Font size
WorksheetsCMU CS 376
Total questions: 92
Worksheet time: 55mins
The three concepts that form what is often referred to as the CIA triad are . These three concepts embody the fundamental security objectives for both data and for information and computing services
A. confidentiality, integrity and availability
B. communication, integrity and authentication
C.confidentiality, integrity, access control
D.communication, information and authenticity
A loss of is the unauthorized disclosure of information
A. authenticity
B. confidentiality
C. reliability
D. integrity
3. (0.200 Point)
Verifying that users are who they say they are and that each input arriving at the system came from a trusted source is .
A. authenticity
B. credibility
C. accountability
D. integrity
A is any action that compromises the security of information owned by an organization.
A. security attack
B. security service
C. security alert
D. security mechanism
is the protection of transmitted data from passive attacks
A. Access control
B. Data control
C. Nonrepudiation
D. Confidentiality
A(n) service is one that protects a system to ensure its availability and addresses the security concerns raised by denial-of-service attacks.
A. replay
B. availability
C. masquerade
D. integrity
A(n) is a potential for violation of security, which exists when there is a circumstance, capability, action, or event that could breach security and cause harm
A. threat
B. attack
A. risk
D. attack vector
The protection of the information that might be derived from the observation of traffic flows is .
A. connectionless confidentiality
B. connection confidentiality
C. traffic-flow confidentiality
D. selective-field confidentiality
Data appended to, or a cryptographic transformation of, a data unit that allows a recipient of the data unit to prove the source and integrity of the data unit and protect against forgery is a(n) .
A. security audit trail
B. digital signature
C. encipherment
D. authentication exchange
techniques map plaintext elements (characters, bits) into ciphertext elements.
A. Transposition
B. Substitution
C. Traditional
D. Symmetric
An original intelligible message fed into the algorithm as input is known as , while the coded message produced as output is called the .
A. decryption, encryption
B. plaintext, ciphertext
C. deciphering, enciphering
D. cipher, plaintext
Restoring the plaintext from the ciphertext is .
A. deciphering
B. transposition
C. steganography
D. encryption
A attack involves trying every possible key until an intelligible translation of the ciphertext is obtained.
A. brute-force
B. Caesar attack
C. ciphertext only
D. chosen plaintext
The takes the ciphertext and the secret key and produces the original plaintext. It is essentially the encryption algorithm run in reverse.
A. Voronoi algorithm
B. decryption algorithm
C. cryptanalysis
D. diagram algorithm
If both sender and receiver use the same key, the system is referred to as:
A. public-key encryption
B. two-key
C. asymmetric
D. conventional encryption
The attack is the easiest to defend against because the opponent has the least amount of information to work with.
A. ciphertext-only
B. chosen ciphertext
C. known plaintext
D. chosen plaintext
The methods of _________conceal the existence of the message in a graphic image.
A. steganography
B. decryptology
C. cryptology
D. cryptograph
A cipher is one that encrypts a digital data stream one bit or one byte at a time.
A. product
B. block
C. key
D. stream
The vast majority of network-based symmetric cryptographic applications make use of ciphers.
A. linear
B. block
C. permutation
D. stream
A cipher is one in which a block of plaintext is treated as a whole and used to produce a ciphertext block of equal length
A.bit
B.product
C.stream
D.block
is when each plaintext element or group of elements is uniquely replaced by a corresponding ciphertext element or group of elements.
A. Substitution
B. Diffusion
C. Streaming
D. Permutation
The criteria used in the design of the focused on the design of the S-boxes and on the P function that takes the output of the S-boxes
A. Avalanche Attack
B. Data Encryption Standard
C. Product Cipher
D. Substitution Key
The greater the number of rounds, the it is to perform cryptanalysis.
A. easier
B. less difficult
C. equally difficult
D.harder
The function F provides the element of in a Feistel cipher.
A. clarification
B. alignment
C. confusion
D. stability
Allowing for the maximum number of possible encryption mappings from the plaintext block is referred to by Feistel as the .
A. ideal substitution cipher
B. round function
C. ideal block cipher
D.diffusion cipher
Authentication applied to the entire original IP packet is .
