wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

NWS QUIZ

Total questions: 126

Worksheet time: 1hrs 5mins

Name
Class
Date
1.

Which command will block login attempts on RouterA for a period of 30 seconds if there are 2 failed login attempts within 10 seconds? 

a)

RouterA(config)# login block-for 10 attempts 2 within 30 

b)

RouterA(config)# login block-for 30 attempts 2 within 10 

c)

RouterA(config)# login block-for 2 attempts 30 within 10 

d)

RouterA(config)# login block-for 30 attempts 10 within 2 

2.

Passwords can be used to restrict access to all or parts of the Cisco IOS. Select the modes and interfaces that can be protected with passwords. (Choose three.) 

a)

VTY interface

b)

console interface

c)

Ethernet interface

d)

boot IOS mode

e)

privileged EXEC mode

3.

5. A network administrator enters the service password-encryption command into the configuration mode of a router. What does this command accomplish? 

a)

This command encrypts passwords as they are transmitted across serial WAN links

b)

This command prevents someone from viewing the running configuration passwords. 

c)

This command enables a strong encryption algorithm for the enable secret password command. 

d)

This command automatically encrypts passwords in configuration files that are currently stored in NVRAM. 

4.

6. On which two interfaces or ports can security be improved by configuring executive timeouts? (Choose two.) 

a)

Fast Ethernet interfaces 

b)

console ports

c)

serial interfaces

d)

vty ports

5.

8. When implementing components into an enterprise network, what is the purpose of a firewall? 

a)

A firewall is a system that inspects network traffic and makes forwarding decisions based solely on Layer 2 Ethernet MAC addresses. 

b)

A firewall is a system that is designed to secure, monitor, and manage mobile devices, including corporate-owned devices and employee-owned devices. 

c)

A firewall is a system that stores vast quantities of sensitive and business-critical information. 

d)

A firewall is a system that enforces an access control policy between internal corporate networks and external networks. 

6.

7. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an attack vector? 

a)

data loss through access to personal or corporate instant messaging and social media sites

b)

the path by which a threat actor can gain access to a server, host, or network 

c)

intercepted emails that reveal confidential corporate or personal information 

d)
  • the unauthorized transfer of data containing valuable corporate information to a USB drive 

 

7.

8. What is the purpose of mobile device management (MDM) software? 

a)

It is used to create a security policy. 

b)

It is used to implement security policies, setting, and software configurations on mobile devices. 

c)

It is used to identify potential mobile device vulnerabilities. 

d)

It is used by threat actors to penetrate the system. 

8.

10. Which type of firewall makes use of a proxy server to connect to remote servers on behalf of clients? 

a)

stateless firewall 

b)

stateful firewall 

c)

application gateway firewall 

d)

packet filtering firewall 

9.

9. Which security implementation will provide management plane protection for a network device? 

a)

antispoofing 

b)

routing protocol authentication 

c)

role-based access control 

d)

access control lists 

10.

14. What is provided by the fail open and close functionality of Snort IPS? 

a)

provides the ability to automatically disable problematic signatures that routinely cause false positives and pass traffic 

b)

blocks the traffic flow or bypasses IPS checking in the event of an IPS engine failure 

c)

keeps Snort current with the latest threat protection and term-based subscriptions 

d)

keeps track of the health of the Snort engine that is running in the service container 

11.

10. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to cloud storage devices? 

a)

intercepted emails that reveal confidential corporate or personal information 

b)

gaining illegal access to corporate data by stealing passwords or cracking weak passwords 

c)

sensitive data lost through access to the cloud that has been compromised due to weak security settings 

d)

the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software 

12.

11. Which security measure is best used to limit the success of a reconnaissance attack from within a campus area network? 

a)

Implement restrictions on the use of ICMP echo-reply messages. 

b)

Implement a firewall at the edge of the network. 

c)

Implement access lists on the border router. 

d)

Implement encryption for sensitive traffic. 

13.

16. What is a characteristic of the connectivity policy setting when configuring Snort threat protection? 

a)

it attempts to balance network security with network performance 

b)

it prioritizes security over connectivity

c)

it provides the lowest level orf protection

d)

it enables the highest number of signatures to be verified

14.

