Pregunta 1
Pregunta
Refer to the exhibit. A network administrator is configuring an IOS IPS. Which statement describes the IPS
signatures that are enabled?
Respuesta
-
These signatures ready here detect attacks within a single packet.
-
These signatures ready here detect attacks that target a single host.
-
These signatures ready here detect attacks that are from the same source.
-
These signatures ready here detect attacks with a sequence of operations
Pregunta 2
Pregunta
What is a zero-day attack?
Respuesta
-
It is a computer attack that occurs on the first day of the month.
-
It is an attack that results in no hosts able to connect to a network.
-
It is a computer attack that exploits unreported software vulnerabilities.
-
It is an attack that has no impact on the network because the software vendor has mitigated the vulnerability.
Pregunta 3
Pregunta
Which command releases the dynamic resources associated with the Cisco IOS IPS on a Cisco router?
Respuesta
-
Router# clear ips statistics
-
Router# clear ip sdee events
-
Router# clear sdee subscriptions
-
Router# clear ip ips configuration
Pregunta 4
Pregunta
What are two actions that an IPS can perform whenever a signature detects the activity for which it is
configured? (Choose two.)
Pregunta 5
Pregunta
What is a disadvantage of network-based IPS devices?
Respuesta
-
They use signature-based detection only.
-
They cannot detect attacks that are launched using encrypted packets.
-
They are implemented in expensive dedicated appliances.
-
They cannot take immediate actions when an attack is detected.
Pregunta 6
Pregunta
What are two disadvantages of using an IDS? (Choose two.)
Respuesta
-
The IDS has no impact on traffic.
-
The IDS does not stop malicious traffic.
-
The IDS works offline using copies of network traffic.
-
The IDS requires other devices to respond to attacks.
-
The IDS analyzes actual forwarded packets.
Pregunta 7
Pregunta
A network administrator was testing an IPS device by releasing multiple packets into the network. The administrator examined the log and noticed that a group of alarms were generated by the IPS that identified normal user traffic. Which term describes this group of alarms?
Respuesta
-
true positive
-
true negative
-
false positive
-
false negative
Pregunta 8
Pregunta
Which Cisco feature sends copies of frames entering one port to a different port on the same switch in order to perform traffic analysis?
Pregunta 9
Pregunta
What is an IPS signature?
Respuesta
-
It is the timestamp that is applied to logged security events and alarms.
-
It is the authorization that is required to implement a security policy.
-
It is a set of patterns used to detect typical intrusive activity.
-
It is a security script that is used to detect unknown threats.
Pregunta 10
Pregunta
What is a disadvantage of a pattern-based detection mechanism?
Respuesta
-
Its configuration is complex.
-
It cannot detect unknown attacks.
-
It is difficult to deploy in a large network.
-
The normal network traffic pattern must be profiled first.
Pregunta 11
Pregunta
Which two devices are examples of endpoints susceptible to malware-related attacks? (Choose two.)
Respuesta
-
switch
-
server
-
wireless access point
-
desktop
-
IP telephony device
Pregunta 12
Pregunta
What would be the primary reason an attacker would launch a MAC address overflow attack?
Respuesta
-
so that the switch stops forwarding traffic
-
so that legitimate hosts cannot obtain a MAC address
-
so that the attacker can see frames that are destined for other hosts
-
so that the attacker can execute arbitrary code on the switch
Pregunta 13
Pregunta
What is a recommended best practice when dealing with the native VLAN?
Pregunta 14
Pregunta
What is the best way to prevent a VLAN hopping attack?
Respuesta
-
Disable STP on all nontrunk ports.
-
Use ISL encapsulation on all trunk links.
-
Use VLAN 1 as the native VLAN on trunk ports.
-
Disable trunk negotiation for trunk ports and statically set nontrunk ports as access ports.
Pregunta 15
Pregunta
What mitigation plan is best for thwarting a DoS attack that is creating a switch buffer overflow?
Pregunta 16
Pregunta
Refer to the exhibit above. What happens when Host 1 attempts to send data?
Respuesta
-
Frames from Host 1 cause the interface to shut down.
-
Frames from Host 1 are dropped and no log message is sent.
-
Frames from Host 1 create a MAC address entry in the running-config.
-
Frames from Host 1 will remove all MAC address entries in the address table.
Pregunta 17
Pregunta
All access ports on a switch are configured with the administrative mode of dynamic auto. An attacker, connected to one of the ports, sends a malicious DTP frame. What is the intent of the attacker?
Respuesta
-
VLAN hopping
-
DHCP spoofing attack
-
MAC flooding attack
-
ARP poisoning attack
Pregunta 18
Pregunta
Refer to the exhibit. A network engineer is securing a network against DHCP spoofing attacks. On all switches, the engineer applied the ip dhcp snooping command and enabled DHCP snooping on all VLANs with the ip dhcp snooping vlan command. What additional step should be taken to configure the security required on the network?
Respuesta
-
Issue the ip dhcp snooping trust command on all uplink interfaces on SW1, SW2 and SW3.
-
Issue the ip dhcp snooping trust command on all interfaces on SW2 and SW3.
-
Issue the ip dhcp snooping trust command on all interfaces on SW1, SW2, and SW3.
-
Issue the ip dhcp snooping trust command on all interfaces on SW1, SW2, and SW3 except interface Fa0/1 on SW1.
Pregunta 19
Pregunta
Which countermeasure can be implemented to determine the validity of an ARP packet, based on the valid MAC-address-to-IP address bindings stored in a DHCP snooping database?
Respuesta
-
DHCP snooping
-
dynamic ARP inspection
-
MAC table inspection
-
Port security snooping
Pregunta 20
Pregunta
What are two purposes for an attacker launching a MAC table flood? (Choose two.)
Respuesta
-
to initiate a man-in-the-middle attack
-
to initiate a denial of service (DoS) attack
-
to capture data from the network
-
to gather network topology information
-
to exhaust the address space available to the DHCP
Pregunta 21
Pregunta
Which type of attacks can be mitigated by port security?
Respuesta
-
dictionary
-
replay
-
MAC-address flooding
-
password
-
VLAN hopping
-
Double tagging
Pregunta 22
Pregunta
What are two actions a hacker may take in a VLAN hopping attack? (Choose two.)
Respuesta
-
replying to ARP requests that are intended for other recipients
-
sending malicious dynamic trunking protocol (DTP) frames
-
replying to DHCP requests that are intended for a DHCP server
-
sending a unicast flood of Ethernet frames with distinct source MAC addresses
-
sending frames with two 802.1Q headers