Test your basic knowledge |

Router Security

Subject : it-skills
Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. DENY TCP ANY HOST <IP Address> EQ 23






2. Proprietary - used by Cisco routers and switches use to identify each other on LAN and WAN segments






3. DENY IP HOST <Inbound IP Address> HOST <Inbound IP Address>






4. Also known as Configuration Auto-Loading - allows routers to load their startup configuration from the network






5. Command to disable CDP on a router






6. Privilege level that is restricted to basic level operations






7. Layer 5






8. The communication layer between the two other layers and provides network security - including ACLs - firewalls - any general public access servers and address translation; also known as the isolation LAN or DMZ






9. Command to disable TCP small server on a router






10. Smurf attacks - can enumerate the network






11. The environment - catastrophic events an unauthorized access






12. Command used to disable the ICMP message Redirect






13. Tunnel Mode Protocol provides integrity - authentication - and non-repudiation and operates directly on top of IP






14. Time can be changed - Routing Table can be killed






15. 0x33 or 51






16. Privilege level that has Global administration capabilities






17. Transport and Tunnel






18. Protects against repeating of secure sessions






19. Public IP address after translation






20. 2000-2699






21. DENY IP <Network ID> <Network WC Mask> ANY






22. Layer 7






23. Forces the user to enter both a valid username and password






24. 33400-34400






25. Must be made at global config mode - created from CON/VTY session or text file - read top to bottom - applied at the interface and only one ACL per direction - per protocol - per interface






26. Router threat that occurs when an attacker manipulates IP packets to falsify IP addresses - causing network disruptions as the router attempts to process the packet






27. Mode where only the payload of the IP packet is encrypted and/or authenticated






28. Broadcast


29. Users - Host PC's - IP Addresses






30. DENY IP 224.0.0.0 15.255.255.255 ANY






31. DNS Poisoning






32. Layer 7






33. Command to disable UDP small server on a router






34. Layer 3






35. What Tunnel Mode is used for






36. Translates multiple local addresses to a pool of global addresses by having the firewall select the first available global address; retains the global address for the duration of the connection






37. Top of the hierarchy - responsible for transporting large amounts of traffic both reliably and quickly and switching traffic as fast as possible throughout the internet






38. Attack that involves a multitude of compromised system attack a single target - denying service to it by exploiting one 'master' system that communicates with other 'zombie' systems






39. Buffer Overflow






40. TCP only - used to filter inbound traffic while allowing return TCP sessions - can be spoofed by attackers and cannot be used with Active FTP






41. No Known Vulnerability






42. DENY IP 127.0.0.0 0.255.255.255 ANY






43. Access-list <number <deny | permit> source source-wildcard source-qualifier destination dest-wildcard dest-qualifier <log | log-input>






44. Permits a host on one LAN segment to initiate a physical broadcast on a different LAN segment






45. Datagram protocol used by some hosts to load their operating system over the network via a central repository of IOS software






46. Accounts without passwords - Type 7 encryption - account privilege higher than 1 - able to be fingered






47. Privilege levels that can have passwords assigned to them






48. 0x2F - or 47






49. UDP Port 514






50. Attack that involves sending a packet to the router with the same IP address in the source and destination address fields - as well as the same port number in the source and destination port field - causing a denial of service