CCNA 200 301 Domain 5: Security
Fundamental- EXAM QUESTIONS AND ALL
CORRECT ANSWERS 100% SOLVED AND
GUARANTEED SUCCESS
The Stuxnet worm was discovered in 2010 and was used to gain sensitive information about
Iran's industrial infrastructure. This worm was probably active for about five years before being
discovered. During this time, the attacker had access to the target. Which type of attack was
Stuxnet? ------- ✔ CORRECT ANSWER ✓✓APT
Which type of threat actor only uses skills and knowledge for defensive purposes? ------- ✔
CORRECT ANSWER ✓✓White Hat
Which statement best describes a suicide hacker? ------- ✔ CORRECT ANSWER ✓✓This hacker is
only concerned with taking down their target for a cause. They have no concerns about being
caught.
Miguel has been practicing his hacking skills. He has discovered a vulnerability on a system that
he did not have permission to attack. Once Miguel discovered the vulnerability, he anonymously
alerted the owner and told him how to secure the system. Which type of hacker is Miguel in this
scenario? ------- ✔ CORRECT ANSWER ✓✓Gray hat
The process of analyzing an organization's security and determining its security holes is called: -
------ ✔ CORRECT ANSWER ✓✓Threat modeling
Your network devices are categorized into the following zone types:
,No-trust zone
Low-trust zone
Medium-trust zone
High-trust zone
Your network architecture employs multiple VLANs for each of these network zones. Each zone
is separated by a firewall that ensures only specific traffic is allowed.
Which of the following is the secure architecture concept used on this network? ------- ✔
CORRECT ANSWER ✓✓Network segmentation
Drag the network attack technique on the left to the appropriate description or example on the
right. (Each technique may be used once, more than once, or not at all.) ------- ✔ CORRECT
ANSWER ✓✓Perpetrators attempt to compromise or affect the operations of a system.
Active attack
Unauthorized individuals try to breach a network from off-site.
External attack
Attempting to find the root password on a web server by brute force.
Active attack
Attempting to gather information without affecting the flow of information on the network.
Passive attack
Sniffing network packets or performing a port scan.
Passive attack
You are a security consultant. You've been hired to evaluate an organization's physical security
practices. All employees must pass through a locked door to enter the main work area. Access is
restricted using a smart card reader. Network jacks are located in the reception area so
employees and vendors can access the company network for work-related purposes. Users
within the secured work area are trained to lock their workstations if they will leave them for
any period of time.
, Which of the following recommendations would you MOST likely make to this organization to
increase their security? ------- ✔ CORRECT ANSWER ✓✓Disable the switch ports connected to
the network jacks in the reception area.
Your organization is frequently visited by sales reps. While on-site, they frequently plug their
notebook systems into any available wall jack, hoping to get internet connectivity. You are
concerned that allowing them to do this could result in the spread of malware throughout your
network.
Which of the following would BEST protect you from guest malware infection? (Select two.) -----
-- ✔ CORRECT ANSWER ✓✓Implement static IP addressing.
Implement MAC address filtering.
Which of the following is the most secure protocol for wireless networks? ------- ✔ CORRECT
ANSWER ✓✓WPA2
Which of the following measures will make your wireless network less visible to the casual
attacker? ------- ✔ CORRECT ANSWER ✓✓Disable SSID broadcast.
What is the least secure place to locate an omnidirectional access point when creating a
wireless network? ------- ✔ CORRECT ANSWER ✓✓Near a window
You have just installed a wireless access point (WAP) for your organization's network. You know
that the radio signals used by the WAP extend beyond your organization's building and are
concerned that unauthorized users outside may be able to access your internal network.
Which of the following steps will BEST protect the wireless network? (Select TWO. Each option
is a complete solution.) ------- ✔ CORRECT ANSWER ✓✓Use the WAP's configuration utility to
reduce the radio signal strength.
Configure the WAP to filter unauthorized MAC addresses.
Fundamental- EXAM QUESTIONS AND ALL
CORRECT ANSWERS 100% SOLVED AND
GUARANTEED SUCCESS
The Stuxnet worm was discovered in 2010 and was used to gain sensitive information about
Iran's industrial infrastructure. This worm was probably active for about five years before being
discovered. During this time, the attacker had access to the target. Which type of attack was
Stuxnet? ------- ✔ CORRECT ANSWER ✓✓APT
Which type of threat actor only uses skills and knowledge for defensive purposes? ------- ✔
CORRECT ANSWER ✓✓White Hat
Which statement best describes a suicide hacker? ------- ✔ CORRECT ANSWER ✓✓This hacker is
only concerned with taking down their target for a cause. They have no concerns about being
caught.
Miguel has been practicing his hacking skills. He has discovered a vulnerability on a system that
he did not have permission to attack. Once Miguel discovered the vulnerability, he anonymously
alerted the owner and told him how to secure the system. Which type of hacker is Miguel in this
scenario? ------- ✔ CORRECT ANSWER ✓✓Gray hat
The process of analyzing an organization's security and determining its security holes is called: -
------ ✔ CORRECT ANSWER ✓✓Threat modeling
Your network devices are categorized into the following zone types:
,No-trust zone
Low-trust zone
Medium-trust zone
High-trust zone
Your network architecture employs multiple VLANs for each of these network zones. Each zone
is separated by a firewall that ensures only specific traffic is allowed.
Which of the following is the secure architecture concept used on this network? ------- ✔
CORRECT ANSWER ✓✓Network segmentation
Drag the network attack technique on the left to the appropriate description or example on the
right. (Each technique may be used once, more than once, or not at all.) ------- ✔ CORRECT
ANSWER ✓✓Perpetrators attempt to compromise or affect the operations of a system.
Active attack
Unauthorized individuals try to breach a network from off-site.
External attack
Attempting to find the root password on a web server by brute force.
Active attack
Attempting to gather information without affecting the flow of information on the network.
Passive attack
Sniffing network packets or performing a port scan.
Passive attack
You are a security consultant. You've been hired to evaluate an organization's physical security
practices. All employees must pass through a locked door to enter the main work area. Access is
restricted using a smart card reader. Network jacks are located in the reception area so
employees and vendors can access the company network for work-related purposes. Users
within the secured work area are trained to lock their workstations if they will leave them for
any period of time.
, Which of the following recommendations would you MOST likely make to this organization to
increase their security? ------- ✔ CORRECT ANSWER ✓✓Disable the switch ports connected to
the network jacks in the reception area.
Your organization is frequently visited by sales reps. While on-site, they frequently plug their
notebook systems into any available wall jack, hoping to get internet connectivity. You are
concerned that allowing them to do this could result in the spread of malware throughout your
network.
Which of the following would BEST protect you from guest malware infection? (Select two.) -----
-- ✔ CORRECT ANSWER ✓✓Implement static IP addressing.
Implement MAC address filtering.
Which of the following is the most secure protocol for wireless networks? ------- ✔ CORRECT
ANSWER ✓✓WPA2
Which of the following measures will make your wireless network less visible to the casual
attacker? ------- ✔ CORRECT ANSWER ✓✓Disable SSID broadcast.
What is the least secure place to locate an omnidirectional access point when creating a
wireless network? ------- ✔ CORRECT ANSWER ✓✓Near a window
You have just installed a wireless access point (WAP) for your organization's network. You know
that the radio signals used by the WAP extend beyond your organization's building and are
concerned that unauthorized users outside may be able to access your internal network.
Which of the following steps will BEST protect the wireless network? (Select TWO. Each option
is a complete solution.) ------- ✔ CORRECT ANSWER ✓✓Use the WAP's configuration utility to
reduce the radio signal strength.
Configure the WAP to filter unauthorized MAC addresses.