Font size
Worksheetsн2сб 3/5
Total questions: 30
Worksheet time: 13mins
If AAA is already enabled, which three CLI steps are required to configure a router with a specific view? (Choose three.)
Create a view using the parser viewcommand
Assign a secret password to the view
Assign commands to the view
Assign users who can use the view
Create a superview using the parser view view-name command
Refer to the exhibit. A network administrator configures a named ACL on the router. Why is there no output displayed when the show command is issued?
The ACL is not activated
The ACL name is case sensitive
The ACL has not been applied to an interface
No packets have matched the ACL statements yet
ACLs are used primarily to filter traffic. What are two additional uses of ACLs? (Choose two.):
specifying internal hosts for NAT
identifying traffic for QoS
specifying source addresses for authentication
reorganizing traffic into VLANs
filtering VTP packets
What two features are added in SNMPv3 to address the weaknesses of previous versions of SNMP? (Choose two.)
authentication
authorization with community string priority
bulk MIB objects retrieval
ACL management filtering
encryption
What network testing tool is used for password auditing and recovery?
Nessus
Metasploit
L0phtcrack
SuperScan
Which type of firewall makes use of a server to connect to destination devices on behalf of clients?
packet filtering firewall
proxy firewall
stateless firewall
stateful firewall
Refer to the exhibit. What will be displayed in the output of the show running-config object command after the exhibited configuration commands are entered on an ASA 5506-X?
host 192.168.1.4
range 192.168.1.10 192.168.1.20
host 192.168.1.4 and range 192.168.1.10 192.168.1.20
host 192.168.1.3, host 192.168.1.4, and range 192.168.1.10 192.168.1.20
host 192.168.1.3 and host 192.168.1.4
Refer to the exhibit. According to the command output, which three statements are true about the DHCP options entered on the ASA? (Choose three.)
The dhcpd address [ start-of-pool ]-[ end-of-pool ] inside command was issued to enable the DHCP server.
The dhcpd address [ start-of-pool ]-[ end-of-pool ] inside command was issued to enable the DHCP client.
The dhcpd enable inside command was issued to enable the DHCP server
The dhcpd auto-config outside command was issued to enable the DHCP client
The dhcpd auto-config outside command was issued to enable the DHCP server
Which two statements describe the characteristics of symmetric algorithms? (Choose two.)
They are commonly used with VPN traffic.
They use a pair of a public key and a private key.
They are commonly implemented in the SSL and SSH protocols.
They provide confidentiality, integrity, and availability.
They are referred to as a pre-shared key or secret key.
A web server administrator is configuring access settings to require users to authenticate first before accessing certain web pages. Which requirement of information security is addressed through the configuration?
availability
integrity
scalability
confidentiality
The use of 3DES within the IPsec framework is an example of which of the five IPsec building blocks?
authentication
nonrepudiation
integrity
Diffie-Hellman
confidentiality
What function is provided by Snort as part of the Security Onion?
to generate network intrusion alerts by the use of rules and signatures
to normalize logs from various NSM data logs so they can be represented, stored, and accessed through a common schema
to display full-packet captures for analysis
to view pcap transcripts generated by intrusion detection tools
What are two drawbacks to using HIPS? (Choose two.)
With HIPS, the success or failure of an attack cannot be readily determined
With HIPS, the network administrator must verify support for all the different operating systems used in the network
HIPS has difficulty constructing an accurate network picture or coordinating events that occur across the entire network
If the network traffic stream is encrypted, HIPS is unable to access unencrypted forms of the traffic
HIPS installations are vulnerable to fragmentation attacks or variable TTL attacks
In an AAA-enabled network, a user issues the configure terminal command from the privileged executive mode of operation. What AAA function is at work if this command is rejected?
authorization
authentication
auditing
accounting
A company has a file server that shares a folder named Public. The network security policy specifies that the Public folder is assigned Read-Only rights to anyone who can log into the server while the Edit rights are assigned only to the network admin group. Which component is addressed in the AAA network service framework?
automation
accounting
authentication
authorization
What is a characteristic of a DMZ zone?
Traffic originating from the inside network going to the DMZ network is not permitted
Traffic originating from the outside network going to the DMZ network is selectively permitted
Traffic originating from the DMZ network going to the inside network is permitted
Traffic originating from the inside network going to the DMZ network is selectively permitted
Which measure can a security analyst take to perform effective security monitoring against network traffic encrypted by SSL technology?
Use a Syslog server to capture network traffic
Deploy a Cisco SSL Appliance
Require remote access connections through IPsec VPN
Deploy a Cisco ASA
Refer to the exhibit. Port security has been configured on the Fa 0/12 interface of switch S1. What action will occur when PC1 is attached to switch S1 with the applied configuration?
Frames from PC1 will be forwarded since the switchport port-security violation command is missing.
Frames from PC1 will be forwarded to its destination, and a log entry will be created.
Frames from PC1 will be forwarded to its destination, but a log entry will not be created.
Frames from PC1 will cause the interface to shut down immediately, and a log entry will be made.
Frames from PC1 will be dropped, and there will be no log of the violation.
What security countermeasure is effective for preventing CAM table overflow attacks?
DHCP snooping
Dynamic ARP Inspection
IP source guard
port security
What are two examples of DoS attacks? (Choose two.)
port scanning
SQL injection
ping of death
phishing
buffer overflow
Which method is used to identify interesting traffic needed to create an IKE phase 1 tunnel?
transform sets
a permit access list entry
hashing algorithms
a security association
When the CLI is used to configure an ISR for a site-to-site VPN connection, which two items must be specified to enable a crypto map policy? (Choose two.)
the hash
the peer
encryption
the ISAKMP policy
a valid access list
How does a firewall handle traffic when it is originating from the public network and traveling to the DMZ network?
Traffic that is originating from the public network is inspected and selectively permitted when traveling to the DMZ network
Traffic that is originating from the public network is usually permitted with little or no restriction when traveling to the DMZ network
Traffic that is originating from the public network is usually forwarded without inspection when traveling to the DMZ network
Traffic that is originating from the public network is usually blocked when traveling to the DMZ network
A client connects to a Web server. Which component of this HTTP connection is not examined by a stateful firewall?
the source IP address of the client traffic
the destination port number of the client traffic
the actual contents of the HTTP connection
the source port number of the client traffic
Which network monitoring technology uses VLANs to monitor traffic on remote switches?
IPS
IDS
TAP
RSPAN
Which rule action will cause Snort IPS to block and log a packet?
log
drop
alert
Sdrop
What is typically used to create a security trap in the data center facility?
IDs, biometrics, and two access doors
high resolution monitors
redundant authentication servers
a server without all security patches applied
A company is concerned with leaked and stolen corporate data on hard copies. Which data loss mitigation technique could help with this situation?
strong PC security settings
strong passwords
shredding
encryption
Upon completion of a network security course, a student decides to pursue a career in cryptanalysis. What job would the student be doing as a cryptanalyst?
cracking code without access to the shared secret key
creating hashing codes to authenticate data
making and breaking secret codes
creating transposition and substitution ciphers
What command is used on a switch to set the port access entity type so the interface acts only as an authenticator and will not respond to any messages meant for a supplicant?
dot1x pae authenticator
authentication port-control auto
aaa authentication dot1x default group radius
dot1x system-auth-control
