WorksheetsCisco_Sem2_Mod10+11
Total questions: 34
Worksheet time: 17mins
True or False, For about 16 years (from 1962 to 1977), the computer controlled launch code for the US nuclear missiles was 00000000
True
False
What is a Distributed Denial of Service (DDoS) attack?
This is an attack in which an organization’s data servers or hosts are compromised to steal confidential information
This is an attack in which an organization’s hosts are infected with malicious software that cause a variety of problems
This is an attack using a Trojan Horse
This is a coordinated attack from many devices, called zombies, with the intention of degrading or halting public access to an organization’s website and resources
Various network security devices are required to protect the network perimeter from outside access, select All of the devices
Virtual Private Network (VPN) enabled router
Next-Generation Firewall (NGFW)
Network Access Control (NAC)
Network Internet Control (NIC)
True or False, endpoints are particularly susceptible to malware-related attacks that originate through email or web browsing.
True
False
What does SMTP stand for?
Simple Male Transfer Protocol
Simple Map Transfer Protocol
Simple Mail Transfiguration Protocol
Simple Mail Transfer Protocol
True or False, the Cisco Web Security Appliance (WSA) is a mitigation technology for web-based threats
True
False
AAA stands for?
Alteration, Authorization, and Accounting
Authentication, Authorization, and Accounting
Authentication, Alteration, and Accounting
Authentication, Authorization, and Alteration
True or False, AAA is a way to control who is permitted to access a network (authenticate), what they can do while they are there (authorize), and to audit what actions they performed while accessing the network (accounting)
True
False
Select the TWO common methods of implementing AAA authentication
Local AAA Authentication
Local AAA Alteration
Server-Based AAA Authentication
Server-Based AAA Alteration
True or False, a primary use of accounting is to combine it with AAA authentication
True
False
This protocol restricts unauthorized workstations from connecting to a LAN through publicly accessible switch ports
802.2X
802.3X
802.1X
802.4X
Select ALL the Switch Attack Categories
MAC Table Attacks
VLAN Attacks
DHCP Attacks
ARP Attacks
STP Attacks
Select ALL the Switch Attack Mitigation Techniques
Port Security
DHCP Snooping
Dynamic ARP Inspection (DAI)
IP Source Guard (IPSG)
DNS Security
True or False, A VLAN hopping attack enables traffic from one VLAN to be seen by another VLAN without the aid of a router
True
False
Select ALL the VLAN Attack Mitigation techniques
Disable trunking on all access ports
Disable auto trunking on trunk links so that trunks must be manually enabled
Be sure that the native VLAN is only used for trunk links
Disable all Access ports
What do DHCP servers dynamically provide?, select ALL correct options
IP address
subnet mask
default gateway
DNS servers
True or False, a DHCP Starvation Attack occurs when a rogue DHCP server is connected to the network and provides false IP configuration parameters to legitimate clients. A rogue server can provide a variety of misleading information
True
False
In a typical attack, a threat actor sends unsolicited ARP Replies to other hosts on the subnet with the MAC Address of the threat actor and the IP address of the default gateway, effectively setting up a ___-__-___-______ attack
(a)
True or False, IP address spoofing is when a threat actor hijacks a valid IP address of another device on the subnet or uses a random IP address
True
False
True or False, Cisco Discovery Protocol (CDP) information is sent out CDP-enabled ports in periodic, unencrypted, unauthenticated broadcasts. CDP information includes the IP address of the device, IOS software version, platform, capabilities, and the native VLAN
True
False
True or False, the first hard disk of 1 GB capacity was developed in 1980. It weighed 249kg and its cost was $40,000 at that time
True
False
True or False, A simple method that many administrators use to help secure the network from unauthorized access is to enable all unused ports on a switch
True
False
True or False, The simplest and most effective method to prevent MAC address table overflow attacks is to disable port security
True
False
True or False, Port security is enabled with the switchport port-security interface configuration command
True
False
True or False, If an active port is configured with the switchport port-security command and more than one device is connected to that port, the port will transition to the error-disabled state
True
False
A switch can be configured to learn about MAC addresses on a secure port in one of three ways, select ALL three
Manually Configured
Dynamically Configured
Dynamically Learned – Sticky
Dynamically Learned
True or False, when introducing a rogue switch and enabling trunking. An attacker can then access all the VLANs on the victim switch from the rogue switch
True
False
True or False, The goal of a DHCP starvation attack is to create a Denial of Service (DoS) for connecting clients
True
False
True or False, In a typical ARP attack, a threat actor can send unsolicited ARP replies to other hosts on the subnet with the MAC Address of the threat actor and the IP address of the default gateway
True
False
To mitigate the chances of ARP spoofing and ARP poisoning, select All of the mitigation techniques
Enable DHCP snooping globally
Enable DHCP snooping on selected VLANs
Enable DAI on selected VLANs
Configure trusted interfaces for DHCP snooping and ARP inspection
True or False, Dynamic Arp Inspection (DAI) can also be configured to check for both destination or source MAC and IP addresses
True
False
True or False, To prevent ARP spoofing and the resulting ARP poisoning, a switch must ensure that only invalid ARP Requests and Replies are relayed
True
False
True or False, To mitigate STP attacks, use PortFast and Bridge Protocol Data Unit (BPDU) Guard
True
False
One million Americans spend an average of 17 days a year doing this?
Sitting on the toilet
Watching TV
Surfing
Fishing
