Cybersecurity Quiz 4

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/118

flashcard set

Earn XP

Description and Tags

5.0 Network Architecture: Sec 5.1 – 5.8

Last updated 1:52 AM on 9/11/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

119 Terms

1
New cards
Network architecture
The selection and placement of media, devices, protocols/services, and data assets.
2
New cards
Network infrastructure
The media, appliances, and addressing/forwarding protocols that support basic connectivity.
3
New cards
Internet Protocol (IP)
Provides the addressing mechanism for logical networks and subnets.
4
New cards
Attack surface
All the points at which a threat actor could gain access to hosts and services.
5
New cards

You are a network engineer for a large corporation that is planning to implement a new intrusion detection system (IDS). The corporation has a high volume of network traffic and requires real-time monitoring for potential security threats.

Which of the following approaches to integrating the IDS into the corporation's network would best meet these requirements?

Using a Test Access Point (TAP) device to provide the IDS with a copy of the network traffic.

6
New cards

You are a network architect for a large organization. The organization is planning to upgrade its network infrastructure to support a new business application. The application requires high availability, secure data transfer, and efficient handling of large data volumes.

Which of the following network design considerations best aligns with the requirements of the new business application?

Implementing a layered network design based on the OSI model with appropriate security controls at each layer.

7
New cards

You are a network engineer for a global company that is implementing a new real-time data processing system. This system requires efficient and reliable data transfer between different network segments.

Which of the following network components would be most critical in ensuring the efficient and reliable transfer of real-time data in this scenario?

Transport protocols

8
New cards

You are a network engineer for a multinational corporation. The corporation is planning to expand its operations to a new location and you are tasked with designing the network for the new site. The network should be robust, scalable, and secure.

Which of the following approaches to setting up network nodes at the new site would best meet these requirements?

Setting up multiple network nodes, each dedicated to a specific function such as routing, switching, and firewalling.

9
New cards

A small start-up has recently launched its first web application. To ensure high availability and to handle potential traffic spikes, the start-up decides to implement a load balancer in its network infrastructure.

The network technician must secure the load balancer against basic threats.

What is the fundamental step the network technician should take to secure the load balancer?

Disable unnecessary services on the load balancer.

10
New cards

The IT manager of a medium-sized organization is designing a new network infrastructure to secure its enterprise infrastructure by implementing an Intrusion Prevention System (IPS) and an Intrusion Detection System (IDS). The manager is considering different deployment methods for the IPS/IDS to optimize their effectiveness.

The organization's network includes multiple security zones, a virtual private network (VPN) for remote access, and a web application firewall (WAF).

Which deployment method provides the MOST comprehensive protection in this scenario?

Deploy the IPS/IDS devices in inline mode at the network perimeter.

11
New cards

An organization implements a new network infrastructure and plans to use an intrusion prevention system (IPS) for security. The IT manager wants to ensure that the IPS will continue to let traffic flow if it fails.

Which failure mode should the IT manager configure the IPS?

Fail-open

12
New cards

A hospital has implemented a security device that processes sensitive patient information. The hospital wants to ensure that in the event of a failure, the confidentiality and integrity of the patient data take priority over the system's availability.

What should the hospital set as the failure mode configuration for this security device?

The security device should be configured to fail-closed.

13
New cards

You are a cybersecurity specialist for a financial institution that is planning to enhance its network security. The institution has decided to adopt a defense in depth strategy.

Which of the following approaches would BEST align with a defense in-depth strategy?

Implementing multiple security measures at different network layers, including firewalls, intrusion detection systems, and regular patch management.

14
New cards

You are a network architect for a rapidly growing startup. The startup is planning to expand its operations and is considering a major upgrade to its network architecture.

Which of the following factors should be your primary consideration when designing the new network architecture?

Balancing costs, compute and responsiveness, scalability, availability, and resilience.

15
New cards
Security zone
Portions of the network or system that have specific security concerns or requirements.
16
New cards
Wireless network
A network that does not require a physical connection.
17
New cards
Guest network
A network that grants internet access only to guest users. A guest network has a firewall to regulate guest user access.
18
New cards
Honeynet
A host (honeypot), network (honeynet), file (honeyfile), or credential/token (honeytoken) set up with the purpose of luring attackers away from assets of actual value and/or discovering attack strategies and weaknesses in the security configuration.
19
New cards
Ad hoc
A decentralized network that allows connections without a traditional base station or router. It allows users to connect two or more devices directly to each other for a specific purpose.
20
New cards
DNS sinkhole
A temporary DNS record that redirects malicious traffic to a controlled IP address.
21
New cards
Jump server
A hardened server that provides access to other hosts.
22
New cards
Agent-based filtering
Agent-based web filtering involves installing a software agent on desktop computers, laptops, and mobile devices. The agents enforce compliance with the organization's web filtering policies.
23
New cards
Screened subnet
A network that contains publicly accessible resources and is located between the private network and an untrusted network, such as the internet. It is protected by a firewall.
24
New cards
Proxy server
A type of firewall that stands as an intermediary between clients requesting resources from other servers.
25
New cards
Internet content filter
Software used to monitor and restrict content delivered across the web to an end user.
26
New cards
Fake telemetry
Deception strategy that returns spoofed data in response to network probes.
27
New cards
All-in-one security appliance
An appliance that combines many security functions into a single device.
28
New cards
Application-aware devices
A device that has the ability to analyze and manage network traffic based on the application-layer protocol.
29
New cards

You are a network security engineer for a large corporation. The company is planning to launch a new software product and wants to provide customer access to this product over the internet.

The company also wants to ensure that the internal production network remains secure.

Which type of common security zone would be the MOST appropriate to implement in this scenario?

Screened Subnet

30
New cards

A company wants to set up a private network that employs internet information services for internal use only, including web servers and email servers that are used by company employees.

What type of network is the company planning to set up?

Intranet

31
New cards

A proxy server can be configured to do which of the following?

Restrict users on the inside of a network from getting out to the internet.

32
New cards

What is the main role of a load balancer in network security?

To distribute network traffic across multiple servers.

33
New cards

You have configured a security device in your network to fail-closed.

Which of the following will happen when an attack occurs?

The device will block access or enter the most secure state available when it fails.

34
New cards

You are implementing security at a local high school that is concerned with students accessing inappropriate material on the internet from the library's computers. The students use the computers to search the internet for research paper content. The school budget is limited.

Which content filtering option would you choose?

Restrict content based on content categories.

35
New cards

You are the office manager of a small financial credit business. Your company handles personal financial information for clients seeking small loans over the internet. You are aware of your obligation to secure clients records, but the budget is an issue for your company.

Which item would provide the BEST security for this situation?

All-in-one security appliance

36
New cards

You are a cybersecurity specialist at a large corporation. Your company has been experiencing an increase in cyber attacks recently. To better understand the tactics and techniques of the attackers, you have decided to set up a honeynet.

Which of the following is the BEST way to set up and use a honeynet?

Set up the honeynet with decoy systems and monitor it for attacker activity.

37
New cards

You are the cybersecurity lead at a large corporation. Recently, your organization has been experiencing an increase in SMTP-based attacks such as open relay, DDoS, and spam attacks. You need to devise a strategy to not only mitigate these attacks but also gather information about the attackers' tactics.

Which of the following would be the BEST solution?

Set up an email honeypot designed to attract and trap these types of attacks.

38
New cards

Which of the following is a limitation of using a DNS sinkhole as a cybersecurity measure?

DNS sinkholes are ineffective if the malware uses a public DNS server or its own DNS server.

39
New cards
Screened subnet
A buffer network (or subnet) that is located between a private network and an untrusted network, such as the internet.
40
New cards
Bastion or sacrificial host
Any host that is exposed to attack and has been hardened or fortified against attack.
41
New cards
Screening router
The router that is most external to the network and closest to the internet.
42
New cards
Dual-homed gateway
A firewall device that typically has three network interfaces. One interface connects to the internet, one interface connects to the public subnet, and one interface connects to the private network.
43
New cards
Screened host gateway
A device residing within the screened subnet that requires users to authenticate in order to access resources within the screened subnet or the intranet.
44
New cards

Which of the following is the BEST solution to allow access to private resources from the internet?

VPN

45
New cards

Which of the following is another name for a firewall that performs router functions?

Screening router

46
New cards

Which of the following is the MOST likely to happen if the firewall managing traffic into the screened subnet fails?

Only the servers in the screened subnet are compromised, but the LAN will stay protected.

47
New cards

Of the following security zones, which one can serve as a buffer network between a private secured network and the untrusted internet?

Screened subnet

48
New cards

In which of the following situations would you MOST likely implement a screened subnet?

You want to protect a public web server from attack.

49
New cards

You have used firewalls to create a demilitarized zone. You have a web server that needs to be accessible to internet users. The web server must communicate with a database server for retrieving product, customer, and order information.

How should you place devices on the network to BEST protect the servers? (Select two.)

Put the database server on the private network; Put the web server inside the screened subnet

50
New cards

What needs to be configured on a firewall to allow traffic directed to the public resource in the screened subnet?

Packet filters

51
New cards

How many network interfaces does a dual-homed gateway typically have?

3

52
New cards

You have a company network that is connected to the internet. You want all users to have internet access, but you need to protect your private network and users. You also need to make a web server publicly available to internet users.

Which solution should you use?

