1/118
5.0 Network Architecture: Sec 5.1 – 5.8
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
You are a network engineer for a large corporation that is planning to implement a new intrusion detection system (IDS). The corporation has a high volume of network traffic and requires real-time monitoring for potential security threats.
Which of the following approaches to integrating the IDS into the corporation's network would best meet these requirements?
Using a Test Access Point (TAP) device to provide the IDS with a copy of the network traffic.
You are a network architect for a large organization. The organization is planning to upgrade its network infrastructure to support a new business application. The application requires high availability, secure data transfer, and efficient handling of large data volumes.
Which of the following network design considerations best aligns with the requirements of the new business application?
Implementing a layered network design based on the OSI model with appropriate security controls at each layer.
You are a network engineer for a global company that is implementing a new real-time data processing system. This system requires efficient and reliable data transfer between different network segments.
Which of the following network components would be most critical in ensuring the efficient and reliable transfer of real-time data in this scenario?
Transport protocols
You are a network engineer for a multinational corporation. The corporation is planning to expand its operations to a new location and you are tasked with designing the network for the new site. The network should be robust, scalable, and secure.
Which of the following approaches to setting up network nodes at the new site would best meet these requirements?
Setting up multiple network nodes, each dedicated to a specific function such as routing, switching, and firewalling.
A small start-up has recently launched its first web application. To ensure high availability and to handle potential traffic spikes, the start-up decides to implement a load balancer in its network infrastructure.
The network technician must secure the load balancer against basic threats.
What is the fundamental step the network technician should take to secure the load balancer?
Disable unnecessary services on the load balancer.
The IT manager of a medium-sized organization is designing a new network infrastructure to secure its enterprise infrastructure by implementing an Intrusion Prevention System (IPS) and an Intrusion Detection System (IDS). The manager is considering different deployment methods for the IPS/IDS to optimize their effectiveness.
The organization's network includes multiple security zones, a virtual private network (VPN) for remote access, and a web application firewall (WAF).
Which deployment method provides the MOST comprehensive protection in this scenario?
Deploy the IPS/IDS devices in inline mode at the network perimeter.
An organization implements a new network infrastructure and plans to use an intrusion prevention system (IPS) for security. The IT manager wants to ensure that the IPS will continue to let traffic flow if it fails.
Which failure mode should the IT manager configure the IPS?
Fail-open
A hospital has implemented a security device that processes sensitive patient information. The hospital wants to ensure that in the event of a failure, the confidentiality and integrity of the patient data take priority over the system's availability.
What should the hospital set as the failure mode configuration for this security device?
The security device should be configured to fail-closed.
You are a cybersecurity specialist for a financial institution that is planning to enhance its network security. The institution has decided to adopt a defense in depth strategy.
Which of the following approaches would BEST align with a defense in-depth strategy?
Implementing multiple security measures at different network layers, including firewalls, intrusion detection systems, and regular patch management.
You are a network architect for a rapidly growing startup. The startup is planning to expand its operations and is considering a major upgrade to its network architecture.
Which of the following factors should be your primary consideration when designing the new network architecture?
Balancing costs, compute and responsiveness, scalability, availability, and resilience.
You are a network security engineer for a large corporation. The company is planning to launch a new software product and wants to provide customer access to this product over the internet.
The company also wants to ensure that the internal production network remains secure.
Which type of common security zone would be the MOST appropriate to implement in this scenario?
Screened Subnet
A company wants to set up a private network that employs internet information services for internal use only, including web servers and email servers that are used by company employees.
What type of network is the company planning to set up?
Intranet
A proxy server can be configured to do which of the following?
Restrict users on the inside of a network from getting out to the internet.
What is the main role of a load balancer in network security?
To distribute network traffic across multiple servers.
You have configured a security device in your network to fail-closed.
Which of the following will happen when an attack occurs?
The device will block access or enter the most secure state available when it fails.
You are implementing security at a local high school that is concerned with students accessing inappropriate material on the internet from the library's computers. The students use the computers to search the internet for research paper content. The school budget is limited.
Which content filtering option would you choose?
Restrict content based on content categories.
You are the office manager of a small financial credit business. Your company handles personal financial information for clients seeking small loans over the internet. You are aware of your obligation to secure clients records, but the budget is an issue for your company.
Which item would provide the BEST security for this situation?
All-in-one security appliance
You are a cybersecurity specialist at a large corporation. Your company has been experiencing an increase in cyber attacks recently. To better understand the tactics and techniques of the attackers, you have decided to set up a honeynet.
