SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Router Security
Start Test
Study First
Subject
:
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. An alternative for both standard and extended ACLs that allow you to refer to an ACL by a descriptive name instead of a number
Second Part of IOS Version
Established Line
Named ACL
ESP Operating Layer
2. Uses server and host keys to authenticate systems
SSH1
BOOTP Vulnerabilities
IP Direct Broadcast Vulnerabilties
no ip mask-reply
3. Release Train Identifier
Overloading
HTTP Identifier
Fifth Part of the IOS Version
Reflexive ACL
4. DENY IP ANY HOST <Broadcast Address>
ACL to block a Smurf Attack or Fraggle Attack
Three Physical Security Vulnerabilities
Encrypted Tunneling Methods
Privilege Levels 2-13
5. Transport and Tunnel
Boot Network
Denial of Service (DoS)
L2TP Operating Layer
Two Modes of IPSec
6. What Transport Mode is used for
ACL to block a Smurf Attack or Fraggle Attack
Anti-Replay
Host-to-Host Communications
TCP Intercept
7. These ACLs filter by network or host IP addresses andspecific protocol type or port numbers - filters by source and destination
Extended IP ACLs
Fifth Part of the IOS Version
Proxy ARP
Tunnel Mode
8. Rewrites the and/or destination IP address of IP packets as they pass through a router or firewall from private to public addresses
Network Address Translation (NAT)
Distributed Denial of Service Attacks
SNMP Trap
Privilege Levels 2-13
9. Routing mode depended on by uRPF in order to function
Host-to-Host Communications
Cisco Express Forwarding (CEF)
Minimum ACLs Required for Reflexive ACLs
SSH
10. UDP Port 514
Access List Rules
GRE Operating Layer
Cisco Express Forwarding (CEF)
syslog
11. Private IP address after translation
Inside Global Address
ACL to block a Smurf Attack or Fraggle Attack
echo - chargen - discard - daytime
Layer 2 Tunneling Protocol (L2TP)
12. Technology
13. DENY TCP ANY HOST <IP Address> EQ 23
Requirements for Reflexive TCP to be removed
ACL to block telnet
Layer 2 Tunneling Protocol (L2TP)
no service udp-small-servers
14. A method of bypassing firewall or proxy restrictions by making the firewall think that it is getting traffic from a web browser
SSH2
Train Identifier 'B'
Proxy ARP
HTTP Tunneling
15. Form of dynamic NAT that maps multiple unregistered IP addresses to a single registered IP address by using different ports; limited to ~64 -000 hosts
Requirements for Reflexive TCP to be removed
Lower IP Extended ACL Range
no ip mask-reply
Overloading
16. Router threat that includes manipulating router updates to cause traffic to flow to unauthorized destinations
Anti-Replay
Privilege Level 0
Rerouting
no service tcp-small-servers
17. None - uses attach application protocol's layer
TLS/SSL Layer
TCP/UDP Chargen Vulnerability
Inside Local Address
Cisco Discovery Protocol (CDP)
18. Protects against repeating of secure sessions
Anti-Replay
Tunnel Mode
SSH Operating Layer
Privilege Levels 2-13
19. This server is used for querying a host about its logged in users
inger Server
Privilege Levels 2-13
Encrypting Traffic
IP Source Routing Vulnerabilities
20. UDP Port 1701
L2TP Identifier
Denial of Service (DoS)
TCP/UDP Chargen Vulnerability
Common uses of Access Lists
21. Major Version - Minor Version - Release - Interim Build - Release Train Identifier
Access List Rules
General Format of Cisco IOS Version
Core Layer
AUX Vulnerability
22. PERMIT TCP ANY ANY ESTABLISHED
Unauthorized Access
IP Spoofing
Extended ACL format
ACL to block TCP SYN Attack
23. Authentication Header (AH) and Encapsulated Security Payload (ESP)
TLS/SSL Identifier
ACL to block spoofed IPs
ntp disable
Two Protocols of Tunnel Mode
24. TCP Port 80
uRPF Strength
HTTP Identifier
Smurf Attack
Denial of Service (DoS)
25. Command to disable CDP on a router
Internet Protocol Security (IPSec)
no ip http server
Local Addresses
no cdp run
26. Protocol used to keep their time-of-day clocks accurate and in sync
SSH Identifier
Network Time Protocol (NTP)
Minimum ACLs Required for Reflexive ACLs
Three Layers of Hierarchical Model
27. None - uses attached application protocol's port
Minimum ACLs Required for Reflexive ACLs
TLS/SSL Identifier
HTTP Tunneling
TCP Intercept
28. Helps to mitigate problems that are caused by the introduction of malformed or spoofed IP source addresses into a network by discarding packets lacking a verifiable IP source address
IPSec AH Identifier
Unicast Reverse-Path Forwarding (uRPF)
HTTP Vulnerability
GRE Operating Layer
29. Layer 3
no ip finger - no service finger
IPSec AH Operating Layer
UDP Traceroute Port Range
IP Directed Broadcast
30. Uses SSL port 443
Minimum ACLs Required for Reflexive ACLs
no ip unreachable
GRE Identifier
HTTPS Strength
31. These ACLs filter by network or host IP address and only filter on source
Devices
Privilege Levels 2-13
Train Idenifier 'E'
Standard IP ACLs
32. Public IP address after translation
Outside Global Address
no ip unreachable
Requirements for Reflexive TCP to be removed
inger Server
33. Can copy - poison - corrupt - or delete the IOS
Global Addresses
ACL to block spoofed IPs
BOOTP Vulnerabilities
Static NAT
34. Privilege level that restricts users to five commands (enable - disable - exit - help quit)
Dynamic NAT
Privilege Level 0
Distributed Denial of Service Attacks
Outside Local Address
35. Layer 7
ACL to block incoming loopback packets
ACL to block telnet
SSH Operating Layer
Inside Local Address
36. Startup-config can be deleted - copied - changed
echo - chargen - discard - daytime
Dynamic NAT
Boot Network Vulnerabilities
Eavesdropping and Information Theft
37. Can discover vulnerabilities - network stats - and firewall discovery
IP Unreachable Vulnerabilities
SSH2
ACL to block TCP SYN Attack
SNMP Trap
38. Software that blocks packets from unreachable hosts - thus allowing only reachable external hosts to initiate connections to a host on an internal network
TCP Intercept
User Account Vulnerabilites
NTP Vulnerabilities
Privilege Level 1
39. The environment - catastrophic events an unauthorized access
Three Physical Security Vulnerabilities
Fifth Part of the IOS Version
Uses for ACLs
Internet Protocol Security (IPSec)
40. Router threat that includes manipulating router updates to cause traffic to flow to unauthorized destinations
Route Injection Attack
Boot Network Vulnerabilities
Proxy ARP Vulnerabilities
TCP/UDP Daytime Vulnerability
41. Rebuild Number
no service tcp-small-servers
Finger Vulnerabilities
Sixth (Optional) Part of the IOS Version
Secure Shell (SSH)
42. Refers to the addresses on the public internet
Outside
ACL to block telnet
L2TP Identifier
Minimum ACLs Required for Reflexive ACLs
43. Permits a host on one LAN segment to initiate a physical broadcast on a different LAN segment
Named ACL
IP Directed Broadcast
SNMP
SSH
44. Users - Host PC's - IP Addresses
ACL to block a Smurf Attack or Fraggle Attack
Finger Vulnerabilities
Rerouting
Boot Network Vulnerabilities
45. Proprietary - used by Cisco routers and switches use to identify each other on LAN and WAN segments
Integrity Validation
Cisco Discovery Protocol (CDP)
Boot Network
IP Directed Broadcast
46. Four TCP/UDP Small Server commands recommended to disable
echo - chargen - discard - daytime
HTTP Vulnerability
Transport Mode
Inside Global Address
47. Command used to disable the ICMP message Host Unreachable
no ip unreachable
IP Unreachable Vulnerabilities
TCP/UDP Daytime Vulnerability
First Part of IOS Version
48. Tunnel Mode Protocol provides integrity - authentication - and non-repudiation and operates directly on top of IP
GRE Operating Layer
Authentication Header (AH)
Proxy ARP Vulnerabilities
TCP Load Distribution
49. Command used to disable the ICMP message Address Mask Reply
Access List Rules
User Account Vulnerabilites
no ip mask-reply
Dynamic NAT
50. Attack that involves sending a packet to the router with the same IP address in the source and destination address fields - as well as the same port number in the source and destination port field - causing a denial of service
Land Attack
Common uses of Access Lists
SSH Operating Layer
Train Identifier 'S'