WorksheetsICS Domain 2 Review
Total questions: 20
Worksheet time: 11mins
Sample IDS log entry: "Device with MAC address XX:XX:XX:XX:XX:XX attempted to access the guest wireless network. Access was denied based on MAC address filtering policy."
MAC addresses remain the same, but IP addresses change
IDS can detect host MAC address quicker than the IP address
MAC addresses can not be spoofed, but IP addresses are susceptible to spoofing
MAC addresses are easier to secure because they don't send data across networks
Which of the following is not true about IP addresses?
Any IP address starting with 10 is private
Trusted networks contain all non-routable IP addresses
Any IP address starting with 192 is private
Most trusted networks use private IP addresses
Which of the following is not typically located in a company's DMZ?
Email server
Directory services
Proxy server
Web server
This security technology is used to watch for potential threats, and log suspicious activities.
IDS
IPS
NAT
Proxy server
Which of the following do switches and wireless access points use to control access through a device?
IP address filtering
Port number filtering
MAC address filtering
Session filtering
What type of address is this?
2001:0db8:0000:abcd:0000:0000:0000:7334
IPv6
IPv4
I sit between the internet and the network. I protect the network, by blocking viruses, malware and worms. I can be both hardware and software
Router
Firewall
Ethernet Cable
Modem
Provide an IDS log sample based on the given questions.
It encrypts network traffic
It monitors network traffic for suspicious activity
It blocks all incoming traffic
It manages user access rights
What is the MOST common form of host-based IDS that employs signature or pattern-matching detection methods?
Anti-Virus
software
Motion Detectors
Firewall
Honeypots
This type of attack overwhelms a server by sending more GET requests than the server can handle.
(a)
IDS Log: Detected ARP spoofing attempt. An attacker is sending frames with the attacker's MAC address associated with the IP address of a legitimate host. What type of attack is this?
(a)
In this IDS log sample, the attacker overwhelms the server with TCP SYN request to prevent the server from responding to client requests.
ARP spoofing
IP spoofing
HTTP flooding
SYN flooding
What device produces this type of log entry?
2023-10-05T14:48:00Z ALERT: Potential HTTP Flood Detected Source IP: 192.168.1.100 Destination IP: 192.168.1.1 R
Firewall
IDS
IPS
Proxy server
Which device should CITA use to enforce corporate policies on BYOD devices connecting to the network?
VPN
QoS
NAC
IPS
Which type of server performs authentication for 802.1x network access?
LDAP
RADIUS
SNMP
TACACTS+
Which cloud service is used for file storage and backups: SaaS, IaaS, or PaaS?
(a)
What type of device/service enhances security by hiding their corporate IP address and by acting as a go-between for internal users and the internet?
IDS
proxy server
RADIUS
VPN
A syslog vulnerability is where entries can be tampered with, which questions data integrity.
True
False
Data is encrypted in SNMPv1 and SNMPv2.
True
False
Which remote desktop tool completely takes over a device so the device's activity cannot be seen?
Remote Assistance
Remote Desktop
TeamViewer
VNC