Which of the following is the BEST way to set up and use a honeynet?
Set up the honeynet with decoy systems and monitor it for attacker activity.
You are the cybersecurity lead at a large corporation. Recently, your organization has been experiencing an increase in SMTP-based attacks such as open relay, DDoS, and spam attacks. You need to devise a strategy to not only mitigate these attacks but also gather information about the attackers' tactics.
Which of the following would be the BEST solution?
Set up an email honeypot designed to attract and trap these types of attacks.
Which of the following is a limitation of using a DNS sinkhole as a cybersecurity measure?
DNS sinkholes are ineffective if the malware uses a public DNS server or its own DNS server.
Which of the following is the BEST solution to allow access to private resources from the internet?
VPN
Which of the following is another name for a firewall that performs router functions?
Screening router
Which of the following is the MOST likely to happen if the firewall managing traffic into the screened subnet fails?
Only the servers in the screened subnet are compromised, but the LAN will stay protected.
Of the following security zones, which one can serve as a buffer network between a private secured network and the untrusted internet?
Screened subnet
In which of the following situations would you MOST likely implement a screened subnet?
You want to protect a public web server from attack.
You have used firewalls to create a demilitarized zone. You have a web server that needs to be accessible to internet users. The web server must communicate with a database server for retrieving product, customer, and order information.
How should you place devices on the network to BEST protect the servers? (Select two.)
Put the database server on the private network; Put the web server inside the screened subnet
What needs to be configured on a firewall to allow traffic directed to the public resource in the screened subnet?
Packet filters
How many network interfaces does a dual-homed gateway typically have?
3
You have a company network that is connected to the internet. You want all users to have internet access, but you need to protect your private network and users. You also need to make a web server publicly available to internet users.
Which solution should you use?
Use firewalls to create a screened subnet. Place the web server inside the screened subnet and the private network behind the screened subnet.
Which of the following terms describes a network device that is exposed to attacks and has been hardened against those attacks?
Bastion or sacrificial host
The security team in a financial organization identified a zero-day vulnerability attack that enables cross-site scripting (XSS) attacks on its internal web portal. The chief information security officer (CISO) instructs the team to take immediate action.
Which action MOST effectively minimizes the threat from the zero-day vulnerability and the potential XSS attacks?
Implement a web application firewall (WAF).
Which of the following are characteristics of a basic packet-filtering firewall? (Select two.)
Stateless; Filters IP address and port
Which of the following BEST describes a stateful inspection?
Determines the legitimacy of traffic based on the state of the connection from which the traffic originated.
When designing a firewall, what is the recommended approach for opening and closing ports?
Close all ports; open only ports required by applications inside the network.
You have just installed a packet-filtering firewall on your network.
Which options are you able to set on your firewall? (Select three.)
Source address of a packet; Destination address of a packet; Port number
A network security administrator's responsibilities include enhancing the enterprise's network infrastructure security posture. They deploy a Next Generation Firewall (NGFW) as part of their defense strategy.
The enterprise mixes internal and external services, including a web application and a virtual private network (VPN) for remote access.
Which of the following should the administrator primarily consider when implementing the NGFW to ensure effective security without disrupting normal operations?
Deploy the NGFW in inline mode, ensuring it analyzes all traffic while maintaining connectivity.
You have been given a laptop to use for work. You connect the laptop to your company network, use it from home, and use it while traveling.
You want to protect the laptop from internet-based attacks.
Which solution should you use?
Host-based firewall
A cyber team implements new hardening techniques after a data loss prevention (DLP) audit revealed increased data exfiltration.
What is a tenet of host-based firewalls?
It provides controls for incoming and outgoing network traffic.
Which of the following are features of an application-level gateway? (Select two.)
Reassembles entire messages; Stops each packet at the firewall for inspection
Which of the following describes how access control lists can be used to improve network security?
An access control list filters traffic based on the IP header information, such as source or destination IP address, protocol, or socket number.
Which VPN tunnel style routes only certain types of traffic?
Split
Which VPN implementation uses routers on the edge of each site?
Site-to-site VPN
A VPN is primarily used for which of the following purposes?
Support secured communications over an untrusted network
The IT department in a large multinational corporation faces challenges managing secure communications for remote desktop connections. The increasing number of remote employees has made it essential to ensure that their remote desktop connections are secure. The IT department is considering various measures to establish secure communication.
