NEW
Font size
WorksheetsChapter Ten Practice Quiz
Total questions: 74
Worksheet time: 37mins
What is a computer network?
A group of computers or other devices that are connected to facilitate the sharing of resources.
A single computer used for personal tasks.
A device used to play video games.
A system for managing personal finances.
What can happen if there is a loss of network connectivity?
It can devastate your business.
It will improve network security.
It will have no impact on daily activities.
It will only affect personal computers.
What was the impact of the civil unrest in Cameroon in January 2017 on the internet?
Regions remained offline for 93 days.
The internet speed increased.
There was no impact on the internet.
The internet was only down for a few hours.
What are some of the impacts of network outages?
Disrupting medical care, communications, employment, education, shopping, and many other aspects of people's lives.
Improving the efficiency of network traffic.
Enhancing the security of personal data.
Reducing the cost of internet services.
What is one method to protect your networks and network resources?
Implementing firewalls and intrusion detection systems.
Ignoring network security.
Using outdated software.
Allowing unrestricted access to all devices.
What is one strategy for reducing the impact of attacks on a network?
Increasing the number of users
Network segmentation
Reducing the number of devices
Increasing bandwidth
What can properly segmented networks help to boost?
Network performance
Number of users
Internet speed
Hardware lifespan
What is the purpose of funneling traffic through choke points in a network?
To increase network speed
To inspect, filter, and control traffic
To reduce the number of users
To increase bandwidth
What can creating redundancies in network design help mitigate?
Network speed
Technical failures or attacks
Number of users
Hardware costs
What is a firewall used for in network security?
Increasing network speed
Maintaining control over network traffic
Reducing the number of users
Increasing bandwidth
Who wrote the paper "Simple and Flexible Datagram Access Controls"?
Jeffrey Mogul
Digital Equipment Corporation
DEC SEAL.3
Figure 10-1
In what year did Digital Equipment Corporation create the first commercial firewall?
1989
1992
1995
2000
What do many of the firewalls in use today examine to maintain network security?
User credentials
Packets (blocks of data)
Hardware components
Software applications
What does a packet filtering firewall examine to allow or disallow traffic?
The contents of each packet individually
The entire network traffic at once
Only the source IP address
Only the destination IP address
Which type of firewall can keep track of the connection state and allows traffic that is part of a new or already established connection?
Packet filtering firewall
Stateful packet inspection firewall
Deep packet inspection firewall
Proxy firewall
What additional capability does a deep packet inspection firewall provide compared to packet filtering and stateful firewalls?
It can examine the entire network traffic at once
It can analyze the actual content of the traffic
It can only filter based on IP addresses
It can only filter based on port numbers
What analogy is used to describe the function of a deep packet inspection firewall?
A security guard checking IDs
A parcel carrier examining a package
A librarian organizing books
A chef preparing a meal
What is a potential vulnerability of packet filtering firewalls?
They can only filter traffic based on port numbers
They can be bypassed by attack traffic that spans more than one packet
They cannot filter traffic based on IP addresses
They are unable to track the state of connections
What is the primary function of a proxy server?
To block all incoming traffic from the internet
To provide security and performance features for applications
To act as a database for storing signatures of malware
To create a demilitarized zone (DMZ)
What is a potential privacy concern associated with deep packet inspection?
It can slow down internet speed
It can block legitimate traffic
It can read every email message and web page you visit
It can only filter out spam emails
What is the purpose of a demilitarized zone (DMZ) in network security?
To allow public-facing servers to be accessed from the outside while protecting the internal network
To monitor network traffic for unauthorized activity
To filter out spam emails from reaching users
To maintain a database of malware signatures
How do signature-based intrusion detection systems (IDS) work?
By creating a demilitarized zone (DMZ)
By maintaining a database of signatures that signal known attacks
By providing a layer of security for applications
By blocking all incoming traffic from the internet
What is one of the functions of proxy servers in a corporate environment?
To create a demilitarized zone (DMZ)
To keep spam from reaching users' email accounts
To monitor network traffic for unauthorized activity
To block all incoming traffic from the internet
What is one of the main drawbacks of signature-based IDS?
It can detect new attacks very well.
It may not detect attacks if there is no signature for them.
It produces a large number of false positives.
It does not require any signatures to detect attacks.
How do anomaly-based IDS typically work?
By comparing incoming traffic to known attack signatures.
By determining the normal kinds of traffic and activity on the network.
By using the same IDS tools as the attacker.
By encrypting all network traffic.
What is a potential disadvantage of anomaly-based IDS?
It cannot detect new attacks.
It may produce a larger number of false positives.
It requires a signature for each attack.
It does not work with encrypted traffic.
What is the benefit of using both signature-based and anomaly-based IDS methods?
It eliminates the need for any signatures.
It provides the advantages of both types of detection.
It reduces the amount of traffic to examine.
It ensures that no attacks are missed.
Where should you typically attach a network IDS?
Directly to the internet.
To a location where it can monitor the traffic going by.
Behind a firewall only.
To a location with minimal traffic.
What is the purpose of packet crafting attacks?
To encrypt network traffic.
To use packets of traffic that carry attacks or malicious code.
To reduce the amount of traffic on the network.
To monitor normal traffic patterns.
Why is it important to protect the traffic that flows over your networks?
To increase the speed of the network.
To prevent eavesdroppers from gleaning information.
To reduce the amount of data sent.
To avoid overloading the network IDS.
What is a Virtual Private Network (VPN) often called?
A bridge
A tunnel
A gateway
A firewall
What is the primary purpose of using a VPN?
To increase internet speed
To send sensitive traffic over insecure networks
To reduce data usage
To block advertisements
What does a VPN client application use to authenticate to the VPN concentrator?
A password
A digital certificate
A VPN client application
A biometric scan
What can companies like StrongVPN help you with?
Increasing your internet speed
Protecting or anonymizing the traffic you're sending over untrusted connections
Reducing your internet bill
Blocking pop-up ads
What is the primary security risk of using public wireless networks?
Slow internet speed
Unauthorized access to your data
High data usage
Limited connectivity range
What is the approximate range of an unamplified 802.11 wireless connection?
100 miles
238 miles
50 miles
500 miles
What are unauthorized wireless access points commonly known as?
Rogue access points
Fake hotspots
Phishing points
Spy networks
What is a potential risk of setting up a rogue access point with poor security?
It can improve network security.
It can provide easy access to the network for unauthorized users.
It can enhance the speed of the network.
It can reduce the number of legitimate devices on the network.
What is a better solution to finding rogue equipment on a network?
Ignoring the issue.
Documenting legitimate devices and regularly scanning for additional devices.
Increasing the network speed.
Reducing the number of devices on the network.
Which tool is mentioned for scanning additional devices on a network?
Telnet
FTP
Kismet
POP
What is the chief method of protecting traffic on a network?
Increasing the number of devices.
Using encryption.
Reducing network speed.
Ignoring unauthorized devices.
Which Wi-Fi Protected Access (WPA) version is the current standard?
WPA
WPA2
WPA3
WEP
What is one of the simplest ways to protect your data on a network?
Using insecure protocols.
Using secure protocols.
Increasing the number of devices.
Reducing network speed.
Which protocol is mentioned as a secure alternative to Telnet?
FTP
POP
SSH
WEP
What is the secure equivalent of FTP mentioned in the text?
Telnet
SFTP
POP
WEP
What is one of the primary uses of network security tools?
To improve network speed
To locate security holes in networks
To increase network bandwidth
To reduce network latency
Which operating system is mentioned as commonly running many network security tools?
Windows
macOS
Linux
Android
What is the name of the well-known distribution that comes with preconfigured security tools?
Ubuntu
Fedora
Kali
CentOS
What is the key to assessing vulnerabilities according to the text?
