Do I Know This Already Nxo

1. A remote user tries logging into a remote network but fails after three additional tries and is disconnected. What useful information should the network administrator gather? (Select the best two answers.)

Answers: b. Invalid password c. Invalid username

The network administrator needs the invalid username (because it is not an allowable username) and the invalid password used, to determine whether the intruder is using a text-based algorithm to generate usernames and passwords.

2. If a remote user Telnets to a router but accidentally types the incorrect password or username, which of the following events is not required by the security administrator in this organization? (Select the best two answers.)

Answers: a. Invalid password b. Invalid username

A security administrator does not want to receive details on valid users accidentally entering incorrect passwords but rather is more concerned with access denied messages, authorization failures, and authentication failures generated by the logon attempts of unauthorized users. A large number of retries would also raise a concern for any security manager, for both valid users and invalid users.

3. What is the first step that should be implemented in securing any network? Answer: d. Define a security policy.

The first step in securing any network must be to define the security policy.

4. Why would a security administrator decide to install a stateful firewall?

Answer: c. Stateful firewalls ensure that all traffic returning from a router originated inside the network, unless a static policy on the firewall permits otherwise.

Each time a TCP connection is established from an inside host accessing the Internet through the PIX Firewall, the information about the connection is logged in a stateful session flow table. The table contains the source and destination addresses, port numbers, TCP sequencing information, and additional flags for each TCP connection associated with that particular host. Stateful firewalls are not cheap and can be compromised if configured incorrectly. Stateless firewalls treat each network frame (or packet) in isolation. A stateless firewall has no way of knowing whether any given packet is part of an existing connection, is trying to establish a new connection, or is just an unauthorized packet. Note that stateful connections not only apply to TCP but also fit stateless firewalls that have the ability to check for the TCP SYN/ACK bits. The established keyword on extended lists does just that, but ACLs on routers are still considered stateless. DNS inquiries (UDP based, of course) are one of the main reasons stateful firewalls are so popular. When a user makes an outgoing inquiry, the stateless firewall can create a temporary incoming rule that allows DNS replies from the DNS server being queried, to the user who made the request, on the ephemeral port that the user chooses.

5. What primary security method can be designed and deployed to secure and protect any IP network after an attack has been documented?

Answer: c. Countermeasures

Countermeasures should be in place in every IP network. Examples of countermeasures are to back up sensitive data and application software and apply all the required patches.

6. A security administrator notices that a log file stored on a local router has increased in size from 32 kb to 64 kb in a matter of seconds. What should the network administrator do?

Answer: c. Log the event as suspicious and notify the incident response team.

Any log file that increases (more data to view) or decreases (for example, cleared by the intruder to hide his actions) should be regarded as suspicious activity.

7. What is the primary responsibility of CERT/CC? Answer: d. Maintain a security standard for networks

CERT/CC's primarily responsibility is to aid in the security of any public network; go to http://www.cert.org for more details.

8. Who can use network scanners and probes? (Select the best two answers.) Answers: a. Intruders b. Security managers Network scanners are used by intruders just as network administrators use them.

9. What is a bastion host?

Answer: c. Network's first line of defense

Bastion hosts are typically the first line of defense. Sometimes, they are sacrificed because they are typically public domain servers and can be quickly restored using backup methods.

10. A TCP SYN attack is what type of attack? Answer: b. DoS

A TCP SYN attack is a form of denial-of-service (DoS) attack.

11. When an intruder sends a large amount of ICMP echo (ping) traffic using IP broadcasts, this type of DoS attack is known as what?

Answer: d. Smurf

A Smurf attack sends a large amount of ICMP or ping requests via a broadcast address, ensuring that all devices on the remote network respond and enabling the intruder to list the IP address that is connected to the network for further DOS-based attacks.

12. Assuming two devices are running IPSec over the Internet, what form of attack is likely to compromise any data sent over the Internet?

Answer: d. Man-in-the-middle

The man-in-the-middle attack can manipulate routing tables and have data re-sent to the wrong destination, thus compromising data. The end result is loss of data connectivity. All of the answers can result in data loss, but man-in-the-middle attack is the most correct answer.

13. What kind of attack sends a large number of ICMP echo request packets with the intent of overflowing the input buffers of the destination machine and causing it to crash?

Answer: a. Ping of death

A ping of death sends a large number of ICMP echo request packets, causing the end device to overflow and possibly causing a remote server to stop functioning for legitimate requests.

14. In the context of intrusion detection, what is an exploit signature? Answer: b. An attack that is recognized and detected on the network

15. A network scanner can be used for what primary function? Answer: c. To exploit network vulnerabilities

This is a typical example of the Cisco testing methodology. Because there is only one best answer, you must eliminate answers before picking the correct option. Option a, "To exploit HTTPs passwords," is clearly incorrect because HTTPs sessions are encrypted. Network signatures require more sophisticated tools than just network scanners. Scanners cannot find the location of intruders, and they cannot advise management of a threat, so option c, "To exploit network vulnerabilities," is the best possible option for this question. The primary function of network scanners is to exploit network vulnerabilities.

