Section 4.3 Flashcards

1
Q

Which version of SNMP is encrypted?

A

version 3

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How can fake Router Advertisements be blocked and on what device is this feature enabled?

A

by enabling Router Advertisement (RA) Guard on switches

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Aside from authentication, what other feature is there to Port Security?

A

maximum number of MAC addresses for an interface

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

DAI

A

Dynamic ARP Inspection

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does DAI help to prevent?

A

ARP spoofing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

CoPP

A

Control Plane Policing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can the Control Plane of a network device be protected?

A

by enabling and configuring Control Plane Policing (CoPP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What do Private VLANs do?

A

isolate users on the same VLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How can unused switchports be protected?

A

by administratively disabling them or enabling 802.1X to require authentication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How can the transport layer be protected?

A

by disabling unused ports and services

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What prevents fake/rogue DHCP servers from handing out IPs?

A

by enabling DHCP snooping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why should the default VLAN be changed?

A

so attackers don’t know where to look to find management and user traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What can be done to reduce vulnerabilities on network devices?

A

patching and updating firmware

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What should be done before a firmware is patched/updated?

A

store backups of older versions along with their config

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is the access control model used in networking devices called?

A

Role-Based Access Control (RBAC)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Besides a firewall, what can be used to filter traffic based on IP address, port, and protocol?

A

Access Control List (ACL)

17
Q

RBAC

A

Role-Based Access Control

18
Q

ACL

A

Access Control List

19
Q

What does Explicit Deny mean?

A

deny specific traffic

20
Q

What does Implicit Deny mean?

A

deny all traffic not specifically allowed

21
Q

Why is MAC filtering not effective?

A

because MAC addresses can be spoofed

22
Q

How can you physically limit access to a wireless network?

A

by controlling coverage with signal strength (power levels)

23
Q

What is Wireless Client Isolation?

A

where users connected to an access point cannot communicate with each other

24
Q

What is Guest Network Isolation?

A

a network that prevents users from accessing the internal network

25
Q

What is Geofencing used for?

A

to allow or disallow actions or device features depending on location