Use firewalls to create a screened subnet. Place the web server inside the screened subnet and the private network behind the screened subnet.

53
New cards

Which of the following terms describes a network device that is exposed to attacks and has been hardened against those attacks?

Bastion or sacrificial host

54
New cards
Firewall
A device, or software running on a device, that inspects network traffic and allows or blocks traffic based on a set of rules.
55
New cards
Web application firewall (WAF)
A firewall designed specifically to protect software running on web servers and their back-end databases from code injection and DoS attacks.
56
New cards
Network firewall
A firewall that is used to regulate traffic in and out of an entire network.
57
New cards
Stateless firewall
A firewall that allows or denies traffic by examining information in IP packet headers.
58
New cards
Stateful firewall
A firewall that allows or denies traffic based on virtual circuits of sessions. A stateful firewall is also known as a circuit-level proxy or circuit-level gateway.
59
New cards

The security team in a financial organization identified a zero-day vulnerability attack that enables cross-site scripting (XSS) attacks on its internal web portal. The chief information security officer (CISO) instructs the team to take immediate action.

Which action MOST effectively minimizes the threat from the zero-day vulnerability and the potential XSS attacks?

Implement a web application firewall (WAF).

60
New cards

Which of the following are characteristics of a basic packet-filtering firewall? (Select two.)

Stateless; Filters IP address and port

61
New cards

Which of the following BEST describes a stateful inspection?

Determines the legitimacy of traffic based on the state of the connection from which the traffic originated.

62
New cards

When designing a firewall, what is the recommended approach for opening and closing ports?

Close all ports; open only ports required by applications inside the network.

63
New cards

You have just installed a packet-filtering firewall on your network.

Which options are you able to set on your firewall? (Select three.)

Source address of a packet; Destination address of a packet; Port number

64
New cards

A network security administrator's responsibilities include enhancing the enterprise's network infrastructure security posture. They deploy a Next Generation Firewall (NGFW) as part of their defense strategy.

The enterprise mixes internal and external services, including a web application and a virtual private network (VPN) for remote access.

Which of the following should the administrator primarily consider when implementing the NGFW to ensure effective security without disrupting normal operations?

Deploy the NGFW in inline mode, ensuring it analyzes all traffic while maintaining connectivity.

65
New cards

You have been given a laptop to use for work. You connect the laptop to your company network, use it from home, and use it while traveling.

You want to protect the laptop from internet-based attacks.

Which solution should you use?

Host-based firewall

66
New cards

A cyber team implements new hardening techniques after a data loss prevention (DLP) audit revealed increased data exfiltration.

What is a tenet of host-based firewalls?

It provides controls for incoming and outgoing network traffic.

67
New cards

Which of the following are features of an application-level gateway? (Select two.)

Reassembles entire messages; Stops each packet at the firewall for inspection

68
New cards

Which of the following describes how access control lists can be used to improve network security?

An access control list filters traffic based on the IP header information, such as source or destination IP address, protocol, or socket number.

69
New cards
Virtual Private Network
A remote access connection that uses encryption to securely send data over an untrusted network.
70
New cards
Tunneling
The practice of encapsulating data from one protocol for safe transfer over another network such as the Internet.
71
New cards
Point-to-Point Tunneling Protocol (PPTP)
A early tunneling protocol developed by Cisco and Microsoft to support VPNs over PPP and TCP/IP. PPTP is highly vulnerable to password cracking attacks and considered obsolete.
72
New cards
Layer 2 Forwarding (L2F)
A tunneling protocol developed by Cisco to establish virtual private network connections over the internet.
73
New cards
Internet Protocol Security (IPsec)
Network protocol suite used to secure data through authentication and encryption as the data travels across the network or the Internet.
74
New cards
Secure Sockets Layer (SSL)
A well-established protocol to secure IP protocols, such as HTTP and FTP. And can also be used to secure other application protocols and as a virtual private networking (VPN) solution.
75
New cards
Transport Layer Security (TLS)
Security protocol that uses certificates for authentication and encryption to protect web communications and other application protocols.
76
New cards

Which VPN tunnel style routes only certain types of traffic?

Split

77
New cards

Which VPN implementation uses routers on the edge of each site?

Site-to-site VPN

78
New cards

A VPN is primarily used for which of the following purposes?

Support secured communications over an untrusted network

79
New cards

The IT department in a large multinational corporation faces challenges managing secure communications for remote desktop connections. The increasing number of remote employees has made it essential to ensure that their remote desktop connections are secure. The IT department is considering various measures to establish secure communication.

Given the challenges the corporation faces, what approach should the IT department adopt to ensure secure communications for remote desktop connections while maintaining the manageability and performance of the enterprise infrastructure?

