Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 5-7

Total questions: 38

Worksheet time: 19mins

Name
Class
Date
1.

What must be done before any role-based CLI views can be created?

a)

Assign multiple privilege levels.

b)

Configure usernames and passwords.

c)

Issue the aaa new-model command.

d)

Create the secret password for the root user.

2.

Which three statements describe limitations in using privilege levels for assigning command authorization? (Choose three.)

a)

The root user must be assigned to each privilege level that is defined.

b)

Commands set on a higher privilege level are not available for lower privilege users.

c)

Creating a user account that needs access to most but not all commands can be a tedious process.

d)

There is no access control to specific interfaces on a router.

e)

It is required that all 16 privilege levels be defined, whether they are used or not.

3.

Which two router commands can a user issue when granted privilege level 0? (Choose two.)

a)

ping

b)

disable

c)

help

d)

configure

e)

show

4.

What does level 5 in the following enable secret global configuration mode command indicate? Router(config)# enable secret level 5 csc5io

a)

The enable secret password can only be set by individuals with privileges for EXEC level 5.

b)

The enable secret password is hashed using SHA.

c)

The enable secret password is hashed using MD5.

d)

The enable secret password grants access to privileged EXEC level 5.

5.

What are three network enhancements achieved by implementing the Cisco IOS software role-based CLI access feature? (Choose three.)

a)

operational efficiency

b)

fault tolerance

c)

cost reduction

d)

security

e)

availability

6.

A network administrator wants to create a new view so that a user only has access to certain configuration commands. In role-based CLI, which view should the administrator use to create the new view?

a)

superview

b)

admin view

c)

CLI view

d)

root view

7.

A network administrator enters the command R1# enable view adminview. What is the purpose of this command?

a)

to enter a superview named adminview

b)

to enter a CLI view named adminview

c)

to create a CLI view named adminview

d)

to enter the root view

8.

Which range of custom privilege levels can be configured on Cisco routers?

a)

0 through 15

b)

2 through 14

c)

1 through 15

d)

2 through 15

e)

1 through 16

9.

Which command will move the show interface command to privilege level 10?

a)

router(config)# show interface level 10

b)

router(config)# privilege exec level 10 show interface

c)

router(config-if)# privilege exec level 10 show interface

d)

router(config-if)# show interface level 10

e)

router(config)# privilege level 10 show interface

10.

What is the default privilege level of user accounts created on Cisco routers?

a)

0

b)

15

c)

1

d)

16

11.

An administrator assigned a level of router access to the user ADMIN using the commands below. Router(config)# privilege exec level 14 show ip route Router(config)# enable algorithm-type scrypt secret level 14 cisco-level-10 Router(config)# username ADMIN privilege 14 algorithm-type scrypt secret cisco-level-10 Which two actions are permitted to the user ADMIN? (Choose two.)

a)

The user can issue the show version command.

b)

The user can only execute the subcommands under the show ip route command.

c)

The user can issue the ip route command.

d)

The user can issue all commands because this privilege level can execute all Cisco IOS commands.

e)

The user can execute all subcommands under the show ip interfaces command.

12.

What service or protocol does the Secure Copy Protocol rely on to ensure that secure copy transfers are from authorized users?

a)

AAA

b)

RADIUS

c)

IPsec

d)

SNMP

13.

When password recovery on a router is being performed and the settings in NVRAM have been bypassed, which step should be taken next?

a)

Copy the contents of RAM to the NVRAM.

b)

Copy the contents of NVRAM to the RAM.

c)

Reload the router.

d)

Reset the router.

14.

Which protocol or service is used to automatically synchronize the software clocks on Cisco routers?

a)

DHCP

b)

NTP

c)

DNS

d)

SNMP

15.

A network engineer wants to synchronize the time of a router with an NTP server at the IPv4 address 209.165.200.225. The exit interface of the router is configured with an IPv4 address of 192.168.212.11. Which global configuration command should be used to configure the NTP server as the time source for this router?

a)

ntp peer 192.168.212.11

b)

ntp peer 209.165.200.225

c)

ntp server 209.165.200.225

d)

ntp server 192.168.212.11

16.

What are three functions provided by the syslog service? (Choose three.)

a)

to select the type of logging information that is captured

b)

to specify the destinations of captured messages

c)

to gather logging information for monitoring and troubleshooting

d)

to periodically poll agents for data

e)

to provide statistics on packets that are flowing through a Cisco device

17.

Which service should be disabled on a router to prevent a malicious host from falsely responding to ARP requests with the intent to redirect the Ethernet frames?

a)

LLDP

b)

reverse ARP

c)

CDP

d)

proxy ARP

18.

What is the purpose of issuing the ip ospf message-digest-key key md5 password command and the area area-id authentication message-digest command on a router?

a)

to enable OSPF MD5 authentication on a per-interface basis

b)

to configure OSPF MD5 authentication globally on the router

c)

to encrypt OSPF routing updates

d)

to facilitate the establishment of neighbor adjacencies

19.

Which service is enabled on a Cisco router by default that can reveal significant information about the router and potentially make it more vulnerable to attack?

a)

FTP

b)

LLDP

c)

CDP

d)

HTTP

20.

