NEW
Font size
WorksheetsFirewalls and Network Security Study Guide Midterm
Total questions: 74
Worksheet time: 19hrs 30mins
Zero-day exploits are new and previously unknown attacks for which no current specific defenses exist.
True
False
You are a network professional. You want to overcome the security shortcomings of the Domain Name System (DNS). Of the following, what is one of those shortcomings?
A fully qualified domain name (FQDN) vulnerability
Use of Microsoft Active Directory
Use of an intrusion detection system (IDS)
Use of a plaintext communication
A combination of intrusion detection and prevention, as well as logging and monitoring, provides the best defense against what kind of attack?
Distributed denial of service (DDoS)
Zero-day exploit
SQL injection
Malicious code
A major U.S. online retailer has discovered that thousands of purchases have been paid for by stolen credit card numbers. An initial analysis of the location of the buyers reveals IP addresses from within the U.S. Upon further investigation, it is found that the actual origin point of the fraudulent buyer is a series of IP addresses located in Asia. What technology is the fraudster using?
IP address fraud
Ingress filtering
Proxy server
Port address translation (PAT)
Integrity is the protection against unauthorized access, while providing authorized users access to resources without obstruction.
True
False
Which type of hacker is a criminal whose career objective is to compromise IT infrastructures?
Professional
Recreational
Script kiddie
Opportunistic
Peer pressure is a form of motivation for some hackers.
False
True
Several times this week, the IT infrastructure chief of a small company has suspected that wireless communications sessions have been intercepted. After investigating, he believes it is some form of insertion attack. He is considering encrypted communications and preconfigured network access as a defense. What type of insertion attack is suspected?
Intrusion detection system (IDS) insertion
Rogue device insertion
Cross-site scripting (XSS)
SQL Injection
A malicious person has installed ransomware on a company user's computer. The ransomware message states that the malicious software will be removed if the user pays a certain amount of money digitally. What is a typical form of payment?
Credit card
PayPal
Debit card
Cryptocurrency
A breach is any attempt to get past a network's defenses.
True
False
Logical networks limit access to data and resources by allowing only those individuals and
devices that require such access.
False
True
A networking instructor is demonstrating the use of a device that, when making a connection to the Internet, issues a series of alternating tones, and is used to translate the digital signals from computers to analog signals used on traditional telephone lines. Although the name is familiar to the students, this particular device is no longer in common use. What is the instructor demonstrating?
Switch
Brouter
Router
Modem
Network switches provide network segmentation through logical addressing.
True
False
In a full connection mesh topology, all devices on a network are connected to all other devices.
True
False
Fatima has been hired as a contractor to decommission a network topology that has been employed by a small company since the 1990s. In studying the project specifications, she reads that this physical topology uses a special packet called tokens, can be unidirectional or bidirectional, and although it has fewer collisions than other types of networks, is rarely seen in the 21st century. Baffled as to what type of network this is, she goes on the Internet and researches the technology. What sort of topology does she find?
Ring
Star
Bus
Mesh
Outbound network traffic should be subjected to the same investigations and analysis as inbound network traffic.
False
True
Isabelle is the cybersecurity engineer for a medium-sized company. She is setting up a firewall for examining inbound network traffic for a variety of characteristics. While remote users working from home should be allowed access to network resources, malicious traffic should be blocked. To differentiate, Isabelle is looking at factors such as whether the inbound traffic is a response to a previous request inside the network, whether it includes blocked domain names, IP addresses and protocols, and whether it conforms to known malicious patterns or is otherwise abnormal. What is she setting up the firewall to practice?
Encryption
Filtering
Modeling
Access management
Removing all unnecessary protocols, uninstalling all unnecessary applications and services, and installing the latest final releases of all device drivers are part of what security process?
Portability
Auditing
Anti-spoofing
Hardening
The chief information officer (CIO) of a large company has been informed by the board of directors that their corporation is anticipating rapid growth over the next two years. She calculates the contingency of building additional capacity into the current network infrastructure. Based on the board's growth estimates, what percentage of additional capacity should she plan for?
