Ch. 10 - Security in Network Design Flashcards

1
Q

To permit I C M P traffic from any IP address or network to any I P address or network

A

access-list acl_2 permit icmp any

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

can be configured to evaluate all log data

Looking for significant events that require attention from the IT staff

A

SIEM (Security Information and Event Management)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Another Cisco command (also used on Arista devices) to secure switch access ports

A

Switchport port-security (or just port-security on Huawei switches)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

On a Juniper switch:

The ____ command restricts the number of MAC addresses allowed in the MAC address table

A

mac-limit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

helps ensure data confidentiality with both encryption and packet authentication by providing:
Message integrity
Encryption

A

CCMP—Short for Counter Mode with CBC (Cipher Block Chaining) MAC (Message Authentication Code) Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Tunnel-based,

Creates an encrypted TLS tunnel between the supplicant and the server

A

PEAP (Protected EAP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A RADIUS server is used in cooperation with an authentication mechanism called

A

EAP (Extensible Authentication Protocol)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly