Switch Security Flashcards

1
Q

If the clients are not on the same subnet as with the DHCP server, you need to configure a _________ on the router

A

IP helper address

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the solution to prevent rogue DHCP servers from being active in your network?

A

DHCP snooping

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does DHCP snooping work?

A

By creating trusted ports that are directly connected to the DHCP server and also your inter-switch links leading down to the host

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the commands to enable DHCP snooping?

A

> SW1 (config) # ip dchp snooping
SW1 (config) # int f0/1
SW1 (config-if) # ip dchp snooping trust

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does ARP do?

A

Address Resolution Protocol, An ARP request is a broadcast message sent by a device on a local network, asking for the MAC address associated with a specific IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does Dynamic ARP Inspection (DAI) do?

A

prevents attackers from spoofing ARP on the network

For example, PC1 with MAC address 1.1.1, was assigned IP address 10.10.10.10 by the DHCP server. Then, if invalid ARP traffic tries to pass through the switch, for example, attacker 3.3.3 saying that it is 10.10.10.10, the switch can see that that MAC address does not map to that IP address and drop the traffic

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

DAI is not do on ______ ports, only enable this for ______ clients

A

trusted, non DHCP

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

When 802.1X is enabled, only ________ traffic is allowed on the switch ports until the _____ and _____ are authenticated

A

authentication, host, user

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Most newer severs use ______ as the authentication server

A

Identity Services Engine (ISE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly