Network+ Network Security Hardening Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Network Security Hardening flashcards as text
A network administrator wants to prevent a compromised switch from becoming the spanning tree root bridge. Which feature should be configured on access layer switches?
Answer: Root Guard on uplink ports toward the core
Root Guard prevents a port from accepting superior BPDUs that would allow a downstream switch to take over as root bridge.
Which hardening measure should be applied to switch access ports connected to end-user workstations to prevent loops from unmanaged switches?
Answer: Enable BPDU Guard with PortFast
PortFast skips STP listening/learning for fast convergence, and BPDU Guard error-disables the port if any BPDU is received, blocking rogue switches.
An engineer is hardening a network against insider threats by ensuring that each department can only communicate with the servers it needs. Which technology accomplishes this at Layer 3?
Answer: Inter-VLAN ACLs or firewall policies between segments
Inter-VLAN ACLs or stateful firewall policies applied at routing boundaries control which VLANs can communicate with specific server segments.
What is the security purpose of enabling syslog to a centralized, remote server rather than storing logs locally on each device?
Answer: It ensures logs are preserved and harder for an attacker to alter after compromising a device
Remote syslog keeps audit logs out of reach of an attacker who has compromised the device, preserving forensic integrity.
Which wireless security configuration is considered deprecated and should NOT be used in a hardened enterprise environment?
Answer: WEP (Wired Equivalent Privacy)
WEP uses RC4 with static keys and has known cryptographic flaws that allow it to be cracked in minutes; it is not acceptable for enterprise use.
A firewall is configured to inspect return traffic for sessions initiated from the inside network. Which firewall capability enables this?
Answer: Stateful inspection tracking session state
Stateful inspection maintains a session table so return traffic matching established outbound sessions is automatically permitted without explicit inbound rules.
Which control plane policing (CoPP) concept protects a router's CPU from being overwhelmed by a denial-of-service attack?
Answer: Rate-limiting traffic destined to the router's own IP address
CoPP uses policy maps to rate-limit traffic directed at the router itself (control plane), preventing CPU exhaustion from floods of management or protocol packets.