16. If a network manager believes that a host has been compromised on a router or host device and wishes to have the Certificate Authority certificate revoked, how can the security team accomplish this?

Answer: b. Contact the Certificate Authority administrator and be prepared to change the secret password.

If the CA certificate has been compromised, because the CA entity issues digital certificates and vouches for the binding between the data items in a certificate (for example, between a router and a PC), the CA certificate must be invalidated and a new CA certificate must be created. This is typically achieved by two administrators using a new secret password. The security manager or administrator contacts the CA administrator and has it revoke the certificate. A new public/private key pair is generated and then a new certificate is requested based on the new keys. This allows the hosts to be secured once more.

17. What is the best mechanism against sniffer-type programs that try to determine the network passwords between hosts and clients? (Select at most three answers.)

Answers: b. IPSec c. One-time passwords d. Kerberos or SSH

Sniffer password programs are useless if IPSec is in use, because the data is completely encrypted. One-time passwords ensure that even if an intruder does compromise the password, it will be invalid because it can be used only once. Finally, SSH and Kerberos are secure protocols and do not send data as clear text, as do applications such as Telnet and POP e-mail. One aspect of this exam's blueprint is that even though Kerberos is removed, it may still appear on the exam.

18. What is the main goal of a Trojan horse application?

Answer: b. A malicious piece of code or programming designed to capture usernames and passwords

A Trojan horse is a malicious piece of code or programming that is disguised as something benign. Typically, a Trojan horse masquerades as a program that claims to rid your computer of viruses but instead introduces a virus into your computer. A Trojan horse may be a piece of code used to capture usernames/passwords, or it may have another agenda, such as to erase your disk, capture your credit card numbers, or control your PC. Trojan horse refers to the wooden horse presented to the city of Troy as gift from the Greeks during the Trojan war, inside of which were Greek soldiers who then launched a sneak attack on Troy once the horse was within the city walls (not a likely test question, of course).

19. Which of the following are traditional defense-in-depth security options? (Select the best two answers.)

Answers: d. Use of authentication e. Implementing a perimeter defense

Traditional defense-in-depth security measures typically include the use of authentication and perimeter defenses such as firewalls and routers with Cisco IOS-based security measures in place.

20. To stop spam e-mail from overwhelming an e-mail server, what step can you take? Answer: c. Install an intrusion detection system that has a signature for spam e-mail. Spam e-mail can be controlled with an IDS server.

21. What is an SYN flood attack?

Answer: c. A flood of TCP connection requests with randomized ports and addresses

This form of DoS attack randomly opens a number of TCP ports, ensuring that network devices are using CPU cycles for bogus requests; it also uses randomized source IP addresses. The key to this style of attack is the use of randomized IP addresses.

22. View the following ARP table:

SimonRules#show arp

Protocol Address Age (min) Hardware Addr Type Interface

22. View the following ARP table:

SimonRules#show arp

Protocol Address Age (min) Hardware Addr Type Interface

Internet 1

3.1.135.11

00b0.8ef5.9038

ARPA

E0

Internet 1

5.1.31.1

00b0.8ef5.908c

ARPA

Internet 1

3.1.30.1

00b0.8ef5.9070

ARPA

Cable4/0

Internet 1

3.1.30.106

200

0010.7bb3.fb7b

ARPA

E0

Internet 1

3.1.30.108

200

0001.64ff.eb3d

ARPA

E0

Internet 1

3.1.30.109

0002.fdfa.0a63

ARPA

E0

What address do you suspect might be involved in launching an attack of some form? (Select the best two answers.)

In the Age column in the show arp output, anything locally connected to the router is indicated with the -. The two entries 10.1.30.106 and 10.1.30.108 are not locally connected devices, and the Age time set to such a high number of minutes indicates a high level of activity that should be considered suspicious.

23. Which of the following describes an attack that falsifies a broadcast ICMP echo request and may include a primary and secondary victim?

Answer: e. A smurf attack

A smurf attack is one in which an intruder sends to an IP broadcast address (or addresses) a large number of ICMP echo (ping) requests, all of which have a victim's spoofed source address.

24. What are the common drawbacks of antivirus software such as Norton Antivirus? (Select the best two answers.)

Answers: a. The software is difficult to keep up to date when new viruses are released.

d. Attackers frequently re-code their programs to bypass antivirus systems.

Antivirus software is still a first form of defense but lacks basic update capability when new worms are created and cannot be easily reprogrammed when new forms of viruses are released by attackers.

1. Define four reasons for why networks must be secured.

Answer: IP networks must provide network security for the following reasons:

■ Inherent technology weaknesses—All network devices and operating systems have inherent vulnerabilities.

■ Configuration weaknesses—Common configuration mistakes can be exploited to open weaknesses.

■ Security policy vulnerabilities—The lack of security policies can lead to vulnerabilities, such as password security.

■ Outside/inside intruders—There are always internal and external people who want to exploit network resources and retrieve sensitive data.

2. What is the function of the CERT/CC organization, and what are its primary objectives?

Answer: The CERT Coordination Center (CERT/CC) is a center of Internet security expertise, located at the Software Engineering Institute, a U.S. federally-funded research and development center operated by Carnegie Mellon University. CERT/CC provides information that helps you to protect your networks from potential problems, react to current problems, and predict and prepare for future problems. Its work involves handling computer security incidents and vulnerabilities, publishing security alerts, researching long-term changes in networked systems, developing security information, and even providing training to help you improve security. CERT/CC does not concern itself with the identity and location of the intruder, but instead tries to restore and prevent similar attacks in the future. CERT/CC is regarded as the industry leader in security concerns.

3. What are the primary steps completed by incident response teams? Answer: Incident responses teams do the following:

Step

Description

1

Verify the incident.

2

Determine the magnitude of the incident (hosts affected and how many).

3

Assess the damage (for example, determine if public servers have been modified).

4

Gather and protect the evidence.

5

Inspect systems to determine damage.

6

Remove hostile or destructive code.

Step

Description

7

Reload necessary operating system software.

8

Restore configurations.

9

Restore and test operations.

10

Patch system to reduce vulnerability.

11

Inspect applications to determine damage.

12

Reload software if necessary.

13

Test functionality.

14

Inspect files to determine damage.

15

Restore files from backup if necessary.

16

Replicate damaged files if no backup is available.

17

Confirm with users that data is restored.

Answer: The CCIE Security candidate is not expected to memorize these tasks but should have knowledge of the general points considered when an incident report is complied.

4. Name common methods used by intruders to disrupt a secure network.

Intruders can use the following methods (and many more) to disrupt a secure network:

■ Session hijacking—The intruder defines himself with a valid IP address after a session has been established to the real IP address, by spoofing IP packets and manipulating the sequence number in an IP packet.

■ Rerouting—Packets from one source are routed to an intruder source. Routing updates are altered to send IP packets to an incorrect destination, allowing the intruder to read and use the IP data inappropriately.

■ Denial-of-service (DoS) attack—A service attack that is used in an attempt to deny legitimate users access to a network they have full rights to.

■ Malicious code.

5. In security, what is TCP session hijacking?

Answer: TCP session hijacking is when an attacker or intruder takes over a TCP session between two machines. Because most authentication occurs at the start of a TCP session only, this attack allows the hacker to gain access to a machine by assuming the role of the trusted source.

6. In security terms, what is a man-in-the-middle attack?

Answer: A man-in-the-middle attack abuses weak or nonexistent authentication mechanisms between two endpoints. By inserting himself between these endpoints, the attacker not only can view information passing back and forth, but can even modify or inject data going into such a connection.

7. What is a signature engine?

Answer: A signature engine is a component designed to support many signatures in a certain category. An engine is composed of a parser and an inspector. Each engine has a set of legal parameters that have allowable ranges or sets of values. Exploit signatures are an identifiable pattern of attack.

8. What is social engineering?

Answer: Social engineering is the act of tricking or coercing employees into providing information, such as usernames or mail user identifications and even passwords. First-level phone support personnel are typically called by intruders, pretending to work for the company, to gain valuable information.

9. What is a ping of death attack?

Answer: A ping of death occurs when a large number of ping request packets cause the end device to overflow. For example, a ping of death can cause a remote server to stop functioning for legitimate requests.

10. What is a Land.C attack?

Answer: A Land.C attack is a program designed to send TCP SYN packets (TCP SYN is used in the TCP connection phase) that specify the target's host address as both source and destination. This program can also cause a system to stop functioning.

11. What does the following Cisco IOS code accomplish on a Cisco IOS router?

no service udp-small-servers no service tcp-small-servers

Answer: These commands disable the minor TCP/UDP servers. When the minor TCP/UDP servers are disabled, access to the Echo, Discard, Chargen, and Daytime ports causes the Cisco IOS software to send a TCP Reset packet (only with the tcp-small-servers command) to the sender and discard the original incoming packet. When these commands are entered in global configuration mode, they do not display when you view the configuration (show running-config or write terminal) because the default is to disable TCP/UDP small servers. Unlike Cisco switches, Cisco IOS software does not display default configuration.

12. What is the secret password for the following Cisco IOS configuration?

enable secret %$@$%&*$@*$**@$** enable pass cisco

Answer: Secret passwords are encrypted using the MD5 hashing algorithm, so you cannot decipher the secret password, which overrides the enable password.

13. What is the purpose of the command service sequence-numbers?

Answer: Essentially, this command enables your syslog entries to be numbered so that you can easily put them back in order.

Continue reading here: CCIE Security Examinations

Was this article helpful?

0 0

Readers' Questions

  • Luis
    Which of the following describes a man in the middle attack?
    7 months ago
  • A man-in-the-middle attack is when a malicious actor intercepts communications between two parties, either by eavesdropping or by intercepting data packets and then relaying them to the other party. The attacker is able to gain access to unencrypted data, modify it, or even impersonate one of the parties. This attack is often used to steal private information, such as login credentials or financial data.