Final Exam Study Set Switches and Routers

0.0(0)
studied byStudied by 0 people
0.0(0)
full-widthCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/29

encourage image

There's no tags or description

Looks like no tags are added yet.

Study Analytics
Name
Mastery
Learn
Test
Matching
Spaced

No study sessions yet.

30 Terms

1
New cards

What is a Standard ACL?

Filters based on source IP only; placed closest to the destination.

2
New cards

What is an Extended ACL?

Filters source/destination IP, ports, and protocols; placed closest to the source.

3
New cards

What is a Named ACL?

An ACL identified by name instead of number; easier to manage.

4
New cards

Which ACL do you use for VTY line filtering?

Extended ACL applied with access-class on VTY lines.

5
New cards

What is implicit deny?

A hidden rule at the end of all ACLs that blocks all traffic not explicitly permitted.

6
New cards

What is a trusted network?

A secure internal network.

7
New cards

What is an untrusted network?

External networks like the Internet.

8
New cards

What is a DMZ?

A semi-secure area for public-facing servers such as web or DNS servers.

9
New cards

What is NAT?

A method to translate private IPs into public IPs for internet access.

10
New cards

How is NAT similar to CIDR?

Both help conserve IPv4 address space.

11
New cards

What is the intention of NAT?

To conserve public IPs and add basic security by hiding internal networks.

12
New cards

Most common network attacks today

Phishing, malware, DDoS, MITM, SQL injection, ransomware.

13
New cards

Advantages of NAT

Conserves IP addresses, hides internal network, allows multiple devices to share a public IP.

14
New cards

Disadvantages of NAT

Breaks end-to-end connectivity, adds overhead, harder to trace IPs.

15
New cards

What is Static NAT?

One private IP to one public IP mapping.

16
New cards

What is Dynamic NAT?

Private IPs mapped to a pool of public IPs.

17
New cards

What is PAT?

Port Address Translation; many private IPs share one public IP using unique port numbers.

18
New cards

Why do we run NAT?

IP conservation, security, multiple device connectivity.

19
New cards

What is an IDS?

Intrusion Detection System; monitors and alerts.

20
New cards

What is an IPS?

Intrusion Prevention System; actively blocks malicious traffic.

21
New cards

What is NGFW?

Next-Generation Firewall; performs deep inspection, app control, IDS/IPS, URL filtering.

22
New cards

What is a DoS attack?

A single source overwhelms a system or service.

23
New cards

What is a DDoS attack?

Multiple sources (botnet) overwhelm a system, harder to mitigate.

24
New cards

What is CDP?

Cisco Discovery Protocol; Cisco-proprietary neighbor discovery.

25
New cards

What is LLDP?

Link Layer Discovery Protocol; vendor-neutral alternative to CDP.

26
New cards

What is NTP?

Network Time Protocol; synchronizes time across devices.

27
New cards

Three SNMP message types

Get, Set, and Trap.

28
New cards

What is Syslog?

A logging system for centralizing device logs and alerts.

29
New cards

SSH vs Telnet

SSH is encrypted; Telnet is unencrypted and insecure.

30
New cards

What is NetFlow?

A traffic analysis tool to track bandwidth, flows, and anomalies.