SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
Router Security
Start Test
Study First
Subject
:
it-skills
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Protects against repeating of secure sessions
CDP Vulnerabilities
Inside Local Address
TCP/UDP Discard Vulnerability
Anti-Replay
2. What Transport Mode is used for
Local Addresses
Host-to-Host Communications
IP Source Routing
Standard ACL format
3. Device - Hostname - IOS - IP Address - Ports - Model
no ip mask-reply
IP Source Routing
CDP Vulnerabilities
Networks
4. 0x33 or 51
IPSec AH Identifier
Privilege Level 0
Standard ACL format
Fraggle Attack
5. Layer 7
HTTP Operating Layer
Three Layers of Hierarchical Model
IP Source Routing Vulnerabilities
ACL to block a Smurf Attack or Fraggle Attack
6. Refers to the addresses on the public internet
Outside
Privilege Level 0
Cisco Discovery Protocol (CDP)
Smurf Attack
7. Data link layer protocol used for tunneling network traffic between two peers over an existing network - often used with IPsec to secure packets
ESP Operating Layer
Three Physical Security Vulnerabilities
Layer 2 Tunneling Protocol (L2TP)
Telnet - HTTP - SNMP Vulnerability
8. Translates multiple local addresses to a pool of global addresses by having the firewall select the first available global address; retains the global address for the duration of the connection
SSH2
TCP/UDP Discard Vulnerability
Syntax for Reflexive ACLs
Dynamic NAT
9. Major Version - Minor Version - Release - Interim Build - Release Train Identifier
Proxy ARP Vulnerabilities
echo - chargen - discard - daytime
General Format of Cisco IOS Version
TCP/UDP Echo Vulnerability
10. Command used to disable the ICMP message Redirect
Privilege Level 0
Second Part of IOS Version
no ip redirect
Lower IP Standard ACL Range
11. Refers to the organization's private network
Inside
Requirements for Reflexive TCP to be removed
Train Identifier 'T'
no ip bootp server
12. Tunnel Mode Protocol provides confidentiality - along with authentication and integrity protection with encryption
Two Types of Router Access
Encapsulation Security Payload (ESP)
Distributed Denial of Service Attacks
TLS/SSL Identifier
13. 2000-2699
ACL to block a Land Attack
First Part of IOS Version
ESP Operating Layer
Higher IP Extended ACL Range
14. When one network protocol called the payload protocol is encapsulated within a different delivery network - or provide a secure path through an untrusted network
Tunneling
Lower IP Standard ACL Range
Privilege Level 1
Standard IP ACLs
15. Router threat that occurs when an attacker manipulates IP packets to falsify IP addresses - causing network disruptions as the router attempts to process the packet
Layer 2 Tunneling Protocol (L2TP)
SSH2
Privilege Level 1
IP Spoofing
16. Protocol that allows data to be exchanged using a secure channel between two computers via encryption
Network Time Protocol (NTP)
Rerouting
BOOTP Vulnerabilities
Secure Shell (SSH)
17. Access-list <number <deny | permit> source source-wildcard source-qualifier destination dest-wildcard dest-qualifier <log | log-input>
Requirements for Reflexive TCP to be removed
Static NAT
AUX Vulnerability
Extended ACL format
18. What Local and Global refer to in NAT
Fourth Part of the IOS Version
Masquerading
Networks
ACL to block a Land Attack
19. Command used to disable HTTP Server
Land Attack
Denial of Service (DoS)
no ip http server
Fifth Part of the IOS Version
20. DNS Poisoning
DNS Lookup Vulnerability
echo - chargen - discard - daytime
Standard IP ACLs
no cdp run
21. Helps to mitigate problems that are caused by the introduction of malformed or spoofed IP source addresses into a network by discarding packets lacking a verifiable IP source address
Unicast Reverse-Path Forwarding (uRPF)
L2TP Identifier
Route Injection Attack
Core Layer
22. Local IP address before translation
Inside Local Address
SSH
IP Unreachable Vulnerabilities
BOOTP Vulnerabilities
23. Datagram protocol used by some hosts to load their operating system over the network via a central repository of IOS software
IPSec AH Identifier
Transport Mode
BOOTP
Three Layers of Hierarchical Model
