Worksheetspalo 2
Total questions: 55
Worksheet time: 28mins
What is the decimal equivalent of 1110?
10
12
14
16
What is the binary equivalent of 250?
1111 1100
1111 1010
1111 1001
1111 1000
Identify the broadcast address from the following.
214.19.21.255/14
192.168.12.127/25
192.168.0.255/16
10.24.36.48/28
Which address class is within the range of 192 to 223?
Class A
Class B
Class C
Class D
An IPv6 address is structured with how many bits?
128
64
256
32
What is another term for a logical address?
IP Address
Physical Address
MAC Address
Burned-In Address
Which subnetwork is 192.168.25.50/28 on?
192.168.25.64
192.168.0.0
192.168.25.48
192.168.25.0
Which area network separates the control and management processes from the underlying networking hardware, making them available as software that can be easily configured and deployed?
LAN
WAN
SD-WAN
CAN
Which DNS record type specifies authoritative information about a DNS zone such as a primary name server, email address of the domain administrator, and domain serial number?
PTR - Pointer:
SOA - Start for Authority:
PTR - Pointer:
CNAME
Which IoT technology is backed by ultra-low latency, massive connectivity and scalability for IoT devices, more efficient use of licensed spectrum, and network slicing for application traffic prioritization?
2G
3G
4G
5G
The network device that is essentially an intelligent hub and uses physical addresses to forward data packets to devices on a network is known as:
Switch
Router
Repeater
Modem
Which layer of the hierarchical networking model is responsible for high-speed routing and switching? Routers and switches at this layer are designed for high-speed packet routing and forwarding.
Access
Core
Distribution
Internet
Which type of extranet will allow businesses within an industry to share information or integrate shared business processes?
Value Add Network - VAN
Campus Area Network - CAN
Metropolitan Area Network - MAN
Storage Area Network - SAN
Which task is typically not included in server and system administration duties?
Account provisioning and de-provisioning
Managing account permissions
Installing and maintaining server software
Maintaining and optimizing network devices
Which application identification technique determines whether the initially detected application protocol is the "real one" or if it is being used as a tunnel to hide the actual application - for example, Tor might run inside HTTPS.
Application protocol detection and decryption
Application protocol decoding
Application signatures
Heuristics
Which Content-ID filtering capability controls the transfer of sensitive data patterns such as credit card and social security numbers in application content and attachments?
File blocking by type
Data filtering
File transfer function control
File filtering by size
Which Linux command gives you extensive help on how to use a command?
help
more
man
guide
Which subscription service complements App-ID by enabling you to configure the next-generation firewall to identify and control access to websites and to protect your organization from websites hosting malware and phishing pages.
URL Filtering
Wildfire
Threat Prevention
On the NGFW, which type of User-ID technique can be configured to probe Microsoft Windows servers for active network sessions of a user?
Client Probing
Server Probing
Internet Probing
Connection Probing
Characteristics of unified threat management (UTM) include all of the following except:
Combines security functions such as firewalls, intrusion detection systems (IDS), anti-malware, and data loss prevention (DLP) in a single appliance.
Enabling all of the security functions in a UTM device can have a significant performance impact.
UTM fully integrates all of the security functions installed on the device.
UTM can be a convenient solution for small networks.
Characteristics of application firewalls include all of the following except:
Proxies traffic rather than permitting direct communication between hosts
Can be used to implement strong user authentication
Masks the internal network from untrusted networks
Is extremely fast and has no impact on network performance
Which VPN technology is currently considered the preferred method for securely connecting a remote endpoint device back to an enterprise network?
Point-to-point Tunneling protocol - PPTP
Secure Socket Layer - SSL
Secure Socket tunneling protocol - SSTP
Internet Protocol Security - IPSEC
At which Data Link sublayer does the physical address reside?
Media Access Control - MAC
Logical Link Control - LLC
Data Access Control - DAC
Network Access Control - NAC
HTTPS interacts with which OSI layer?
Application
Physical
Data Link
Session
Which OSI layer handles flow control, data segmentation, and reliability?
Application
Physical
Transport
Data Link
At which OSI layer does the PDU contain sequence and acknowledgement numbers?
Application
4
Data Link
6
Which OSI layer determines the route a packet takes from sender to receiver?
7
1
3
4
Which OSI layer is responsible for setting up, maintaining, and ending ongoing information exchanges across a network?
6
3
2
5
Which layer of the OSI model does Project 802 divide into two sublayers?
Physical
Data Link
Network
Session
Which term refers to stripping header information as a PDU is passed from one layer to a higher layer?
De-encapsulation
Encapsulation
Packetization
PDU stripping
Which of the following problems can occur at the Physical layer of the OSI Model?
NIC driver problems
Incorrect IP addresses
Signal errors caused by noise
In the Kipling Model of Zero Trust which allows security solutions to track where accessed data resides?
What
How
Who
Where
Which control point in a Zero-Trust Model scans all content for malicious activity and data theft?
Access
Transaction
Device/Workload
Identity
In the Kipling Model of Zero Trust which asks for the asserted identity of the user or entity that attempts resource access?
How
What
Who
When
Zero Trust is intended to remedy the deficiencies of perimeter-centric strategies.
True
False
In the Kipling Model of Zero Trust which entifies the application used to access protected data?
What
When
How
Where
Select True or False - Zero Trust eliminates Implicit Trust
True
False
Which Microsoft Zero Trust Guiding Principle minimizes blast radius and segment access?
Trust and Verify
Least Privileged Access
Assume Breach
Verify Explicitly
The following are limitations of Zero Trust Network Access 1:
Doesn't protect data
Secures all apps
Adheres to the principles of Least Privileged Access
Which of the following is an appropriate explanation of the functions of Zero Trust?
CART Model
Cooper Test
Kipling Method
Keynesian Theory
Which of the following statements is the best way to describe Zero Trust?
Zero Trust endpoint applications are automatically verified
Zero Trust eliminates the need for user authentication
Never Trust - Always Verify
Always Trust - Always Verify
An effective SASE solution needs to service the following requirements - Select the best answer.
All of the answers
Diversity - Carrier Agnostic
Scalability
Mobility
Select the phrase below that best fills in the blank in the following sentence - A successful SASE deployment employs a __________ approach, as it services a company's need to provide application resources for a hybrid work demand.
cloud first
mobile
proprietary
restricted
The term SASE stands for:
Secure Access Services Edge
Standards Authentication Services Enforcement
Services Authentication Services Edge
Secure Access Standards Enforcement
Which of the following is NOT one of the 10 Tenets of an Effective SASE Solution?
Agility
Monitoring and Reporting
Cost Reduction
Complexity
Which of the following is NOT one of the Ten Benefits of SASE?
Website Enrollments
Authentication Capabilities
Default Routes
Service Connections
Which Prisma Access Architecture Layer provides SD-WAN, VPN, ZTNA, and QoS capabilities?
Management
Network-as-a-service
Security-as-a-service
Public Cloud
Which SASE tenet is able to accurately detect devices for full visibility and enforce policies to ensure security across the network, eliminating the need for additional IoT security solutions?
Autonomous Digital Experience Monitoring - ADEM
Internet of Things - IoT
Zero Trust Network Access - ZTNA
Cloud Access Security Broker - CASB
Which SASE tenet provides segment-wise insights across the entire service delivery path, allowing real and synthetic traffic analysis that enables organizations to proactively drive remediation of digital experience problems?
Autonomous Digital Experience Monitoring - ADEM
Internet of Things - IoT
Zero Trust Network Access - ZTNA
Cloud Access Security Broker - CASB
Which SASE tenet should enable complete visibility and control over all traffic, regardless of where a user may be located, to ensure the secure use of cloud-based apps and other web services?
Zero Trust Network Access - ZTNA
Secure Web Gateway - SWG
Autonomous Digital Experience Monitoring - ADEM
Cloud Access Security Broker - CASB
Which tenet is a core component of SASE, creating a single platform for administrators to manage security controls for all application types?
Cloud Access Security Broker - CASB
Zero Trust Network Access - ZTNA
Data Loss Prevention - DLP
Software Defined - Wide Area Network - SD-WAN
Which of the following terms describes the process of making and using codes to secure the transmission of information?
Steganography
Cryptography
Algorithm
Cryptanalysis
PKI systems are based on public-key cryptosystems and include digital certificates and certificate authorities.
True
False
Which of the following is considered to be the strongest symmetric encryption cryptosystem?
Data Encryption Standard (DES)
Triple DES (3DES)
Advanced Encryption Standard (AES)
RSA Algorithm
Packet-Filtering Firewalls operate at Layer 3 (network layer) of the Open Systems Interconnection (OSI) model.
True
False
