Back to overview

CompTIA Securtiy+ Set10 A_3_1_Secure_Network_Design

CompTIA Securtiy+ Set10 A_3_1_Secure_Network_Design

Subject
Sciences / Computer science
Language of creation
English
34 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 1

Question

0062
A company is developing a new secure technology and requires computers being used for development to be
isolated. Which of the following should be implemented to provide the MOST secure environment?

Answer

  • A perimeter firewall and IDS
  • An air gapped computer network
  • A honeypot residing in a DMZ
  • A bastion host
  • An ad hoc network with NAT

Card 2

Question

0120
Which of the following precautions MINIMIZES the risk from network attacks directed at multifunction printers, as
well as the impact on functionality at the same time?
 

Answer

  • Installing a software-based IPS on all devices
  • Isolating the systems using VLANs
  • Enabling full disk encryption
  • Implementing a unique user PIN access function

Card 3

Question

0140
A security administrator is configuring a new network segment, which contains devices that will be accessed by
external users, such as web and FTP server. Which of the following represents the MOST secure way to configure
the new network segment?

Answer

  • The segment should be placed on a separate VLAN, and the firewall rules should be configured to allow external traffic.
  • The segment should be placed in the existing internal VLAN to allow internal traffic only.
  • The segment should be placed on an intranet, and the firewall rules should be configured to allow external traffic.
  • The segment should be placed on an extranet, and the firewall rules should be configured to allow both internal and external traffic.

Card 4

Question

0144
A workstation puts out a network request to locate another system. Joe, a hacker on the network, responds before
the real system does, and he tricks the workstation into communicating with him. Which of the following BEST
describes what occurred?

Answer

  • The hacker used a race condition.
  • The hacker used a pass-the-hash attack.
  • The hacker exploited importer key management.
  • The hacker exploited a weak switch configuration.

Card 5

Question

0172
A security administrator is creating a subnet on one of the corporate firewall interfaces to use as a DMZ which is
expected to accommodate at most 14 physical hosts.
Which of the following subnets would BEST meet the requirements?

Answer

  • 192.168.0.16 255.25.255.248
  • 192.168.0.16/28
  • 192.168.1.50 255.255.25.240
  • 192.168.2.32/27

Card 6

Question

0193
A network administrator wants to ensure that users do not connect any unauthorized devices to the company
network. Each desk needs to connect a VoIP phone and computer.

Which of the following is the BEST way to accomplish this?

Answer

  • Enforce authentication for network devices
  • Enable and configure port channels
  • Configure the phones on one VLAN, and computers on another
  • Make users sign an Acceptable Use Agreement

Card 7

Question

0200
A security engineer is faced with competing requirements from the networking group and database
administrators. The database administrators would like ten application servers on the same subnet for ease of
administration, whereas the networking group would like to segment all applications from one another.


Which of the following should the security administrator do to rectify this issue?

Answer

  • Recommend performing a security assessment on each application, and only segment the applications with the most vulnerability
  • Recommend classifying each application into like security groups and segmenting the groups from one another
  • Recommend segmenting each application, as it is the most secure approach
  • Recommend that only applications with minimal security features should be segmented to protect them

Card 8

Question

0204
A network administrator is attempting to troubleshoot an issue regarding certificates on a secure website. During
the troubleshooting process, the network administrator notices that the web gateway proxy on the local network
has signed all of the certificates on the local machine.

Which of the following describes the type of attack the proxy has been legitimately programmed to perform?

Answer

  • Transitive access
  • Replay
  • Spoofing
  • Man-in-the-middle

Card 9

Question

0258
An attacker uses a network sniffer to capture the packets of a transaction that adds $20 to a gift card. The attacker
then user a function of the sniffer to push those packets back onto the network again, adding another $20 to the
gift card. This can be done many times.

Which of the following describes this type of attack?

Answer

  • Integer overflow attack
  • Smurf attack
  • Replay attack
  • Buffer overflow attack
  • Cross-site scripting attack

Card 10

Question

0277
Which of the following BEST describes an attack where communications between two parties are intercepted and
forwarded to each party with neither party being aware of the interception and potential modification to the
communications?

