Font size
WorksheetsLesson 2 and 3
Total questions: 15
Worksheet time: 5mins
Which of the following best describes a DHCP Starvation attack?
An attack that creates DHCP requests for IP addresses using false MAC addresses, to drain the DHCP pool.
An attack that broadcasts DHCP requests with spoofed IP addresses, until the DHCP server crashes.
An attack that changes a DHCP server configuration to prevent distribution of IP addresses.
An attack that distributes fake IP addresses via a rogue DHCP server.
Which of the following methods can be used to perform a DoS attack?
Poisoning ARP tables.
Decrypting the network access password.
Sniffing packets associated with the server.
VLAN Hopping.
What does AAA stand for?
Authentication, Authorization, and Accounting
Attention, Authentication, and Authorization
Authentication, Authorization, and Auditing
Affirmation, Authorization, and Accounting
What are the differences between TACACS+ and RADIUS? (Choose two)
TACACS+ uses TCP by default, RADIUS uses UDP by default.
TACACS+ logs commands, RADIUS does not log commands.
RADIUS encrypts entire packets, TACACS+ encrypts credentials.
TACACS+ does not support command authorization, RADIUS supports command authorization.
The Yersinia attack tool primarily exploits which kind of vulnerabilities?
Social engineering
Network protocol vulnerabilities
Masquerading vulnerabilities
Software vulnerabilities
Which of the following countermeasures or controls can be used to mitigate CAM Table Overflow?
Configuring static MAC addresses
Implementing 802.1x
Configuring port security
All of these
interface fastEthernet 0/1 will do?
It will configure bit flipping for 0s and 1s.
It will configure the Cisco Fast and Easy Security feature.
It will allow configuration of the fastEthernet 0/1 port on the switch.
It will make the Ethernet interface on 0/1 faster.
Which of the following ways can be used to execute VLAN hopping? (choose two)
Switch Spoofing
Double Tagging
Hopscotch Tagging
Double Spoofing
Switch Tagging
How does switch spoofing work?
It manipulates a Cisco proprietary protocol called Dynamic Trunking Protocol (DTP).
The switch is configured to be a different virtual switch on a remote network, causing disruption to network trunks in cloud environments.
An attacker sends a large amount of traffic to a specific address, causing theswitch’s CAM table to overflow.
An attacker uses a victim’s STP cookie to log in to a website, posing as the victim.
Which of the following is a step in the DHCP Spoofing attack process?
The attacker sends forged DHCP responses to devices on the network.
A large amount of DHCP discover packets are sent.
Disabling a VPN server's ability to act as a DHCP server.
Forged responses are sent with a new MAC address for a switch and a NetBIOS server.
Which of the following components receives credentials from a user and submits them to the authenticator?
Supplicant
Sender
Authenticator
Authentication Server
During an attack investigation, it was concluded that the switch started acting like a hub. What could have happened to it?
The switch’s CAM table was flooded.
The switch’s violation mode switched to “shutdown.”
NTP authentication.
LLDP stopped working.
What is the purpose of the Port Security feature?
It restricts the number of MAC addresses that can access a specific port.
It prevents SSH connections to the switch.
It prevents Telnet connections to the switch.
It prevents switch shutdown.
Which of the following is a method of mitigating NTP attacks?
NTP Authentication
False Update Prevention
Router Authentication
NTP Access Control
A rogue DHCP server does which of the following?
Manipulates network settings by assigning improper IP addresses and settings.
Starves the DHCP pool.
Assigns proper MAC addresses and settings to clients.
Acts as the default gateway.