Over 50 percent
20 percent
10 percent
30 percent
Networked systems that are no longer used or monitored can become network entry points for hackers.
False
True
The sole use of ingress and egress filtering is to eliminate spoofing.
True
False
Passive threats are those you must seek out to be harmed, such as visiting a malicious website.
True
False
Rachel is a network technician. She is writing a proposal that recommends which firewall type to purchase to replace an aging and failing unit. She wants to be able to protect two separate internal network segments with one hardware firewall. What is her recommendation?
Next-generation
Virtual
Dual-homed
Triple-homed
Augustine is a network engineer for a mid-sized company. He needs to deploy a new firewall, which was expensive to purchase and is complex to configure. In preparation for installation and configuration, he attends training conducted by the firewall vendor. Which of the following types of firewalls is he most likely planning to install?
Commercial
Personal
Appliance
Native
A guideline for firewall selection is to never skimp on throughput.
False
True
Basic packet filtering provided by routers can be used to protect subnets within a network.
True
False
The network infrastructure supervisor is designing a firewall placement strategy that will protect the organization's Internet-facing web and email servers and the internal network. Which design will provide the best protection?
Placing the web and email servers, configured with the latest patches and anti-malware applications, on the Internet in front of the firewall, while placing the internal network behind the firewall
Using an intrusion detection system/intrusion prevention system (IDS/IPS) with edge and web servers facing the Internet, and placing the firewall behind them but ahead of the internal network
Using two firewalls to create a demilitarized zone (DMZ); one firewall is placed between the Internet and the servers, the other firewall is located behind the first firewall and the servers protecting the internal network
Placing the firewall between the Internet and a single network hosting both the servers and the internal network, using port forwarding to direct traffic to the servers
Which of the following can affect the confidentiality of documents stored on a server?
A distributed denial of service (DDoS) attack
A denial of service (DoS) attack
A server breach
Information about the server being accessed
Chang is a network engineer. He is revising the company's firewall implementation procedure. He is reviewing the procedural element requiring placement of network firewalls at chokepoints and mapping out the network structure to pinpoint the location where firewalls are to be placed. Which of the following is he focusing on?
Network design
Change documentation
Journaling firewall deployment
Transaction security
A best practice is to use strong authentication and nonrepudiation methods for all transactions over the Internet.
True
False
What network device concentrates communication signals, accepts only basic commands, and provides statistics such as throughput measures and uptime percentages?
Active Hub
Dumb Hub
Router
Gateway
Which network device differentiates network traffic using Layer 2 of OSI Model?
Active Hub
Dumb Hub
Router
Switch
A wireless network topology uses some wire.
True
False
In a full connection mesh topology, all device on a network are connected to all other devices.
True
False
Norman is a network engineer. He is creating a series of logical networks based on different departments for a new branch office. Although the physical location of each computer for a particular department may be located in different areas or on different floors of the building, they have to operate as if they are on a single physical network. Norman's solution involves putting the accounting engineering, and marketing computer nodes on different subnets. What sort of network topology does Norman create?
Access Point
Local Area Network (LAN)
Star
Virtual Local Area Network (VLAN)
A small office/home office (SOHO) environment can be a workgroup or a client/server network.
True
False
Which boundary network creates a series of subnets separated by firewalls?
Demilitarized Zone (DMZ)
Extranet
Intranet
N-tier
When considering network expenditures, sunk costs should not influence future choices
True
False
A hacker is attempting to access a company's router using false Internet Control Message Protocol (ICMP) type 5 redirect messages. What is the hacker's goal?
To spoof or manipulate routing data
To add false entries into the router's access control list
To bypass the firewall
To delete all of the device's routing protocols
Mario is the network security engineer for his company. He discovered that, periodically, a remote user working from home accesses certain resources on the network that are not part of her regular duties. Mario has questioned the user and her supervisor, and has accessed the user's workstation. Mario believes the user is not the source of these intrusions and strongly suspects a malicious source is responsible. What is the most likely explanation?
The user has fooled Mario into believing her innocence and she really is the malicious intruder.
An external hacker has gained access to the user's authentication and is accessing confidential company resources.
Mario has erroneously interpreted the firewall logs, and the user has not accessed such data.
The user requires periodic access to data that is only sometimes part of her job duties.
The chief information officer (CIO) is working with the chief financial officer
(CFO) on next year's budget for new networking equipment. The CIO is explaining that lowest cost equipment isn't the only deciding factor. The hardware must conform to high security standards to prevent a malicious person from hacking into the network and accessing valuable company data.
Which of the following considerations does not specifically require a hacker to have physical access to the equipment?
Portability
Remote connection
Removable case
Reset button
Every morning when James logs into his computer and attempts to access
Microsoft 365, he is asked to enter his password. After that, he is sent a text on his mobile phone with a six-digit code he must enter. In terms of multifactor authentication, his password is something he knows. What is the text message?
Something he knows
Something he has
Something he is or does
Something he types
A firewall is a filtering device that watches for traffic that fails to comply with rules defined by the firewall administrator. What does the firewall inspect?
Packet header
Packet trailer
Packet encryption
Packet latency
Hao is a network security engineer for a mid-sized company. She is redesigning the infrastructure and its resources to provide greater protection from both external and internal threats. She wants to place firewall devices not only where the local area network (LAN) connects to the Internet, but also within the network.
Although she doesn't suspect any employees of misusing computer resources, there is always the potential that one might send unauthorized emails or other messages containing confidential company information to a competitor. What redundant solution should she select that will most likely detect malicious behavior by an internal employee?
Firewall in the demilitarized zone (DMZ)
Firewalls at each subnet
Host firewalls
Host firewalls and firewalls at each subnet
Charles is an IT help desk technician. He gets a ticket from a branch office saying that they lost Internet connectivity. He investigates remotely over a backup maintenance link and determines that this was done by design; the office's firewall deliberately severed the connection. Which of the following does this functionality define?
Port forwarding
Reverse proxy
Stateful inspection
Bastion host
When setting up port forwarding on an external firewall to pass HTTP traffic from the Internet to an internal web server, the external address and port are 208.40.235.38:8081. What is the internal IP address and port, assuming the most common port for that protocol?
192.168.5.74:21
192.168.5.74:25
192.168.5.74:80
192.168.5.74:123
Shamika is a networking student who has just moved into a small house with two other roommates. She has purchased a new DSL modem and is planning on configuring the built-in firewall. She needs to change the default username and password for the device first. What is her concern?
The default usemame and password are likely available on the Internet and anyone could use those credentials to hack into the modem and access the home network.
The DSL company has those credentials and could use them to monitor their network communications.
She will be unable to configure the firewall until those temporary default credentials have been changed.
She is being overly cautious as home networks are a low priority for hackers.
Rachel is a network technician. She is writing a proposal that recommends which firewall type to purchase to replace an aging and failing unit. She wants to be able to protect two separate internal network segments with one hardware firewall. What is her recommendation?
Dual-homed
Next-generation
Triple-homed
Virtual
Logan is a network administrator. He is considering a firewall purchase for a branch office being built by his company. Above all other considerations, the design requires a device capable of a high degree of imposing user access restrictions. What is this called?
Audit capacities
Authentication
Privilege control
Security assurance
If a server has a public IP address, it is a potential target for hacker attack.
True
False
Which of the following can affect the confidentiality of documents stored on a server?
A distributed denial of service (DDoS) attack
Information about the server being accessed
A server breach
A denial of service (DoS) attack
It is often more difficult to preserve a user's privacy on the Internet than in the physical world.
True
False
Charles is a network engineer. He is revising the company's firewall implementation procedure. He is reviewing the procedural element requiring placement of network firewalls at chokepoints and mapping out the network structure to pinpoint the location where firewalls are to be placed. Which of the following is he focusing on?
