CCNA 5.0 - Security Fundamentals Flashcards

1
Q

True or false: TACACS+ is Cisco-proprietary.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What port/protocol does TACACS+ use?

A

TCP 49

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What port/protocol does RADIUS use?

A

UDP 1812 and 1813

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What global command hides passwords in the config?

A

service password-encryption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

If neither an enable password or secret is configured, what will console users experience?

A

They’ll be able to go straight from user exec to privileged exec without having to put in a password.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

If neither an enable password or secret is configured, what will telnet/SSH users experience?

A

Their session requests will be rejected.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the default hashing method on a Cisco device?

A

Message Digest 5 (MD5)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What does the 7 indicate in “enable secret 7…”?

A

The password has been encrypted, not hashed, and can be retrieved with special tools. (Vigenere cypher)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does the 8 indicate in “enable secret 8…”?

A

SHA-256 was used to hash the password

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What does the 9 indicate in “enable secret 9…”?

A

The password was hashed with Scrypt

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What global command allows you to choose the hashing method for enable secret?

A

enable algorithm-type (type) secret (password)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Port security can handle a maximum of how many MAC addresses?

A

132

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the three port security violation modes?

A

Protect, Restrict, Shutdown

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In port security, what does Protect mode do?

A

Drops all traffic that doesn’t match the security configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In port security, what does Restrict mode do?

A

Drops all traffic that doesn’t match the security configuration, and sends log/SNMP messages.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In port security, what does Shutdown mode do?

A

Drops all traffic, sends log/SNMP, and err-disables the port.

17
Q

Which is the default port security violation mode?

18
Q

If one or more ports are shut down due to port security, what global config command can be used to automatically recover?

A

errdisable recovery

19
Q

True or false: port security Protect mode will increment the violation counter even though the port remains up.

A

False - the violation counter will not increment in Protect mode, it will simply drop offending traffic.

20
Q

What two global commands are required to enable DHCP Snooping?

A

1) ip dhcp snooping
2) ip dhcp snooping vlan (number)

21
Q

If a switch is not configured as a DHCP relay agent, what command is also necessary?

A

no ip dhcp snooping information option

22
Q

What interface command should be used if a DoS attack against DHCP snooping is suspected?

A

ip dhcp snooping limit rate (seconds)

23
Q

What global commands are used in conjunction with DHCP snooping limit rate commands?

A

1) errdisable recovery cause dhcp-rate-limit
2) errdisable recovery interval (seconds)

24
Q

True or false: when DHCP snooping is enabled globally, all ports are considered untrusted.

A

True - interfaces must be manually configured to be trusted

25
Q

Which happens first, DHCP or ARP?

26
Q

Dynamic ARP Inspection relies on what other security technology running on a switch?

A

DHCP Snooping

27
Q

Do DHCP Snooping and DAI work in the interface ASIC or the switch CPU?

A

the switch CPU, making both features a vulnerability

28
Q

What global command configures DAI on a VLAN?

A

ip arp inspection vlan (number)

29
Q

What interface command configures a trusted DAI port?

A

ip arp inspection trust

30
Q

What is the difference between IPSec tunnel mode vs transport mode?

A

Tunnel mode is used for site-to-site encryption, in which the entire IP packet including header is encrypted then encapsulated.

Transport mode is for user-level remote access, and only the data is encrypted. The original IP header is used.