Font size
WorksheetsLAN Security Concepts Cisco
Total questions: 22
Worksheet time: 8mins
Which attack encrypts the data on hosts in an attempt to extract a monetary payment from the victim?
Malware
RansomWare
DataBreach
DDoS
Which devices are specifically designed for network security? (Choose three)
VPN-Enabled Router
NGFW
WLC
Switch
NAC
Which device monitors SMTP traffic to block threats and encrypt outgoing messages to prevent data loss?
NAC
ESA
WSA
NGFW
Which device monitors HTTP traffic to block access to risky sites and encrypt outgoing messages?
WSA
NGFW
ESA
NAC
Which AAA component is responsible for collecting and reporting usage data for auditing and billing purposes?
Accounting
Authorization
Authentication
Which AAA component is responsible for controlling who is permitted to access the network?
Accounting
Authorization
Authentication
Which AAA component is responsible for determining what the user can access?
Authentication
Authorization
Accounting
In an 802.1X implementation, which device is responsible for relaying responses?
Authenticator
Router
Supplicant
Authentication Server
Client
Which of the following mitigation techniques are used to protect Layer 3 through Layer 7 of the OSI Model? (Choose three.)
VPN
DHCP Snooping
FireWalls
IPS Devices
IPSG
Which of the following mitigation techniques prevents many types of attacks including MAC address table overflow and DHCP starvation attacks?
DAI
IPSG
Port Security
DHCP snooping
Which of the following mitigation techniques prevents MAC and IP address spoofing?
Port Security
DAI
IPSG
DHCP snooping
Which of the following mitigation techniques prevents ARP spoofing and ARP poisoning attacks?
DAI
DHCP snooping
IPSG
Port Security
Which of the following mitigation techniques prevents DHCP starvation and DHCP spoofing attacks?
DAI
DHCP snooping
IPSG
Port Security
What is the behavior of a switch as a result of a successful MAC address table attack?
The Switch will shut down
The Switch interfaces will transition to error-disable state
The Switch will forward all received frames to all other ports within the VLAN
The switch will drop all received frames
What would be the primary reason a threat actor would launch a MAC address overflow attack?
So that the threat actor can see frames that are destinated to other devices
So that the threat actor can execute arbitrary code on the switch
So that the Switch stops forwarding traffic
So that legitimate hosts cannot obtain a MAC Address
What mitigation technique must be implemented to prevent MAC address overflow attacks?
DHCP snooping
Port Security
DAI
IPSG
A threat actor changes the MAC address of the threat actor's device to the MAC address of the default gateway. What type of attack is this?
Address spoofing
ARP spoofing
CDP reconnaissance
DHCP starvation
STP attack
A threat actor sends a BPDU message with priority 0. What type of attack is this?
Address spoofing
ARP spoofing
CDP reconnaissance
DHCP starvation
STP attack
A threat actor leases all the available IP addresses on a subnet. What type of attack is this?
Address spoofing
ARP spoofing
CDP reconnaissance
DHCP starvation
STP attack
A threat actor sends a message that causes all other devices to believe the MAC address of the threat actor's device is the default gateway. What type of attack is this?
Address spoofing
ARP spoofing
CDP reconnaissance
DHCP starvation
STP attack
A threat actor configures a host with the 802.1Q protocol and forms a trunk with the connected switch. What type of attack is this?
Address spoofing
VLAN hopping
CDP reconnaissance
DHCP starvation
STP attack
A threat actor discovers the IOS version and IP addresses of the local switch. What type of attack is this?
Address spoofing
VLAN hopping
CDP reconnaissance
DHCP starvation
STP attack
