Section 4.3 Flashcards
Which version of SNMP is encrypted?
version 3
How can fake Router Advertisements be blocked and on what device is this feature enabled?
by enabling Router Advertisement (RA) Guard on switches
Aside from authentication, what other feature is there to Port Security?
maximum number of MAC addresses for an interface
DAI
Dynamic ARP Inspection
What does DAI help to prevent?
ARP spoofing
CoPP
Control Plane Policing
How can the Control Plane of a network device be protected?
by enabling and configuring Control Plane Policing (CoPP)
What do Private VLANs do?
isolate users on the same VLAN
How can unused switchports be protected?
by administratively disabling them or enabling 802.1X to require authentication
How can the transport layer be protected?
by disabling unused ports and services
What prevents fake/rogue DHCP servers from handing out IPs?
by enabling DHCP snooping
Why should the default VLAN be changed?
so attackers don’t know where to look to find management and user traffic
What can be done to reduce vulnerabilities on network devices?
patching and updating firmware
What should be done before a firmware is patched/updated?
store backups of older versions along with their config
What is the access control model used in networking devices called?
Role-Based Access Control (RBAC)
Besides a firewall, what can be used to filter traffic based on IP address, port, and protocol?
Access Control List (ACL)
RBAC
Role-Based Access Control
ACL
Access Control List
What does Explicit Deny mean?
deny specific traffic
What does Implicit Deny mean?
deny all traffic not specifically allowed
Why is MAC filtering not effective?
because MAC addresses can be spoofed
How can you physically limit access to a wireless network?
by controlling coverage with signal strength (power levels)
What is Wireless Client Isolation?
where users connected to an access point cannot communicate with each other
What is Guest Network Isolation?
a network that prevents users from accessing the internal network
What is Geofencing used for?
to allow or disallow actions or device features depending on location