14. Which attack involves threat actors positioning themselves between a source and destination with the intent of transparently monitoring, capturing, and controlling the communication? 

a)

man-in-the-middle attack 

b)

SYN flood attack 

c)

DoS attack 

d)

ICMP attack 

15.

15. What is the motivation of a white hat attacker? 

a)

fine tuning network devices to improve their performance and efficiency 

b)

taking advantage of any vulnerability for illegal personal gain 

c)

studying operating systems of various platforms to develop a new system 

d)

discovering weaknesses of networks and systems to improve the security level of these systems 

16.

18. What is a network tap? 

a)

a Cisco technology that provides statistics on packets flowing through a router or multilayer switch 

b)

a feature supported on Cisco switches that enables the switch to copy frames and forward them to an analysis device 

c)

a passive device that forwards all traffic and physical layer errors to an analysis device 

d)

a technology used to provide real-time reporting and long-term analysis of security events 

17.

1. Why are traditional network security perimeters not suitable for the latest consumer-based network endpoint devices? 

a)

These devices are not managed by the corporate IT department. 

b)

These devices pose no risk to security as they are not directly connected to the corporate network. 

c)

These devices connect to the corporate network through public wireless networks. 

d)

These devices are more varied in type and are portable. 

18.

19. Which statement describes the function of the SPAN tool used in a Cisco switch? 

a)

It is a secure channel for a switch to send logging to a syslog server. 

b)

It provides interconnection between VLANs over multiple switches. 

c)

It supports the SNMP trap operation on a switch. 

d)

It copies the traffic from one switch port and sends it to another switch port that is connected to a monitoring device. 

19.

21. What is an advantage of HIPS that is not provided by IDS? 

a)

HIPS provides quick analysis of events through detailed logging. 

b)

HIPS protects critical system resources and monitors operating system processes.

c)

HIPS monitors network processes and protects critical files. 

d)

HIPS deploys sensors at network entry points and protects critical network segments. 

20.

20. A network administrator is trying to download a valid file from an internal server. However, the process triggers an alert on a NMS tool. What condition describes this alert? 

a)

false negative 

b)

false positive

c)

t

d)

true positive

21.

22. What information must an IPS track in order to detect attacks matching a composite signature? 

a)

the total number of packets in the attack

b)

the state of packets related to the attack 

c)

the attacking period used by the attacker 

d)

the network bandwidth consumed by all packets 

22.

17. Which security feature or device would more likely be used within a CAN than a SOHO or data center? 

a)

security trap 

b)

ESA/WSA 

c)

virtual security gateway 

d)

wireless router 

23.

20. Which condition describes the potential threat created by Instant On in a data center? 

a)

when the primary firewall in the data center crashes 

b)

when an attacker hijacks a VM hypervisor and then launches attacks against other devices in the data center 

c)

when the primary IPS appliance is malfunctioning 

d)

when a VM that may have outdated security policies is brought online after a long period of inactivity. 

24.

21. What functional area of the Cisco Network Foundation Protection framework is responsible for device-generated packets required for network operation, such as ARP message exchanges and routing advertisements? 

a)

data plane 

b)

control plane

c)

management plane

d)

forwarding plane

25.

22. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of using social networking? 

a)

sensitive data lost through access to the cloud that has been compromised due to weak security settings 

b)

gaining illegal access to corporate data by stealing passwords or cracking weak passwords 

c)

data loss through access to personal or corporate instant messaging and social media sites 

d)

the retrieval of confidential or personal information from a lost or stolen device that was not configured to use encryption software 

26.

23. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes the risk of access to removable media? 

a)

the potential of causing great damage because of direct access to the building and its infrastructure devices 

b)

intercepted emails that reveal confidential corporate or personal information 

c)

the unauthorized transfer of data containing valuable corporate information to a USB drive 

d)

data loss through access to personal or corporate instant messaging and social media sites 

27.

24. What is the purpose of a reconnaissance attack on a computer network?

a)

to gather information about the target network and system 

b)

to redirect data traffic so that it can be monitored 

c)

to prevent users from accessing network resources 

d)

to steal data from the network servers 

28.

25. A security service company is conducting an audit in several risk areas within a major corporation. What statement describes an internal threat? 

a)

data loss through access to personal or corporate instant messaging and social media sites 

b)

the unauthorized transfer of data containing valuable corporate information to a USB drive 

c)

the potential of causing great damage because of direct access to the building and its infrastructure devices 

d)

gaining illegal access to corporate data by stealing passwords or cracking weak passwords 

29.

