WorksheetsNetwork Security Baselines
Total questions: 14
Worksheet time: 12mins
Which of the following is a primary reason for establishing network security baselines in an organization?
To prevent zero-day attacks by using predefined signatures
To define a minimum standard of security configurations across devices
To enable seamless network integration with third-party vendors
To ensure all network components use identical encryption methods
How does the Security Content Automation Protocol (SCAP) contribute to network security baseline compliance?
By detecting and removing malware from network endpoints
By enabling automated monitoring and comparison against defined baselines
By providing real-time analysis of network traffic patterns
By enforcing access control policies based on user roles
Which network configuration change can reduce the likelihood of unauthorized access to router management interfaces?
Enabling SNMPv1 for remote monitoring
Using HTTPS and disabling HTTP on management interfaces
Configuring default SNMP community strings
Disabling SSH access to the router
What is the purpose of using a secure baseline configuration for all organizational assets?
To establish consistent security controls and mitigate common vulnerabilities
To increase network traffic speed and prevent latency
To reduce encryption overhead on network resources
To enable quick data recovery in case of a breach
Which protocol should be avoided when configuring secure remote access to network devices, due to its lack of encryption?
HTTPS
SNMPv3
Telnet
SSH
What key information does a heat map provide to network administrators in the context of wireless network management?
List of connected device
Signal strength, interference levels, and channel usage
IP address allocation across wireless access points
Data transfer rates per access point
Which wireless security standard is no longer considered secure and is not recommended for use?
WPA2
WPA3
WEP
WPA2-Personal
How does WPA3 improve upon WPA2 in terms of preventing offline password attacks?
By using a single shared password for all connected devices
By replacing PSK authentication with Simultaneous Authentication of Equals (SAE)
By requiring complex passphrases for network connections
By implementing RADIUS authentication by default
Network Access Control (NAC) can enforce compliance by using which of the following approaches?
Agent-based and agentless monitoring of device status and compliance
Dynamic IP routing to isolate non-compliant devices
Encryption enforcement on all client devices
Static routing based on user credentials
In a network environment, what key function does a RADIUS server provide?
Packet filtering and forwarding
Authentication, Authorization, and Accounting for network access
IP address assignment for connected clients
Intrusion prevention through signature-based detection
What advantage does Network Access Control (NAC) provide through dynamic VLAN assignment?
Efficient bandwidth allocation across network segments
Restricts device connectivity based on compliance and user roles
Directs all external traffic to a secure VLAN
Provides load balancing for network traffic
In WPA3, which feature ensures that traffic is encrypted even on open networks?
SAE (Simultaneous Authentication of Equals)
Enhanced Open
RADIUS authentication
WPA2 compatibility mode
Which tool is specifically used for assessing compliance with CIS Benchmarks?
CIS-CAT Pro
Wireshark
OpenVAS
Nessus
What does Simultaneous Authentication of Equals (SAE) in WPA3-Personal mode mitigate that WPA2-PSK is vulnerable to?
Offline dictionary and brute force attacks
Man-in-the-middle attacks on encrypted data
Unauthorized device connections via SSID spoofing
Cross-site scripting attacks on network credentials