24. This layer controls user and workgroup acess to the Internetwork resources at the local level using segmentation of networks to create separate collision domains - AKA an organization's trusted network
Access Layer
Fraggle Attack
IP Source Routing Vulnerabilities
UDP Traceroute Port Range
25. Rewrites the and/or destination IP address of IP packets as they pass through a router or firewall from private to public addresses
Network Address Translation (NAT)
ESP Operating Layer
Two Types of Router Access
Common uses of Access Lists
26. Two - one Inbound or Evaluated and one Outbound or Reflected
Privilege Level 15
ESP Operating Layer
Standard ACL format
Minimum ACLs Required for Reflexive ACLs
27. Provides nonrepudiation - ensuring that traffic is from a trusted party
Tunneling
Authenticating Peers
Established Line
Encrypted Tunneling Methods
28. DENY IP ANY HOST <Broadcast Address>
ACL to block a Smurf Attack or Fraggle Attack
no ip bootp server
CDP Vulnerabilities
AUX Vulnerability
29. Commands to disable Finger Server
no ip finger - no service finger
TCP Intercept Watch Mode
Transport Layer Security (TLS) and Secure Sockets Layer (SSL)
Smurf Attack
30. Layer 3
TCP/UDP Daytime Vulnerability
Tunnel Mode
GRE Operating Layer
inger Server
31. Also known as Configuration Auto-Loading - allows routers to load their startup configuration from the network
Fraggle Attack
Distributed Denial of Service Attacks
Boot Network
IP Mask Reply Vulnerabilities
32. Cryptographic protocols that provide secure communications on the Internet for such thing as WWW - email - faxing - IM - and other data transfers
BOOTP
HTTP Vulnerability
Network Address Translation (NAT)
Transport Layer Security (TLS) and Secure Sockets Layer (SSL)
33. Can copy - poison - corrupt - or delete the IOS
TLS/SSL Layer
IP Mask Reply Vulnerabilities
BOOTP Vulnerabilities
Named ACL
34. TCP Port 22
IPSec AH Identifier
HTTP Tunneling
SSH Identifier
TCP/UDP Daytime Vulnerability
35. Access - Distribution - Core
no ip redirect
Three Layers of Hierarchical Model
Authenticating Peers
Common uses of Access Lists
36. Service Provider
37. ESP - SSH - SSL/TLP
Network-to-Network Communications
Finger Vulnerabilities
Encrypted Tunneling Methods
Two Protocols of Tunnel Mode
38. Router threat that involves a hacker inserting a spoofed TCP/IP packet into a stream - thereby enabling commands to be executed on the remote host
Unicast Reverse-Path Forwarding (uRPF)
Session Hijacking
no ip finger - no service finger
ACL to block a Smurf Attack or Fraggle Attack
39. Command to disable UDP small server on a router
Outside Global Address
uRPF Strength
Higher IP Extended ACL Range
no service udp-small-servers
40. Router threat where access by an entity or individual other than authorized users
SNMP
TCP Intercept
Unauthorized Access
Third Part of the IOS Version
41. Software that blocks packets from unreachable hosts - thus allowing only reachable external hosts to initiate connections to a host on an internal network
TCP Intercept
ACL to block a Land Attack
Train Idenifier 'E'
Tunnel Mode
42. DENY IP <Network ID> <Network WC Mask> ANY
Encapsulation Security Payload (ESP)
ACL to block spoofed IPs
no ip bootp server
Route Injection Attack
43. Geolocational positioning
TCP/UDP Daytime Vulnerability
SSH Operating Layer
Train Idenifier 'E'
no ip http server
44. Private IP address after translation
Encapsulation Security Payload (ESP)
Inside Global Address
IP Source Routing
no ip redirect
45. Access-list <number> <deny | permit> source source-wildcard log
Standard ACL format
no ip finger - no service finger
Authenticating Peers
Train Identifier 'B'
46. Uses server and host keys to authenticate systems
Overloading
GRE Identifier
Session Hijacking
SSH1
47. Command used to disable NTP on an interface
SNMP Trap
ntp disable
Distribution Layer
no ip finger - no service finger
48. TCP and UDP Port 161
Static NAT
Access Layer
Fifth Part of the IOS Version
SNMP
49. Layer 3
IPSec AH Operating Layer
ESP Identifier
TCP/UDP Chargen Vulnerability
Common uses of Access Lists
50. TCP and UDP Port 162
Denial of Service (DoS)
ACL to block TCP SYN Attack
Common uses of Access Lists
SNMP Trap