1. Which privilege level is predefined for the privileged EXEC mode? 

a)

level 1

b)

level 0

c)

level 15

d)

level 16

30.

2. What is a requirement to use the Secure Copy Protocol feature? 

a)

At least one user with privilege level 1 has to be configured for local authentication. 

b)

A command must be issued to enable the SCP server side functionality. 

c)

A transfer can only originate from SCP clients that are routers. 

d)

The Telnet protocol has to be configured on the SCP server side. 

31.

4. Which syslog message type is accessible only to an administrator and only via the Cisco CLI? 

a)

errors 

b)

alerts 

c)

debugging 

d)

Emergency 

32.

6. An administrator needs to create a user account with custom access to most privileged EXEC commands. Which privilege command is used to create this custom account? 

a)

privilege exec level 15 

b)

privilege exec level 0 

c)

privilege exec level 1 

d)

privilege exec level 2 

33.

26. A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac . What is the purpose of this configuration command? 

a)

to check the destination MAC address in the Ethernet header against the MAC address table 

b)

to check the destination MAC address in the Ethernet header against the user-configured ARP ACLs 

c)

to check the destination MAC address in the Ethernet header against the target MAC address in the ARP body 

d)

to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body 

34.

10. What is the one major difference between local AAA authentication and using the login local command when configuring device access authentication? 

a)
  • The login local command requires the administrator to manually configure the usernames and passwords, but local AAA authentication does not. 

b)

Local AAA authentication allows more than one user account to be configured, but login local does not. 

c)

Local AAA authentication provides a way to configure backup methods of authentication, but login local does not. 

d)

The login local command uses local usernames and passwords stored on the router, but local AAA authentication does not. 

35.

11. Which two UDP port numbers may be used for server-based AAA RADIUS authentication? (Choose two.) 

a)

1812

b)

1645

c)

1813

d)

49

36.

12. Which command will move the show access-lists command to privilege level 14? 

a)

router(config)# privilege level 14 command show access-lists 

b)

router(config)# privilege exec level 14 show access-lists 

c)

router(config)# set privilege level 14 show access-lists 

d)

router(config)# show access-lists privilege level 14 

37.

13. Which authentication method stores usernames and passwords in the router and is ideal for small networks? 

a)

server-based AAA over TACACS+ 

b)

local AAA over RADIUS 

c)

local AAA over TACACS+ 

d)

local AAA 

38.

27. What is the primary function of the aaa authorization command? 

a)

limit authenticated user access to AAA client services 

b)

permit AAA server access to AAA client services 

c)

permit authenticated user access to AAA client services 

d)

limit AAA server access to AAA client services 

39.

18. What IOS privilege levels are available to assign for custom user-level privileges? 

a)

levels 1 through 15 

b)

levels 0, 1, and 15 

c)

levels 2 through 14 

d)

levels 0 and 1 

40.

20. What is the biggest issue with local implementation of AAA? 

a)

Local implementation cannot provide secure authentication. Local implementation does not scale well. 

b)

Local implementation cannot provide secure authentication. 

c)

Local implementation supports only RADIUS servers. 

d)

Local implementation supports only TACACS+ servers. 

41.

11. How does a firewall handle traffic when it is originating from the public network and traveling to the private network? 

a)

Traffic that is originating from the public network is usually blocked when traveling to the private network. 

b)

Traffic that is originating from the public network is usually permitted with little or no restrictions when traveling to the private network. 

c)

Traffic that is originating from the public network is not inspected when traveling to the private network. 

d)

Traffic that is originating from the public network is selectively permitted when traveling to the private network. 

42.

21. What is the result in the self zone if a router is the source or destination of traffic? 

a)

No traffic is permitted

b)

All traffic is permitted

c)

Only traffic that originates in the router is permitted

d)

only traffic that is destined for the router is permitted

43.

1. When creating an ACL, which keyword should be used to document and interpret the purpose of the ACL statement on a Cisco device? 

a)

remark 

b)

established 

c)

eq 

d)

description

44.

