Firewall and Switch Protection Flashcards

1
Q

What is a CAM table overflow attack?

A

Generating fake MAC addresses repeatedly sending frames into the switch to overload memory capacity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is TTL?

A

Time to live (L3)

Decrements packet TTL value each hop, prevents loops

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is STP?

A

Spanning Tree Protocol (L2)

Prevents loops by blocking redundant paths

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are flood guards?

A

Limits specific protocol activity on network in case STP is disabled, i.e set the threshold for broadcast activity ideally based on baseline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Why would an administrator put an explicit deny rule despite the default implicit deny?

A

Implicit deny is not logged, so explicit deny can generate events based on deny rule

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is private, public vs hybrid cloud?

A

Private VMs have no connection to internet
Public VMs accessible over internet
Hybrid Combination of public and private

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is Community cloud?

A

Organisations striving for same objectives in a collaborative effort share cloud infrastructure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is ARP poisoning?

A

Spoofing, i.e sending incorrect ARP of default gateway to rogue computer to do packet sniffing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is DNS poisoning?

A

Changing DNS server to rogue computer to see DNS resolution of victim

How well did you know this?
1
Not at all
2
3
4
5
Perfectly