Ch.7 Flashcards

1
Q

a monitoring technique used by an intrusion detection system (IDS) that creates a baseline of normal activities and compares actions against the baseline. Whenever there is a significant deviation from this baseline, an alarm is raised

A

anomaly-based monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

a firewall that can identify the applications that send packets through the firewall and then make decisions about the applications

A

application-aware firewall

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

a specialized intrusion detection system (IDS) that is capable of using “contextual knowledge” in real time

A

application-aware IDS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

an intrusion prevention system (IPS) that knows information such as the applications that are running as well as the underlying operating systems

A

application-aware IPS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

a special proxy server that knows the application protocols that it supports

A

application-aware proxy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

a monitoring technique used by an IDS that uses the normal processes and actions as the standard and compares actions against it

A

behavior-based monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

searching incoming web content to match keywords

A

content inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

a defense that uses multiple types of security devices to protect a network. Also called LAYERED SECURITY

A

defense in depth

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

a separate network that rests outside the secure network perimeter: untrusted outside users can access the DMZ but cannot enter the secure network

A

demilitarized zone (DMZ)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

a set of individual instructions to control the actions of a firewall

A

firewall rules

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

a monitoring technique used by an intrusion detection system (IDS) that uses an algorithm to determine if a threat exists

A

heuristic monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

a software-based application that runs on a local host computer that can detect an attack as it occurs

A

host-based intrusion detection system (HIDS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

a device that detects an attack as it occurs

A

intrusion detection system (IDS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

a defense that uses multiple types of security devices to protect a network. Also called DEFENSE IN DEPTH

A

layered security

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

a dedicated network device that can direct requests to different servers based on a variety of factors

A

load balancer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

searching for malware in incoming web content

A

malware inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

a technique that examines the current state of a system or network device before it is allowed to connect to the network

A

network access control (NAC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

a technique that allows private IP addresses to be used on the public Internet

A

network address translation (NAT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

a technology that monitors network traffic to immediately react to block a malicious attack

A

network intrusion prevention system (NIPS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

hardware or software that captures packets to decode and analyze their contents

A

protocol analyzer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

a computer or an application program that intercepts user requests from the internal secure network and then processes those requests on behalf of the user

A

proxy server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

any combination of hardware and software that enables remote users to access a local internal network

A

remote access

23
Q

a computer or an application program that routes incoming requests to the correct server

A

reverse proxy

24
Q

a device that can forward packets across computer networks

A

router

25
Q

a monitoring technique used by an intrusion detection system (IDS) that examines network traffic to look for well-known patterns and compares that activities against a predefined signature

A

signature-based monitoring

26
Q

a technique that uses IP addresses to divide a network into network, subnet, and host

A

subnetting (subnet addressing)

27
Q

a device that connects network segments and forwards only frames intended for that specific device or frames sent to all devices

A

switch

28
Q

network hardware that provides multiple security functions

A

unified threat management (UTM)

29
Q

restricting access to unapproved websites

A

URL filtering

30
Q

a technology that allows scattered users to be logically grouped together even though they may be attached to different switches

A

virtual LAN (VLAN)

31
Q

a technology that enables use of an unsecured public network as if it were a secure private network

A

virtual private network (VPN)

32
Q

a device that aggregates VPN connections

A

VPN concentrator

33
Q

a special type of application-aware firewall that looks at the applications using HTTP

A

web application firewall

34
Q

a device that can block malicious content in real time as it appears (without first knowing the URL of a dangerous site).

A

web security gateway

35
Q
  1. Which secure feature does a load balancer NOT provide?

a. hide HTTP error pages
b. remove server identification headers from HTTP responses
c. filter packets based on protocol settings
d. block denial-of-service (DoS) attacks

A

C

36
Q
  1. Which of these would NOT be a filtering mechanism found in a firewall rule?

a. source address
b. date
c. protocol
d. direction

A

b

37
Q
  1. A(n)_____ can identify the application that send packets and then make decisions about filtering based on it.

a. application-aware firewall
b. reverse proxy
c. Internet content filter
d. web security gateway

A

a

38
Q
  1. Which function does an Internet content filter NOT perform?

a. URL filtering
b. malware inspection
c. content inspection
d. intrusion detection

A

d

39
Q
  1. How does network address translation (NAT) improve security?

a. it discards unsolicited packets
b. it filters based on protocol
c. it masks the IP address of the NAT device
d. NATs do not improve security

A

A

40
Q
  1. How does a virtual LAN (VLAN) allow devices to be grouped?

a. based on subnets
b. logically
c. directly to hubs
d. only around core switches

A

b

41
Q
  1. Which device is easiest for an attacker to take advantage of in order to capture and analyze packets?

a. hub
b. switch
c. router
d. load balancer

A

a

42
Q
  1. Which of these is NOT an attack against a switch?

a. MAC address impersonation
b. ARP poisoning
c. MAC flooding
d. ARP impersonation

A

d

43
Q
  1. Which statement regarding a demilitarized zone (DMZ) is NOT true?

a. It can be configured to have one or two firewalls
b. It provides an extra degree of security
c. It typically includes an email or web server
d. It contains servers that are used only by internal network users

A

d

44
Q
  1. Which statement about network address translation (NAT) is true?

a. It can be stateful or stateless
b. It substitutes MAC addresses for IP addresses
c. It removes private addresses when the packet leaves the network
d. It can be found only on core routers

A

c

45
Q
  1. Which of these is NOT an advantage of a load balancer?

a. The risk of overloading a desktop client is reduced
b. Network hosts can benefit from having optimized bandwidth
c. Network downtime can be reduced
d. DoS attacks can be detected and stopped

A

a

46
Q
  1. A (n)___________intercepts internal user requests and then processes those requests on behalf of the users.

a. content filter
b. host detection server
c. proxy server
d. Intrusion prevention device

A

C

47
Q
  1. A reverse proxy _____.

a. only handles outgoing request
b. is the same as a proxy server
c. must be used together with a firewall
d. routes incoming requests to the correct server

A

d

48
Q
  1. Which is the preferred location for installation of a spam filter?

a. on the POP3 server
b. with the SMTP server
c. on the local host client
d. on the proxy server

A

b

49
Q
  1. A _____ watches for attacks and sounds an alert only when one occurs.

a. firewall
b. network intrusion prevention system (NIPS)
c. proxy intrusion device
d. network intrusion detection system (NIDS)

A

d

50
Q
  1. A multipurpose security device is known as _____.

a. Cohesive Attack Management System (Co-AMS)
b. Proxy Security System (PSS)
c. Intrusion Detection/Prevention (ID/P)
d. Unified Threat Management (UTM)

A

d

51
Q
  1. Each of these can be used to hide information about the internal network EXCEPT _____.

a. a protocol analyzer
b. subnetting
c. a proxy server
d. network address translation (NAT)

A

a

52
Q
  1. What is the difference between a network intrusion detection system (NIDS) and a network intrusion prevention system (NIPS)?

a. There is no difference; a NIDS and a NIPS are equal
b. A NIPS can take actions more quickly to combat an attack
c. A NIDS provides more valuable information about attacks
d. A NIPS is much slower because it uses protocol analysis

A

b

53
Q
  1. If a device is determined to have an out-of-date virus signature file, then Network Access Control (NAC) can redirect that device to a network by ______.

a. a Trojan horse
b. TCP/IP hijacking
c. Address Resolution Protocol (ARP) poisoning
d. DHCP man-in-middle

A

c

54
Q
  1. A firewall using ______ is the most secure type of firewall.

a. stateful packet filtering
b. network intrusion detection system replay
c. stateless packet filtering
d. reverse proxy analysis

A

a