5. In the creation of an IPv6 ACL, what is the purpose of the implicit final command entries, permit icmp any any nd-na and permit icmp any any nd-ns? 

a)

to allow IPv6 to MAC address resolution 

b)

to allow forwarding of ICMPv6 packets 

c)

to allow automatic address configuration 

d)

to allow forwarding of IPv6 multicast packets 

45.

26. Which AAA component can be established using token cards? 

a)

accounting 

b)

authentication 

c)

auditing 

d)

authorization 

46.

21. Which task is necessary to encrypt the transfer of data between the ACS server and the AAA-enabled router? 

a)

Use identical reserved ports on the server and the router. 

b)

Create a VPN tunnel between the server and the router. 

c)

Configure the key exactly the same way on the server and the router.

d)

Specify the single-connection keyword. 

47.

13. Designing a ZPF requires several steps. Which step involves dictating the number of devices between most-secure and least-secure zones and determining redundant devices? 

a)

design the physical infrastructure 

b)

establish policies between zones 

c)

identify subsets within zones and merge traffic requirements 

48.

23. A student is learning role-based CLI access and CLI view configurations. The student opens Packet Tracer and adds a router. Which command should be used first for creating a CLI view named TECH-View? 

a)

Router# enable view 

b)

Router(config)# aaa new-model 

c)

Router# enable view TECH-view 

d)

Router(config)# parser view TECH-view 

49.

16. What is the first step in configuring a Cisco IOS zone-based policy firewall via the CLI? 

a)

Define traffic classes. 

b)

Assign router interfaces to zones

c)

Define firewall policies

d)

Cr

50.

25. Because of implemented security controls, a user can only access a server with FTP. Which AAA component accomplishes this? 

a)

authorization 

b)

authorization 

c)

accounting 

d)

authentication 

51.

15. When using Cisco IOS zone-based policy firewall, where is the inspection policy applied? 

a)

to a zone 

b)

to a global service policy 

c)

to an interface 

d)

to a zone pair 

52.

17. What is one benefit of using a stateful firewall instead of a proxy server? 

a)

ability to perform user authentication 

b)

better performance

c)

ability to perform packet filtering

d)

prevention of Layer 7 attacks

53.

30. To facilitate the troubleshooting process, which inbound ICMP message should be permitted on an outside interface? 

a)

echo request

b)

echo reply

c)

time-stamp request

d)

u

54.

18. Which statement describes a typical security policy for a DMZ firewall configuration? 

a)

Traffic that originates from the DMZ interface is selectively permitted to the outside interface. 

b)

Return traffic from the inside that is associated with traffic originating from the outside is permitted to traverse from the inside interface to the outside interface. 

c)

Return traffic from the outside that is associated with traffic originating from the inside is permitted to traverse from the outside interface to the DMZ interface. 

d)

Traffic that originates from the outside interface is permitted to traverse the firewall to the inside interface with few or no restrictions. 

55.

19. What is one limitation of a stateful firewall? 

a)

weak user authentication

b)

cannot filter unnecessary traffic

c)

not as effective with UDP or ICMP based traffic

d)

poor log information

56.

20. Which statement describes Cisco IOS Zone-Based Policy Firewall operation? 

a)

The pass action works in only one direction. 

b)

Router management interfaces must be manually assigned to the self zone. 

c)

A router interface can belong to multiple zones. 

d)

Service policies are applied in interface configuration mode. 

57.

21. What type of data does the DLP feature of Cisco Email Security Appliance scan in order to prevent customer data from being leaked outside of the company? 

a)

inbound messages 

b)

outbound messages 

c)

messages stored on a client device 

d)

messages stored on the email server 

58.

22. What is the goal of the Cisco NAC framework and the Cisco NAC appliance? 

a)

to ensure that only hosts that are authenticated and have had their security posture examined and approved are permitted onto the network 

b)

to monitor data from the company to the ISP in order to build a real-time database of current spam threats from both internal and external sources 

c)

to provide anti-malware scanning at the network perimeter for both authenticated and non-authenticated devices 

d)

to provide protection against a wide variety of web-based threats, including adware, phishing attacks, Trojan horses, and worms 

59.

23. Which Cisco solution helps prevent MAC and IP address spoofing attacks? 

a)

Port Security DHCP Snooping 

b)

DHCP Snooping 

c)

IP Source Guard 

d)

Dynamic ARP Inspection 

60.

