Test your basic knowledge |

Router Security

Subject : it-skills
Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Top of the hierarchy - responsible for transporting large amounts of traffic both reliably and quickly and switching traffic as fast as possible throughout the internet






2. Accounts without passwords - Type 7 encryption - account privilege higher than 1 - able to be fingered






3. Router threat that includes manipulating router updates to cause traffic to flow to unauthorized destinations






4. Layer 3






5. Must be made at global config mode - created from CON/VTY session or text file - read top to bottom - applied at the interface and only one ACL per direction - per protocol - per interface






6. When one network protocol called the payload protocol is encapsulated within a different delivery network - or provide a secure path through an untrusted network






7. Command used to disable the ICMP message Host Unreachable






8. Broadcast


9. Refers to the addresses on the public internet






10. Public IP address after translation






11. These ACLs filter by network or host IP addresses andspecific protocol type or port numbers - filters by source and destination






12. Provides nonrepudiation - ensuring that traffic is from a trusted party






13. Command used to disable NTP on an interface






14. DENY IP ANY HOST <Broadcast Address>






15. Software that passively monitors the connection requests flowing through the router; if a connection fails - the software sends a Reset to the server to clear up its state






16. 0x2F - or 47






17. Layer 7






18. Major Version






19. 1300-1999






20. Form of dynamic NAT that maps multiple unregistered IP addresses to a single registered IP address by using different ports; limited to ~64 -000 hosts






21. Technology


22. Helps to mitigate problems that are caused by the introduction of malformed or spoofed IP source addresses into a network by discarding packets lacking a verifiable IP source address






23. Lists interfaces - routing table - ARP table - physical and network addresses - time last booted






24. Service Provider


25. 33400-34400






26. Public IP address before translation






27. Time can be changed - Routing Table can be killed






28. Privilege level that restricts users to five commands (enable - disable - exit - help quit)






29. Command used to disable HTTP Server






30. Layer 7






31. Command used to disable the ICMP message Address Mask Reply






32. The communication layer between the two other layers and provides network security - including ACLs - firewalls - any general public access servers and address translation; also known as the isolation LAN or DMZ






33. Router threat that occurs when an attacker manipulates IP packets to falsify IP addresses - causing network disruptions as the router attempts to process the packet






34. An extension of static mapping which allows for one global address to be mapped to multiple inside addresses; can be used for websites with multiple back end servers






35. Ip access-list <standard | extended> name - permit TCP any any established






36. DENY IP HOST <Inbound IP Address> HOST <Inbound IP Address>






37. ACK and RST






38. The environment - catastrophic events an unauthorized access






39. Attack that involves sending a large amount of UDP Echo packets to a subnet's broadcast address with a spoofed source IP address from that subnet






40. Access - Distribution - Core






41. 0x33 or 51






42. Access-list <number <deny | permit> source source-wildcard source-qualifier destination dest-wildcard dest-qualifier <log | log-input>






43. Enterprise


44. Device - Hostname - IOS - IP Address - Ports - Model






45. Attack that involves sending a packet to the router with the same IP address in the source and destination address fields - as well as the same port number in the source and destination port field - causing a denial of service






46. Tunnel Mode Protocol provides integrity - authentication - and non-repudiation and operates directly on top of IP






47. None - uses attached application protocol's port






48. Four TCP/UDP Small Server commands recommended to disable






49. Minor Version






50. Attack that involves sending a large amount of ICMP Echo packets to a subnet's broadcast address with a spoofed source IP address from that subnet