Caution
The goal of self-assessment is to gauge your mastery of the topics in this chapter. If you do not know the answer to a question or are only partially sure of the answer, you should mark this question wrong for purposes of the self-assessment. Giving yourself credit for an answer you correctly guess skews your self-assessment results and might provide you with a false sense of security.
1. What is the default inactivity expire time period on a Cisco Catalyst switch CAM table?
a. 1 minute b. 5 minutes c. 10 minutes d. 50 minutes
2. What are three methods of implementing port security?
a. Active secure MAC addresses, fixed secure MAC address, and closed secure MAC address b. Static secure MAC address, dynamic secure MAC addresses, and sticky secure MAC addresses c. Default secure MAC address, evasive secure MAC address, and evading secure MAC address d. Stinky secure MAC addresses, dynamite secure MAC, and clammy secure MAC addresses
3. Which command enables port security on an interface?
a. switchport mode port-security b. switchport mode interface-security c. switchport interface-security d. switchport port-security
4. What is the default action mode for security violations?
a. Protect b. Restrict c. Shutdown
5. The DTP state on a trunk port may be set to what?
a. Auto, on, off, undesirable, or non-negotiate b. Auto, on, off, desirable, or non-negotiate c. Auto, on, off, desirable, or negotiate d. Auto, on, off, undesirable, or negotiate
6. What are the two different types of VLAN hopping attacks?
a. Switch spoofing and double tagging b. Switch goofing and double teaming c. Switch impersonation and double grouping d. Switch imitation and double alliance
7. Which features of Cisco IOS Software enable you to mitigate STP manipulation? (Select two.)
a. spanning-tree portfast bpduguard b. spanning-tree guard rootguard c. set spantree global-default loopguard enable d. set udld enable
8. What are the three types of private VLAN ports?
a. Neighborhood, remote, and loose b. Community, isolated, and promiscuous c. Communal, remote, and licentious d. Area, secluded, and wanton
9. What common tool is used to launch MAC overflow attacks?
a. Dsniff b. Macof c. Arpspoof d. Tablstuf
10. Protect mode security is recommended for trunk ports.
a. True b. False
11. What are the three factors when designing a Layer 2 protected network?
a. Number of users groups b. Number of DNS zones c. Number of switches d. Number of buildings e. Number of security zones
The answers to the "Do I Know This Already?" quiz are found in the appendix. The suggested choices for your next step are as follows:
• 9 or less overall score Read the entire chapter. This includes the "Foundation Topics" and "Foundation Summary" sections and the "Q&A" section.
• 10 or 11 overall score If you want more review on these topics, skip to the "Foundation Summary" section and then go to the
4 PREV
Continue reading here: STP Manipulation Attacks
Was this article helpful?