Font size
WorksheetsSec+ - 9A - Network Security Baselines
Total questions: 2
Worksheet time: 12mins
Secure baselines and configuration guides are essential for establishing standardized rules and procedures to enhance information technology security, manageability, and operational efficiency. The Center for Internet Security (CIS) Benchmarks and Security Technical Implementation Guides (STIGs) provide comprehensive best practice guides for securing IT systems and data, covering various domains like networks, operating systems, and applications.
Tools such as Puppet, Chef, Ansible, and Group Policy assist in automating the deployment of secure baseline configurations, ensuring consistency and detecting deviations. Security Content Automation Protocol (SCAP) compliant tools and CIS-CAT Pro aid in monitoring and verifying system adherence to secure baselines.
Hardening involves improving device security by changing default configurations to mitigate vulnerabilities and reduce the risk of cyberattacks. For network equipment like switches and routers, changing default credentials, disabling unnecessary services, using secure management protocols, implementing access control lists (ACLs), enabling logging and monitoring, and configuring port security are recommended practices.
Similarly, for server hardware and operating systems, changing default credentials, disabling unnecessary services, applying software security patches and updates regularly, implementing the least privilege principle, using firewalls and intrusion detection systems (IDS), configuring secure baselines, enforcing strong access controls, enabling logging and monitoring, and using antivirus and antimalware solutions are suggested.
Wireless network installation considerations involve optimizing coverage, minimizing interference, and ensuring secure configurations. Factors like WAP placement, site surveys, heat maps, and wireless encryption are crucial for establishing a secure and efficient wireless network.
Wi-Fi authentication methods include personal, open, and enterprise authentication. WPA2 and WPA3 are the primary standards for securing Wi-Fi networks, with WPA3 introducing enhancements like Simultaneous Authentication of Equals (SAE) and Enhanced Open to improve security.
Network access control (NAC) plays a crucial role in authenticating users and devices, enforcing compliance with security policies, and identifying and quarantining suspicious or noncompliant devices. NAC can be implemented using agent-based or agentless configurations to ensure network security.
Which organization is recognized globally for publishing and maintaining best practice guides for securing IT systems and data?
ISO
CIS
NIST
DISA
What do Configuration Management tools like Puppet, Chef, and Ansible help organizations with?
Automating deployment of secure baseline configurations
Ensuring physical security of servers
Monitoring network traffic
Creating access control lists
Which tool is designed to assess system configurations against CIS's secure baseline benchmarks?
OpenSCAP
CIS-CAT Pro
SCC
RADIUS
What concept describes improving a device's security by changing its default configuration?
Hardening
Patching
Baseline configuration
Encryption
Which practice is recommended to secure network equipment like switches and routers?
Leaving default credentials unchanged
Enabling all unnecessary services
Using Telnet for remote management
Implementing access control lists (ACLs)
What does WPS stand for in the context of Wi-Fi?
Wireless Performance System
Wi-Fi Protected Setup
Wireless Power Saving
Wi-Fi Privacy Standards
Which authentication method uses a passphrase to generate the key used for encryption in WPA2?
Simultaneous Authentication of Equals (SAE)
Open authentication
Pre-Shared Key (PSK)
Extensible Authentication Protocol (EAP)
Which protocol provides a port-based network access control framework for enterprise wireless networks?
DHCP
RADIUS
EAP
HTTPS
What is the purpose of Network Access Control (NAC)?
Encrypting network traffic
Restricting access based on user profiles
Enhancing Wi-Fi performance
Authenticating wireless stations
Which method of NAC evaluation uses a software agent installed on devices?
Agentless
DHCP fingerprinting
Dynamic VLAN assignment
Agent-based
What is the primary goal of Secure Baselines and Configuration Guides?
Maximizing network performance
Enhancing information technology security
Automating network configuration
Enforcing strict access controls
What type of network equipment uses default settings from the developer or manufacturer?
Switches and Routers
Servers
Wireless Access Points
Firewalls
Which protocol is used in WPA3 for mutual authentication of nodes?
TKIP
CCMP
SAE
WPS
What is the primary purpose of a site survey in wireless network installation?
Assessing network bandwidth
Optimizing coverage and minimizing interference
Configuring encryption settings
Determining device compatibility
Which tool uses QR codes or NFC tags for securely configuring client devices with Wi-Fi network information?
WPA2
WPS
WPA3
EasyConnect
Which of the following is NOT an example of a measure to improve the security of switches and routers?
Enabling logging and monitoring
Using Telnet for remote management
Configuring port security
Changing default credentials
Which encryption protocol is used in WPA3 to replace the RC4 stream cipher?
AES Galois Counter Mode Protocol (GCMP)
Temporal Key Integrity Protocol (TKIP)
Advanced Encryption Standard (AES)
Dragonfly handshake
What is the purpose of WPS (Wi-Fi Protected Setup)?
To automate the process of securely configuring access points
To increase Wi-Fi bandwidth
To disable Wi-Fi encryption
To monitor network traffic
What is an example of a network access control (NAC) feature?
Dynamic VLAN assignment
Wireless encryption
Remote Desktop Protocol (RDP)
File Transfer Protocol (FTP)
Have you submitted your standup form yet?
Click the link below
Not yet
I have now.
