Chapter 7 Flashcards

Share

1
Q

An enterprise-wide VPN can include elements of both the client-to-site and site-to site models.

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

After L2TP establishing a VPN tunnel, GRE is used to transmit L2TP data frames through the tunnel.

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PPP can support several types of Network layer protocols that might use the connection.

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A community cloud is a service shared between multiple organizations, but not available publicly.

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A Type 2 hypervisor installs on a computer before any OS, and is therefore called a bare-metal hypervisor.

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Office 365 is an example of an SaaS implementation with a subscription model

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Digital certificates are issued, maintained, and validated by an organization called a certificate authority (CA).

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The HTTPS (HTTP Secure) protocol utilizes the same TCP port as HTTP, port 80.

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

FTPS (FTP Security or FTP Secure) and SFTP (Secure FTP) are two names for the same protocol.

True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The Virtual Network Computing (VNC) application uses the cross-platform remote frame buffer (RFB) protocol.

True
False

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which type of cloud service model involves hardware services that are provided virtually, including network infrastructure devices such as virtual servers?

IaaS
PaaS
SaaS
XaaS

A

IaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What cloud service model involves providing applications through an online user interface, providing for compatibility with a multitude of different operating systems and devices?

IaaS
PaaS
SaaS
XaaS

A

SaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of scenario would be best served by using a Platform as a Service (PaaS)
cloud model?

A group of developers needs access to multiple operating
systems and the runtime libraries that the OS provides

An organization wishes to gain access to applications through
an online user interface, while maintaining compatibility across
operating systems

An organization needs to have a hosted virtual network
infrastructure for their services, which are run on virtual
machines

A small organization needs to have high availability for their web
server

A

A group of developers needs access to multiple operating systems and the runtime libraries that the OS provides

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When using public and private keys to connect to an SSH server from a Linux device, where must your public key be placed before you can connect?

In an authorization file under your home directory on your
computer

In an authorization file on the host where the SSH server is

In the /etc/ssh/keys folder

In the /var/run/ssh/public folder

A

In an authorization file on the host where the SSH server is

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The combination of a public key and a private key are known by what term below?

key set
key team
key pair
key tie

A

key pair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What security encryption protocol requires regular re-establishment of a connection and can be used with any type of TCP/IP transmission?

L2TP
TLS
IPsec
SSL

A

IPsec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

At what layer of the OSI model does the IPsec encryption protocol operate?

Physical layer
Network layer
Transport layer
Application layer

A

Network layer

18
Q

The PPP headers and trailers used to create a PPP frame that encapsulates Network layer packets vary between 8 and 10 bytes in size due to what field?

priority
FCS
FEC
encryption

A

FCS

19
Q

When using a site-to-site VPN, what type of device sits at the edge of the LAN and establishes the connection between sites?

VPN proxy
VPN server
VPN transport
VPN gateway

A

VPN gateway

20
Q

Amazon and Rackspace both utilize what virtualization software below to create their cloud environments?

VMware vSphere
Oracle VirtualBox
Parallels
Citrix Xen

A

Citrix Xen

21
Q

What open-source VPN protocol utilizes OpenSSL for encryption and has the ability
to possibly cross firewalls where IPsec might be blocked?

Layer 2 Tunneling Protocol (L2TP)

Point-to-Point Tunneling Protocol (PPTP)

Generic Routing Encapsulation (GRE)

OpenVPN

A

OpenVPN

22
Q

VMware Player and Linux KVM are both examples of what type of hypervisor?

Type 1 hypervisor
Type 2 hypervisor
barebones hypervisor
bare-metal hypervisor

A

Type 2 hypervisor

23
Q

Which statement regarding the use of a bridged mode vNIC is accurate?

The vNIC will its own IP address on the physical LAN

The vNIC will be assigned a NAT-ed IP address

The vNIC will only be able to communicate across the bridge to
the host PC

The vNIC will utilize the host PC’s IP address.

A

The vNIC will its own IP address on the physical LAN

24
Q

When is it appropriate to utilize the NAT network connection type?

Only when the VM requires an IP address on the physical LAN

Whenever the VM does not need to be access at a known
address by other network nodes

Only if the VM does not need to communicate with the host PC

Only if the VM is intended for VM-to-host communications.

A

Whenever the VM does not need to be access at a known address by other network nodes.