Transaction security
Network design
Change documentation
Journaling firewall deployment
The network infrastructure supervisor is designing a firewall placement strategy that will protect the organization's Internet-facing web and email servers and the internal network. Which design will provide the best protection?
Placing the firewall between the Internet and a single network hosting both the servers and the internal network, using port forwarding to direct traffic to the servers
Placing the web and email servers, configured with the latest patches and anti-malware applications, on the Internet in front of the firewall, while placing the internal network behind the firewall
Using an intrusion detection system/intrusion prevention system (IDS/IPS) with edge and web servers facing the Internet, and placing the firewall behind them but ahead of the internal network
Using two firewalls to create a demilitarized zone (DMZ); one firewall is placed between the internet and the servers, the other firewall is located behind the first firewall and the servers connecting the internal network
Tonya is redesigning her company's network infrastructure to accommodate rapid growth. Several departments are highly specialized. Tonya needs to allow Network News Transfer Protocol (NNTP) on some but not all subnets. Her budget is limited. Which of the following is the best solution?
Install firewalls at the demilitarized zone (DMZ) to filter packets by protocol, port, and destination subnet, and then perform port forwarding.
Install firewalls at each network segment with rules to filter specific traffic for each one as required.
Configure existing routers to filter NNTP packets.
Configure the native firewall on each workstation to filter traffic based on the guirements for the subnet they're on.
Which of the following is a concern when considering the use of a demilitarized zone (DMZ) firewall solution to access high value data on an internal network?
Expense
Poorly constructed firewall rules
Encryption
Virtual private network (VPN) server vulnerabilities
Israel is a network technician who has just deployed a new firewall. Before putting it in production, he wants to test the firewall's ability to filter traffic according to its ruleset, without risking the internal network. What is the best solution?
Place the firewall in a virtual network environment and simulate traffic.
Place the firewall outside the demilitarized zone (DMZ) with a production firewall behind it protecting the internal network.
Place the firewall outside the demilitarized zone (DMZ) and use the tracert command.
Place the firewall within the demilitarized zone (DMZ) and use the ping command.
What is an example of security through obscurity?
Assuming your system will not be noticed when connecting to the Internet
Using the default service port of a network service
Keeping an encryption algorithm secret
Using a non-standard operating system for workstations such as FreeBSD
In an N-tier deployment, multiple subnets are deployed in series to separate private resources from public.
True
False
Carl is a network engineer for a mid-sized company. He has been assigned the task of positioning hardware firewalls in the IT infrastructure based on common pathways of communication. After analyzing the problem, on what aspect of the network does he base his design?
Wireless access points
Cellular network
Remote access
Traffic patterns
With diversity of defense, most layers use a different security mechanism.
True
False
Amy is a network engineering consultant. She is designing security for a small to medium-sized government contractor working on a project for the military. The government contractor's network is comprised of 30 workstations plus a wireless printer, and it needs remote authentication. Which of the following is a type of authentication solution she should deploy?
Local authentication at the firewall that does not integrate with single sign-on (SSO)
IEEE 802.1x
Port-based network access (admission) control (PNAC)
RADIUS
Alejandro is a cybersecurity contractor. He was hired by a Fortune 500 company to redesign their network security system, which was originally implemented when they were a much smaller organization. The company's current solution is to use multiple firewall platforms from different vendors to protect internal resources. Alejandro proposes a type of infrastructure security method that, in addition to firewalls, adds tools such as an intrusion detection system (IDS), antivirus, strong authentication, virtual private network (VPN) support, and granular access control. What is this solution called?
Least privilege
Diversity of defense
N-tier deployment
Defense in Depth
What is the basic service of a reverse proxy?
Hides the identity of a client connecting to the Internet
Hides the identity of a web server accessed by a client over the Internet
Hides the identity of subnet hosts connecting to a database server
Hides the identity of hackers trying to defraud online retailers
Which of the following is a firewall, proxy, and routing service that does NOT support caching, encryption endpoint, or load balancing? The service can be found on almost any service or device that supports network address translation.
