Do I Know This Already Quiz Prq
Table 21-1 outlines the major headings in this chapter and the corresponding "Do I Know This Already?" quiz questions.
|
Foundation Topics Section |
Questions Covered in This Section |
Score |
|
Router and Switch Device Security |
1-3 |
|
|
4-6 |
||
|
7-9 |
||
|
Total Score |
||
In order to best use this pre-chapter assessment, remember to score yourself strictly. You can find the answers in Appendix A, "Answers to the 'Do I Know This Already?' Quizzes."
1. Consider the following configuration commands, which will be pasted into a router's configuration. Assuming no other AAA configuration or other security-related configuration exists before pasting in this configuration, which of the following is true regarding the process and sequences for authentication of a user attempting to enter privileged mode?
enable secret fred enable authentication wilma username barney password betty aaa new-model aaa authentication enable default group radius local aaa authentication enable wilma group fred local aaa authentication login default group radius local aaa authentication login fred line group radius none radius-server host 10.1.1.1 auth-port 1812 acct-port 1646 radius-server host 10.1.1.2 auth-port 1645 acct-port 1646 radius-server key cisco radius-server host 10.1.1.3 auth-port 1812 acct-port 1646 radius-server host 10.1.1.4 auth-port 1645 acct-port 1646 radius-server key cisco aaa group server radius fred server 10.1.1.3 auth-port 1645 acct-port 1646 server 10.1.1.4 auth-port 1645 acct-port 1646 line con 0 password cisco login authentication fred line vty 0 4 password cisco a. The user will only need to supply a password of "fred" without a username.
b. The RADIUS server at either 10.1.1.1 or 10.1.1.2 must approve the username/password supplied by the user.
c. The RADIUS server at 10.1.1.3 is checked first; if no response, then the server at 10.1.1.4 is checked.
d. None of these answers is correct.
2. Using the same exhibit and conditions as question 1, which of the following is true regarding the process and sequences for authentication of a user attempting to log in through the console?
a. A simple password of "cisco" will be required.
b. The user will supply a username/password, which will be authenticated if either server 10.1.1.1 or 10.1.1.2 returns a RADIUS message approving the user.
c. The username/password is presented to the RADIUS server at 10.1.1.3 first; if no response, then the server at 10.1.1.4 is checked next.
d. None of these answers is correct.
3. Using the same exhibit and conditions as question 1, which of the following is true regarding the process and sequences for authentication of a user attempting to log in via Telnet?
a. A simple password of cisco will be required.
b. The router will attempt authentication with RADIUS server 10.1.1.1 first; if no response, then 10.1.1.2; if no response, then it will require password cisco.
c. The router will attempt authentication with RADIUS server 10.1.1.1 first; if no response, then 10.1.1.2; if no response, then it will require a username/password of betty/barney.
d. The username/password is presented to the RADIUS server at 10.1.1.3 first; if no response, then the server at 10.1.1.4 is checked next.
e. If neither 10.1.1.1 nor 10.1.1.2 respond, the user cannot be authenticated, and is rejected.
f. None of the other answers is correct.
4. Which of the following are considered best practices for Layer 2 security?
a. Inspect ARP messages to prevent hackers from causing hosts to create incorrect ARP table entries.
c. Put all management traffic in VLAN 1, but no user traffic.
d. Configure DTP to use the auto setting.
e. Shut down unused ports.
5. Assuming a Cisco 3550 switch, which of the following is true regarding the port security feature?
a. The default maximum number of MACs allowed to be reached on an interface is three.
b. Sticky-learned MAC addresses are automatically added to the startup configuration once they are learned the first time.
c. Dynamic (non-sticky) learned MAC addresses are added to the running configuration, but they can be saved using the copy run start command.
d. A port must be set to be a static access or trunking port for port security to be allowed on the interface.
e. None of the other answers is correct.
6. Which of the following is true regarding the use of IEEE 802.1X for LAN user authentication?
a. The EAPoL protocol is used between the authenticator and authentication server.
b. The supplicant is client software on the user's device.
c. A switch acts in the role of 802.1X authentication server.
d. The only traffic allowed to exit a currently unauthenticated 802.1X port are 802.1X-related messages.
7. The following ACE is typed into configuration mode on a router: access-list 1 permit 10.44.38.0 0.0.3.255. If this statement had instead used a different mask, with nothing else changed, which of the following choices for mask would result in a match for source IP address 10.44.40.18?
8. An enterprise uses a registered class A network. A smurf attack occurs from the Internet, with the enterprise receiving lots of ICMP Echoes, destined to subnet broadcast address 9.1.1.255, which is the broadcast address of an actual deployed subnet (9.1.1.0/24) in the enterprise. The packets all have a source address of 9.1.1.1. Which of the following tools might help mitigate the effects of the attack?
a. Ensure that the no ip directed-broadcast command is configured on the router interfaces connected to the 9.1.1.0/24 subnet.
b. Configure an RPF check so that the packets would be rejected based on the invalid source IP address.
c. Routers will not forward packets to subnet broadcast addresses, so there is no need for concern in this case.
d. Filter all packets sent to addresses in subnet 9.1.1.0/24.
9. Which of the following statements is true regarding the router Cisco IOS Software TCP intercept feature?
a. Always acts as a proxy for incoming TCP connections, completing the client-side connection, and only then creating a server-side TCP connection.
b. Can monitor TCP connections for volume and for incomplete connections, as well as serve as a TCP proxy.
c. If enabled, must operate on all TCP connection requests entering a particular interface.
d. None of the other answers is correct.
Continue reading here: Switch Security Best Practices for Unused and User Ports
Was this article helpful?