Answer

  • Spear phishing
  • Man-in-the-middle
  • Transitive access
  • URL hijacking

Card 11

Question

0300
While performing surveillance activities, an attacker determines that an organization is using 802.1X to secure LAN
access.

Which of the following attack mechanisms can the attacker utilize to bypass the identified network security?

Answer

  • MAC spoofing
  • Pharming
  • Xmas attack
  • ARP poisoning

Card 12

Question

0307
A consultant has been tasked to assess a client's network. The client reports frequent network outages. Upon
viewing the spanning tree configuration, the consultant notices that an old and slow performing edge switch on
the network has been elected to be the root bridge.

Which of the following explains this scenario?

Answer

  • The switch also serves as the DHCP server
  • The switch has the lowest MAC address
  • The switch has the fastest uplink port
  • The switch has spanning tree loop protection enabled

Card 13

Question

0327
A company is deploying a new VoIP phone system. They require 99.999% uptime for their phone service and are
concerned about their existing data network interfering with the VoIP phone system. The core switches in the
existing data network are almost fully saturated.

Which of the following options will provide the best performance and availability for both the VoIP traffic, as well
as the traffic on the existing data network?

Answer

  • Put the VoIP network into a different VLAN than the existing data network
  • Upgrade the edge switches from 10/100/1000 to improve network speed
  • Physically separate the VoIP phones from the data network
  • Implement flood guards on the data network

Card 14

Question

0342
Which of the following is the appropriate network structure used to protect servers and services that must be
provided to external clients without completely eliminating access for internal users?

Answer

  • NAC
  • VLAN
  • DMZ
  • Subnet

Card 15

Question

0398
A vice president at a manufacturing organization is concerned about desktops being connected to the network.
Employees need to log onto the desktop’s local account to verify that a product is being created within
specifications; otherwise, the desktops should be as isolated as possible. Which of the following is the BEST way to
accomplish this?

Answer

  • Put the desktops in the DMZ.
  • Create a separate VLAN for the desktops.
  • Air gap the desktops.
  • Join the desktops to an ad-hoc network.

Card 16

Question

0449
A network administrator needs to allocate a new network for the R&D1 group. The network must not be accessible
from the Internet regardless of the network firewall or other external misconfigurations. Which of the following
settings should the network administrator implement to accomplish this?

Answer

  • Use NAT on the R&D network
  • Configure the OS default TTL to 1
  • Implement a router ACL
  • Enable protected ports on the switch

Card 17

Question

0453
An analyst receives an alert from the SIEM showing an IP address that does not belong to the assigned network
can be seen sending packets to the wrong gateway. Which of the following network devices is misconfigured and
which of the following should be done to remediate the issue?

Answer

  • Firewall; implement an ACL on the interface
  • Router; place the correct subnet on the interface
  • Switch; modify the access port to trunk port
  • Proxy; add the correct transparent interface

Card 18

Question

0498
An external attacker can modify the ARP cache of an internal computer. Which of the following types of attacks is
described?

Answer

  • Replay
  • Spoofing
  • DNS poisoning
  • Client-side attack

Card 19

Question

0582
A network administrator is creating a new network for an office. For security purposes, each department should
have its resources isolated from every other department, but be able to communicate back to central servers.
Which of the following architecture concepts would BEST accomplish this?

Answer

  • Air gapped network
  • Load balanced network
  • Network segmentation
  • Network address translation

Card 20

Question

0587
Students at a residence hall are reporting Internet connectivity issues. The university's network administrator
configured the residence hall's network to provide public IP addresses to all connected devices, but many student
devices are receiving private IP addresses due to rogue devices. The network administrator verifies the residence
hall's network is correctly configured and contacts the security administrator for help. Which of the following
configurations should the security administrator suggest for implementation?

Answer

  • Router ACLs
  • Flood guard
  • BPDU guard
  • DHCP snooping

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.