Securing the Data Plane in IPv6 Flashcards

1
Q

Can these numbers 2345, 3456 be valid first four characters of a globally routable IPv6 address?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the valid first four characters of a link-local address?

A

FE80

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the default method for determining the interface ID for a link-local address on ethernet?

A

EUI-64

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many groups of four hexadecimal characters does an IPv6 address contain?

A

8

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which routing protocols have both an IPv4 and IPv6 version?

A

RIP, EIGRP, OSPF

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which best practices apply to networks that run both IPv4 and IPv6?

A

Physical security, Routing protocol authentication, Authorization of administrators, Written security policy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which protocols, if abused, could impair an IPv6 network, but not IPv4?

A

NDP, Solicited node multicast addresses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

If a rogue IPv6 router is allowed on the network, which information could be incorrectly delivered to the clients on that network?

A

IPv6 default gateway, IPv6 DNS server, IPv6 network address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Why is tunneling any protocol (including IPv6) through another protocol a security risk?

A

The innermost contents of the original packets may be hidden from normal security filters, The tunnels, if they extend beyond the network perimeter, may allow undesired traffic through the tunnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is one method to protect against a rogue IPv6 router?

A

RA guard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly