Font size
S
M
L
XL
WorksheetsMCyber_Chap5N6
Total questions: 26
Worksheet time: 25mins
Name
Class
Date
1.
City Center Hospital provides WLAN connectivity to its employees. The security policy requires that communication between employee mobile devices and the access points must be encrypted. What is the purpose of this requirement?
a)
To ensure that users who connect to an AP are employees of the hospital
b)
To prevent a computer virus on a mobile device from infecting other devices
c)
To prevent the contents of intercepted messages from being read
d)
To block denial of service attacks originating on the Internet
2.
What is a feature that can be used by an administrator to prevent unauthorized users from connecting to a wireless access point?
a)
MAC filtering
b)
Software firewall
c)
WPA encryption
d)
Proxy server
3.
What is an advantage of SSID cloaking?
a)
Clients will have to manually identify the SSID to connect to the network.
b)
It is the best way to secure a wireless network.
c)
SSIDs are very difficult to discover because APs do not broadcast them.
d)
It provides free Internet access in public locations where knowing the SSID is of no concern.
4.
For which discovery mode will an AP generate the most traffic on a WLAN?
a)
Passive mode
b)
Open mode
c)
Mixed mode
d)
Active mode
5.
At a local college, students are allowed to connect to the wireless network without using a password. Which mode is the access point using?
a)
Network
b)
Open
c)
Passive
d)
Shared-key
6.
An employee connects wirelessly to the company network using a cell phone. The employee then configures the cell phone to act as a wireless access point that will allow new employees to connect to the company network. Which type of security threat best describes this situation?
a)
Cracking
b)
Denial of service
c)
Rogue access point
d)
Spoofing
7.
The company handbook states that employees cannot have microwave ovens in their offices. Instead, all employees must use the microwave ovens located in the employee cafeteria. What wireless security risk is the company trying to avoid?
a)
Improperly configured devices
b)
Rogue access points
c)
Accidental interference
d)
Interception of data
8.
Which two roles are typically performed by a wireless router that is used in a home or small business? (Choose two.)
a)
Repeater
b)
Access point
c)
WLAN controller
d)
Ethernet switch
e)
RADIUS authentication server
9.
What method of wireless authentication is dependent on a RADIUS authentication server?
a)
WEP
b)
WPA Personal
c)
WPA2 Personal
d)
WPA2 Enterprise
10.
Which wireless encryption method is the most secure?
a)
WPA2 with AES
b)
WPA2 with TKIP
c)
WEP
d)
WPA
11.
Which parameter is commonly used to identify a wireless network name when a home wireless AP is being configured?
a)
Ad hoc
b)
BESS
c)
ESS
d)
SSID
12.
Which wireless parameter refers to the frequency bands used to transmit data to a wireless access point?
a)
SSID
b)
Security mode
c)
Scanning mode
d)
Channel settings
13.
Which device can control and manage a large number of corporate APs?
a)
Switch
b)
WLC
c)
Router
d)
LWAP
14.
A wireless engineer is comparing the deployment of a network using WPA2 versus WPA3 authentication. How is WPA3 authentication more secure when deployed in an open WLAN network in a newly built company-owned cafe shop?
a)
WPA3 uses DPP to securely onboard available IoT devices
b)
WPA3 prevents brute force attacks by using SAE
c)
WPA3 requires the use of a 192-bit cryptographic suite
d)
WPA3 uses OWE to encrypt wireless traffic
15.
What is the purpose of a personal firewall on a computer?
a)
To increase the speed of the Internet connection
b)
To protect the computer from viruses and malware
c)
To filter the traffic that is moving in and out of the PC
d)
To protect the hardware against fire hazard
16.
What is the main difference between the implementation of IDS and IPS devices?
a)
An IDS can negatively impact the packet flow, whereas an IPS can not.
b)
An IDS needs to be deployed together with a firewall device, whereas an IPS can replace a firewall.
c)
An IDS would allow malicious traffic to pass before it is addressed, whereas an IPS stops it immediately.
d)
An IDS uses signature-based technology to detect malicious packets, whereas an IPS uses profile-based technology.
17.
Which protocol provides authentication, integrity, and confidentiality services and is a type of VPN?
a)
MD5
b)
AES
c)
IPsec
d)
ESP
18.
What is a feature of the TACACS+ protocol?
a)
It utilizes UDP to provide more efficient packet transfer.
b)
It hides passwords during transmission using PAP and sends the rest of the packet in plaintext.
c)
It encrypts the entire body of the packet for more secure communications.
d)
It combines authentication and authorization as one process.
19.
Which firewall feature is used to ensure that packets coming into a network are legitimate responses to requests initiated from internal hosts?
a)
Application filtering
b)
Stateful packet inspection
c)
Packet filtering
d)
URL filtering
20.
Refer to the exhibit. The network “A” contains multiple corporate servers that are accessed by hosts from the Internet for information about the corporation. What term is used to describe the network marked as “A”?
a)
Perimeter security boundary
b)
Internal network
c)
DMZ
d)
Untrusted network
21.
Which statement describes the Cisco Cloud Web Security?
a)
It is a secure web server specifically designed for cloud computing.
b)
It is a cloud-based security service to scan traffic for malware and policy enforcement.
c)
It is an advanced firewall solution to guard web servers against security threats.
d)
It is a security appliance that provides an all-in-one solution for securing and controlling web traffic.
22.
Which two statements are true about NTP servers in an enterprise network? (Choose two.)
a)
NTP servers ensure an accurate time stamp on logging and debugging information
b)
NTP servers control the mean urne between failures (MTBF) for key network devices
c)
NTP servers at stratum 1 are directly connected to an authoritative time source
d)
All NTP servers synchronize directly to a stratum 1 time source
e)
There can only be one NTP server on an enterprise network
23.
How is a source IP address used in a standard ACL?
a)
It is used to determine the default gateway of the router that has the ACL applied.
b)
It is the address that is unknown, so the ACL must be placed on the interface closest to the source address.
c)
It is the address to be used by a router to determine the best path to forward packets.
d)
It is the criterion that is used to filter traffic.
24.
Which option allows administrators to monitor and manage network devices?
a)
NetFlow
b)
NTP servers control the mean urne between failures (MTBF) for key network devices
c)
SNMP
d)
Syslog Servers
25.
What is a function of a proxy firewall?
a)
Uses signatures to detect patterns in network traffic
b)
Connects to remote servers on behalf of clients
c)
Drops or forwards traffic based on packet header information
d)
Filters IP traffic between bridged interfaces
26.
What network monitoring technology enables a switch to copy and forward traffic sent and received on multiple interfaces out another interface toward a network analysis device?
a)
Port mirroring
b)
NetFlow
c)
SNMP
d)
Network tap
Reset
