Network+ Extra 5 Flashcards

1
Q

is a common Layer 2 protocol that offers features such as multilink interface, looped link detection, error detection, and authentication.

A

Point-to-Point Protocol (PPP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

can permit or deny access to a network based on characteristics of the device seeking admission, rather than just checking user credentials.

A

Network Admission Control (NAC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

An Extensible Authentication Protocol (EAP) specifies how authentication is performed by IEEE 802.1X (EAP-FAST/EAP-MD5/EAP-TLS).

A

EAP/802.1X

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Challenge-Handshake Authentication Protocol (CHAP) performs a one-way authentication for a remote-access connection. However, authentication is performed through a three-way handshake (challenge, response, and acceptance messages) between a server and a client. The three-way handshake allows a client to be authenticated without sending credential information across a network. Password Authentication Protocol (PAP) is an unencrypted plain-text method for password exchange that should be avoided.

A

CHAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Microsoft Challenge-Handshake Authentication Protocol (MS-CHAP) is a Microsoft-enhanced version of CHAP, offering a collection of additional features not present with CHAP, including two-way authentication.

A

MS-CHAP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The firewall interface connecting to the inside network (trusted network) is configured as belonging to the INSIDE zone. The firewall interface connecting to the Internet (an untrusted network) is configured as belonging to the OUTSIDE zone.

A

INSIDE/OUTSIDE ZONES - FIREWALL

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

(_____) Main mode involves three exchanges of information between the _____ peers. One peer, called the initiator, sends one or more proposals to the other peer, called the responder. The proposals include supported encryption and authentication protocols and key lifetimes. In addition, the proposals indicate whether or not perfect forward secrecy (PFS) should be used. PFS makes sure that a session key remains secure, even if one of the private keys used to derive the session key becomes compromised. Main mode has 3 exchanges :

Exchange 1: The responder selects a proposal it received from the initiator.

Exchange 2: Diffie-Hellman (DH) securely establishes a shared secret key over the unsecured medium.

Exchange 3: An Internet Security Association and Key Management Protocol (ISAKMP) session is established. This secure session is then used to negotiate an IPSec session

A

IPSec (Main Mode)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

(_____) Aggressive mode more quickly achieves the same results as main mode, using only three packets. The initiator sends the first packet, which contains all the information necessary to establish a security association (SA), which is an agreement between the two _____ peers about the cryptographic parameters to be used in the ISAKMP session. The responder sends the second packet, which contains the security parameters selected by the responder (the proposal, keying material, and its ID). This second packet is used by the responder to authenticate the session. The third and final packet, which is sent by the initiator, finalizes the authentication of the ISAKMP session.

A

IPSec (Aggressive Mode)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

(_____) Quick mode negotiates the parameters (the SA) for the _____ session. This negotiation occurs within the protection of an ISAKMP session.

A

IPSec (Quick Mode)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Both AH and ESP offer origin authentication and integrity services, which ensure that IPSec peers are who they claim to be and that the data was not modified in transit.

A

IPSec (AH/ESP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly