Network+ 8th Edition Chapter 10 Questions with Verified Answers
(Correct Update)
Question 1: 4. Which adaptation of EAP utilizes EAP-MSCHAPv2 inside of an encrypted TLS
tunnel?
a. EAP-TLS
b. Protected EAP (PEAP)
c. EAP-FAST
d. LEAP
Answer: Protected EAP (PEAP)
Question 2: 5. What aspect of AAA is responsible for determining what a user can and cannot
do with network resources?
a. authentication
b. authorization
c. accounting
d. accessibility
Answer: authorization
Question 3: User access to network resources falls into one of these two categories: 1) the
privilege or right to execute, install, and uninstall software, and 2) permission to read, modify,
create, or delete data files and folders.
Answer: True
Question 4: A stateless firewall inspects each incoming packet to determine whether it belongs
to a currently active connection.
Answer: False
Question 5: 6. What kind of firewall can block designated types of traffic based on application
data contained within packets?
a. stateful firewall
b. stateless firewall
c. content-filtering firewall
d. packet-filtering firewall
Answer: content-filtering firewall
Page 1
, Question 6: 8. What IEEE standard includes an encryption key generation and management
scheme known as TKIP?
a. 802.11i
b. 802.11h
c. 802.1X
d. 802.11j
Answer: 802.11i
Question 7: 11. In Open System Authentication, how does authentication occur?
a. The client sends a pre-shared key along with the access point's SSID.
b. The client requests an encrypted tunnel, after which, the client's MAC serves as the
authentication.
c. The access point forces the client to authenticate via a captive portal, after which all
communication is encrypted.
d. The client "authenticates" using only the SSID name. In other words, no real authentication
occurs.
Answer: The client "authenticates" using only the SSID name. In other words, no real authentication
occurs.
Question 8: 12. Enforcing a virtual security perimeter using a client's geographic location is
known by what term?
a. geohashing
b. geofencing
c. geolocating
d. geolocking
Answer: geofencing
Question 9: When utilizing Kerberos, an access granting ticket is the same as a key.
Answer: False
Question 10: 14. When using Kerberos, what is the purpose of a ticket?
a. It is the name for a Kerberos client or user.
b. It is a key used by the client to gain access to services that are protected by the key on the
network.
c. It is a temporary set of credentials that a client uses to prove to other servers that its identity
has been validated.
d. It is the event that is generated when auditing a resource and unauthorized access is
attempted.
Answer: It is a temporary set of credentials that a client uses to prove to other servers that its identity
has been validated.
Page 2
(Correct Update)
Question 1: 4. Which adaptation of EAP utilizes EAP-MSCHAPv2 inside of an encrypted TLS
tunnel?
a. EAP-TLS
b. Protected EAP (PEAP)
c. EAP-FAST
d. LEAP
Answer: Protected EAP (PEAP)
Question 2: 5. What aspect of AAA is responsible for determining what a user can and cannot
do with network resources?
a. authentication
b. authorization
c. accounting
d. accessibility
Answer: authorization
Question 3: User access to network resources falls into one of these two categories: 1) the
privilege or right to execute, install, and uninstall software, and 2) permission to read, modify,
create, or delete data files and folders.
Answer: True
Question 4: A stateless firewall inspects each incoming packet to determine whether it belongs
to a currently active connection.
Answer: False
Question 5: 6. What kind of firewall can block designated types of traffic based on application
data contained within packets?
a. stateful firewall
b. stateless firewall
c. content-filtering firewall
d. packet-filtering firewall
Answer: content-filtering firewall
Page 1
, Question 6: 8. What IEEE standard includes an encryption key generation and management
scheme known as TKIP?
a. 802.11i
b. 802.11h
c. 802.1X
d. 802.11j
Answer: 802.11i
Question 7: 11. In Open System Authentication, how does authentication occur?
a. The client sends a pre-shared key along with the access point's SSID.
b. The client requests an encrypted tunnel, after which, the client's MAC serves as the
authentication.
c. The access point forces the client to authenticate via a captive portal, after which all
communication is encrypted.
d. The client "authenticates" using only the SSID name. In other words, no real authentication
occurs.
Answer: The client "authenticates" using only the SSID name. In other words, no real authentication
occurs.
Question 8: 12. Enforcing a virtual security perimeter using a client's geographic location is
known by what term?
a. geohashing
b. geofencing
c. geolocating
d. geolocking
Answer: geofencing
Question 9: When utilizing Kerberos, an access granting ticket is the same as a key.
Answer: False
Question 10: 14. When using Kerberos, what is the purpose of a ticket?
a. It is the name for a Kerberos client or user.
b. It is a key used by the client to gain access to services that are protected by the key on the
network.
c. It is a temporary set of credentials that a client uses to prove to other servers that its identity
has been validated.
d. It is the event that is generated when auditing a resource and unauthorized access is
attempted.
Answer: It is a temporary set of credentials that a client uses to prove to other servers that its identity
has been validated.
Page 2