Showing posts with label Protecting Networks. Show all posts
Showing posts with label Protecting Networks. Show all posts

Which of the following is most likely to use network segmentation as an alternate security method?

Which of the following is most likely to use network segmentation as an alternate security method?


a. SCADA systems
b. Mainframes
c. Android
d. Gaming consoles



Answer: A

Network segmentation is one of the most effective controls an organization can implement in order to mitigate the effect of a network intrusion. Due to the sensitive nature of supervisory control and data acquisition (SCADA) systems, they would most likely use network segmentation. Answer B is incorrect because mainframes would most likely use security layers. Answer C is incorrect because Android would most likely use security layers. Answer D is incorrect. Most gaming consoles use firmware version control as an alternative security method.

Which of the following protocols supports DES, 3DES, RC2, and RSA2 encryption along with CHAP authentication, but was not widely adopted?

Which of the following protocols supports DES, 3DES, RC2, and RSA2 encryption along with CHAP authentication, but was not widely adopted?




a. S-HTTP
b. S/MIME
c. HTTP
d. PPTP



Answer: A

An alternative to HTTPS is the Secure Hypertext Transport Protocol (S-HTTP), which was developed to support connectivity for banking transactions and other secure web communications. S-HTTP was not adopted by the early web browser developers (for example, Netscape and Microsoft) and so remains less common than the HTTPS standard. Additionally, S-HTTP encrypts individual messages so it cannot be used for VPN security. Answer B is incorrect. S/MIME is used to encrypt electronic mail transmissions over public networks. Answer C is incorrect because HTTP is used for unsecured web-based communications. Answer D is incorrect because Point-to-Point Tunneling Protocol (PPTP) is a network protocol that enables the secure transfer of data from a remote client to a private enterprise server by creating a virtual private network (VPN) across TCP/IP-based data networks.

It is suspected that some recent network compromises are originating from the use of RDP. Which of the following TCP port traffic should be monitored?

It is suspected that some recent network compromises are originating from the use of RDP. Which of the following TCP port traffic should be monitored?




a. 3389
b. 139
c. 138
d. 443




Answer: A

TCP port 3389 is used by RDP. Answer B is incorrect because UDP uses port 139 for network sharing. Answer C is incorrect because port 138 is used to allow NetBIOS traffic for name resolution. Answer D is incorrect because port 443 is used for HTTPS.

Which of the following are examples of protocol analyzers? (Check all correct answers.)

Which of the following are examples of protocol analyzers? (Check all correct answers.)




a. Metasploit
b. Wireshark
c. OVAL
d. Microsoft Message Analyzer
b. Wireshark



Answer: D

Windows Server operating systems come with a protocol analyzer called by Microsoft Message Analyzer. Third-party programs such as Wireshark can also be used for network monitoring. Metasploit is a framework used for penetration testing, and OVAL is intended as an international language for representing vulnerability information using an XML schema for expression; therefore, answers A and C are incorrect.

Which of the following are not methods for minimizing a threat to a web server? (Choose the two best answers.)

Which of the following are not methods for minimizing a threat to a web server? (Choose the two best answers.)




a. Disable all nonweb services
b. Ensure Telnet is running
c. Disable nonessential services
d. Enable logging



Answer: B & D.

Having Telnet enabled presents security issues and is not a primary method for minimizing threat. Logging is important for secure operations and is invaluable when recovering from a security incident. However, it is not a primary method for reducing threat. Answer A is incorrect because disabling all nonweb services might provide a secure solution for minimizing threats. Answer C is incorrect because each network service carries its own risks; therefore, it is important to disable all nonessential services.

What is a system that is intended or designed to be broken into by an attacker called?

What is a system that is intended or designed to be broken into by an attacker called?




a. Honeypot
b. Honeybucket
c. Decoy
d. Spoofing system



Answer: A

A honeypot is a system that is intended to be sacrificed in the name of knowledge. Honeypot systems allow investigators to evaluate and analyze the attack strategies used. Law enforcement agencies use honeypots to gather evidence for prosecution.