24. What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol? 

a)

VLAN hopping 

b)

DHCP spoofing 

c)

ARP poisoning 

d)

ARP spoofing 

61.

34. When implementing a ZPF, what is the default security setting when forwarding traffic between two interfaces in the same zone? 

a)

Traffic between interfaces in the same zone is selectively forwarded based on Layer 3 information. 

b)

Traffic between interfaces in the same zone is not subject to any policy and passes freely. 

c)

Traffic between interfaces in the same zone is blocked. 

d)

Traffic between interfaces in the same zone is selectively forwarded based on the default policy restrictions. 

62.

6. Which Snort IPS feature enables a router to download rule sets directly from cisco.com or snort.org

a)

Snort rule set pull

b)

Signature allowed listing

c)

S

d)

S

63.

7. What is a minimum system requirement to activate Snort IPS functionality on a Cisco router? 

a)

at least 4 GB flash 

b)

at least 4 GB RAM

c)

ISR 2900 or higher 

d)

K9 license 

64.

8. What is PulledPork? 

a)

an open source network IPS that performs real-time traffic analysis and generates alerts when threats are detected on IP networks 

b)

a centralized management tool to push the rule sets based on preconfigured policy, to Cisco routers 

c)

a virtual service container that runs on the Cisco ISR router operating system 

d)

a rule management application that can be used to automatically download Snort rule updates 

65.

11. What situation will generate a true negative IPS alarm type? 

a)

a verified security incident that is detected 

b)

a known attack that is not detected 

c)

normal traffic that is correctly being ignored and forwarded 

d)

normal traffic that generates a false alarm 

66.

20. What technology has a function of using trusted third-party protocols to issue credentials that are accepted as an authoritative identity? 

a)

digital signatures 

b)

hashing algorithms 

c)

PKI certificates 

d)

symmetric keys 

67.

4. In an 802.1x deployment, which device is a supplicant? 

a)

RADIUS server

b)

access point 

c)

switch

d)

end-user station 

68.

5. A company implements 802.1X security on the corporate network. A PC is attached to the network but has not authenticated yet. Which 802.1X state is associated with this PC? 

a)

err-disabled

b)

disabled

c)

unauthroized

d)

forwarding

69.

7. Which command is used as part of the 802.1X configuration to designate the authentication method that will be used? 

a)

dot1x system-auth-control 

b)

aaa authentication dot1x 

c)

a

d)

d

70.

8. What is involved in an IP address spoofing attack? 

a)

A rogue node replies to an ARP request with its own MAC address indicated for the target IP address. 

b)

Bogus DHCPDISCOVER messages are sent to consume all the available IP addresses on a DHCP server. 

c)

A rogue DHCP server provides false IP configuration parameters to legitimate DHCP clients. 

d)

A legitimate network IP address is hijacked by a rogue node. 

71.

9. At which layer of the OSI model does Spanning Tree Protocol operate? 

a)

Layer 1

b)

Layer 2

c)

L

d)

L

72.

10. A network administrator uses the spanning-tree loopguard default global configuration command to enable Loop Guard on switches. What components in a LAN are protected with Loop Guard? 

a)

All Root Guard enabled ports. 

b)

All PortFast enabled ports. 

c)

All point-to-point links between switches. 

d)

All BPDU Guard enabled ports. 

73.

17. What is the behavior of a switch as a result of a successful CAM table attack? 

a)

The switch will drop all received frames. 

b)

The switch interfaces will transition to the error-disabled state. 

c)

The switch will forward all received frames to all other ports. 

d)

The switch will shut down. 

74.

19. What device is considered a supplicant during the 802.1X authentication process? 

a)

the router that is serving as the default gateway 

b)

the authentication server that is performing client authentication 

c)

the client that is requesting authentication 

d)

the switch that is controlling network access 

75.

21. Which requirement of secure communications is ensured by the implementation of MD5 or SHA hash generating algorithms?  

a)

nonrepudiation 

b)

authentication 

c)

integrity 

d)

confidentiality 

76.

11. Which procedure is recommended to mitigate the chances of ARP spoofing? 

a)

Enable DHCP snooping on selected VLANs. 

b)

Enable IP Source Guard on trusted ports. 

c)

Enable DAI on the management VLAN. 

d)

Enable port security globally. 

77.

