Network Security & Best Practices Flashcards
7 cards from real CCST practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Best Practices flashcards as text
Which type of attack involves an attacker secretly relaying and possibly altering communications between two parties who believe they are communicating directly?
Answer: Man-in-the-middle attack
A man-in-the-middle (MitM) attack occurs when an attacker secretly intercepts and potentially alters communications between two parties.
What is the primary purpose of a DMZ (Demilitarized Zone) in network security?
Answer: To host public-facing services while isolating them from the internal network
A DMZ is a network segment that hosts public-facing services (like web servers) while keeping them isolated from the internal trusted network.
Which 802.1X component is responsible for authenticating end-user devices before granting network access?
Answer: Authentication Server
In 802.1X, the Authentication Server (typically a RADIUS server) verifies the credentials provided by the supplicant.
A technician discovers that a switch port is receiving BPDU frames from an unauthorized device. Which Cisco feature should be enabled to protect against rogue switches?
Answer: BPDU Guard
BPDU Guard disables a port when unexpected BPDU frames are received, preventing unauthorized switches from influencing the Spanning Tree topology.
What does the principle of 'defense in depth' mean in network security?
Answer: Using multiple layers of security controls so that if one fails, others still protect the network
Defense in depth uses multiple overlapping security layers so that a failure in one control does not compromise the entire network.
Which protocol provides secure remote management of network devices and encrypts all traffic, including authentication?
Answer: SSH
SSH (Secure Shell) encrypts all session data including credentials, unlike Telnet which transmits everything in plaintext.
An attacker floods a network with spoofed TCP SYN packets to exhaust server resources. What type of attack is this?
Answer: SYN flood (DoS)
A SYN flood exploits the TCP three-way handshake by sending many SYN packets without completing the handshake, exhausting server connection resources.