Which IDS function evaluates data collected from sensors?

Which IDS function evaluates data collected from sensors?




a. Operator
b. Manager
c. Alert
d. Analyzer



Answer: D

The analyzer function uses data sources from sensors to analyze and determine whether an attack is under way.

A junior administrator bursts into your office with a report in his hand. He claims that he has found documentation proving that an intruder has been entering the network on a regular basis. Which of the following implementations of IDS detects intrusions based on previously established rules that are in place on your network?

A junior administrator bursts into your office with a report in his hand. He claims that he has found documentation proving that an intruder has been entering the network on a regular basis. Which of the following implementations of IDS detects intrusions based on previously established rules that are in place on your network?




a. MD-IDS
b. AD-IDS
c. HIDS
d. NIDS


Answer: A

By comparing attack signatures and audit trails, a misuse-detection IDS determines whether an attack is occurring.

Which of the following is an active response in an IDS?

Which of the following is an active response in an IDS?





a. Sending an alert to a console
b. Shunning
c. Reconfiguring a router to block an IP address
d. Making an entry in the security audit file


Answer: C

Dynamically changing the system's configuration to protect the network or a system is an active response.

You're the administrator for Acme Widgets. After attending a conference on buzzwords for management, your boss informs you that an IDS should be up and running on the network by the end of the week. Which of the following systems should be installed on a host to provide IDS capabilities?

You're the administrator for Acme Widgets. After attending a conference on buzzwords for management, your boss informs you that an IDS should be up and running on the network by the end of the week. Which of the following systems should be installed on a host to provide IDS capabilities?




a. Network sniffer
b. NIDS
c. HIDS
d. VPN


Answer: C

A host-based IDS (HIDS) is installed on each host that needs IDS capabilities.

Security has become the utmost priority at your organization. You're no longer content to act reactively to incidents when they occur—you want to start acting more proactively. Which system performs active network monitoring and analysis and can take proactive steps to protect a network?

Security has become the utmost priority at your organization. You're no longer content to act reactively to incidents when they occur—you want to start acting more proactively. Which system performs active network monitoring and analysis and can take proactive steps to protect a network?



a. IDS
b. Sniffer
c. Router
d. Switch






Answer: A


An IDS is used to protect and report network abnormalities to a network administrator or system. It works with audit files and rule-based processing to determine how to act in the event of an unusual situation on the network.

Which device monitors network traffic in a passive manner?

Which device monitors network traffic in a passive manner?




a. Sniffer
b. IDS
c. Firewall
d. Web browser



Answer: A

Sniffers monitor network traffic and display traffic in real time. Sniffers, also called network monitors, were originally designed for network maintenance and troubleshooting.

Which type of active response fools the attacker into thinking the attack is succeeding while the system monitors the activity and potentially redirects the attacker to a system that is designed to be broken?

Which type of active response fools the attacker into thinking the attack is succeeding while the system monitors the activity and potentially redirects the attacker to a system that is designed to be broken?




a. Pretexting
b. Shamming
c. Deception
d. Scamming


Answer: C

A deception active response fools the attacker into thinking the attack is succeeding while the system monitors the activity and potentially redirects the attacker to a system that is designed to be broken.

The IDS console is known as what?

The IDS console is known as what?




a. Manager
b. Window
c. Dashboard
d. Screen


Answer: A

The IDS console is known as the manager.

Which of the following is the process in which a law enforcement officer or a government agent encourages or induces a person to commit a crime when the potential criminal expresses a desire not to go ahead?

Which of the following is the process in which a law enforcement officer or a government agent encourages or induces a person to commit a crime when the potential criminal expresses a desire not to go ahead?




a. Enticement
b. Entrapment
c. Deceit
d. Sting


Answer: B

Entrapment is the process in which a law enforcement officer or a government agent encourages or induces a person to commit a crime when the potential criminal expresses a desire not to go ahead.