Quiz 10 Flashcards

1
Q

A DMZ is .

Question 1 options:

a semi-trusted network

a trusted network

an untrusted network

not actually a network

A

a semi-trusted network

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

A screening router would be an appropriate choice for meeting the security needs of
a .
Question 2 options:

DMZ

none of the above

small office network

home network

A

none of the above.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which of the following computers is likely to be found in a DMZ? (Choose all that apply.)
Question 3 options:

A) domain controller

B) e-mail server

C) customer information database

D) Web server

A

B) e-mail server
D) Web server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following issues should you consider in firewall design? (Choose all that apply.)
Question 4 options:

A) authorization

B) fault tolerance

C) log size

D) load balancing

A

B) fault tolerance
D) load balancing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A proxy server . (Choose all that apply.)

Question 5 options:

A) uses fewer system resources than a software firewall

B) can filter Application layer content

C) is the same as a reverse firewall

D) is designed to improve Web access

A

B) can filter Application layer content

D) is designed to improve Web access

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What enables servers in a server farm to work together to handle requests?

Question 7 options:

a router

a switch

load-balancing software

a networking hub

A

load-balancing software

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the main problem with using a screening router?

Question 6 options:

The router alone cannot stop many types of attacks.

The router cannot be used with a firewall.

The router might not provide an adequate screen.

The router can be configured incorrectly.

A

The router alone cannot stop many types of attacks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

For which of the following reasons would you consider creating a protected subnet
within an already protected internal network? (Choose all that apply.)
Question 8 options:

A) to protect Web servers

B) to protect the company’s reputation

C) to protect customer information

D) to protect management servers

A

A) to protect Web servers

C) to protect customer information

D) to protect management servers

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Which of the following functions can a bastion host perform? (Choose all that apply.)

Question 10 options:

A) FTP server

B) e-mail server

C) domain controller

D) security management server

A

A) FTP server

B) e-mail server

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A corporation with several branch offices has decided to maintain multiple firewalls,
one to protect each branch office’s network. What is the most efficient way to maintain
these firewalls?
Question 9 options:

Send information about the security policy to each network administrator.

Set up remote desktop management software.

Use a centralized security workstation.

Broadcast configuration instructions periodically by e-mail.

A

Use a centralized security workstation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which of the following can hide internal IP addresses from the Internet? (Choose all that apply.)
Question 11 options:

A) state tables

B) packet filters

C) proxy servers

D) NAT

A

C) proxy servers

D) NAT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Hardening a bastion host involves which of the following measures?

Question 12 options:

installing current patches

disabling unnecessary services

all of the above

removing unnecessary accounts

A

all of the above

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

To isolate all external Web requests to a specific Web server on the DMZ, it would be
best to use many-to-one NAT.

Question 13 options:
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A bastion host is usually located on the internal network.

Question 14 options:
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In a Cisco ASA 5505 firewall, security level 100 is the least secure level.

Question 15 options:
True
False

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly