Deck 11: Network Security

Full screen (f)
exit full mode
Question
Network security is more often compromised "from the inside" than from external sources.
Use Space or
up arrow
down arrow
to flip the card.
Question
The use of certificate authorities to associate public keys with certain users is known as ____.

A) PGP
B) PKI
C) IPSec
D) SSL
Question
A ____ attack occurs when a system becomes unable to function because it has inundated with requests for services and can't respond to any of them.

A) flashing
B) denial-of-service
C) war driving
D) phishing
Question
Encryption is the last means of defense against data theft.
Question
____ is a public key encryption system that can verify the authenticity of an e-mail sender and encrypt e-mail data in transmission.

A) PGP
B) SSH
C) IPSec
D) SSL
Question
In a ____ attack, a person redirects or captures secure transmissions as they occur.

A) denial-of service
B) man-in-the-middle
C) war driving
D) phishing
Question
A security policy should state exactly which hardware, software, architecture, or protocols will be used to ensure security.
Question
A ____ firewall is a router (or a computer installed with software that enables it to act as a router) that examines the header of every packet of data it receives to determine whether that type of packet is authorized to continue to its destination.

A) packet-filtering
B) gateway
C) proxy
D) selective
Question
A(n) ____ is a password-protected and encrypted file that holds an individual's identification information, including a public key.

A) digital certificate
B) authentication file
C) access control list
D) authentication certificate
Question
The combination of a public key and a private key is known as a ____.

A) key lock
B) key frame
C) key pair
D) key set
Question
A router that is not configured to drop packets that match certain or suspicious characteristics is an example of a risk associated with ____.

A) people
B) transmission and hardware
C) protocols and software
D) Internet access
Question
A ____ attack occurs when a hacker uses programs that try a combination of a user ID and every word in a dictionary to gain access to the network.

A) flashing
B) denial-of-service
C) dictionary
D) brute force
Question
A NOS that contains a "back door"is an example of a risk associated with ____.

A) people
B) transmission and hardware
C) protocols and software
D) Internet access
Question
By default, the 802.11 standard offers substantial security.
Question
____ is a social engineering practice in which a person attempts to glean access or authentication information by posing as someone who needs that information.

A) Cracking
B) Hacking
C) War driving
D) Phishing
Question
Human errors, ignorance, and omissions cause more than half of all security breaches sustained by networks.
Question
A ____ attack occurs when an Internet chat user sends commands to a victim's machine that causes the screen to fill with garbage characters and requires the victim to terminate their chat sessions.

A) flashing
B) denial-of-service
C) war driving
D) phishing
Question
A ____ attack occurs when a hacker tries numerous possible character combinations to find the key that will decrypt encrypted data.

A) flashing
B) denial-of-service
C) dictionary
D) brute force
Question
____ software searches a node for open ports.

A) Phishing
B) Sniffing
C) Authentication
D) Port scanner
Question
A ____ main function is to examine packets and determine where to direct them based on their Network layer addressing information.

A) switch's
B) gateway's
C) router's
D) proxy server's
Question
In ____, both computers verify the credentials of the other.

A) mutual authorization
B) mutual access
C) mutual authentication
D) mutual verification
Question
Define SSH (secure shell) and explain the threats it guards against. Include an explanation of the encryption algorithms that may be used with it.
Question
RADIUS and TACACS belong to a category of protocols known as AAA (____).

A) access, authorization, and accounting
B) authentication, authorization, and accounting
C) authentication, authorization, and authority
D) authentication, authorization, and access
Question
____ is a method of encrypting TCP/IP transmissions above the network layer.

A) PGP
B) IPSec
C) PAP
D) SSL
Question
____________________ is the use of an algorithm to scramble data into a format that can be read only by reversing the algorithm.
Question
Describe who should conduct a security audit and the advantages of doing so, if any.
Question
Describe one potential flaw in CHAP and MS-CHAP authentication and explain how it is resolved.
Question
A(n) ____________________ identifies an organization's security risks, levels of authority, designated security coordinator and team members, responsibilities for each team member, and responsibilities for each employee.
Question
Explain how to block traffic attempting to exit a LAN and discuss why an administrator would want to do this.
Question
Describe the SCP (Secure CoPy) utility.
Question
Describe the two phases IPSec use to accomplish authentication.
Question
A(n) ____________________ is a software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
Question
Describe the three-way handshake used in CHAP.
Question
A VPN ____ authenticates VPN clients and establishes tunnels for VPN connections.

A) router
B) service
C) concentrator
D) certificate authority
Question
In ____, a hacker forges name server records to falsify his host's identity.

A) IP spoofing
B) DNS spoofing
C) ID spoofing
D) DHCP spoofing
Question
A(n) ____________________ is a thorough examination of each aspect of the network to determine how it might be compromised.
Question
In general, information is ____________________ if it could be used by other parties to impair an organization's functioning, decrease customers' confidence, cause a financial loss, damage an organization's status, or give a significant advantage to a competitor.
Question
Define and describe PAP.
Question
____ protocols are the rules that computers follow to accomplish authentication.

A) Access
B) Availability
C) Authority
D) Authentication
Question
Describe what distinguishes 802.1x from other authentication standards.
Question
Describe an advantage of using EAP.
Question
Match between columns
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
Stateful
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
proxy service
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
IDS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
HIDS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
public key encryption
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
content filtering
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
IPS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
private key encryption
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
proxy server
Data is encrypted using a single key.
Stateful
Data is encrypted using a single key.
proxy service
Data is encrypted using a single key.
IDS
Data is encrypted using a single key.
HIDS
Data is encrypted using a single key.
public key encryption
Data is encrypted using a single key.
content filtering
Data is encrypted using a single key.
IPS
Data is encrypted using a single key.
private key encryption
Data is encrypted using a single key.
proxy server
Software that can only detect and log suspicious activity.
Stateful
Software that can only detect and log suspicious activity.
proxy service
Software that can only detect and log suspicious activity.
IDS
Software that can only detect and log suspicious activity.
HIDS
Software that can only detect and log suspicious activity.
public key encryption
Software that can only detect and log suspicious activity.
content filtering
Software that can only detect and log suspicious activity.
IPS
Software that can only detect and log suspicious activity.
private key encryption
Software that can only detect and log suspicious activity.
proxy server
A firewall that protects only the computer on which it is installed.
Stateful
A firewall that protects only the computer on which it is installed.
proxy service
A firewall that protects only the computer on which it is installed.
IDS
A firewall that protects only the computer on which it is installed.
HIDS
A firewall that protects only the computer on which it is installed.
public key encryption
A firewall that protects only the computer on which it is installed.
content filtering
A firewall that protects only the computer on which it is installed.
IPS
A firewall that protects only the computer on which it is installed.
private key encryption
A firewall that protects only the computer on which it is installed.
proxy server
The host that runs the proxy service.
Stateful
The host that runs the proxy service.
proxy service
The host that runs the proxy service.
IDS
The host that runs the proxy service.
HIDS
The host that runs the proxy service.
public key encryption
The host that runs the proxy service.
content filtering
The host that runs the proxy service.
IPS
The host that runs the proxy service.
private key encryption
The host that runs the proxy service.
proxy server
A firewall that can block designated types of traffic based on application data contained within packets.
Stateful
A firewall that can block designated types of traffic based on application data contained within packets.
proxy service
A firewall that can block designated types of traffic based on application data contained within packets.
IDS
A firewall that can block designated types of traffic based on application data contained within packets.
HIDS
A firewall that can block designated types of traffic based on application data contained within packets.
public key encryption
A firewall that can block designated types of traffic based on application data contained within packets.
content filtering
A firewall that can block designated types of traffic based on application data contained within packets.
IPS
A firewall that can block designated types of traffic based on application data contained within packets.
private key encryption
A firewall that can block designated types of traffic based on application data contained within packets.
proxy server
Data is encrypted using two keys.
Stateful
Data is encrypted using two keys.
proxy service
Data is encrypted using two keys.
IDS
Data is encrypted using two keys.
HIDS
Data is encrypted using two keys.
public key encryption
Data is encrypted using two keys.
content filtering
Data is encrypted using two keys.
IPS
Data is encrypted using two keys.
private key encryption
Data is encrypted using two keys.
proxy server
Software that can react to suspicious activity.
Stateful
Software that can react to suspicious activity.
proxy service
Software that can react to suspicious activity.
IDS
Software that can react to suspicious activity.
HIDS
Software that can react to suspicious activity.
public key encryption
Software that can react to suspicious activity.
content filtering
Software that can react to suspicious activity.
IPS
Software that can react to suspicious activity.
private key encryption
Software that can react to suspicious activity.
proxy server
A firewall that can view a data stream.
Stateful
A firewall that can view a data stream.
proxy service
A firewall that can view a data stream.
IDS
A firewall that can view a data stream.
HIDS
A firewall that can view a data stream.
public key encryption
A firewall that can view a data stream.
content filtering
A firewall that can view a data stream.
IPS
A firewall that can view a data stream.
private key encryption
A firewall that can view a data stream.
proxy server
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/42
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 11: Network Security
1
Network security is more often compromised "from the inside" than from external sources.
True
2
The use of certificate authorities to associate public keys with certain users is known as ____.

A) PGP
B) PKI
C) IPSec
D) SSL
B
3
A ____ attack occurs when a system becomes unable to function because it has inundated with requests for services and can't respond to any of them.

A) flashing
B) denial-of-service
C) war driving
D) phishing
B
4
Encryption is the last means of defense against data theft.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
5
____ is a public key encryption system that can verify the authenticity of an e-mail sender and encrypt e-mail data in transmission.

A) PGP
B) SSH
C) IPSec
D) SSL
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
6
In a ____ attack, a person redirects or captures secure transmissions as they occur.

A) denial-of service
B) man-in-the-middle
C) war driving
D) phishing
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
7
A security policy should state exactly which hardware, software, architecture, or protocols will be used to ensure security.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
8
A ____ firewall is a router (or a computer installed with software that enables it to act as a router) that examines the header of every packet of data it receives to determine whether that type of packet is authorized to continue to its destination.

A) packet-filtering
B) gateway
C) proxy
D) selective
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
9
A(n) ____ is a password-protected and encrypted file that holds an individual's identification information, including a public key.

A) digital certificate
B) authentication file
C) access control list
D) authentication certificate
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
10
The combination of a public key and a private key is known as a ____.

A) key lock
B) key frame
C) key pair
D) key set
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
11
A router that is not configured to drop packets that match certain or suspicious characteristics is an example of a risk associated with ____.

A) people
B) transmission and hardware
C) protocols and software
D) Internet access
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
12
A ____ attack occurs when a hacker uses programs that try a combination of a user ID and every word in a dictionary to gain access to the network.

A) flashing
B) denial-of-service
C) dictionary
D) brute force
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
13
A NOS that contains a "back door"is an example of a risk associated with ____.

A) people
B) transmission and hardware
C) protocols and software
D) Internet access
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
14
By default, the 802.11 standard offers substantial security.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
15
____ is a social engineering practice in which a person attempts to glean access or authentication information by posing as someone who needs that information.

A) Cracking
B) Hacking
C) War driving
D) Phishing
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
16
Human errors, ignorance, and omissions cause more than half of all security breaches sustained by networks.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
17
A ____ attack occurs when an Internet chat user sends commands to a victim's machine that causes the screen to fill with garbage characters and requires the victim to terminate their chat sessions.

A) flashing
B) denial-of-service
C) war driving
D) phishing
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
18
A ____ attack occurs when a hacker tries numerous possible character combinations to find the key that will decrypt encrypted data.

A) flashing
B) denial-of-service
C) dictionary
D) brute force
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
19
____ software searches a node for open ports.

A) Phishing
B) Sniffing
C) Authentication
D) Port scanner
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
20
A ____ main function is to examine packets and determine where to direct them based on their Network layer addressing information.

A) switch's
B) gateway's
C) router's
D) proxy server's
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
21
In ____, both computers verify the credentials of the other.

A) mutual authorization
B) mutual access
C) mutual authentication
D) mutual verification
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
22
Define SSH (secure shell) and explain the threats it guards against. Include an explanation of the encryption algorithms that may be used with it.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
23
RADIUS and TACACS belong to a category of protocols known as AAA (____).

A) access, authorization, and accounting
B) authentication, authorization, and accounting
C) authentication, authorization, and authority
D) authentication, authorization, and access
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
24
____ is a method of encrypting TCP/IP transmissions above the network layer.

A) PGP
B) IPSec
C) PAP
D) SSL
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
25
____________________ is the use of an algorithm to scramble data into a format that can be read only by reversing the algorithm.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
26
Describe who should conduct a security audit and the advantages of doing so, if any.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
27
Describe one potential flaw in CHAP and MS-CHAP authentication and explain how it is resolved.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
28
A(n) ____________________ identifies an organization's security risks, levels of authority, designated security coordinator and team members, responsibilities for each team member, and responsibilities for each employee.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
29
Explain how to block traffic attempting to exit a LAN and discuss why an administrator would want to do this.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
30
Describe the SCP (Secure CoPy) utility.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
31
Describe the two phases IPSec use to accomplish authentication.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
32
A(n) ____________________ is a software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
33
Describe the three-way handshake used in CHAP.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
34
A VPN ____ authenticates VPN clients and establishes tunnels for VPN connections.

A) router
B) service
C) concentrator
D) certificate authority
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
35
In ____, a hacker forges name server records to falsify his host's identity.

A) IP spoofing
B) DNS spoofing
C) ID spoofing
D) DHCP spoofing
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
36
A(n) ____________________ is a thorough examination of each aspect of the network to determine how it might be compromised.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
37
In general, information is ____________________ if it could be used by other parties to impair an organization's functioning, decrease customers' confidence, cause a financial loss, damage an organization's status, or give a significant advantage to a competitor.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
38
Define and describe PAP.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
39
____ protocols are the rules that computers follow to accomplish authentication.

A) Access
B) Availability
C) Authority
D) Authentication
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
40
Describe what distinguishes 802.1x from other authentication standards.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
41
Describe an advantage of using EAP.
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
42
Match between columns
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
Stateful
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
proxy service
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
IDS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
HIDS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
public key encryption
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
content filtering
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
IPS
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
private key encryption
A software application on a network host that acts as an intermediary between the external and internal networks, screening all incoming and outgoing traffic.
proxy server
Data is encrypted using a single key.
Stateful
Data is encrypted using a single key.
proxy service
Data is encrypted using a single key.
IDS
Data is encrypted using a single key.
HIDS
Data is encrypted using a single key.
public key encryption
Data is encrypted using a single key.
content filtering
Data is encrypted using a single key.
IPS
Data is encrypted using a single key.
private key encryption
Data is encrypted using a single key.
proxy server
Software that can only detect and log suspicious activity.
Stateful
Software that can only detect and log suspicious activity.
proxy service
Software that can only detect and log suspicious activity.
IDS
Software that can only detect and log suspicious activity.
HIDS
Software that can only detect and log suspicious activity.
public key encryption
Software that can only detect and log suspicious activity.
content filtering
Software that can only detect and log suspicious activity.
IPS
Software that can only detect and log suspicious activity.
private key encryption
Software that can only detect and log suspicious activity.
proxy server
A firewall that protects only the computer on which it is installed.
Stateful
A firewall that protects only the computer on which it is installed.
proxy service
A firewall that protects only the computer on which it is installed.
IDS
A firewall that protects only the computer on which it is installed.
HIDS
A firewall that protects only the computer on which it is installed.
public key encryption
A firewall that protects only the computer on which it is installed.
content filtering
A firewall that protects only the computer on which it is installed.
IPS
A firewall that protects only the computer on which it is installed.
private key encryption
A firewall that protects only the computer on which it is installed.
proxy server
The host that runs the proxy service.
Stateful
The host that runs the proxy service.
proxy service
The host that runs the proxy service.
IDS
The host that runs the proxy service.
HIDS
The host that runs the proxy service.
public key encryption
The host that runs the proxy service.
content filtering
The host that runs the proxy service.
IPS
The host that runs the proxy service.
private key encryption
The host that runs the proxy service.
proxy server
A firewall that can block designated types of traffic based on application data contained within packets.
Stateful
A firewall that can block designated types of traffic based on application data contained within packets.
proxy service
A firewall that can block designated types of traffic based on application data contained within packets.
IDS
A firewall that can block designated types of traffic based on application data contained within packets.
HIDS
A firewall that can block designated types of traffic based on application data contained within packets.
public key encryption
A firewall that can block designated types of traffic based on application data contained within packets.
content filtering
A firewall that can block designated types of traffic based on application data contained within packets.
IPS
A firewall that can block designated types of traffic based on application data contained within packets.
private key encryption
A firewall that can block designated types of traffic based on application data contained within packets.
proxy server
Data is encrypted using two keys.
Stateful
Data is encrypted using two keys.
proxy service
Data is encrypted using two keys.
IDS
Data is encrypted using two keys.
HIDS
Data is encrypted using two keys.
public key encryption
Data is encrypted using two keys.
content filtering
Data is encrypted using two keys.
IPS
Data is encrypted using two keys.
private key encryption
Data is encrypted using two keys.
proxy server
Software that can react to suspicious activity.
Stateful
Software that can react to suspicious activity.
proxy service
Software that can react to suspicious activity.
IDS
Software that can react to suspicious activity.
HIDS
Software that can react to suspicious activity.
public key encryption
Software that can react to suspicious activity.
content filtering
Software that can react to suspicious activity.
IPS
Software that can react to suspicious activity.
private key encryption
Software that can react to suspicious activity.
proxy server
A firewall that can view a data stream.
Stateful
A firewall that can view a data stream.
proxy service
A firewall that can view a data stream.
IDS
A firewall that can view a data stream.
HIDS
A firewall that can view a data stream.
public key encryption
A firewall that can view a data stream.
content filtering
A firewall that can view a data stream.
IPS
A firewall that can view a data stream.
private key encryption
A firewall that can view a data stream.
proxy server
Unlock Deck
Unlock for access to all 42 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 42 flashcards in this deck.