wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ - 9A - Network Security Baselines

Total questions: 2

Worksheet time: 12mins

Name
Class
Date
1-19.

Secure baselines and configuration guides are essential for establishing standardized rules and procedures to enhance information technology security, manageability, and operational efficiency. The Center for Internet Security (CIS) Benchmarks and Security Technical Implementation Guides (STIGs) provide comprehensive best practice guides for securing IT systems and data, covering various domains like networks, operating systems, and applications.

Tools such as Puppet, Chef, Ansible, and Group Policy assist in automating the deployment of secure baseline configurations, ensuring consistency and detecting deviations. Security Content Automation Protocol (SCAP) compliant tools and CIS-CAT Pro aid in monitoring and verifying system adherence to secure baselines.

Hardening involves improving device security by changing default configurations to mitigate vulnerabilities and reduce the risk of cyberattacks. For network equipment like switches and routers, changing default credentials, disabling unnecessary services, using secure management protocols, implementing access control lists (ACLs), enabling logging and monitoring, and configuring port security are recommended practices.

Similarly, for server hardware and operating systems, changing default credentials, disabling unnecessary services, applying software security patches and updates regularly, implementing the least privilege principle, using firewalls and intrusion detection systems (IDS), configuring secure baselines, enforcing strong access controls, enabling logging and monitoring, and using antivirus and antimalware solutions are suggested.

Wireless network installation considerations involve optimizing coverage, minimizing interference, and ensuring secure configurations. Factors like WAP placement, site surveys, heat maps, and wireless encryption are crucial for establishing a secure and efficient wireless network.

Wi-Fi authentication methods include personal, open, and enterprise authentication. WPA2 and WPA3 are the primary standards for securing Wi-Fi networks, with WPA3 introducing enhancements like Simultaneous Authentication of Equals (SAE) and Enhanced Open to improve security.

Network access control (NAC) plays a crucial role in authenticating users and devices, enforcing compliance with security policies, and identifying and quarantining suspicious or noncompliant devices. NAC can be implemented using agent-based or agentless configurations to ensure network security.

1.

Which organization is recognized globally for publishing and maintaining best practice guides for securing IT systems and data?


a)

ISO

b)

CIS

c)

NIST

d)

DISA

2.

What do Configuration Management tools like Puppet, Chef, and Ansible help organizations with?


a)

Automating deployment of secure baseline configurations

b)
  • Ensuring physical security of servers

c)

Monitoring network traffic

d)

Creating access control lists

3.

Which tool is designed to assess system configurations against CIS's secure baseline benchmarks?

a)

OpenSCAP

b)

CIS-CAT Pro

c)

SCC

d)

RADIUS

4.

What concept describes improving a device's security by changing its default configuration?


a)

Hardening

b)

Patching

c)

Baseline configuration

d)

Encryption

5.

Which practice is recommended to secure network equipment like switches and routers?

a)

Leaving default credentials unchanged

b)

Enabling all unnecessary services

c)

Using Telnet for remote management

d)
  • Implementing access control lists (ACLs)

6.

What does WPS stand for in the context of Wi-Fi?

a)

Wireless Performance System

b)

Wi-Fi Protected Setup

c)

Wireless Power Saving

d)

Wi-Fi Privacy Standards

7.

Which authentication method uses a passphrase to generate the key used for encryption in WPA2?

a)
  • Simultaneous Authentication of Equals (SAE)

b)

Open authentication

c)

Pre-Shared Key (PSK)

d)
  • Extensible Authentication Protocol (EAP)

8.

Which protocol provides a port-based network access control framework for enterprise wireless networks?

a)

DHCP

b)

RADIUS

c)

EAP

d)

HTTPS

9.

What is the purpose of Network Access Control (NAC)?

a)

Encrypting network traffic

b)

Restricting access based on user profiles

c)

Enhancing Wi-Fi performance

d)

Authenticating wireless stations

10.

Which method of NAC evaluation uses a software agent installed on devices?

a)

Agentless

b)

DHCP fingerprinting

c)

Dynamic VLAN assignment

d)

Agent-based

11.

What is the primary goal of Secure Baselines and Configuration Guides?

a)

Maximizing network performance

b)

Enhancing information technology security

c)

Automating network configuration

d)

Enforcing strict access controls

12.

What type of network equipment uses default settings from the developer or manufacturer?

a)

Switches and Routers

b)

Servers

c)

Wireless Access Points

d)

Firewalls

13.

Which protocol is used in WPA3 for mutual authentication of nodes?

a)

TKIP

b)

CCMP

c)

SAE

d)

WPS

14.

What is the primary purpose of a site survey in wireless network installation?

a)

Assessing network bandwidth

b)

Optimizing coverage and minimizing interference

c)

Configuring encryption settings

d)

Determining device compatibility

15.

Which tool uses QR codes or NFC tags for securely configuring client devices with Wi-Fi network information?

a)

WPA2

b)

WPS

c)

WPA3

d)

EasyConnect

16.

Which of the following is NOT an example of a measure to improve the security of switches and routers?

a)

Enabling logging and monitoring

b)

Using Telnet for remote management

c)

Configuring port security

d)

Changing default credentials

17.

Which encryption protocol is used in WPA3 to replace the RC4 stream cipher?

a)

AES Galois Counter Mode Protocol (GCMP)

b)

Temporal Key Integrity Protocol (TKIP)

c)

Advanced Encryption Standard (AES)

d)

Dragonfly handshake

18.

What is the purpose of WPS (Wi-Fi Protected Setup)?

a)

To automate the process of securely configuring access points

b)

To increase Wi-Fi bandwidth

c)

To disable Wi-Fi encryption

d)

To monitor network traffic

19.

What is an example of a network access control (NAC) feature?

a)

Dynamic VLAN assignment

b)

Wireless encryption

c)

Remote Desktop Protocol (RDP)

d)

File Transfer Protocol (FTP)

20.

Have you submitted your standup form yet?

Click the link below

https://airtable.com/appg2CeX4DA9Y7hDi/shrUyD9aoryvXZgfu

a)

Not yet

b)

I have now.