Test your basic knowledge |

Router Security

Subject : it-skills
Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An alternative for both standard and extended ACLs that allow you to refer to an ACL by a descriptive name instead of a number






2. Uses server and host keys to authenticate systems






3. Release Train Identifier






4. DENY IP ANY HOST <Broadcast Address>






5. Transport and Tunnel






6. What Transport Mode is used for






7. These ACLs filter by network or host IP addresses andspecific protocol type or port numbers - filters by source and destination






8. Rewrites the and/or destination IP address of IP packets as they pass through a router or firewall from private to public addresses






9. Routing mode depended on by uRPF in order to function






10. UDP Port 514






11. Private IP address after translation






12. Technology


13. DENY TCP ANY HOST <IP Address> EQ 23






14. A method of bypassing firewall or proxy restrictions by making the firewall think that it is getting traffic from a web browser






15. Form of dynamic NAT that maps multiple unregistered IP addresses to a single registered IP address by using different ports; limited to ~64 -000 hosts






16. Router threat that includes manipulating router updates to cause traffic to flow to unauthorized destinations






17. None - uses attach application protocol's layer






18. Protects against repeating of secure sessions






19. This server is used for querying a host about its logged in users






20. UDP Port 1701






21. Major Version - Minor Version - Release - Interim Build - Release Train Identifier






22. PERMIT TCP ANY ANY ESTABLISHED






23. Authentication Header (AH) and Encapsulated Security Payload (ESP)






24. TCP Port 80






25. Command to disable CDP on a router






26. Protocol used to keep their time-of-day clocks accurate and in sync






27. None - uses attached application protocol's port






28. Helps to mitigate problems that are caused by the introduction of malformed or spoofed IP source addresses into a network by discarding packets lacking a verifiable IP source address






29. Layer 3






30. Uses SSL port 443






31. These ACLs filter by network or host IP address and only filter on source






32. Public IP address after translation






33. Can copy - poison - corrupt - or delete the IOS






34. Privilege level that restricts users to five commands (enable - disable - exit - help quit)






35. Layer 7






36. Startup-config can be deleted - copied - changed






37. Can discover vulnerabilities - network stats - and firewall discovery






38. Software that blocks packets from unreachable hosts - thus allowing only reachable external hosts to initiate connections to a host on an internal network






39. The environment - catastrophic events an unauthorized access






40. Router threat that includes manipulating router updates to cause traffic to flow to unauthorized destinations






41. Rebuild Number






42. Refers to the addresses on the public internet






43. Permits a host on one LAN segment to initiate a physical broadcast on a different LAN segment






44. Users - Host PC's - IP Addresses






45. Proprietary - used by Cisco routers and switches use to identify each other on LAN and WAN segments






46. Four TCP/UDP Small Server commands recommended to disable






47. Command used to disable the ICMP message Host Unreachable






48. Tunnel Mode Protocol provides integrity - authentication - and non-repudiation and operates directly on top of IP






49. Command used to disable the ICMP message Address Mask Reply






50. Attack that involves sending a packet to the router with the same IP address in the source and destination address fields - as well as the same port number in the source and destination port field - causing a denial of service