4.5 + 4.6 mitigation, hardening Flashcards

1
Q

What is a DMVPN?

A

Dynamic Multipoint Virtual Private Network, it is a secure network that allows permanent VPN connections to remain open without traffic needing to pass through a VPN concentrator.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

flood guard

A

Configures a maximum number of MAC addresses and disables a port if unrecongized MACs appear.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

root guard

A

Prevents rogue bridges from becoming the root bridge and distrupting STP.
changes interface status to root-inconsistent (listening state) if detected

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

BPDU guard

A

Bypasses listening and learning states of STP for faster convergeance, disables interfaces if it detects a BPDU frame.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

DHCP snooping

A

IP tracking on layer 2 device, prevents rogue DHCP servers. Trusted/untrusted devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

native VLAN

A

Interfaces not assigned to a specific VLAN, doesn’t add an 802.1Q header (non-trunked freames)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Data going into interfaces not assigned to a VLAN goes where?

A

native VLAN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

default VLAN

A

the VLAN associated wtih an interface by default

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is the default VLAN for the native VLAN? Why is this significant?

A

VLAN 1

Keeps user data and mangement protocols separate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

SYN guard

A

prevents syn flooding in SDN

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what is FIM?

A

File integrity monitoring.

Scans critical files in real time or on-demand such as SFC/Tripwire, makes sure it wasn’t changed

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

SFC/Tripwire are examples of what?

A

FIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

SFC/Tripwire are examples of what?

A

FIM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is BPDU

A

Bridge Protocol Data Units are frames that contain information about the spanning tree protocol.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What can prevent a network from becoming overwhelmed with MAC address entries?

A

flood guard

How well did you know this?
1
Not at all
2
3
4
5
Perfectly