A. security mode
B. cipher mode
C. tunnel mode
D. transport mode
Asymmetric encryption is also known as
A. public-key encryption
B. private-key encryption
C. optimal encryption
D. digital-key encryption
Public-key encryption is also known as ________
A. digital-key encryption
B.asymmetric encryption
C. one-way time exchange encryption
D. optimal-key encryption
Asymmetric encryption can be used for___________
A.both confidentiality and authentication
B. neither confidentiality nor authentication
C. confidentiality
D. authentication
The plaintext is recovered from the ciphertext using the paired key and a___________
A.digital signature
B. recovery encryption
C. decryption algorithm
D. encryption algorithm
The most widely used public-key cryptosystem is .
A. optimal asymmetric encryption
B. asymmetric encryption
C. RSA
D. DES
are two related keys, a public key and a private key that are used to perform complementary operations, such as encryption and decryption or signature generation and signature verification
A. Asymmetric keys
B. Key exchanges
C. Symmetric keys
D. Cipher keys
A is a cryptographic algorithm that uses two related keys, a public key, and a private key. The two keys have the property that deriving the private key from the public key is computationally infeasible.
A.Private Key (Symmetric) Cryptographic Algorithm
B. Key Exchange Cryptographic Algorithm
C. Public Key (Asymmetric) Cryptographic Algorithm
D. RSA Digital Cryptographic Algorithm
The key used in symmetric encryption is referred to as a key.
A. public
B. secret
C. private
D. decryption
The readable message or data that is fed into the algorithm as input is the___________
A. ciphertext
B. exchange
C. plaintext
D. encryption
Two issues to consider with the computation required to use RSA are encryption/decryption and .
A. time complexity
B. trap-door one-way functions
C. key generation
D. asymmetric encryption padding
depend on the running time of the decryption algorithm
A. Mathematical attacks
B. Timing attacks
C. Chosen ciphertext attacks
D. Brute-force attacks
Authentication applied to all of the packet except for the IP header is ___
A. tunnel mode
B. transport mode
C. association mode
D. security mode
Which technology is a primary method that IPsec uses to implement data integrity?
A.MD5
B.AES
C.RSA
D.DH
What are the source and destination addresses used for an encrypted IPsec packet?
A. Original sender and receiver IP addresses
B. Original sender’s and outbound VPN gateway’s addresses
C. Sending and receiving VPN gateways
D. Sending VPN gateway and original destination address in the packet
Which phase is used for private management traffic between the two VPN peers?
A. IPsec
B. IKE Phase 1
C. IKE Phase 2
A. IKE Phase 3
What method is used to allow two VPN peers to establish shared secret keys and to establish those keys over an untrusted network?
A. AES
B. SHA
C. RSA
D. DH
What are the two main methods for authenticating a peer as the last step of IKE Phase 1? (Choose all that apply).
RSA signatures, using digital certificates to exchange public keys
A. PSK (pre-shared key)
A. DH Group 2
TCP three-way handshake
A customer has asked for its wireless equipment to be managed as securely as possible. Which three management protocols will provide encrypted access to the equipment? (Choose three)
A. Secure Shell
B. HTTPS
C.. SNMPv3
D.Telnet
E. SNMPv2c
F.HTTP
A customer has completed the installation of an 802.11ac greenfield deployment at their corporate headquarters. They would like to leverage 802.11ac enhanced speeds on the trusted employee WLAN. In order to configure the employee WLAN, what Layer 2 security policies are valid?
A. WPA2 (TKIP)
B. WPA(AES)
C. OPEN
A. WEP
An engineer wants to set up guest wireless that requires users to log in via a splash page prior to accessing the network. Which authentication method should be configured?
A. LDAP
B. RADIUS
C. local authentication
A. WebAuth
A. PSK
An engineer would like to setup secure authentication for a wireless network that will utilize single sign-on. Which two authentication methods can be used to accomplish this? (Choose two.)
A. LDAP
B. RADIUS
C. Local authentication
A. WEP
A. PSK
While undergoing a security audit, a network administrator is told to set up the WLANs with at least 128-bit encryption but also keeping the 802.11n speeds. What WLAN configuration would meet the requirements?
A. Static WEP
B. WPA-TKIP
C. WPA2-AES
D. CKIP
What Cisco Catalyst switch feature can be used to define ports as trusted for DHCP server connections?
DHCP snooping
port security
802.1x
A. private VLANs
Which statement about named ACLs (Access Control Lists) is true?
They support standard and extended ACLs
They are used to filter usernames and passwords for Telnet and SSH
They are used to filter Layer 7 traffic.
They support standard ACLs only.