Given the challenges the corporation faces, what approach should the IT department adopt to ensure secure communications for remote desktop connections while maintaining the manageability and performance of the enterprise infrastructure?
Implement TLS for all remote desktop connections
Which VPN protocol typically employs IPsec as its data encryption mechanism?
L2TP
Which statement BEST describes IPsec when used in tunnel mode?
The entire data packet, including headers, is encapsulated
Which of the following is commonly used in the first phase of Internet Key Exchange (IKE) negotiations for authenticating the identity of peers?
Digital certificates
A network engineer has the task of creating a remote access solution for a global enterprise. The solution should secure encrypted communication for the company's employees worldwide and detect potential security threats in real time.
Which configuration should the network engineer deploy to meet these requirements?
A VPN utilizing IKE and IPSec protocols, combined with an inline intrusion detection system (IDS)
In addition to Authentication Header (AH), IPSec is comprised of what other service?
Encapsulating Security Payload (ESP)
A salesperson in your organization spends most of her time traveling between customer sites. After a customer visit, she must complete various managerial tasks, such as updating your organization's order database.
Because she rarely comes back to your home office, she usually accesses the network from her notebook computer using Wi-Fi access provided by hotels, restaurants, and airports.
Many of these locations provide unencrypted public Wi-Fi access, and you are concerned that sensitive data could be exposed. To remedy this situation, you decide to configure her notebook to use a VPN when accessing the home network over an open wireless connection.
Which key steps should you take when implementing this configuration? (Select two.)
Configure the browser to send HTTPS requests through the VPN connection; Configure the VPN connection to use IPsec
Which of the following BEST describes zero-trust security?
Only devices that pass both authentication and authorization are trusted.
An international business is experiencing an increase in remote work scenarios, resulting in a significant rise in employees using personal devices and smart appliances for work.
This development raises potential issues related to unauthorized network access and adherence to security standards.
Which of the following solutions MOST effectively addresses these security issues?
Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.
A large enterprise recently introduced a bring your own device (BYOD) policy and is seeing an uptick in the use of Internet of Things (IoT) devices in the office.
Concerns about unauthorized network access and compliance with security standards accompany these changes.
Assess the following options and determine the MOST suitable strategy to alleviate these security concerns.
Deploy agent-based Network Access Control (NAC) with dynamic Virtual Local Area Networks (VLANs) and firewall integration.
You are part of a committee that is meeting to define how Network Access Control (NAC) should be implemented in the organization.
Which step in the NAC process is this?
Plan
In a Network Access Control (NAC) system, a nonpersistent (or dissolvable) agent is used during the posture assessment process.
Which of the following statements about a nonpersistent NAC agent is true?
A nonpersistent agent is loaded into memory during posture assessment but is not installed on the device.
As a network administrator, you have implemented a Network Access Control (NAC) system with automatic remediation capabilities in your organization.
One day, you notice that a significant number of devices are being quarantined frequently by the NAC system due to non-compliance with security policies.
What should be your next course of action?
Investigate the root cause of the frequent non-compliance and address it.
Which of the following applies the appropriate policies in order to provide a device with the access it's defined to receive?
Authorization
Which of the following defines all the prerequisites a device must meet in order to access a network?
Authentication
Which of the steps in the Network Access Control (NAC) implementation process occurs once the policies have been defined?
Apply
Which of the following NAC agent types would be used for IoT devices?
Agentless
A major software vendor becomes aware of a new zero-day vulnerability in one of its products due to an anonymous tip. The vulnerability could potentially allow unauthorized access to sensitive data stored in the software.
The vendor is currently creating a patch to address the issue.
Which of the following BEST describes the current risk to the software users and the appropriate response from the software vendor?
The risk to the users is significant, and the vendor should quietly create a patch without informing the users until it is ready.
In the context of information security, an organization discovers a zero-day vulnerability in its database software.
At the same time, a known hacking group has expressed intentions to target entities using this specific software.
Which of the following BEST describes this situation's relation to vulnerability, threat, and risk?
The organization increases its risk of a security breach due to the threat and vulnerability.
In a rapidly evolving IT environment, a cloud service provider offers various services to businesses, enabling them to store and process data securely. To enhance security, the provider regularly updates its systems and software.
Despite these efforts, a security researcher discovers a previously unknown vulnerability in one of the cloud-specific applications, leaving customer data exposed to potential threats.
In this scenario, which vulnerability is the security researcher likely to have found in the cloud-specific application?
Zero-day vulnerability