← All ICND1 Flashcard Decks

Network Security Basics Flashcards

7 cards from real ICND1 practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Network Security Basics flashcards as text
  1. Which command enables port security on a Cisco switch interface?

    Answer: switchport port-security

    The command 'switchport port-security' enables port security on a switch interface after setting it to access mode.

  2. What does the 'restrict' violation mode do when a port security violation occurs?

    Answer: Drops packets from unknown MACs and increments a violation counter

    The 'restrict' mode drops packets from unauthorized MAC addresses and increments the security violation counter without shutting down the port.

  3. Which AAA component is responsible for tracking the actions a user performs after being authenticated?

    Answer: Accounting

    Accounting records what a user does after being authenticated, such as commands executed and duration of access.

  4. What is the default behavior of a Cisco router when an ACL is applied to an interface but a packet does not match any ACE?

    Answer: The packet is dropped

    Every Cisco ACL has an implicit 'deny any' at the end, so unmatched packets are dropped by default.

  5. Which type of attack involves sending frames with a spoofed source MAC address to overflow a switch's MAC address table?

    Answer: MAC flooding attack

    A MAC flooding attack overwhelms the switch's CAM table with fake MAC addresses, causing the switch to behave like a hub and broadcast all traffic.

  6. Which protocol does SSH use for secure remote management of Cisco devices?

    Answer: TCP port 22

    SSH operates over TCP port 22 and provides encrypted remote access, replacing Telnet which uses TCP port 23.

  7. What is the purpose of the 'service password-encryption' command on a Cisco device?

    Answer: Encrypts all plaintext passwords in the running configuration

    The 'service password-encryption' command applies Cisco's weak Type 7 encryption to all plaintext passwords stored in the configuration file.