Comprehensive Security Solutions Flashcards
What separates the authentication and authorization process into three operations? A. XTACACS B. TACACS+ C. TACACS D. RADIUS
B. TACACS+ has added functionality and has extended attribute control and accounting processes. TACACS+ also separates the authentication and authorization process into three processes.
Which of the following is proprietary to Cisco? A. XTACACS B. DIAMETER C. TACACS D. RADIUS
A. XTACACS is proprietary to Cisco.
Which of the following designs uses one packet filtering router between a trusted and untrusted network? A. Screened host B. Screened subnet C. Dual-homed gateway D. Single-tier packet filter
D. A single-tier packet filter design has one packet-filtering router installed between the trusted and untrusted network.
Which of the following correctly represents a broadcast physical address? A. 00 00 0C 34 44 01 01 B. 00 00 FF FF FF C. FF FF FF FF FF FF D. 01 00 0C 34 44 01
C. Broadcast MAC addresses appear as FF FF FF FF FF FF.
You have been asked to examine some network traffic with Wireshark and have noticed that some traffic is addressed to 224.3.9.5. What class of address is this? A. Class C B. Class D C. Class B D. Class A
B. An address of 224.3.9.5 is class D, or multicast, traffic.
You have been scanning a network and have found TCP 53 open. What might you conclude from this? A. DNS is configured for lookups.
B. A DNS zone transfer might be possible.
C. DNSSEC has been configured.
D. SMTP is being used.
B. DNS uses UDP port 53 for DNS queries and TCP port 53 for zone transfers.
You have just scanned your network and found UDP port 123. What service makes use of this port? A. Portmapper B. NTP C. Finger D. LDAP
B. Port 123 is used by NTP.
Which of the following is not offered by Kerberos for Windows users? A. Interoperability B. Nondelegated authentication C. Mutual authentication D. Simplified trust management
B. Kerberos offers Windows users faster connections, mutual authentication, delegated authentication, simplified trust management, and interoperability.
LDAPS provides for security by making use of which one of the following? A. DES B. SSL C. SET D. PGP
B. LDAPS provides for security by using SSL.
DNSSEC does not protect against which of the following? A. Masquerading B. Domain spoofing C. Domain kiting D. Signature verification
C. DNSSEC does not protect against domain kiting.
Which DNS record holds zone replication TTL information? A. PTR B. NS C. MX D. SOA
D. The SOA record holds zone replication TTL information.
Which version of SNMP provides built-in security? A. Version C
B. Version B
C. Version 2
D. Version 3
D. Version 3 is more secure than previous versions of SNMP and offers encryption.
While using Wireshark, you have captured traffic on UDP port 69. What service or application might this be? A. FTP B. Finger C. SSH D. CTFTP
D. TFTP uses port 69 by default.
Which of the following is not a valid UPD header field? A. Source port B. Length C. Checksum D. Flag
D. UDP is composed of four fields: source, destination, length, and checksum.
In DNS, what is another name for an alias? A. MX B. CNAME C. SOA D. NS
B. The CNAME record is an alias.