โ† All COMPTIA Flashcard Decks

Network+ Network Security Hardening Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Security Hardening flashcards as text
  1. A network administrator wants to prevent VLAN hopping attacks. Which action is the MOST effective countermeasure?

    Answer: Disable DTP and set all unused ports to a non-default VLAN

    Disabling DTP prevents dynamic trunk negotiation, and assigning unused ports to an isolated VLAN stops double-tagging VLAN hopping attacks.

  2. Which hardening technique involves replacing default credentials on network devices immediately after deployment?

    Answer: Default credential remediation

    Default credential remediation means changing manufacturer-set usernames and passwords before a device goes into production.

  3. An administrator enables 802.1X port-based authentication on all switch access ports. What does this primarily enforce?

    Answer: Network access control requiring authentication before connectivity

    802.1X requires endpoints to authenticate (typically via RADIUS) before the switch port transitions from an unauthorized to an authorized state.

  4. Which protocol should replace Telnet for remote router management to ensure confidentiality?

    Answer: SSH

    SSH encrypts the management session, whereas Telnet transmits all data including passwords in plaintext.

  5. A firewall rule base should follow which principle to reduce attack surface?

    Answer: Implicit deny with explicit permits only for required traffic

    Implicit deny (deny-all by default) ensures only explicitly approved traffic flows, minimizing exposure to unintended access.

  6. What is the purpose of network segmentation using DMZ architecture?

    Answer: To isolate publicly accessible servers from the internal trusted network

    A DMZ places internet-facing services in a separate zone so that a compromised server cannot directly reach internal resources.

  7. An administrator configures a switch to send only SNMPv3 traps with authentication and encryption. Which two SNMPv3 features provide this?

    Answer: authPriv mode using MD5/SHA and DES/AES

    SNMPv3 authPriv mode enables both message authentication (MD5 or SHA) and privacy encryption (DES or AES) for trap messages.