20. Which term describes the role of a Cisco switch in the 802.1X port-based access control? 

a)

agent 

b)

supplicant 

c)

authenticator 

d)

authentication server 

78.

13. Which protocol should be used to mitigate the vulnerability of using Telnet to remotely manage network devices? 

a)

SNMP 

b)

TFTP 

c)

SSH 

d)

SCP 

79.

14. How can DHCP spoofing attacks be mitigated? 

a)

by disabling DTP negotiations on nontrunking ports 

b)

by the application of the ip verify source command to untrusted ports  

c)

by implementing DHCP snooping on trusted ports 

d)

by implementing port security 

80.

16. Two devices that are connected to the same switch need to be totally isolated from one another. Which Cisco switch security feature will provide this isolation? 

a)

PVLAN Edge 

b)

DTP 

c)

SPAN 

d)

BPDU guard 

81.

18. Which protocol defines port-based authentication to restrict unauthorized hosts from connecting to the LAN through publicly accessible switch ports? 

a)

RADIUS 

b)

TACACS+ 

c)

SSH 

d)

802.1x 

82.

25. What is the result of a DHCP starvation attack? 

a)

The IP addresses assigned to legitimate clients are hijacked. 

b)

Legitimate clients are unable to lease IP addresses. 

c)

The attacker provides incorrect DNS and default gateway information to clients. 

d)

Clients receive IP address assignments from a rogue DHCP server. 

83.

to check the destination MAC address in the Ethernet header against the source MAC address in the ARP body 

a)

RSA 

b)

AES 

c)

MD5 

d)

PKI 

84.

2. What is the keyspace of an encryption algorithm? 

a)

the set of procedures used to calculate asymmetric keys 

b)

the mathematical equation that is used to create a key 

c)

the set of hash functions used to generate a key 

d)

the set of all possible values used to generate a key 

85.

3. Alice and Bob are using a digital signature to sign a document. What key should Alice use to sign the document so that Bob can make sure that the document came from Alice? 

a)

private key from Bob 

b)

private key from Alice 

c)

public key from Bob 

d)

username and password from Alice 

86.

7. What popular encryption algorithm requires that both the sender and receiver know a pre-shared key? 

a)

PKI 

b)

MD5

c)

AES

d)

HMAC

87.

8. In which method used in cryptanalysis does the attacker know a portion of the plaintext and the corresponding ciphertext?  

a)

meet-in-the-middle 

b)

Ciphertext 

c)

brute-force 

d)

chosen-plaintext  

88.

10. What technology supports asymmetric key encryption used in IPsec VPNs? 

a)

3DES 

b)

IKE 

c)

SEAL 

d)

AES 

89.

11. What are two symmetric encryption algorithms? (Choose two.) 

a)

3DES 

b)

HMAC 

c)

AES 

d)

SHA 

90.

12. Which two items are used in asymmetric encryption? (Choose two.)

a)

a token 

b)

a private key 

c)

a DES key 

d)

a public key 

91.

13. What are two properties of a cryptographic hash function? (Choose two.) 

a)

Complex inputs will produce complex hashes. 

b)

Hash functions can be duplicated for authentication purposes. 

c)

The hash function is one way and irreversible. 

d)

The input for a particular hash algorithm has to have a fixed size. 

e)

The output is a fixed length. 

92.

14. Which statement describes asymmetric encryption algorithms? 

a)

They have key lengths ranging from 80 to 256 bits. 

b)

They include DES, 3DES, and AES. 

c)

They are also called shared-secret key algorithms. 

d)
  • They are relatively slow because they are based on difficult computational algorithms. 

 

93.

15. An IT enterprise is recommending the use of PKI applications to securely exchange information between the employees. In which two cases might an organization use PKI applications to securely exchange information between users? (Choose two.) 

a)

HTTPS web service 

b)

802.1x authentication 

c)

local NTP server 

d)

FTP transfers 

94.

16. Two users must authenticate each other using digital certificates and a CA. Which option describes the CA authentication procedure? 

a)

The users must obtain the certificate of the CA and then their own certificate. 

b)

The CA is always required, even after user verification is complete. 

c)

CA certificates are retrieved out-of-band using the PSTN, and the authentication is done in-band over a network. 

d)

After user verification is complete, the CA is no longer required, even if one of the involved certificates expires. 

95.

17. The following message was encrypted using a Caesar cipher with a key of 2: 

fghgpf vjg ecuvng 

What is the plaintext message? 

a)

invade the castle 

b)

defend the castle 

c)

defend the region 

d)

invade the region 

96.

18. In a hierarchical CA topology, where can a subordinate CA obtain a certificate for itself? 

a)

from the root CA or another subordinate CA at a higher level 

b)

from the root CA or another subordinate CA at the same level 

c)

from the root CA or from self-generation 

d)

from the root CA or another subordinate CA anywhere in the tree 

97.

19. What is the purpose for using digital signatures for code signing? 

a)

to establish an encrypted connection to exchange confidential data with a vendor website 

b)

to verify the integrity of executable files downloaded from a vendor website 

c)

to authenticate the identity of the system with a vendor website 

d)

to generate a virtual ID 

98.

22. What is an example of the one-time pad cipher? 

a)

RC4 

b)

rail fence 

c)

Caesar 

d)
  • Vigenère 

99.

23. A company is developing a security policy for secure communication. In the exchange of critical messages between a headquarters office and a branch office, a hash value should only be recalculated with a predetermined code, thus ensuring the validity of data source. Which aspect of secure communications is addressed? 

a)

data integrity 

b)

non-repudiation 

c)

data confidentiality 

d)

origin authentication 

100.

24. What is the purpose of a digital certificate? 

a)

It guarantees that a website has not been hacked. 

b)

It provides proof that data has a traditional signature attached. 

c)

It ensures that the person who is gaining access to a network device is authorized. 

d)
  • It authenticates a website and establishes a secure connection to exchange confidential data. 

 

101.

2. What technology is used to negotiate security associations and calculate shared keys for an IPsec VPN tunnel? 

a)

PSK 

b)

SHA

c)

3DES

d)

IKE

102.

4. What takes place during IKE Phase 2 when establishing an IPsec VPN? 

a)

Traffic is exchanged between IPsec peers. 

b)

IPsec security associations are exchanged. 

c)

ISAKMP security associations are exchanged. 

d)

Interesting traffic is identified. 

103.

8. When the CLI is used to configure an ISR for a site-to-site VPN connection, what is the purpose of the crypto map command in interface configuration mode? 

a)

to configure the transform set 

b)

to bind the interface to the ISAKMP policy 

c)

to force IKE Phase 1 negotiations to begin 

d)

to negotiate the SA policy 

104.

9. Which statement describes the effect of key length in deterring an attacker from hacking through an encryption key? 

a)

The length of a key does not affect the degree of security. 

b)

The shorter the key, the harder it is to break. 

c)

The length of a key will not vary between encryption algorithms. 

d)

The longer the key, the more key possibilities exist. 

105.

10. Which two statements describe a remote access VPN? (Choose two.) 

a)

It may require VPN client software on hosts. 

b)

It requires hosts to send TCP/IP traffic through a VPN gateway

c)

It connects entire networks to each other. 

d)

It is used to connect individual hosts securely to a company network over the Internet. 

106.

11. Which protocol creates a virtual point-to-point connection to tunnel unencrypted traffic between Cisco routers from a variety of protocols? 

a)

IKE 

b)

IPsec 

c)

OSPF 

d)

GRE 

107.

 

12. How is “tunneling” accomplished in a VPN? 

a)

New headers from one or more VPN protocols encapsulate the original packets. 

b)

All packets between two hosts are assigned to a single physical medium to ensure that the packets are kept private. Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers. 

c)

Packets are disguised to look like other types of traffic so that they will be ignored by potential attackers. 

d)

A dedicated circuit is established between the source and destination devices for the duration of the connection. 

108.

15. Which is a requirement of a site-to-site VPN? 

a)

It requires hosts to use VPN client software to encapsulate traffic. 

b)

It requires the placement of a VPN server at the edge of the company network. 

c)

It requires a VPN gateway at each end of the tunnel to encrypt and decrypt traffic. 

d)

It requires a client/server architecture. 

109.

16. Consider the following configuration on a Cisco ASA: 
crypto ipsec transform-set ESP-DES-SHA esp-des esp-sha-hmac 
What is the purpose of this command? 

a)

to define only the allowed encryption algorithms 

b)

to define what traffic is allowed through and protected by the tunnel 

c)

to define the encryption and integrity algorithms that are used to build the IPsec tunnel 

d)

to define the ISAKMP parameters that are used to establish the tunnel 

110.