Bastion host
Demilitarized zone (DMZ)
Port-based network access (admission) control (PNAC)
Port forwarding
All firewalls, including those using static packet filtering, stateful inspection, and application proxy, have one thing in common. What is it?
Default permit
Default reject
Rules
Transport Layer Security (TLS)
You are a networking contractor who has been hired by a small-to-mid-sized company to configure their firewall. The firewall comes preconfigured with a common ruleset that allows web, email, instant messaging, and file transfer traffic using default ports. The company wants to allow access to secure websites and common website protocols but block access to insecure Internet websites. Which of the following is the best solution?
Allow access to HTTP, HTTPS, and SQL and Java, but deny TCP and UDP
Allow access to HTTPS, SQL, and Java, but deny access to HTTP
Deny access to HTTP, HTTPS, SQL, and Java, but allow access to TCP and UDP
Allow access to SMTP, POP3, and HTTP, but deny access to HTTPS, SQL, and Java
Duncan runs a small writing and editing business. He employs two people in his small office/home office (SOHO). He also has general knowledge of networking, including how to configure a basic firewall to protect the network. His off-the-shelf firewall has rulesets built in with several main elements. He is currently setting rules for TCP and UDP. What element is he working with?
Source address
Base protocol
Source port
Target port
Shoshana is a network technician for a mid-sized organization. She is configuring firewall rules. She is in a firewall's graphical interface and sets a rule as TCP, 192.168.42.0/24, ANY, ANY, 443, Allow. In what order is the ruleset organizing protocols, source addresses, source and target ports, and actions?
Protocol, source address, source port, target address, target port, action
Action, target port, target address, source port, source address, protocol
Source port, source address, protocol, target port, target address, action
Target port, source address, source port, target address, protocol, action
Which of the following is needed when determining what firewall traffic to allow and what to block?
A complete inventory of all needed or desired network communications
A complete inventory of all unneeded and unwanted network communications
A list of available port numbers and protocols
Which type of traffic to deny only inside the network and which type to deny to enter the network from the Internet
A network technician is configuring rules on one of her company's externally facing firewalls. Her network has a host address range of 192.168.42.140-190. She wants to allow all hosts access to a certain port except for hosts 188, 189, and 190. What rule or rules must she write?
A single rule allowing hosts 140-187 is all that is necessary; the default-deny rule takes care of blocking the remaining nonincluded hosts.
Multiple rules to use this configuration; one or more rules must define Deny exceptions for 188, 189, and 190, followed by the Allow rule for the 140-190 range.
A Deny rule for 188, 189, and 190, and then exception rules for the 140-187 range.
The default Deny all rule needs to be placed first in the list, and then an exception rule for the 140-187 range.
Sarah is a network technician. She is setting up a ruleset for a firewall in her company's demilitarized zone (DMZ). For email, she creates an allow-exception rule permitting Simple Mail Transfer Protocol (SMTP) traffic on port 25 to leave the internal network for the Internet. Her supervisor examines her work and points out a possible problem. What is it?
Lenita used the wrong port. SMTP uses port 21.
The allow-exception rule could create a loophole threatening internal communications on the same port.
Lenita should have used a deny-exception rule just prior to the Allow rule.
The allow-exception rule could create a bottleneck, slowing down traffic to and from the Internet.
Elissa is a network technician. She is configuring firewall rules for one of her company's branch offices, which provides online retail sales of their products.
She is configuring rules to block traffic based on a traditional model but needs to allow a particular type of traffic. What should she allow?
All Internet Control Message Protocol (ICMP) traffic coming from the Internet
Any traffic specifically directed to the firewall
All traffic from port 80 originating from the office's web server, which is in a protected subnet
Inbound Transmission Control Protocol (TCP) traffic on port 53 to external Domain Name System (DNS) zone transfer requests
In an N-tier deployment, multiple subnets are deployed in series to separate private resources from public.
True
False
