SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Router Security
Start Test
Study First
Subject
:
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. DENY TCP ANY HOST <IP Address> EQ 23
Privilege Level 15
ACL to block telnet
Generic Routing Encapsulation (GRE)
no ip unreachable
2. Proprietary - used by Cisco routers and switches use to identify each other on LAN and WAN segments
ntp disable
Unauthorized Access
Cisco Discovery Protocol (CDP)
Network Address Translation (NAT)
3. DENY IP HOST <Inbound IP Address> HOST <Inbound IP Address>
IPSec AH Operating Layer
Inside
Dynamic NAT
ACL to block a Land Attack
4. Also known as Configuration Auto-Loading - allows routers to load their startup configuration from the network
Boot Network
Two Protocols of Tunnel Mode
Cisco Discovery Protocol (CDP)
no ip finger - no service finger
5. Command to disable CDP on a router
Two Types of Router Access
Land Attack
no cdp run
Requirements for Reflexive TCP to be removed
6. Privilege level that is restricted to basic level operations
IP Direct Broadcast Vulnerabilties
Outside
Reflexive ACL
Privilege Level 1
7. Layer 5
L2TP Operating Layer
Static NAT
Minimum ACLs Required for Reflexive ACLs
Two Types of Router Access
8. The communication layer between the two other layers and provides network security - including ACLs - firewalls - any general public access servers and address translation; also known as the isolation LAN or DMZ
ACL to block IP multicast
AUX Vulnerability
Distribution Layer
Integrity Validation
9. Command to disable TCP small server on a router
Standard IP ACLs
Proxy ARP
no service tcp-small-servers
Network-to-Network Communications
10. Smurf attacks - can enumerate the network
Reflexive ACL
no service tcp-small-servers
IP Direct Broadcast Vulnerabilties
Networks
11. The environment - catastrophic events an unauthorized access
Three Physical Security Vulnerabilities
User Account Vulnerabilites
Cisco Discovery Protocol (CDP)
TCP Intercept Watch Mode
12. Command used to disable the ICMP message Redirect
Extended IP ACLs
Lower IP Extended ACL Range
UDP Traceroute Port Range
no ip redirect
13. Tunnel Mode Protocol provides integrity - authentication - and non-repudiation and operates directly on top of IP
SSH Identifier
Authentication Header (AH)
no ip http server
Higher IP Standard ACL Range
14. Time can be changed - Routing Table can be killed
Two Protocols of Tunnel Mode
no service tcp-small-servers
NTP Vulnerabilities
SSH Operating Layer
15. 0x33 or 51
IPSec AH Identifier
Three Layers of Hierarchical Model
Overloading
ACL to block a Smurf Attack or Fraggle Attack
16. Privilege level that has Global administration capabilities
Privilege Level 15
GRE Operating Layer
Syntax for Reflexive ACLs
Land Attack
17. Transport and Tunnel
Transport Mode
uRPF Strength
Two Modes of IPSec
Core Layer
18. Protects against repeating of secure sessions
BOOTP
Anti-Replay
Second Part of IOS Version
Proxy ARP Vulnerabilities
19. Public IP address after translation
Outside Global Address
TCP/UDP Daytime Vulnerability
Outside
Unicast Reverse-Path Forwarding (uRPF)
20. 2000-2699
Reflexive ACL
TCP Intercept
Network Address Translation (NAT)
Higher IP Extended ACL Range
21. DENY IP <Network ID> <Network WC Mask> ANY
ACL to block spoofed IPs
TCP Load Distribution
Denial of Service (DoS)
Fourth Part of the IOS Version
22. Layer 7
Local Addresses
HTTP Operating Layer
SNMP Trap
L2TP Identifier
23. Forces the user to enter both a valid username and password
Core Layer
login local
no service tcp-small-servers
Secure Shell (SSH)
24. 33400-34400
Rerouting
UDP Traceroute Port Range
Core Layer
ACL to block telnet
25. Must be made at global config mode - created from CON/VTY session or text file - read top to bottom - applied at the interface and only one ACL per direction - per protocol - per interface
Train Identifier 'B'
Access List Rules
Second Part of IOS Version
SNMP Vulnerabilities
26. Router threat that occurs when an attacker manipulates IP packets to falsify IP addresses - causing network disruptions as the router attempts to process the packet
