โ† All ICND1 Flashcard Decks

Network Security Basics Flashcards

7 cards from real ICND1 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Basics flashcards as text
  1. Which command configures the maximum number of MAC addresses allowed on a port security-enabled interface?

    Answer: switchport port-security maximum 2

    The 'switchport port-security maximum' command sets the number of MAC addresses allowed on the interface before a violation occurs.

  2. What distinguishes RADIUS from TACACS+ in terms of protocol and encryption?

    Answer: RADIUS uses UDP and encrypts only the password; TACACS+ uses TCP and encrypts the entire payload

    RADIUS uses UDP (ports 1812/1813) and only encrypts the password field, while TACACS+ uses TCP port 49 and encrypts the entire authentication payload.

  3. What is the purpose of a DMZ (Demilitarized Zone) in network security architecture?

    Answer: A network segment that hosts public-facing services while isolating them from the internal network

    A DMZ is a perimeter network segment that hosts public-accessible servers (web, email, DNS) while preventing direct access to the internal corporate network.

  4. Which type of IDS/IPS detection method identifies attacks by comparing traffic patterns against a database of known attack signatures?

    Answer: Signature-based detection

    Signature-based detection compares network traffic or system behavior against a database of known attack patterns to identify threats.

  5. Which Cisco feature uses 802.1X to enforce authentication before allowing a device to access the network?

    Answer: Network Access Control (NAC)

    Cisco NAC leverages 802.1X port-based authentication to verify device identity and compliance before granting network access.

  6. What is a 'social engineering' attack in the context of network security?

    Answer: Manipulating people into revealing confidential information or performing actions that compromise security

    Social engineering attacks exploit human psychology rather than technical vulnerabilities, tricking users into divulging passwords or granting unauthorized access.

  7. Which command verifies that SSH version 2 is configured on a Cisco device?

    Answer: show ip ssh

    The 'show ip ssh' command displays the SSH version, authentication timeout, and retry settings configured on the Cisco device.

Network Security Basics Flashcards โ€” ICND1 Study Cards with Answers