Chapter 7 Flashcards

Share

1
Q

An enterprise-wide VPN can include elements of both the client-to-site and site-to site
models.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

After L2TP establishing a VPN tunnel, GRE is used to transmit L2TP data frames
through the tunnel.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

PPP can support several types of Network layer protocols that might use the
connection.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A community cloud is a service shared between multiple organizations, but not
available publicly.

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A Type 2 hypervisor installs on a computer before any OS, and is therefore called a
bare-metal hypervisor.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Office 365 is an example of an SaaS implementation with a subscription model

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
Digital certificates are issued, maintained, and validated by an organization called a
certificate authority (CA).
A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

The HTTPS (HTTP Secure) protocol utilizes the same TCP port as HTTP, port 80.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

FTPS (FTP Security or FTP Secure) and SFTP (Secure FTP) are two names for the
same protocol.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
The Virtual Network Computing (VNC) application uses the cross-platform remote
frame buffer (RFB) protocol.
A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which type of cloud service model involves hardware services that are provided
virtually, including network infrastructure devices such as virtual servers?

A

IaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What cloud service model involves providing applications through an online user
interface, providing for compatibility with a multitude of different operating systems
and devices?

A

SaaS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What type of scenario would be best served by using a Platform as a Service (PaaS)
cloud model?

A

A group of developers needs access to multiple operating systems and the
runtime libraries that the OS provides.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When using public and private keys to connect to an SSH server from a Linux
device, where must your public key be placed before you can connect?

A

In an authorization file on the host where the SSH server is.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The combination of a public key and a private key are known by what term below?

A

key pair

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What security encryption protocol requires regular re-establishment of a connection
and can be used with any type of TCP/IP transmission?

A

IPsec

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

At what layer of the OSI model does the IPsec encryption protocol operate?

A

Network layer

18
Q

The PPP headers and trailers used to create a PPP frame that encapsulates Network
layer packets vary between 8 and 10 bytes in size due to what field?

19
Q

When using a site-to-site VPN, what type of device sits at the edge of the LAN and
establishes the connection between sites?

A

VPN gateway

20
Q

Amazon and Rackspace both utilize what virtualization software below to create
their cloud environments?

A

Citrix Xen

21
Q

What open-source VPN protocol utilizes OpenSSL for encryption and has the ability
to possibly cross firewalls where IPsec might be blocked?

22
Q

VMware Player and Linux KVM are both examples of what type of hypervisor?

A

Type 2 hypervisor

23
Q

Which statement regarding the use of a bridged mode vNIC is accurate?

A

The vNIC will its own IP address on the physical LAN.

24
Q

When is it appropriate to utilize the NAT network connection type?

A

Whenever the VM does not need to be access at a known address by other
network nodes.

25
By default, what network connection type is selected when creating a VM in VMware, VirtualBox, or KVM?
NAT mode
26
Which statement regarding the IKEv2 tunneling protocol is accurate?
IKEv2 offers fast throughput and good stability when moving between wireless hotspots.
27
The use of certificate authorities to associate public keys with certain users is known by what term?
public-key infrastructure
28
What is NOT a potential disadvantage of utilizing virtualization?
Virtualization software increases the complexity of backups, making creation of usable backups difficult.
29
``` A vSwitch (virtual switch) or bridge is a logically defined device that operates at what layer of the OSI model? ```
Layer 2
30
Which of the following virtualization products is an example of a bare-metal hypervisor?
Citrix XenServer
31
In a software defined network, what is responsible for controlling the flow of data?
SDN controller
32
What term is used to describe a space that is rented at a data center facility by a service provider?
point of presence (PoP)
33
Which of the following statements regarding the Point-to-Point (PPP) protocol is NOT accurate?
PPP can support strong encryption, such as AH or ESP.
34
Why is the telnet utility a poor choice for remote access to a device?
It provides poor authentication and no encryption.
35
What statement regarding the SSH (Secure Shell) collection of protocols is accurate?
SSH supports port forwarding
36
In order to generate a public and private key for use with SSH, what command line utility should you use?
ssh-keygen
37
``` Regarding VNC (Virtual Network Computing or Virtual Network Connection), what statement is accurate? ```
VNC is open source, allowing companies to develop their own software based on VNC.
38
Which file transfer protocol has no authentication or security for transferring files, uses UDP, and requires very little memory to use?
Trivial FTP (TFTP)
39
What special enterprise VPN supported by Cisco devices creates VPN tunnels between branch locations as needed rather than requiring constant, static tunnels?
Dynamic Multipoint VPN
40
Which of the following is NOT a task that a VPN concentrator is responsible for?
A VPN concentrator shuts down established connections with malicious traffic occurs.