wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

н2сб 3/5

Total questions: 30

Worksheet time: 13mins

Name
Class
Date
1.

If AAA is already enabled, which three CLI steps are required to configure a router with a specific view? (Choose three.)

a)

Create a view using the parser viewcommand

b)

Assign a secret password to the view

c)

Assign commands to the view

d)

Assign users who can use the view

e)

Create a superview using the parser view view-name command

2.

Refer to the exhibit. A network administrator configures a named ACL on the router. Why is there no output displayed when the show command is issued?

a)

The ACL is not activated

b)

The ACL name is case sensitive

c)

The ACL has not been applied to an interface

d)

No packets have matched the ACL statements yet

3.

ACLs are used primarily to filter traffic. What are two additional uses of ACLs? (Choose two.):

a)
  • specifying internal hosts for NAT

b)
  • identifying traffic for QoS

c)
  • specifying source addresses for authentication

d)
  • reorganizing traffic into VLANs

e)
  • filtering VTP packets

4.

What two features are added in SNMPv3 to address the weaknesses of previous versions of SNMP? (Choose two.)

a)
  • authentication

b)
  • authorization with community string priority

c)
  • bulk MIB objects retrieval

d)
  • ACL management filtering

e)
  • encryption

5.

What network testing tool is used for password auditing and recovery?

a)
  • Nessus

b)
  • Metasploit

c)
  • L0phtcrack

d)
  • SuperScan

6.

Which type of firewall makes use of a server to connect to destination devices on behalf of clients?

a)
  • packet filtering firewall

b)
  • proxy firewall

c)
  • stateless firewall

d)
  • stateful firewall

7.

Refer to the exhibit. What will be displayed in the output of the show running-config object command after the exhibited configuration commands are entered on an ASA 5506-X?

a)
  • host 192.168.1.4

b)
  • range 192.168.1.10 192.168.1.20

c)
  • host 192.168.1.4 and range 192.168.1.10 192.168.1.20

d)
  • host 192.168.1.3, host 192.168.1.4, and range 192.168.1.10 192.168.1.20

e)
  • host 192.168.1.3 and host 192.168.1.4

8.

Refer to the exhibit. According to the command output, which three statements are true about the DHCP options entered on the ASA? (Choose three.)

a)
  • The dhcpd address [ start-of-pool ]-[ end-of-pool ] inside command was issued to enable the DHCP server.

b)
  • The dhcpd address [ start-of-pool ]-[ end-of-pool ] inside command was issued to enable the DHCP client.

c)

The dhcpd enable inside command was issued to enable the DHCP server

d)

The dhcpd auto-config outside command was issued to enable the DHCP client

e)
  • The dhcpd auto-config outside command was issued to enable the DHCP server

9.

Which two statements describe the characteristics of symmetric algorithms? (Choose two.)

a)
  • They are commonly used with VPN traffic.

b)
  • They use a pair of a public key and a private key.

c)
  • They are commonly implemented in the SSL and SSH protocols.

d)
  • They provide confidentiality, integrity, and availability.

e)
  • They are referred to as a pre-shared key or secret key.

10.

A web server administrator is configuring access settings to require users to authenticate first before accessing certain web pages. Which requirement of information security is addressed through the configuration?

a)
  • availability

b)
  • integrity

c)
  • scalability

d)
  • confidentiality

11.

The use of 3DES within the IPsec framework is an example of which of the five IPsec building blocks?

a)
  • authentication

b)
  • nonrepudiation

c)
  • integrity

d)
  • Diffie-Hellman

e)
  • confidentiality

12.

What function is provided by Snort as part of the Security Onion?

a)
  • to generate network intrusion alerts by the use of rules and signatures

b)
  • to normalize logs from various NSM data logs so they can be represented, stored, and accessed through a common schema

c)
  • to display full-packet captures for analysis

d)
  • to view pcap transcripts generated by intrusion detection tools

13.

What are two drawbacks to using HIPS? (Choose two.)

a)

With HIPS, the success or failure of an attack cannot be readily determined

b)

With HIPS, the network administrator must verify support for all the different operating systems used in the network

c)

HIPS has difficulty constructing an accurate network picture or coordinating events that occur across the entire network

d)

If the network traffic stream is encrypted, HIPS is unable to access unencrypted forms of the traffic

e)

HIPS installations are vulnerable to fragmentation attacks or variable TTL attacks

14.

In an AAA-enabled network, a user issues the configure terminal command from the privileged executive mode of operation. What AAA function is at work if this command is rejected?

a)
  • authorization

b)
  • authentication

c)
  • auditing

d)
  • accounting

15.

A company has a file server that shares a folder named Public. The network security policy specifies that the Public folder is assigned Read-Only rights to anyone who can log into the server while the Edit rights are assigned only to the network admin group. Which component is addressed in the AAA network service framework?

a)
  • automation

b)
  • accounting

c)
  • authentication

d)
  • authorization

16.

What is a characteristic of a DMZ zone?

a)

Traffic originating from the inside network going to the DMZ network is not permitted

b)

Traffic originating from the outside network going to the DMZ network is selectively permitted

c)

Traffic originating from the DMZ network going to the inside network is permitted

d)

Traffic originating from the inside network going to the DMZ network is selectively permitted

17.

Which measure can a security analyst take to perform effective security monitoring against network traffic encrypted by SSL technology?

a)

Use a Syslog server to capture network traffic

b)

Deploy a Cisco SSL Appliance

c)

Require remote access connections through IPsec VPN

d)

Deploy a Cisco ASA

18.

Refer to the exhibit. Port security has been configured on the Fa 0/12 interface of switch S1. What action will occur when PC1 is attached to switch S1 with the applied configuration?

a)
  • Frames from PC1 will be forwarded since the switchport port-security violation command is missing.

b)
  • Frames from PC1 will be forwarded to its destination, and a log entry will be created.

c)
  • Frames from PC1 will be forwarded to its destination, but a log entry will not be created.

d)
  • Frames from PC1 will cause the interface to shut down immediately, and a log entry will be made.

e)
  • Frames from PC1 will be dropped, and there will be no log of the violation.

19.

What security countermeasure is effective for preventing CAM table overflow attacks?

a)
  • DHCP snooping

b)
  • Dynamic ARP Inspection

c)
  • IP source guard

d)
  • port security

20.

What are two examples of DoS attacks? (Choose two.)

a)
  • port scanning

b)
  • SQL injection

c)
  • ping of death

d)
  • phishing

e)
  • buffer overflow

21.

Which method is used to identify interesting traffic needed to create an IKE phase 1 tunnel?

a)
  • transform sets

b)
  • a permit access list entry

c)
  • hashing algorithms

d)
  • a security association

22.

When the CLI is used to configure an ISR for a site-to-site VPN connection, which two items must be specified to enable a crypto map policy? (Choose two.)

a)
  • the hash

b)
  • the peer

c)
  • encryption

d)
  • the ISAKMP policy

e)
  • a valid access list

23.

How does a firewall handle traffic when it is originating from the public network and traveling to the DMZ network?

a)

Traffic that is originating from the public network is inspected and selectively permitted when traveling to the DMZ network

b)

Traffic that is originating from the public network is usually permitted with little or no restriction when traveling to the DMZ network

c)

Traffic that is originating from the public network is usually forwarded without inspection when traveling to the DMZ network

d)

Traffic that is originating from the public network is usually blocked when traveling to the DMZ network

24.

A client connects to a Web server. Which component of this HTTP connection is not examined by a stateful firewall?

a)
  • the source IP address of the client traffic

b)
  • the destination port number of the client traffic

c)
  • the actual contents of the HTTP connection

d)
  • the source port number of the client traffic

25.

Which network monitoring technology uses VLANs to monitor traffic on remote switches?

a)
  • IPS

b)
  • IDS

c)
  • TAP

d)
  • RSPAN

26.

Which rule action will cause Snort IPS to block and log a packet?

a)
  • log

b)
  • drop

c)
  • alert

d)
  • Sdrop

27.

What is typically used to create a security trap in the data center facility?

a)
  • IDs, biometrics, and two access doors

b)
  • high resolution monitors

c)
  • redundant authentication servers

d)
  • a server without all security patches applied

28.

A company is concerned with leaked and stolen corporate data on hard copies. Which data loss mitigation technique could help with this situation?

a)
  • strong PC security settings

b)
  • strong passwords

c)
  • shredding

d)
  • encryption

29.

Upon completion of a network security course, a student decides to pursue a career in cryptanalysis. What job would the student be doing as a cryptanalyst?

a)
  • cracking code without access to the shared secret key

b)
  • creating hashing codes to authenticate data

c)
  • making and breaking secret codes

d)
  • creating transposition and substitution ciphers

30.

What command is used on a switch to set the port access entity type so the interface acts only as an authenticator and will not respond to any messages meant for a supplicant?

a)
  • dot1x pae authenticator

b)
  • authentication port-control auto

c)
  • aaa authentication dot1x default group radius

d)
  • dot1x system-auth-control