Question 22 (practice exam 12)

Q: What type of log would be most useful for confirming the presence of a rogue access point on a corporate network? A: Switch log

Q: Why is a switch log helpful in detecting a rogue access point? A: A rogue access point must physically connect to the network, which can be identified by analyzing switch interface activity and MAC addresses.

Q: Which of the following would NOT be effective for detecting a rogue access point? A: UTM (Unified Threat Management) log

Q: Why would a UTM log be ineffective for identifying a rogue access point? A: From the UTM's perspective, traffic from a rogue access point would appear similar to other network traffic.

Q: What is the purpose of a WAF (Web Application Firewall)? A: To secure web applications, not to detect rogue access points on the network.

Q: Which type of log is focused on preventing data loss, rather than identifying rogue devices? A: DLP (Data Loss Prevention) log

Q: What is a key reason for analyzing switch logs when investigating potential rogue access points? A: To identify any new devices and MAC addresses that have connected to the network.