WorksheetsDOMAIN 4 - Communications & Network Security
Total questions: 21
Worksheet time: 25mins
What is the first phase of the TCP three-way handshake sequence?
A. SYN flagged packet
B. ACK flagged packet
C. FIN flagged packet
D. SYN/ACK flagged packet
UDP is a connectionless protocol that operates at the Transport Layer of the OSI model and uses ports to manage simultaneous connections.
Which of the following terms is also related to UDP?
Bits
Logical addressing
Data reformatting
Simplex
During a security assessment of a wireless network, Jim discovers that LEAP is in use on a network using WPA. What recommendation should Jim make?
A. Continue to use LEAP. It provides better security than TKIP for WPA networks.
B. Use an alternate protocol like PEAP or EAP-TLS and implement WPA2 if supported.
C. Continue to use LEAP to avoid authentication issues but move to WPA2.
D. Use an alternate protocol like PEAP or EAP-TLS and implement Wired Equivalent Privacy to avoid wireless security issues.
Jake has been told that there is a layer 3 problem with his network. Which of the following is associated with layer 3 in the OSI model?
A. IP addresses
B. TCP and UDP protocols
C. MAC addresses
D. Sending and receiving bits via hardware
Frank is responsible for ensuring that his organization has reliable, supported network hardware. Which of the following is not a common concern for network administrators as they work to ensure their network continues to be operational?
A. If the devices have vendor support
B. If the devices are under warranty
C. If major devices support redundant power supplies
D. If all devices support redundant power supplies
Among the many aspects of a security solution, the most important is whether it addresses a specific need (i.e., a threat) for your assets. But there are many other aspects of security you should consider as well. A significant benefit of a security control is when it goes unnoticed by users. What is this called?
A. Invisibility
B. Transparency
C. Diversion
D. Hiding in plain sight
What speed and frequency range are used by 802.11n?
A. 5 GHz only
B. 900 MHz and 2.4 GHz
C. 2.4 GHz and 5 GHz
D. 2.4 GHz only
Melissa wants to combine multiple physical networks in her organization in a way that is transparent to users but allows the resources to be allocated as needed for networked services. What type of network should she deploy?
A. iSCSI
B. A virtual network
C. SDWAN
D. A CDN
Which email security solution provides two major usage modes: (1) signed messages that provide integrity, sender authentication, and nonrepudiation; and (2) an enveloped message mode that provides integrity, sender authentication, and confidentiality?
A. S/MIME
B. MOSS
C. PEM
D. DKIM
Alicia’s company has implemented multifactor authentication using SMS messages to provide a numeric code. What is the primary security concern that Alicia may want to express about this design?
A. SMS messages are not encrypted.
B. SMS messages can be spoofed by senders.
C. SMS messages may be received by more than one phone.
D. SMS messages may be stored on the receiving phone
Up Next: Secure Network Component
A ______________ is an intelligent hub because it knows the hardware addresses of the systems connected on each outbound port. Instead of repeating traffic on every outbound port, it repeats traffic only out of the port on which the destination is known to exist.
A. Repeater
B. Switch
C. Bridge
D. Router
What type of security zone can be positioned so that it operates as a buffer between the secured private network and the internet and can host publicly accessible services?
A. Honeypot
B. Screened subnet
C. Extranet
D. Intranet
Michele wants to replace FTP traffic with a secure replacement. What secure protocol should she select instead?
A. TFTP
B. HFTPS
C. SecFTP
D. SFTP
How do you distinguish between a bridge and a router?
A. A bridge simply connects multiple networks, a router examines each packet to determine which network to forward it to.
B. "Bridge" and "router" are synonyms for equipment used to join two networks.
C. The bridge is a specific type of router used to connect a LAN to the global Internet.
D. The bridge connects multiple networks at the data link layer, while router connects multiple networks at the network layer
What network tool can be used to protect the identity of clients while providing Internet access by accepting client requests, altering the source addresses of the requests, mapping requests to clients, and sending the modified requests out to their destination?
A. A switch
B. A proxy
C. A router
D. A firewall
What features can IPsec provide for secure communication?
A. Encryption, access control, nonrepudiation and message authentication
B. Protocol convergence, content distribution, micro-segmentation, and network virtualization
C. Encryption, authorization, nonrepudiation, and message integrity checking
A. Micro-segmentation, network virtualization, encryption, and message authentication
Sue modifies her MAC address to one that is allowed on a network that uses MAC filtering to provide security. What is the technique Sue used, and what non-security issue could her actions cause?
A. Broadcast domain exploit, address conflict
B. Spoofing, token loss
C. Spoofing, address conflict
D. Sham EUI creation, token loss
The CISO has requested a report on the potential communication partners throughout the company. There is a plan to implement VPNs between all network segments in order to improve security against eavesdropping and data manipulation. Which of the following cannot be linked over a VPN?
A. Two distant internet-connected LANs
B. Two systems on the same LAN
C. A system connected to the internet and a LAN connected to the internet
D. Two systems without an intermediary network connection
Modern networks are built on multilayer protocols, such as TCP/IP. This provides for flexibility and resiliency in complex network structures. All of the following are implications of multilayer protocols except which one?
A. VLAN hopping
B. Multiple encapsulation
C. Filter evasion using tunneling
D. Static IP addressing
A(n) _________________ firewall is able to make access control decisions based on the content of communications as well as the parameters of the associated protocol and software.
A. Application-level
B. Stateful inspection
C. Circuit-level
D. Static packet filtering