Using the latest hardware
Conducting thorough and regular assessments
Installing the newest software
Increasing network bandwidth
What are zero-day attacks?
Attacks that occur on the first day of the month
Attacks that exploit known vulnerabilities
Attacks that exploit unknown vulnerabilities
Attacks that happen only on weekends
What is Kismet used for?
Detecting wireless access points
Cracking WEP encryption
Scanning for malware
Increasing network speed
Which tools are mentioned for cracking WEP, WPA, and WPA2 encryption?
Kismet and Aircrack-NG
WPATty and Aircrack-NG
WPATty and Kismet
Aircrack-NG and Kali
What are the two main categories of scanners mentioned in the text?
Port scanners and vulnerability scanners
Hardware scanners and software scanners
Network scanners and system scanners
Security scanners and performance scanners
What is Nmap primarily considered as?
A vulnerability scanner
A packet sniffer
A port scanner
A network analyzer
What additional capabilities does Nmap have besides being a port scanner?
It can intercept network traffic
It can search for hosts on a network and identify operating systems
It can filter and sort network traffic
It can analyze wireless networks
What is a packet sniffer also known as?
A network mapper
A protocol analyzer
A vulnerability scanner
A network scanner
Which tool is described as a classic sniffer invented in the 1980s?
Wireshark
Nmap
Kismet
Tcpdump
What is the Windows version of Tcpdump called?
WinSniff
WinDump
WinCapture
WinAnalyzer
Which tool was previously known as Ethereal?
Tcpdump
Nmap
Wireshark
Kismet
Which tool is mentioned as being able to sniff from wireless networks?
Tcpdump
Nmap
Wireshark
Kismet
What is a disadvantage of well-equipped portable network analyzers like the OptiView Portable Network Analyzer?
They are difficult to use
They are not compatible with most networks
They are often expensive
They have limited capabilities
What is a honeypot in network security?
A system that detects, monitors, and sometimes tampers with the activities of an attacker.
A tool used to encrypt data for secure transmission.
A device that blocks unauthorized access to a network.
A software that scans for malware on a computer.
What is the purpose of configuring a honeypot to display fake vulnerabilities?
To attract attackers and monitor their activities.
To improve the performance of the network.
To provide secure access to authorized users.
To encrypt data for secure transmission.
What is a honeynet?
A network of honeypots with centralized monitoring.
A tool for encrypting network traffic.
A device that blocks unauthorized access to a network.
A software that scans for malware on a computer.
What is the primary use of honeynets?
Understanding malware activity on a large scale.
Encrypting data for secure transmission.
Blocking unauthorized access to a network.
Scanning for malware on a computer.
What is Scapy used for in network security?
Constructing specially crafted ICMP packets to map the topology of firewalls.
Encrypting data for secure transmission.
Blocking unauthorized access to a network.
Scanning for malware on a computer.
What can Scapy's abilities be scripted to do?
Manipulate network traffic and test how firewalls and IDS respond.
Encrypt data for secure transmission.
Block unauthorized access to a network.
Scan for malware on a computer.
For what might you use the tool Kismet?
To secure VPN connections
To scan for devices on a wireless network
To implement firewalls
To create network redundancies
What are the three main types of wireless encryption?
WEP, WPA, WPA2
SSL, TLS, SSH
AES, DES, RSA
HTTP, HTTPS, FTP
What tool might you use to scan for devices on a network?
Wireshark
Nmap
Scapy
Kismet
Which tools can you use to sniff traffic on a wireless network?
Wireshark and Tcpdump
VPN and SSL
Nmap and Scapy
IDS and IPS
Why would you use a honeypot?
To attract and study attackers and their tools
To encrypt network traffic
To create network redundancies
To implement firewalls
What would you use if you needed to send sensitive data over an untrusted network?
VPN
Firewall
Honeypot
Nmap
What would you use a DMZ to protect?
Internal network from external threats
Wireless network from interference
Data from being encrypted
Devices from being scanned
