| < Free Open Study > |
If you found the information in this chapter a bit overwhelming, you are not alone. This is
At this point, you should know the following at the very least:
Understand the seven
Be able to identify and describe various network topologies and the cabling used for each.
Be able to define security-
Understand the most popular network countermeasures that can be implemented to protect a network from possible intrusion and attacks.
Have a basic understanding of network devices such as repeaters, hubs, routers, and bridges.
Understand media security procedures and security baselines.
If you want to pass this newly developed exam and acquire this important certification that is considered in high demand, the time to focus is now! Please use the knowledge you have
| < Free Open Study > |
| < Free Open Study > |
|
1. |
|
|
|
2. |
Which IEEE specification is
|
|
|
3. |
Which type of network cabling is the most difficult to tap into and
|
|
|
4. |
Which statement is true regarding firewalls?
|
|
|
5. |
Which of the following describe an FDDI ring? (Choose three)
|
|
|
6. |
Which of the following choices forms a
|
|
|
7. |
Of the following protocols, which protocol uses a one-way hash function to assist with the authentication process?
|
|
|
8. |
Which of the following practices should be followed in order to harden an internal network from outside influences? (Choose four)
|
|
|
9. |
Which of the following protocols is used to map or 'resolve' an IP address to a system's physical hardware address?
|
|
|
10. |
Which of the following provides a type of firewall by hiding internal IP addresses from outside networks?
|
|
|
11. |
Which device does not forward all broadcast traffic and has the ability to forward data packets to other networks based on IP address information?
|
|
|
12. |
Which TCP port is HTTP associated with?
|
|
|
13. |
Which intrusion detection device is used to lure and trap possible network
|
|
|
14. |
What is the name used when access to part of an internal network is granted to outside venders and customers?
|
|
|
15. |
Which of the following is a small plastic device that can be used for storage, authentication, or memory purposes?
|
|
|
16. |
How long are IPv6 addresses?
|
|
|
17. |
Which statement best describes a DMZ?
|
|
|
18. |
How long are IPv6 addresses?
|
|
|
19. |
FTP uses which TCP ports?
|
|
Answers
|
1. |
Correct answer = A The minimum cable type needed to support 10BaseT is Category3. An RJ-11 phone connector is used for earlier categories of UTP to connect a modem to a typical phone jack or your phone to a phone jack. Catagory4 and Category5 cable types do support 10Baset Ethernet specifications. However, they are not the minimum category type needed to support 10BaseT. |
|
2. |
Correct answer = C 802.3 is concerned with Carrier-Sense Multiple Access with Collision detection in local area Ethernet networks. The 802.5 specification is for Token Ring LANs. 802.11 is an IEEE specification for wireless communications. |
|
3. |
Correct answer = D
Fiber-
|
|
4. |
Correct answer = B Properly configured firewalls will protect an internal network from an external network. An antivirus program and updated operating system service packs would be used to protect your internal network from a virus that resides on workstations on your internal network. Firewalls do not provide protection through dial-up modem connections nor do they protect against natural disasters. |
|
5. |
Correct answers = A, B, and C Answers A, B, and C are all true statements regarding FDDI rings. Option D is a sort of a trick. FDDI uses fiber cable, which as you are already aware is more difficult to tap into than most other cable types. FDDI uses token passing technology not CSMA/CD (Carrier-Sense Multiple Access with Collision Detection.) CSMA/CD is used in Ethernet networks. |
|
6. |
Correct answer = B A circuit gateway forms a sort of tunnel through a firewall allowing two specified hosts to interact. Packet filters examine UDP, TCP ports, and packet header information. They can identify good from bad packet information. Application proxies (or gateways) are concerned more with specific applications and actual data. FDDI is a network topology standard that utilizes dual fiber-optic rings. |
|
7. |
Correct answer = B
CHAP uses a secret one-way hash value that is generated by the requester and sent to the server. PAP is a basic type of authentication where a username and password are transmitted unencrypted across a network to an authenticating host. PPP is a
|
|
8. |
Correct answers = A, B, D, and E
The only incorrect answer to this question is C. If you chose answer C,
|
|
9. |
Correct answer = D Address Resolution Protocol (ARP) is a protocol used to map an IP (Internet Protocol) address at the network layer of the OSI model to a physical hardware address at the MAC (Media access Control) sublayer. HyperText Transport Protocol Secure (HTTPS) is a secure protocol used to transmit messages over the Internet. SDLC is based on a primary/secondary communications model where a secure connection is established between a mainframe (host) and a client. High Level Data Link Control (HDLC) is a transmission protocol that operates at the Data Link layer (layer 2) of the OSI model. |
|
10. |
Correct answer = B
Network Address Translation (NAT) is an Internet standard most often used with routers to provide firewall security by hiding an internal private networks range of IP addresses from outside networks. Address Resolution Protocol (ARP) is a protocol used to map an IP (Internet Protocol) address at the Network layer of the OSI mode, to a physical hardware address at the MAC (Media access Control) sublayer. Password Authentication Protocol (PAP) is a basic type of authentication where a username and password are transmitted unencrypted across a network to an authenticating host. Secure Remote Procedure Call (RPC) is
|
|
11. |
Correct answer = B
A router operates at the Network layer of the OSI reference model and has the ability to forward information based on a network or individual computer's TCP/IP address. A router has the ability to filter out broadcast traffic. Bridges are limited in their capabilities. They forward packet information based on MAC addresses. A bridge proliferates or broadcasts (
|
|
12. |
Correct answer = D HTTP traffic uses TCP port 80. FTP uses TCP port 21. SMTP uses TCP port 25. DNS uses UDP port 53. Please refer to Table 4.2. |
|
13. |
Correct answer = B
The main goal of a honey pot or 'mouse trap' if you will, is to trap, track, and record the trails of a possible attacker. A false positive is simply a report or an alert from an IDS that details something other than an attack. A false negative error occurs when an IDS completely misses
|
|
14. |
Correct answer = D
When part of an internal network or intranet has been made accessible to outside sources, that part of the internal network is referred to as an extranet. Ethernet is a LAN architecture technology developed by Xerox that supports CSMA/CD. You should have learned this as a prerequisite to
|
|
15. |
Correct answer = B A smart card is a small plastic card that contains a microchip. It can be used for data storage and memory purposes as well as a security authentication device. A CD-R is an optical storage disk capable of storing large amounts of data. Intelligent token is an invalid selection. Although a tape cartridge is often used for data storage, it is not an authentication device nor is it used for memory purposes. |
|
16. |
Correct answer = D IPv6 allows for IP addresses to be lengthened from the IPv4 limitation of 32 bits to 128 bits. IPv6 also allows for better authentication, privacy, and improved data delivery assurance. All other choices are invalid. |
|
17. |
Correct answer = C The DMZ sits between a private and a public network and can be made up of one or several systems that house Web pages and non-critical company data that can be accessed from outside an intranet or LAN. BNC and BNC barrel connectors are typically used to attach or connect a bus cable to a device or connect one piece of the bus cable to another. Answers B and D are invalid. |
|
18. |
Correct answer = D IPv6 allows for IP addresses to be lengthened from the IPv4 limitation of 32 bits to 128 bits. IPv6 also allows for better authentication, privacy, and improved data delivery assurance. All other choices are invalid. |
|
19. |
Correct answer = B FTP uses TCP ports 20 and 21. SMTP uses TCP port 25. Telnet uses TCP port 23. HTTP uses TCP port 80. You'd better know this for any security exam! |
| < Free Open Study > |