Train Identifier 'B'
Finger Vulnerabilities
no ip redirect
IP Spoofing
27. Mode where only the payload of the IP packet is encrypted and/or authenticated
Flags used by Established Line
Uses for ACLs
Transport Mode
ESP Identifier
28. Broadcast
29. Users - Host PC's - IP Addresses
HTTP Operating Layer
Finger Vulnerabilities
login local
ntp disable
30. DENY IP 224.0.0.0 15.255.255.255 ANY
ACL to block IP multicast
Outside
IP Source Routing Vulnerabilities
User Account Vulnerabilites
31. DNS Poisoning
Privilege Level 1
DNS Lookup Vulnerability
Named ACL Format
no service udp-small-servers
32. Layer 7
SSH Operating Layer
Integrity Validation
Requirements for Reflexive TCP to be removed
Smurf Attack
33. Command to disable UDP small server on a router
Boot Network
Lower IP Standard ACL Range
no service udp-small-servers
Higher IP Standard ACL Range
34. Layer 3
Tunnel Mode
Second Part of IOS Version
ESP Operating Layer
Two Protocols of Tunnel Mode
35. What Tunnel Mode is used for
Network-to-Network Communications
Tunnel Mode
Fraggle Attack
SSH Operating Layer
36. Translates multiple local addresses to a pool of global addresses by having the firewall select the first available global address; retains the global address for the duration of the connection
Train Idenifier 'E'
Dynamic NAT
Lower IP Extended ACL Range
SNMP
37. Top of the hierarchy - responsible for transporting large amounts of traffic both reliably and quickly and switching traffic as fast as possible throughout the internet
Authentication Header (AH)
Core Layer
Land Attack
HTTPS Strength
38. Attack that involves a multitude of compromised system attack a single target - denying service to it by exploiting one 'master' system that communicates with other 'zombie' systems
HTTP Identifier
Distributed Denial of Service Attacks
Encapsulation Security Payload (ESP)
syslog
39. Buffer Overflow
no ip mask-reply
Networks
IP Source Routing
TCP/UDP Chargen Vulnerability
40. TCP only - used to filter inbound traffic while allowing return TCP sessions - can be spoofed by attackers and cannot be used with Active FTP
Three Physical Security Vulnerabilities
Named ACL Format
ACL to block a Smurf Attack or Fraggle Attack
Established Line
41. No Known Vulnerability
HTTP Tunneling
Standard ACL format
TCP/UDP Discard Vulnerability
Overloading
42. DENY IP 127.0.0.0 0.255.255.255 ANY
Outside Global Address
no ip finger - no service finger
ACL to block incoming loopback packets
Privilege Levels 2-13
43. Access-list <number <deny | permit> source source-wildcard source-qualifier destination dest-wildcard dest-qualifier <log | log-input>
Established Line
Train Identifier 'T'
TCP/UDP Daytime Vulnerability
Extended ACL format
44. Permits a host on one LAN segment to initiate a physical broadcast on a different LAN segment
ACL to block a Smurf Attack or Fraggle Attack
Requirements for Reflexive TCP to be removed
IP Directed Broadcast
Outside Global Address
45. Datagram protocol used by some hosts to load their operating system over the network via a central repository of IOS software
BOOTP
Secure Shell (SSH)
Privilege Level 15
Proxy ARP
46. Accounts without passwords - Type 7 encryption - account privilege higher than 1 - able to be fingered
IP Source Routing
L2TP Identifier
User Account Vulnerabilites
SNMP Trap
47. Privilege levels that can have passwords assigned to them
TCP Intercept Watch Mode
Train Idenifier 'E'
Privilege Levels 2-13
Denial of Service (DoS)
48. 0x2F - or 47
TLS/SSL Identifier
GRE Identifier
Syntax for Reflexive ACLs
Outside
49. UDP Port 514
Finger Vulnerabilities
Unauthorized Access
echo - chargen - discard - daytime
syslog
50. Attack that involves sending a packet to the router with the same IP address in the source and destination address fields - as well as the same port number in the source and destination port field - causing a denial of service
Land Attack
Local Addresses
no cdp run
Minimum ACLs Required for Reflexive ACLs