โ† All COMPTIA Flashcard Decks

Network+ Network Security Hardening Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Security Hardening flashcards as text
  1. An administrator wants to harden a wireless network against deauthentication frame attacks. Which feature should be enabled?

    Answer: Management Frame Protection (802.11w)

    802.11w Management Frame Protection cryptographically protects management frames such as deauthentication and disassociation frames.

  2. Which network hardening practice reduces the risk of ARP poisoning on a LAN segment?

    Answer: Implementing Dynamic ARP Inspection (DAI) on switches

    Dynamic ARP Inspection validates ARP packets against the DHCP snooping binding table and drops spoofed ARP replies.

  3. A security policy requires all remote site-to-site communications to be encrypted. Which technology is MOST appropriate?

    Answer: IPsec VPN

    IPsec VPN provides authentication and encryption for site-to-site traffic, satisfying the confidentiality requirement.

  4. Which log source is MOST useful for detecting port scanning activity against network infrastructure?

    Answer: Firewall/IDS deny logs with connection attempts

    Firewall deny logs and IDS alerts capturing rapid sequential connection attempts to multiple ports are the primary indicators of port scanning.

  5. What is the main security benefit of enabling NTP authentication on network devices?

    Answer: It prevents attackers from injecting false time updates that could disrupt logs and certificates

    NTP authentication (MD5 or SHA keys) ensures that time updates come from a trusted server, preventing time-based attacks on certificate validity and log integrity.

  6. A hardening guide recommends disabling CDP on external-facing router interfaces. Why?

    Answer: CDP advertises device model and IOS version, providing reconnaissance data to attackers

    CDP (Cisco Discovery Protocol) broadcasts device type, platform, and software version; on external interfaces this information aids attacker reconnaissance.

  7. Which action best implements the principle of least privilege for network device administrator accounts?

    Answer: Assigning privilege levels or role-based access so each admin only has permissions required for their job function

    Role-based access control or privilege-level assignments limit each account to only the commands and resources necessary for that administrator's duties.