They are used to rate limit traffic destined to targeted networks
Which identification number is valid for an extended ACL?
1
64
100
299
1099
Refer to the exhibit. While you troubleshoot a connectivity issue to a PC behind R1, you enter the 12 show access-lists command to generate this output. Which reason for the problem is most likely
true?
The permit all ACL entry on R1 is inactive
The ACL of R1 is misconfigured.
A deny all ACL entry is currently active on R1
An implicit deny is causing R1 to block network traffic
When you are troubleshooting an ACL issue on a router, which command can help you to verify which interfaces are affected by the ACL?
A. show ip access-lists
A. show access-lists
show interface
show IP interface
list ip interface
A network administrator is configuring ACLs on a Cisco router, to allow traffic from hosts on networks 192.168.146.0, 192.168.147.0, 192.168.148.0, and 192.168.149.0 only. Which two
ACL statements, when combined, are the best for accomplishing this task? (Choose two.)
A.access-list 10 permit ip 192.168.146.0 0.0.1.255
B. access-list 10 permit ip 192.168.147.0 0.0.255.255
C. access-list 10 permit ip 192.168.148.0 0.0.1.255
D. access-list 10 permit ip 192.168.149.0 0.0.255.255
E . access-list 10 permit ip 192.168.146.0 0.0.0.255
F. access-list 10 permit ip 192.168.146.0 255.255.255.0
In which solution is a router ACL used?
filtering packets that are passing through a router
A. to change the default administrative distance of a route in the route table
protecting a server from unauthorized access
A. controlling path selection, based on the route metric
Which IPsec security protocol should be used when confidentiality is required?
MD5
PSK
AH
ESP
A network administrator needs to configure port security on a switch. Which two statements are true? (Choose two.)
The network administrator can apply port security to dynamic access ports.
The network administrator can apply port security to EtherChannels.
When dynamic MAC address learning is enabled on an interface, the switch can learn new addresses, up to the maximum defined.
The sticky learning feature allows the addition of dynamically learned addresses to the running configuration.
The network administrator can configure static secure or sticky secure MAC addresses in the voice VLAN
On which options are standard access lists based?
A. destination address and wildcard mask
destination address and subnet mask
source address and subnet mask
source address and wildcard mask
Which component of VPN technology ensures that data is unaltered between the sender and recipient?
A. encryption
A. authentication
A. key exchange
A. data integrity
How does using the service password-encryption command on a router provide additional security?
by encrypting all passwords passing through the router
by encrypting passwords in the plain text configuration file
by requiring entry of encrypted passwords for access to the device
by configuring an MD5 encrypted key to be used by routing protocols to validate routing exchanges
by automatically suggesting encrypted passwords for use in configuring the router
When are packets processed by an inbound access list?
before they are routed to an outbound interface
after they are routed to an outbound interface
before and after they are routed to an outbound interface
after they are routed to an outbound interface but before being placed in the outbound queue
The company internetwork is subnetted using 29 bits. Which wildcard mask should be used to configure an extended access list to permit or deny access to an entiresubnetwork?
255.255.255.224
255.255.255.248
0.0.0.224
0.0.0.8
0.0.0.3
0.0.0.7
What are three valid reasons to assign ports to VLANs on a switch? (Choose three.)
A. to make VTP easier to implement
A. to isolate broadcast traffic
A. to increase the size of the collision domain
B. to allow more devices to connect to the network
to logically group hosts according to function
to increase network security
Which protocol should be used to establish a secure terminal connection to a remote network
ARP
SSH
TELNET
WEP
SNMPv1
SNMPv2
What three pieces of information can be used in an extended access list to filter traffic? (Choose three.)
A. protocol
B. VLAN number
C. TCP or UDP port numbers
D. source switch port number
E. source IP address and destination IP address
Which command is necessary to permit SSH or Telnet access to a Cisco switch that is otherwise configured for these vty line protocols?
A. transport output all
B. transport preferred all
C. transport type all
D. transport input all
What features can protect the data plane? (Choose three.)
A. policing
B. ACLs
C. IPS
D. antispoofing
F. DHCP-snooping
Which of the following statements is true regarding a stateless packetfiltering firewall? (Select the best answer.)
A. It can operate at Layer 4 of the OSI model.
B. It is more secure than a stateful packetfiltering firewall.
C. It tracks packets as a part of a stream.
D. It is not susceptible to IP spoofing attacks
Which of the following statements is true of all firewalls? (Select the best answer.)
A. They maintain a state table
B. They hide the source of network connections.
C. They operate at Layer 7 of the OSI model.
D. They are multihomed devices.
Which feature can validate address requests and filter out invalid messages?
A. IP Source Guard
B. port security
C. DHCP snooping
D. dynamic ARP inspection
Select the action that results from executing these commands.
A. A dynamically learned MAC address is saved in the startup-configuration file.
B. A dynamically learned MAC address is saved in the running-configuration file.
C. A dynamically learned MAC address is saved in the VLAN database.
D. Statically configured MAC addresses are saved in the startup-configuration file if frames from that address are received.
E. Statically configured MAC addresses are saved in the running-configuration file if frames from that address are received.
A network administrator needs to configure port security on a switch. Which two statements are true? (Choose two)
A. The network administrator can apply port security to dynamic access ports.
B. The network administrator can apply port security to EtherChannels.
C. When dynamic MAC address learning is enabled on an interface, the switch can learn new addresses, up to the maximum defined.
D. The sticky learning feature allows the addition of dynamically learned addresses to the running 17 configuration.
E. The network administrator can configure static secure or sticky secure MAC addresses in the voice VLAN.
What are three reasons that an organization with multiple branch offices and roaming users might implement a Cisco VPN solution instead of point-to-point WAN links? (Choose three.)
A. reduced cost
B. better throughput
C. broadband incompatibility
D. increased security
E. scalability
Which feature can you use to monitor traffic on a switch by replicating it to another port or ports on the same switch?
A. copy run start
B. traceroute
C. the ICMP Echo IP SLA
D. SPAN
Which keywords can be substituted for access list wildcards while configuring access lists? (Choose two.)
A. all
B. any
C. host
D. range
E. subnet
Which IEEE mechanism is responsible for the authentication of devices when they attempt to connect to a local network?
A. 802.1x
B. 802.11
C. 802.2x
D. 802.3x
Where does a switch maintain DHCP snooping information ?
A. in the MAC address table
B. in the CAM table
C. in the DHCP binding database
D. in the VLAN database
Which command can you enter in a network switch configuration so that learned mac addresses are saved in configuration as they connect?
A. Switch(confg-if)#Switch port-security
B. Switch(confg-if)#Switch port-security Mac-address sticky
C. Switch(confg-if)#Switch port-security maximum 10
D. Switch(confg-if)#Switch mode access
Which one of the following follows best practices for a secure password?
A. ABC123!
B. SlE3peR1#
C. tough-passfraze
D. InterEstIng-PaSsWoRd
(a) encryption is a form of cryptosystem in which encryption and decryption are performed using the same key
The two types of attack on an encryption algorithm are cryptanalysis based on properties of the encryption algorithm, and _______-_______which involves trying all possible keys.
(a)
One of the simplest and besr-known polyalphabetic ciphers is (a) cipher. In this scheme, the set of related monoalphabetic substitution rules consists of the 26 Caesar ciphers with shifts of 0 through 25. Each cipher is denoted by a key letter which is the ciphertext letter that substitutes for the plaintext letter a.
A ___________cipher processes the input one block of elements at a time producing an output block for each input block whereas a ____________cipher processes the input elements continuously producing output one element at a time.
(a)
The earliest known and simplest use of a substitution cipher was called the (a) cipher and involved replacing each letter of the alphabet with the letter standing three places further down the alphabet.
The best known multiple letter encryption cipher is the (a) which treats diagrams in the plaintext as single units and translates these units into ciphertext diagrams.
A (a) is an encryption/decryption scheme in which a block of plaintext is treated as a whole and used to produce a ciphertext block of equal length
The most widely used encryption scheme is based on the (a) adopted in 1977 by the National Bureau of Standards as Federal Information Processing Standard 46.
(a) encryption is a form of cryptosystem in which encryption and decryption are performed using a public key and a private key.
Asymmetric encryption transforms plaintext into (a) using one of two keys and an encryption algorithm.
The difficulty of attacking (a) is based on the difficulty of finding the prime factors of a composite number.
Public-key cryptography is asymmetric, involving the use of two separate keys, in contrast to (a) encryption, which uses only one key.
"The sender ‘signs’ a message with its private key. Signing is achieved by a cryptographic algorithm applied to the message or to a small block of data that is a function of the message," is a description of a (a) .