Implement TLS for all remote desktop connections

80
New cards

Which VPN protocol typically employs IPsec as its data encryption mechanism?

L2TP

81
New cards

Which statement BEST describes IPsec when used in tunnel mode?

The entire data packet, including headers, is encapsulated

82
New cards

Which of the following is commonly used in the first phase of Internet Key Exchange (IKE) negotiations for authenticating the identity of peers?

Digital certificates

83
New cards

A network engineer has the task of creating a remote access solution for a global enterprise. The solution should secure encrypted communication for the company's employees worldwide and detect potential security threats in real time.

Which configuration should the network engineer deploy to meet these requirements?

A VPN utilizing IKE and IPSec protocols, combined with an inline intrusion detection system (IDS)

84
New cards

In addition to Authentication Header (AH), IPSec is comprised of what other service?

Encapsulating Security Payload (ESP)

85
New cards

A salesperson in your organization spends most of her time traveling between customer sites. After a customer visit, she must complete various managerial tasks, such as updating your organization's order database.

Because she rarely comes back to your home office, she usually accesses the network from her notebook computer using Wi-Fi access provided by hotels, restaurants, and airports.

Many of these locations provide unencrypted public Wi-Fi access, and you are concerned that sensitive data could be exposed. To remedy this situation, you decide to configure her notebook to use a VPN when accessing the home network over an open wireless connection.

Which key steps should you take when implementing this configuration? (Select two.)

Configure the browser to send HTTPS requests through the VPN connection; Configure the VPN connection to use IPsec

86
New cards
Network access control (NAC)
A general term for the collected protocols, policies, and hardware that authenticate and authorize access to a network at the device level.
87
New cards
Bring your own device (BYOD)
Security framework and tools to facilitate use of personally owned devices to access corporate networks and data.
88
New cards

Which of the following BEST describes zero-trust security?

Only devices that pass both authentication and authorization are trusted.

89
New cards

An international business is experiencing an increase in remote work scenarios, resulting in a significant rise in employees using personal devices and smart appliances for work.

This development raises potential issues related to unauthorized network access and adherence to security standards.

Which of the following solutions MOST effectively addresses these security issues?

Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.

90
New cards

A large enterprise recently introduced a bring your own device (BYOD) policy and is seeing an uptick in the use of Internet of Things (IoT) devices in the office.

Concerns about unauthorized network access and compliance with security standards accompany these changes.

Assess the following options and determine the MOST suitable strategy to alleviate these security concerns.

Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.

91
New cards

You are part of a committee that is meeting to define how Network Access Control (NAC) should be implemented in the organization.

Which step in the NAC process is this?

Plan

92
New cards

In a Network Access Control (NAC) system, a nonpersistent (or dissolvable) agent is used during the posture assessment process.

Which of the following statements about a nonpersistent NAC agent is true?

A nonpersistent agent is loaded into memory during posture assessment but is not installed on the device.

93
New cards

As a network administrator, you have implemented a Network Access Control (NAC) system with automatic remediation capabilities in your organization.

One day, you notice that a significant number of devices are being quarantined frequently by the NAC system due to non-compliance with security policies.

What should be your next course of action?

Investigate the root cause of the frequent non-compliance and address it.

94
New cards

Which of the following applies the appropriate policies in order to provide a device with the access it's defined to receive?

Authorization

95
New cards

Which of the following defines all the prerequisites a device must meet in order to access a network?

Authentication

96
New cards

Which of the steps in the Network Access Control (NAC) implementation process occurs once the policies have been defined?

Apply

97
New cards

Which of the following NAC agent types would be used for IoT devices?

Agentless

98
New cards

A major software vendor becomes aware of a new zero-day vulnerability in one of its products due to an anonymous tip. The vulnerability could potentially allow unauthorized access to sensitive data stored in the software.

The vendor is currently creating a patch to address the issue.

Which of the following BEST describes the current risk to the software users and the appropriate response from the software vendor?

The risk to the users is significant, and the vendor should quietly create a patch without informing the users until it is ready.

99
New cards

In the context of information security, an organization discovers a zero-day vulnerability in its database software.

At the same time, a known hacking group has expressed intentions to target entities using this specific software.

Which of the following BEST describes this situation's relation to vulnerability, threat, and risk?

The organization increases its risk of a security breach due to the threat and vulnerability.

100
New cards

In a rapidly evolving IT environment, a cloud service provider offers various services to businesses, enabling them to store and process data securely. To enhance security, the provider regularly updates its systems and software.

Despite these efforts, a security researcher discovers a previously unknown vulnerability in one of the cloud-specific applications, leaving customer data exposed to potential threats.

In this scenario, which vulnerability is the security researcher likely to have found in the cloud-specific application?

Zero-day vulnerability