25
Q

By default, what network connection type is selected when creating a VM in VMware, VirtualBox, or KVM?

host-only mode
bridged mode
NAT mode
lockdown mode

A

NAT mode

26
Q

Which statement regarding the IKEv2 tunneling protocol is accurate?

IKEv2 is an older, Layer 2 protocol developed by Microsoft that
encapsulates VPN data frames

IKEv2 is based on technology developed by Cisco and
standardized by the IETF

IKEv2 is an open-source VPN protocol that utilizes OpenSSL for
encryption

IKEv2 offers fast throughput and good stability when moving
between wireless hotspots

A

IKEv2 offers fast throughput and good stability when moving between wireless hotspots

27
Q

The use of certificate authorities to associate public keys with certain users is known by what term?

public-key organization
certified infrastructure
public-key infrastructure
symmetric identification

A

public-key infrastructure

28
Q

What is NOT a potential disadvantage of utilizing virtualization?

Multiple virtual machines contending for finite resources can
compromise performance

Increased complexity and administrative burden can result from
the use of virtual machines

Licensing costs can be high due to every instance of
commercial software requiring a separate license

Virtualization software increases the complexity of backups,
making creation of usable backups difficult

A

Virtualization software increases the complexity of backups, making creation of usable backups difficult

29
Q

A vSwitch (virtual switch) or bridge is a logically defined device that operates at what layer of the OSI model?

Layer 1
Layer 2
Layer 4
Layer 7

A

Layer 2

30
Q

Which of the following virtualization products is an example of a bare-metal hypervisor?

Citrix XenServer
VirtualBox
VMware Player
Linux KVM

A

Citrix XenServer

31
Q

In a software defined network, what is responsible for controlling the flow of data?

flow director
vRouter
SDN controller
SDN switch

A

SDN controller

32
Q

What term is used to describe a space that is rented at a data center facility by a service provider?

point of presence (PoP)
service location (SL)
central service point (CSP)
locally exchanged data point (ledp)

A

point of presence (PoP)

33
Q

Which of the following statements regarding the Point-to-Point (PPP) protocol is NOT accurate?

PPP can negotiate and establish a connection between two
endpoints

PPP can utilize an authentication protocol, such as MS-CHAPv2
or EAP to authenticate a client

PPP can support several Network layer protocols, such as IP,
that might use the connection

PPP can support strong encryption, such as AH or ESP

A

PPP can support strong encryption, such as AH or ESP

34
Q

Why is the telnet utility a poor choice for remote access to a device?

It provides no mechanism for authentication

It does not allow for control of a computer remotely

It cannot be used over a public WAN connection

It provides poor authentication and no encryption

A

It provides poor authentication and no encryption

35
Q

What statement regarding the SSH (Secure Shell) collection of protocols is accurate?

SSH provides a graphical view of the remote computer

SSH does not protect against DNS spoofing

SSH does not protect against IP spoofing

SSH supports port forwarding

A

SSH supports port forwarding

36
Q

In order to generate a public and private key for use with SSH, what command line utility should you use?

ssh-keygen
key-generate
ssh-newkey
gpg –ssh

A

ssh-keygen

37
Q

Regarding VNC (Virtual Network Computing or Virtual Network Connection), what statement is accurate?

VNC is faster than Remote Desktop, and requires less network
bandwidth

VNC is open source, allowing companies to develop their own
software based on VNC

VNC uses the Remote Desktop Protocol (RDP)

VNC is a standard developed by Microsoft and used by
Windows Remote Desktop

A

VNC is open source, allowing companies to develop their own software based on VNC

38
Q

Which file transfer protocol has no authentication or security for transferring files, uses UDP, and requires very little memory to use?

File Transfer Protocol (FTP)
FTP Secure (FTPS)
Secure FTP (SFTP)
Trivial FTP (TFTP)

A

Trivial FTP (TFTP)

39
Q

What special enterprise VPN supported by Cisco devices creates VPN tunnels between branch locations as needed rather than requiring constant, static tunnels?

Dynamic Multipoint VPN
Dynamic SmartVPN
Symmetric VPN Autodial
Auto Switched VPN Service

A

Dynamic Multipoint VPN

40
Q

Which of the following is NOT a task that a VPN concentrator is responsible for?

A VPN concentrator authenticates VPN clients

A VPN concentrator establishes tunnels for VPN connections

A VPN concentrator shuts down established connections when
malicious traffic occurs

A VPN concentrator manages encryption for VPN transmissions

A

A VPN concentrator shuts down established connections with malicious traffic occurs