17. What is needed to define interesting traffic in the creation of an IPsec tunnel? 

a)

security associations 

b)

hashing algorithm 

c)

access list 

d)

transform set 

111.

18. What is a function of the GRE protocol? 

a)

to configure the set of encryption and hashing algorithms that will be used to transform the data sent through the IPsec tunnel 

b)

to encapsulate multiple OSI Layer 3 protocol packet types inside an IP tunnel 

c)

to configure the IPsec tunnel lifetime 

d)

to provide encryption through the IPsec tunnel 

112.

20. Two corporations have just completed a merger. The network engineer has been asked to connect the two corporate networks without the expense of leased lines. Which solution would be the most cost effective method of providing a proper and secure connection between the two corporate networks? 

a)

Cisco AnyConnect Secure Mobility Client with SSL 

b)

Cisco Secure Mobility Clientless SSL VPN 

c)

remote access VPN using IPsec 

d)

site-to-site VPN 

113.

22. What type of traffic is supported by IPsec? 

a)

IPsec supports all IPv4 traffic. 

b)

IPsec supports layer 2 multicast traffic. 

c)
  • IPsec only supports unicast traffic. 

 

d)

IPsec supports all traffic permitted through an ACL. 

114.

1. A network analyst wants to monitor the activity of all new interns. Which type of security testing would track when the interns sign on and sign off the network? 

a)

vulnerability scanning 

b)

password cracking 

c)

network scanning 

d)
  • integrity checker 

 

115.

3. What testing tool is available for network administrators who need a GUI version of Nmap? 

a)

SuperScan 

b)

Zenmap 

c)

Nessus 

d)

SIEM 

116.

4. What is the goal of network penetration testing? 

a)

determining the feasibility and the potential consequences of a successful attack 

b)

detecting potential weaknesses in systems 

c)

detecting configuration changes on network systems 

d)
  • detecting weak passwords 

 

117.

5. How does network scanning help assess operations security? 

a)

It can detect open TCP ports on network systems. 

b)

It can detect weak or blank passwords. 

c)

It can simulate attacks from malicious sources. 

d)

It can log abnormal activity. 

118.

10. What can be configured as part of a network object? 

a)

interface type 

b)

IP address and masK

c)

upper layer protocol 

d)

source and destination MAC address 

119.

11. What is the function of a policy map configuration when an ASA firewall is being configured? 

a)

binding a service policy to an interface 

b)

binding class maps with actions 

c)

identifying interesting traffic 

d)

using ACLs to match traffic 

120.

12. What is the purpose of configuring an IP address on an ASA device in transparent mode? 

a)

management 

b)

routing 

c)

NAT

d)

VPN connectivity 

121.

13. Which license provides up to 50 IPsec VPN users on an ASA 5506-X device? 

a)

the most commonly pre-installed Base license 

b)

a purchased Security Plus upgrade license 

c)

a purchased Base license 

d)

a purchased AnyConnect Premium license 

122.

14. What mechanism is used by an ASA device to allow inspected outbound traffic to return to the originating sender who is on an inside network? 

a)

access control lists 

b)

Network Address Translation 

c)

security zones 

d)

stateful packet inspection 

123.

15. When configuring interfaces on an ASA, which two pieces of information must be included? (Choose two.) 

a)

group association 

b)

service level 

c)

security level 

d)

name 

e)

access list 

124.

17. What interface configuration command is used on an ASA to request an IP address from an upstream DSL device? 

a)

ip address ip-address netmask 

b)

ip address dhcp setroute 

c)

dhcpd address IP_address1 [ -IP_address2 ] if_name ip address pppoe 

d)

ip address pppoe 

125.

19. What is the purpose of the Tripwire network testing tool? 

a)

to perform vulnerability scanning 

b)

to provide information about vulnerabilities and aid in penetration testing and IDS signature development 

c)

to assess configuration against established policies, recommended best practices, and compliance standards 

d)

to detect unauthorized wired network access 

126.

20. A network analyst is testing the security of the systems and networks of a corporation. What tool could be used to audit and recover passwords? 

a)

L0phtCrack 

b)

SuperScan 

c)

Nessus 

d)

Metasploit