Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Switch Security Configuration Quiz

Total questions: 27

Worksheet time: 14mins

Name
Class
Date
1.

What is a recommended best practice when dealing with the native VLAN?

a)

Use port security.

b)

Turn off DTP.

c)

Assign it to an unused VLAN.

d)

Assign the same VLAN number as the management VLAN.

2.

On what switch ports should PortFast be enabled to enhance STP stability?

a)

All end-user ports.

b)

Only ports that attach to a neighboring switch.

c)

All trunk ports that are not root ports.

d)

Only ports that are elected as designated ports.

3.

Which command would be best to use on an unused switch port if a company adheres to the best practices as recommended by Cisco?

a)

ip dhcp snooping

b)

switchport port-security violation shutdown

c)

shutdown

d)

switchport port-security mac-address sticky

4.

Which two features on a Cisco Catalyst switch can be used to mitigate DHCP starvation and DHCP spoofing attacks? (Choose two.)

a)

DHCP snooping

b)

DHCP server failover

c)

extended ACL

d)

port security

5.

What is the best way to prevent a VLAN hopping attack?

a)

Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.

b)

Use VLAN 1 as the native VLAN on trunk ports.

c)

Use ISL encapsulation on all trunk links.

d)

Disable STP on all nontrunk ports.

6.

Which procedure is recommended to mitigate the chances of ARP spoofing?

a)

Enable port security globally.

b)

Enable DAI on the management VLAN.

c)

Enable DHCP snooping on selected VLANs.

d)

Enable IP Source Guard on trusted ports.

7.

What are two types of switch ports that are used on Cisco switches as part of the defense against DHCP spoofing attacks? (Choose two.)

a)

unknown port

b)

trusted DHCP port

c)

unauthorized port

d)

untrusted port

8.

Which two commands can be used to enable PortFast on a switch? (Choose two.)

a)

S1(config-if)# enable spanning-tree portfast

b)

S1(config)# spanning-tree portfast default

c)

S1(config-if)# spanning-tree portfast

d)

S1(config)# enable spanning-tree portfast default

9.

An administrator who is troubleshooting connectivity issues on a switch notices that a switch port configured for port security is in the err-disabled state. How should the administrator re-enable the port without disrupting network operation?

a)

Issue the shutdown command followed by the no shutdown command on the interface.

b)

Reboot the switch.

c)

Issue the no switchport port-security violation shutdown command on the interface.

d)

Issue the no switchport port-security command, then re-enable port security.

10.

A network administrator is configuring DHCP snooping on a switch. Which configuration command should be used first?

a)

ip dhcp snooping limit rate

b)

ip dhcp snooping

c)

ip dhcp snooping vlan

d)

ip dhcp snooping trust

11.

A network administrator is configuring DAI on a switch with the command ip arp inspection validate dst-mac. What is the purpose of this configuration command?

a)

To check the destination MAC address in the Ethernet header against the target MAC address in the ARP body.

b)

To check the destination MAC address in the Ethernet header against the user-configured ARP ACLs.

c)

To check the destination MAC address in the Ethernet header against the source MAC address in the ARP body.

d)

To check the destination MAC address in the Ethernet header against the MAC address table.

12.

Which security feature should be enabled in order to prevent an attacker from overflowing the MAC address table of a switch?

a)

storm control

b)

port security

c)

BPDU filter

d)

root guard

13.

What Layer 2 attack is mitigated by disabling Dynamic Trunking Protocol?

a)

VLAN hopping

b)

ARP spoofing

c)

DHCP spoofing

d)

ARP poisoning

14.

A network administrator is configuring DAI on a switch. Which command should be used on the uplink interface that connects to a router?

a)

ip arp inspection trust

b)

ip dhcp snooping

c)

ip arp inspection vlan

d)

spanning-tree portfast

15.

Where are dynamically learned MAC addresses stored when sticky learning is enabled with the switchport port-security mac-address sticky command?

a)

NVRAM

b)

RAM

c)

ROM

d)

flash

16.

Which method would mitigate a MAC address flooding attack?

a)

Configuring port security

b)

Increasing the size of the CAM table

c)

Using ACLs to filter broadcast traffic on the switch

d)

Increasing the speed of switch ports

17.

Which action will bring an error-disabled switch port back to an operational state?

a)

Clear the MAC address table on the switch.

b)

Issue the shutdown and no shutdown interface config commands.

c)

Remove and reconfigure port security on the interface.

d)

Issue the switchport mode access interface config command.

18.

Which two statements are true regarding switch port security? (Choose two.)

a)

After entering the sticky parameter, only MAC addresses subsequently learned are converted to secure MAC addresses.

b)

The three configurable violation modes all log violations via SNMP.

c)

If fewer than the maximum number of MAC addresses for a port are configured statically, dynamically learned addresses are added to CAM until the maximum number is reached.

d)

Dynamically learned secure MAC addresses are lost when the switch reboots.

19.

Port security has been enabled on access ports to allow a maximum of two MAC addresses. Which port security violation would drop the frame and send a notification to the syslog server if the maximum number of MAC addresses is exceeded?

a)

Shutdown

b)

Warning

c)

Restrict

d)

Protect

20.

Which feature should be configured on PortFast enabled switches to prevent rogue switches from being added to a network?

a)

DAI

b)

Port security

c)

BPDU guard

d)

DHCP snooping

21.

Which port security feature enables switches to automatically learn and retain MAC addresses for each port?

a)

Dynamic secure MAC addresses

b)

Sticky secure MAC addresses

c)

Auto secure MAC addresses

d)

Static secure MAC addresses

22.

Assume that BPDU Guard has been enabled globally on all access ports. However, one port must not be configured with the feature. Which command would explicitly disable BPDU Guard on that switch port?

a)

S1(config)# no spanning-tree portfast bpduguard default

b)

S1(config-if)# no enable spanning-tree bpduguard

c)

S1(config-if)# no spanning-tree portfast bpduguard

d)

S1(config)# no spanning-tree bpduguard default

23.

Which DAI command checks the source MAC address in the Ethernet header against the target MAC address in the ARP body?

a)

ip arp inspection validate dst-mac

b)

ip arp inspection validate src-mac

c)

ip arp inspection validate dst-mac ip

d)

ip arp inspection validate ip

24.

What is the result of entering the ip dhcp snooping limit rate 4 interface configuration command?

a)

The port can receive up to 4 DHCP offer messages per second.

b)

The port can send up to 4 DHCP messages per second.

c)

The port can receive up to 4 DHCP discovery messages per second.

d)

The port can send up to 4 DHCP offer discovery messages per second.

25.

Port security has been enabled on a switch port. What is the default violation mode in use by default?

a)

Restrict

b)

Shutdown

c)

Disabled

d)

Protect

26.

What techniques should be done to mitigate VLAN attacks? (Choose three.)

a)

Disable DTP.

b)

Set the native VLAN to an unused VLAN.

c)

Enable trunking manually.

d)

Enable BPDU guard.

e)

Enable Source Guard.

27.

Port security has been enabled on interface Fa0/1 and the show port-security interface fa0/1 command has been entered. What does the Port Status 'Secure-up' message indicate?

a)

The Fa0/1 port is currently error-disabled.

b)

The Fa0/1 port violation mode is 'protect'.

c)

There are no hosts connected to the secured Fa0/1 port.

d)

There is a host connected to the secured Fa0/1 port.