SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Comptia Security +: Network Security
Start Test
Study First
Subjects
:
certifications
,
comptia-security-+
,
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Twisted pair cable with speed capability of 1Gbps
false positive
extranet
VLAN
cat5
2. Packet filtering - proxies - stateful inspection
HIDS
router
twisted pair
firewalls
3. One process on every system - use local system resources - detect attacks that NIDS misses - examine data after decrypted - can be OS specific - more expensive
bastion host
protocol
HIDS
honeynet
4. A method - used by switches and email servers - of delivering messages which are temporarily held by an intermediary before being sent to their final destination
coaxial
switch
cat3
store and forward
5. User / registered ports
proxy
1024 - 49 -151
fraggle
repeater
6. Cable used most in networks - maximum speed 1Gbps - maximum length 100 meters - susceptible to tap
website spoofing
VLAN
twisted pair
repeater
7. Malicious activity not reported or detected
private
false negative
content filter
protocol analyzer
8. Crashing a computer by sending oversized packets (over 64 bytes) that it doesn't know how to handle
1024 - 49 -151
active
stateful inspection
ping of death
9. Level 2 firewall often used to filter web traffic
10base2
proxy
switch
encrypt session key
10. A pool of public IP addresses is shared by a collection of private IP addresses
dynamic NAT
DNS spoofing
SYN flood
honeypot
11. An attack where an attacker captures sensitive information and sends it again later in an attempt to replicate the transaction
application gateway
replay
SYN flood
extranet
12. Amplifies the signal of incoming packets before broadcasting them to the network
extranet
subnet
split horizon DNS
repeater
13. Examines a entire packet and determines action based on a complex set of rules
cat3
application gateway
0 - 1023
port
14. Known as thinnet - 10mbps - limited to 185 meters
content filter
IP spoofing
allow by default
10base2
15. Bastion host - dual homed firewall - multi homed firewall - screened host - screened subnet
fraggle
packet filter
firewall architectures
application gateway
16. A logical group of computers connected via a switch/hub that share the same network prefix in their IP address
subnet
PBX (Private Branch Exchange)
null session
active
17. Firewall with several NICs connected to different networks
NAT
source - destination - protocol
multi homed
website spoofing
18. Ping flooding - ping of death - smurf - fraggle - SYN flood - land - teardrop - email flood
DoS attacks
coaxial
port address translation
VLAN
19. Two authoritative sources for your domain namespace with differing contents depending on whether the query is internal or external
split horizon DNS
subnet
smurf
blind
20. IDS response method using logging and notification
screened host
proxy server
null session
passive
21. DMZ implementation using two firewalls with different rule sets for the DMZ and intranet
zone transfer
network
allow by default
layered
22. Blocks all traffic from passing through the firewall except for traffic that is explicitly allowed - also known as restrictive access - best practice
private
firewalls
subnet
deny by default
23. IDS that relies on the identification of known attack signatures
knowledge based
cat5
man in the middle and replay
HIDS
24. Generate random TCP sequence numbers and encrypt traffic countermeasure what attacks
risk mitigation
man in the middle and replay
0 - 1023
informed
25. A flaw in TCP/IP to verify that a packet really comes from the addess indicated in the IP header leads to this attack
network
man in the middle
IP spoofing
informed
26. Acts as an organizations internal phone system
passive
protocol
broadcast domain
PBX (Private Branch Exchange)
27. Allows all traffic except traffic that is specifically denied - also known as permissive access
promiscuous
allow by default
application
firewalls
28. A group of hosts on logical network segment that communicate as if they were attached to the same broadcast domain - regardless of their physical location
smurf
IP spoofing
VLAN
extranet
29. Type of IP addresses not routed on the internet: 10.x.x.x - 172.16.x.x - 192.168.x.x
proxy server
DMZ
screened subnet
private
30. A level 3 firewall that remembers / tracks network connections - maintains a state table - distinguish which side of a firewall a connection was initiated - higher security
NIDS network connections
bastion host
protocol
stateful inspection
31. Forging an IP address with the address of a trusted host
IP spoofing
router
dual homed
fraggle
32. A decoy system - intentionally left exposed to attract/distract attackers - logs and monitors attacker activities
honeypot
tcp/ip hijacking
session hijacking
screened host
33. Known as thicknet - 10mbps - limited to 500 meters
10Base5
defense in depth
encrypt session key
router
34. A logical connection point allowing computers and software to communicate and exchange data
port address translation
screened subnet
port
null session
35. A physical or logical subnetwork that houses systems accessible to a larger untrusted network - usually the Internet - also known as DMZ
screened subnet
land attack
router
0 - 1023
36. A DoS attack that subverts the normal "three way handshake" of TCP/IP by sending SYN packets - but no corresponding ACK packets
SYN flood
content filter
source - destination - protocol
honeypot
37. Examines content passing through and makes a decision on the data based on a set of criteria - normal uses email filtering and web browsing
router
broadcast domain
content filter
tcp/ip hijacking
38. Firewall that communicates directly with a perimeter router and the internal network - 2 NICs - screens internal traffic
screened host
ping flooding
source - destination - protocol
network
39. A packet filtering firewall works at this layer of the OSI model
active
store and forward
network
1024 - 49 -151
40. A feature of firewalls / routers that disguise the IP address of internal systems allowing connection to the Internet using one public address
NAT
NIDS network connections
packet filter
risk mitigation
41. Network configuration that permits selected outsiders access internal information systems
extranet
store and forward
NIDS
subnet
42. Used to pass data from one VLAN to another
ARP
DoS attacks
repeater
router
43. Promiscuous NIC to sniff passing traffic - admin NIC to send alerts to centralized management system
active
false negative
informed
NIDS network connections
44. Unauthenticated Windows session where an attacker can gather list of users - groups - machines - shares - user and host SID
man in the middle and replay
DNS spoofing
active
null session
45. Bbenign activity reported as malicious
port
active
encrypt session key
false positive
46. Twisted pair cable with speed capability of 10Mbps
split horizon DNS
cat3
zone transfer
SYN flood
47. A server that sits between an intranet and it's Internet connection - masking all IP addresses
proxy server
website spoofing
active
zone transfer
48. Used by ISPs - single public network IP address is shared among many hosts on a private network - also known as PAT
honeynet
router
port address translation
protocol analyzer
49. Unauthenticated connections - creating the potential for a successful connection as an anonymous user
spoofing
HIDS
VLAN
null session
50. IP spoofing attack where the attacker can only send packets and has to guess about replies
blind
null session
active
spoofing