NETWORK SECURITY, FIREWALLS, AND VPNS
3RD EDITION
CHAPTER NO. 01: FUNDAMENTALS OF NETWORK SECURITY
MULTIPLE-CHOICE QUESTIONS
1. Which of the following is described as "confidence in your expectation that others will act in
your best interest"?
A. Security
B. Threat
C. Trust
D. Permission
Answer: C Reference: CH01, What Is Network Security?
Explanation: Trust is confidence in your expectation that others will act in your best interest.
With computers and networks, trust is the confidence that other users will act in accordance with
your organization's security rules and corporate mission and vision.
Type: Multiple Choice Difficulty: Easy Category: Understand
2. Estefan is a network professional for an e-commerce company. The chief information officer
(CIO) wants the customer web portal downtime to be reduced from 5 minutes per year to 30
seconds per year. The change should occur over the next 6 months. What security objective must
Estefan employ to accomplish this goal?
A. Nonrepudiation
B. Authorization
C. Authentication
D. Availability
Answer: D Reference: CH01, What Is Network Security?
Explanation: Availability is the protection against downtime, loss of data, and blocked access,
while providing consistent uptime, protecting data, and supporting authorized access to
resources.
,Type: Multiple Choice Difficulty: Medium Category: Apply
3. Kristin's position in IT focuses on using antivirus, anti-spyware, and vulnerability software
patch management in order to maintain security and integrity. Which IT infrastructure domain is
she protecting?
A. User Domain
B. Workstation Domain
C. LAN Domain
D. LAN-to-WAN Domain
Answer: B Reference: CH01, What Are You Trying to Protect?
Explanation: Workstation devices, such as desktop computers, laptops, or Voice over Internet
Protocol (VoIP) phones typically require security countermeasures such as antivirus, anti-
spyware, and vulnerability software patch management to maintain the integrity of the device
and the network.
Type: Multiple Choice Difficulty: Hard Category: Apply
4. To secure the System/Application Domain of an IT infrastructure, what is the primary focus?
A. In a collection of servers and virtualized systems, defending both data and server computing
power
B. Protecting a system where the hacker does not have to be physically present to attack the
network
C. Defending against hackers targeting routers, circuits, switches, firewalls, and equivalent gear
at remote locations
D. Mainly educating users about social engineering techniques, such as clever wording
intimidation, to prevent loss of private information and reduction in network security
Answer: A Reference: CH01, What Are You Trying to Protect?
Explanation: In the System/Application Domain, collections of servers hosting applications,
virtualized systems, or databases are valuable targets. Sometimes the data hosted is the target.
Sometimes the computing power of the servers is the resource the hacker wishes to seize.
Type: Multiple Choice Difficulty: Medium Category: Analyze
5. Which of the following must be done first to accomplish an organization's security goals?
,A. Create a security group.
B. Develop a graphic security design.
C. Create a continuous improvement plan.
D. Write down security goals.
Answer: D Reference: CH01, Goals of Network Security
Explanation: To accomplish your organization's security goals, you need to write down those
goals and develop a thorough plan to execute them. Without a written plan, security will be
haphazard at best and will likely fail to protect your assets. With a written plan, network security
is on the path to success.
Type: Multiple Choice Difficulty: Easy Category: Understand
6. Temika is the IT security officer for her company. The CIO has told her that network security
success is not about preventing all possible attacks or compromises. Of the following, what goal
or accomplishment should she work toward?
A. Installing a single, comprehensive defense component designed to prevent all possible attacks
B. A variety of perfect security components
C. Continually improving the state of security so that, as time passes, the network is better
protected than it was in the past
D. More budget friendly security controls, such as administrative controls, rather than more
expensive technical controls
Answer: C Reference: CH01, How Can You Measure the Success of Network Security?
Explanation: Network security success is not about preventing all possible attacks or
compromises. Instead, you work to continually improve the state of security so that in the future,
the network is better protected than it was in the past.
Type: Multiple Choice Difficulty: Medium Category: Apply
7. Which of the following roles is most commonly responsible for observing system and user
activity, looking for violations, trends toward bottlenecks, and attempts to perform violations?
A. Auditors
B. Network administrators
C. Senior management
D. Support supervisors
, Answer: A Reference: CH01, Who is Responsible for Network Security?
Explanation: Auditors watch for problems and violations. Auditors investigate the network,
looking for anything not in compliance with the written security policy. Auditors watch the
activity of systems and users to look for violations, trends toward bottlenecks, and attempts to
perform violations.
Type: Multiple Choice Difficulty: Medium Category: Understand
8. A company has discovered that confidential business information has been steadily acquired
by a competitor over the past six months. The IT security team has been unable to find the leaks.
The team suspects a form of side-channel eavesdropping may be involved. What is the suspected
hacking method?
A. An employee has been paid to leak company secrets to the competitor.
B. The competitor is using a phreaking attack.
C. A zero-day exploit has breached a previously unknown vulnerability.
D. The company's wireless network has been hacked.
Answer: B Reference: CH01, Enhancing the Security of Wired Versus Wireless LAN
Infrastructures
Explanation: An exploit known as "Van Eck phreaking" uses side-channel attack vectors to
eavesdrop on electronic devices from a distance. This technique is neither perfect nor simple to
perform, but it has been demonstrated on LCD and CRT monitors, as well as on keyboard cables.
Type: Multiple Choice Difficulty: Hard Category: Apply
9. As part of the Bring Your Own Device (BYOD) program, the company CIO is encouraging
employees to use their personal devices for business purposes. However, an attacker with the
right kind of antenna can access the wireless network from a great distance, putting internal
assets at risk. Of the following, what is the best solution?
A. Turn off all wireless access.
B. Physically isolate wireless access from the wired network.
C. Use a firewall on each device.
D. Use virtual private networking.
Answer: B Reference: CH01, Enhancing the Security of Wired Versus Wireless LAN
Infrastructures