Back to overview

CompTIA Securtiy+ Set10 A_3_1_Secure_Network_Design

CompTIA Securtiy+ Set10 A_3_1_Secure_Network_Design

Subject
Sciences / Computer science
Language of creation
English
34 flashcards No ratings yet 0 views
Add to my sets

Sign in to add this set to your collection. You will return here afterwards.

Cards in this set

Card 21

Question

0637
A company is planning to build an internal website that allows for access to outside contractors and partners. A
majority of the content will only be to internal employees with the option to share.

Which of the following concepts is MOST appropriate?

Answer

  • VPN
  • Proxy
  • DMZ
  • Extranet

Card 22

Question

0648
Which of the following differentiates ARP poisoning from a MAC spoofing attack?

Answer

  • ARP poisoning uses unsolicited ARP replies.
  • ARP poisoning overflows a switch's CAM table.
  • MAC spoofing uses DHCPOFFER/DHCPACK packets.
  • MAC spoofing can be performed across multiple routers.

Card 23

Question

0651
A company has just completed a vulnerability scan of its servers. A legacy application that monitors the HVAC
system in the datacenter presents several challenges, as the application vendor is no longer in business.

Which of the following secure network architecture concepts would BEST protect the other company servers if the
legacy server were to be exploited?

Answer

  • Virtualization
  • Air gap
  • VLAN
  • Extranet

Card 24

Question

0690
Which of the following enables sniffing attacks against a switched network?

Answer

  • ARP poisoning
  • IGMP snooping
  • IP spoofing
  • SYN flooding

Card 25

Question

0721
A network technician is designing a network for a small company. The network technician needs to implement an
email server and web server that will be accessed by both internal employees and external customers. Which of
the following would BEST secure the internal network and allow access to the needed servers?

Answer

  • Implementing a site-to-site VPN for server access.
  • Implementing a DMZ segment for the server.
  • Implementing NAT addressing for the servers.
  • Implementing a sandbox to contain the servers.

Card 26

Question

0727
An organization has air gapped a critical system.

Which of the following BEST describes the type of attacks that are prevented by this security measure?

Answer

  • Attacks from another local network segment
  • Attacks exploiting USB drives and removable media
  • Attacks that spy on leaked emanations or signals
  • Attacks that involve physical intrusion or theft

Card 27

Question

0877
A network administrator at a large organization is reviewing methods to improve the security of the wired LAN.
Any security improvement must be centrally managed and allow corporate-owned devices to have access to the
intranet but limit others to Internet access only. Which of the following should the administrator recommend?

Answer

  • 802.1X utilizing the current PKI infrastructure
  • SSO to authenticate corporate users
  • MAC address filtering with ACLs on the router
  • PAM for users account management

Card 28

Question

0893
While reviewing the wireless router, the systems administrator of a small business determines someone is
spoofing the MAC address of an authorized device. Given the table below:

Host      IP                       Mac 

pc1       192.168.1.20       00 1e 1b 43 21 b2

pc2       192.168.1.20       31 1c 3c 13 25 c4

pc3       192.168.1.20       20 a2 22 45 11 d2

unknown  192.168.1.20   12 44 b2 ff a1 22

Which of the following should be the administrator’s NEXT step to detect if there is a rogue system without
impacting availability?

Answer

  • Conduct a ping sweep.
  • Physically check each system.
  • Deny Internet access to the “UNKNOWN” hostname.
  • Apply MAC filtering.

Card 29

Question

0914
After segmenting the network, the network manager wants to control the traffic between the segments. Which of
the following should the manager use to control the network traffic?

 

Answer

  • A DMZ
  • A VPN
  • A VLAN
  • An ACL

Card 30

Question

0945
Which of the following types of attack is being used when an attacker responds by sending the MAC address of the
attacking machine to resolve the MAC to IP address of a valid server?

Answer

  • Session hijacking
  • IP spoofing
  • Evil twin
  • ARP poisoning

Card 31

Question

0948

A security analyst has received several reports of an issue on an internal web application. Users state they are
having to provide their credentials twice to log in. The analyst checks with the application team and notes this is
not an expected behavior. After looking at several logs, the analyst decides to run some commands on the
gateway and obtains the following output:

internet adr           physical address  type

192.168.1.1          ff ec ab 00 aa 78  dynamic

192.168.1.5          ff 00 5e 48 00 fb  dynamic

192.168.1.8          00 0c 29 1a e7 fa  dynamic

192.168.1.10        fc 41 5e 48 00 ff  dynamic

224.215.54.47      ff 00 5e 48 00 fb  dynamic

Which of the following BEST describes the attack the company is experiencing?

 

Answer

  • MAC flooding
  • URL redirection
  • ARP poisoning
  • DNS hijacking

Card 32

Question

0949
A system in the network is used to store proprietary secrets and needs the highest level of security possible. Which
of the following should a security administrator implement to ensure the system cannot be reached from the
Internet?

Answer

  • VLAN
  • Air gap
  • NAT
  • Firewall

Card 33

Question

0993
A security administrator is adding a NAC requirement for all VPN users to ensure the connecting devices are
compliant with company policy. Which of the following items provides the HIGHEST assurance to meet this
requirement?

Answer

  • Implement a permanent agent.
  • Install antivirus software.
  • Use an agentless implementation.
  • Implement PKI.

Card 34

Question

1014
A technician is auditing network security by connecting a laptop to open hardwired jacks within the facility to
verify they cannot connect. Which of the following is being tested?

Answer

  • Port security
  • Layer 3 routing
  • Secure IMAP
  • S/MIME

How to use this set

Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.