Network Security Flashcards

1
Q

What are the two categories of control plane security controls:

A

signaling protection (routing protocol authC and STP)
control plane processes protection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which devices support MPP (management plane protection)?

A

Routers and switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which Cisco devices do not support TACACS+?

A

NGFW, WSA, ESA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Cisco offers centralized operational tools to simplify and help you manage your network security deployment. What are some?

A

These tools include Cisco Security Manager, Firepower Management Center (FMC), Cisco Content Security Management Appliance (SMA), Cisco Defense Orchestrator, and Cisco Configuration Professional (CCP) for Catalyst.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some signs a network device has been compromised?

A

The signs of a compromise in a network can take many forms, including network devices that are exfiltrating data, forwarding packets to unexpected destinations, sending unrequested ICMP replies, and more

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the steps in the process of protecting and monitoring infrastructure devices?

A

Harden devices.

Instrument the network.

Establish a baseline.

Analyze deviations from the baseline.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The routed control plane shares the CPU of the main router with two other groups of processes:

A

The management processes, which provide device management functions.

The slow data path processes (process switching or the Cisco Express Forwarding process path), which manage traffic that cannot be managed by the fast data path. (The fast path consists of interrupt switching functions of Cisco Express Forwarding, or hardware-assisted forwarding.)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Where are infrastructure ACLs typically applied?

A

input direction at all the network edge routers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which Cisco IOS tool does CoPP use to protect the router CPU?

A

Modular QoS CLI (MQC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How does CPPr work?

A

CPPr extends the CoPP functionality by automatically classifying all CPU-bound traffic into three queues (or subinterfaces) under the aggregate control plane interface. Each subinterface receives and processes a specific type of CPU-bound traffic, and each subinterface has a separate traffic policy that is attached to it, which makes the limit configuration easier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the steps to configure CPPr?

A

Create traffic classes that describe valid control plane traffic. You can configure as many traffic classes as you need, depending on the required granularity of your policy.

Create a traffic policy that will permit, deny, or rate-limit the configured traffic classes and therefore conserve process layer resources, or even act as a device firewall by hiding most device resources from the network.

Apply the configured traffic policy to a required CPPr subinterface.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are the three control plane subinterfaces that are automatically created by control plane protection?

A

Host, Cisco Express Forwarding-exception subinterface, transit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which two secure authentication types can be used with OSPF authentication on Cisco IOS routers?

A

MD5 & SHA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which Cisco IOS command applies the CPPr policy to the host subinterface?

A

Service-policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Routing processes run in which network device plane?

A

Control Plane

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Which option is required to configure scalable and easy-to-maintain infrastructure ACLs?

A

contiguous address space assigned to infrastructure IP addresses

17
Q

Which Cisco IOS feature provides early rate limiting and drops traffic that is destined for the central processor of the network device by applying QoS policies to a virtual aggregate CPU-bound queue?

A

Control Plane Policing

18
Q

Which option describes a benefit of prefilter policies?

A

Prefilter policies are used to exclude traffic that does not need inspection, for better device performance.