Which statement describes SNMP operation?

a)

An SNMP agent that resides on a managed device collects information about the device and stores that information remotely in the MIB that is located on the NMS.

b)

A get request is used by the SNMP agent to query the device for data.

c)

An NMS periodically polls the SNMP agents that are residing on managed devices by using traps to query the devices for data.

d)

A set request is used by the NMS to change configuration variables in the agent device.

21.

When SNMPv1 or SNMPv2 is being used, which feature provides secure access to MIB objects?

a)

message integrity

b)

packet encryption

c)

source validation

d)

community strings

22.

What are two reasons to enable OSPF routing protocol authentication on a network? (Choose two.)

a)

to prevent data traffic from being redirected and then discarded

b)

to ensure faster network convergence

c)

to provide data security through encryption

d)

to prevent redirection of data traffic to an insecure link

e)

to ensure more efficient routing

23.

What are SNMP trap messages?

a)

unsolicited messages that are sent by the SNMP agent and alert the NMS to a condition on the network

b)

messages that are used by the NMS to change configuration variables in the agent device

c)

messages that are used by the NMS to query the device for data

d)

messages that are sent periodically by the NMS to the SNMP agents that reside on managed devices to query the device for data

24.

Which technology allows syslog messages to be filtered to different devices based on event importance?

a)

syslog severity levels

b)

syslog service timestamps

c)

syslog service identifiers

d)

syslog facilities

25.

What is a characteristic of the Cisco IOS Resilient Configuration feature?

a)

It maintains a secure working copy of the bootstrap startup program.

b)

Once issued, the secure boot-config command automatically upgrades the configuration archive to a newer version after new configuration commands have been entered.

c)

The secure boot-image command works properly when the system is configured to run an image from a TFTP server.

d)

A snapshot of the router running configuration can be taken and securely archived in persistent storage.

26.

What is a feature of the TACACS+ protocol?

a)

It combines authentication and authorization as one process.

b)

It encrypts the entire body of the packet for more secure communications.

c)

It hides passwords during transmission using PAP and sends the rest of the packet in plaintext.

d)

It utilizes UDP to provide more efficient packet transfer.

27.

Which two protocols are used to provide server-based AAA authentication? (Choose two.)

a)

SSH

b)

SNMP

c)

TACACS+

d)

802.1x

e)

RADIUS

28.

Which functionality does the TACACS single-connection keyword provide to AAA services?

a)

allows the use of differing keys between the TACACS+ server and the AAA client

b)

enhances the performance of the TCP connection

c)

maintains a single UDP connection for the life of the session

d)

encrypts the data transfer between the TACACS+ server and the AAA client

29.

What are three access control security services? (Choose three.)

a)

authorization

b)

accounting

c)

access

d)

authentication

e)

repudiation

30.

What is the purpose of the network security accounting function?

a)

to keep track of the actions of a user

b)

to provide challenge and response questions

c)

to require users to prove who they are

d)

to determine which resources a user can access

31.

What does the TACACS+ protocol provide in a AAA deployment?

a)

AAA connectivity via UDP

b)

authorization on a per-user or per-group basis

c)

password encryption without encrypting the packet

d)

compatibility with previous TACACS protocols

32.

Which term describes the ability of a web server to keep a log of the users who access the server, as well as the length of time they use it?

a)

accounting

b)

authentication

c)

assigning permissions

d)

authorization

33.

What is the first required task when configuring server-based AAA authentication?

a)

Configure the IP address of the server.

b)

Specify the type of server providing the authentication.

c)

Configure the type of AAA authentication.

d)

Enable AAA globally.

34.

What is a characteristic of AAA accounting?

a)

Accounting can only be enabled for network connections.

b)

Users are not required to be authenticated before AAA accounting logs their activities on the network.

c)

Accounting is concerned with allowing and disallowing authenticated users access to certain areas and programs on the network.

d)

Possible triggers for the aaa accounting exec default command include start-stop and stop-only.

35.

When a method list for AAA authentication is being configured, what is the effect of the keyword local?

a)

It uses the enable password for authentication.

b)

It defaults to the vty line password for authentication.

c)

The login succeeds, even if all methods return an error.

d)

It accepts a locally configured username, regardless of case.

36.

Which statement describes a difference between RADIUS and TACACS+?

a)

RADIUS separates authentication and authorization whereas TACACS+ combines them as one process.

b)

RADIUS uses TCP whereas TACACS+ uses UDP.

c)

RADIUS encrypts only the password whereas TACACS+ encrypts all communication.

d)

RADIUS is supported by the Cisco Secure ACS software whereas TACACS+ is not.

37.

A user complains about not being able to gain access to a network device configured with AAA. How would the network administrator determine if login access for the user account is disabled?

a)

Use the show aaa user command.

b)

Use the show running-configuration command.

c)

Use the show aaa sessions command.

d)

Use the show aaa local user lockout command.

38.

Which component of AAA is used to determine which resources a user can access and which operations the user is allowed to perform?

a)

authorization

b)

authentication

c)

accounting

d)

auditing