Implementation Flashcards
Which IPSec mode is used to create a VPN between two gateways
Tunnel mode
Who can change a resource’s category in a mandatory access control environment?
Administrators only
What is the purpose of content inspection
To search for malicious code or behavior
Which information do routers use to forward packets to their destinations?
The network address and subnet mask
Where should you physically store mobile devices to prevent theft?
- Locked cabinet
* Safe
What is Lightweight Extensible Authentication Protocol (LEAP)
A proprietary wireless LAN authentication method developed by Cisco Systems
Between which two OSI layers does Secure Sockets Layer (SSL) operate?
- Between the OSI Transport and Application layers
* Layer 4 to Layer 7
What is the purpose of Remote Access Dial-In User Service (RADIUS)?
Enables remote access users to log onto a network through a shared authentication database
What is a TMP?
A dedicated processor that uses cryptographic keys to perform a variety of tasks
What would a certification authority (CA) do if a private key associated with a certificate had been compromised?
Revoke the certificate
Which settings ensure that accounts are not used beyond a certain date and/or time?
Account expiration
What is the purpose of network access control (NAC)?
Ensures that the computer on the network meets an organization’s security policies
What are the two modes of WPA and WPA2?
- Personal, aka
- Preshared Key
- WPA-PSK / WPA2-PSK
- Enterprise
What is the name of the area that connects to a firewall and offers services to untrusted networks?
Demilitarized zone (DMZ)
Which security-server application and protocol implement authentication of users from a central server over UDP?
Remote Authentication Dial-In User Service (RADIUS)
What is the purpose of an aggregation switch?
Combine multiple streams of bandwitdh into one
Which type of IDS detects malicious packets on a network?
Network intrusion detection system (NIDS)
What is a sandbox in a secure staging deployment?
A test environment that is completely isolated from the rest of the network
What does the acronym MAC denote?
Mandatory Access Control
What application or service uses TCP/UDP port 3389?
Remote Desktop Protocol (RDP)
Which audit category will audit all instances of users exercising their rights?
Audit Privilege Use audit category
Which setting ensures that repeated attempts to guess a user’s password is not possible beyond the configured value?
Account lockout
What is the purpose of BitLocker To Go?
Ensure that USB flash drives issued by the organization are protected by encryption
What does the subject field in an X.509 v3 certificate contain?
The name of the certificate owner