To mitigate the chances of ARP spoofing and ARP poisoning, select All of the mitigation techniques

a)

Enable DHCP snooping globally

b)

Enable DHCP snooping on selected VLANs

c)

Enable DAI on selected VLANs

d)

Configure trusted interfaces for DHCP snooping and ARP inspection

31.

True or False, Dynamic Arp Inspection (DAI) can also be configured to check for both destination or source MAC and IP addresses

a)

True

b)

False

32.

True or False, To prevent ARP spoofing and the resulting ARP poisoning, a switch must ensure that only invalid ARP Requests and Replies are relayed

a)

True

b)

False

33.

True or False, To mitigate STP attacks, use PortFast and Bridge Protocol Data Unit (BPDU) Guard

a)

True

b)

False

34.

One million Americans spend an average of 17 days a year doing this?

a)

Sitting on the toilet

b)

Watching TV

c)

Surfing

d)

Fishing