NETWORK DEFENSE ESSENTIALS (NDE)
QUESTIONS WITH COMPLETE SOLUTIONS
Which,of,the,following,network,security,elements,ensures,the,security,and,integrity,of,data,in,transit?,,AN
S,-,Network,Security,Protocols,-,
Network,security,protocols,implement,security,related,operations,to,ensure,the,security,and,integrity,of,
data,in,transit.,The,network,security,protocols,ensure,the,security,of,the,data,passing,through,the,networ
k.
Which,of,the,following,network,security,elements,restricts,the,access,to,organization's,resources,based,o
n,identity,management?,,ANS,-,Network,Security,Controls,-,
Network,security,controls,are,the,security,features,that,should,be,appropriately,configured,and,impleme
nted,to,ensure,network,security.,These,security,controls,work,together,to,allow,or,restrict,the,access,to,or
ganization's,resources,based,on,identity,management.
Which,of,the,following,information,assurance,principles,ensures,that,the,information,is,not,modified,or,ta
mpered,by,any,unauthorized,parties?,,ANS,-,Integrity,-,
Integrity,protects,data,and,does,not,allow,modification,,deletion,,or,corruption,of,data,without,proper,au
thorization.
Which,of,the,following,information,assurance,principles,ensures,that,a,party,in,a,communication,cannot,d
eny,sending,the,message?,,ANS,-,Nonrepudiation,-,
Non-repudiation,ensures,that,a,party,in,a,communication,cannot,deny,sending,the,message.
Which,of,the,following,is,NOT,a,benefit,of,network,defense?,,ANS,-,Lack,of,compliance,-,
Network,security,helps,organizations,avoid,penalties,for,lack,of,compliance.,The,real-
time,monitoring,of,data,flows,helps,organizations,enhance,their,compliance,posture.
Which,of,the,following,is,NOT,a,challenge,of,network,defense?,,ANS,-
,Abundance,of,network,security,skills,-,
Organizations,are,failing,to,defend,themselves,against,rapidly,increasing,network,attacks,owing,to,the,lac
k,of,network,security,skills.
,Which,of,the,following,network,defense,techniques,examines,the,causes,for,attacks,in,networks,by,using,f
ault-finding,mechanisms,,security,forensics,techniques,,and,post-mortem,analysis?,,ANS,-
,Retrospective,approach,-,
The,retrospective,approach,examines,the,causes,for,attacks,in,the,network.,These,include:
Fault,finding,mechanisms,such,as,protocol,analyzers,and,traffic,monitors.
Security,forensics,techniques,such,as,CSIRT,and,CERT.
Post-mortem,analysis,mechanism,including,risk,and,legal,assessments.
Danny,,a,security,professional,,wants,to,safeguard,his,organization's,network,from,hacking,attempts,and,
virus,attacks.,For,this,reason,,he,follows,a,network,defense,approach,that,examines,the,causes,for,attacks
,in,the,network,and,includes,fault,finding,,security,forensics,,and,post-mortem,analysis,techniques.
Which,of,the,following,network,defense,approaches,was,followed,by,Danny,in,the,above,scenario?,,ANS,-
,Retrospective,approach,-,
The,retrospective,approach,examines,the,causes,for,attacks,in,the,network.,These,include:
Fault,finding,mechanisms,such,as,protocol,analyzers,and,traffic,monitors.
Security,forensics,techniques,such,as,CSIRT,and,CERT.
Post-mortem,analysis,mechanism,including,risk,and,legal,assessments.
Which,of,the,following,components,of,technical,security,controls,protects,the,information,passing,throug
h,the,network,and,preserves,the,privacy,and,reliability,of,the,data?,,ANS,-,Encryption,and,protocols,-,
Encryption,and,protocols,protect,the,information,passing,through,the,network,and,preserve,the,privacy,a
nd,reliability,of,the,data.
Which,of,the,following,components,of,technical,network,security,controls,examines,the,network,devices,
and,identifies,weaknesses,in,the,network?,,ANS,-,Auditing,-,
Auditing,refers,to,the,tracking,and,examining,of,the,activities,of,network,devices,in,a,network.,This,mecha
nism,helps,in,identifying,weaknesses,in,the,network.
Which,of,the,following,protocols,provides,centralized,authentication,,authorization,,and,accounting,(AAA
),for,remote,access,servers,to,communicate,with,a,central,server?,,ANS,-,RADIUS,-,
The,Remote,Authentication,Dial-
in,User,Service,protocol,provides,centralized,authentication,,authorization,,and,accounting,(AAA),for,rem
ote-access,servers,to,communicate,with,a,central,server.
,Which,of,the,following,protocols,is,an,application,layer,protocol,that,provides,cryptographic,privacy,and,a
uthentication,for,network,communication,and,enhances,the,security,of,emails?,,ANS,-,PGP,-,
Pretty,good,privacy,(PGP),is,an,application,layer,protocol,which,provides,cryptographic,privacy,and,authe
ntication,for,network,communication.,Pretty,good,privacy,(PGP),is,an,encryption,and,decryption,compute
r,program,that,is,used,for,providing,confidentiality,and,validation,during,communication.,PGP,enhances,t
he,security,of,emails.
James,,a,network,specialist,joined,an,organization.,He,was,provided,with,administrator,privileges,,throug
h,which,he,can,access,the,files,and,servers,and,perform,administrative,activities.
Which,of,the,following,information,assurance,principles,authorizes,James,to,access,the,server,or,system,fi
les?,,ANS,-,Authentication,-,
Authentication,is,a,process,of,authorizing,users,with,the,credentials,provided,,by,comparing,them,to,thos
e,in,a,database,of,authorized,users,on,an,authentication,server,,to,grant,access,to,the,network.,It,guarant
ees,that,the,files,or,data,passing,through,the,network,is,safe.
Clark,,a,network,security,specialist,,was,assigned,to,secure,an,organization's,network.,Clark,implemented,
a,network,defense,approach,that,can,tackle,network,attacks,such,as,DoS,and,DDoS,and,includes,security,
monitoring,methods,such,as,IDS,,SIMS,,TRS,,and,IPS.
Which,of,the,following,network,defense,approaches,did,Clark,implement,in,the,above,scenario?,,ANS,-
,Reactive,approach,-,
This,approach,addresses,attacks,and,threats,that,the,preventative,approach,may,have,failed,to,avert.,DoS
,and,DDoS,attacks,are,examples,of,the,reactive,approach.,It,is,necessary,to,implement,both,preventive,an
d,reactive,approaches,to,ensure,the,security,of,the,network.,Reactive,approaches,include,security,monito
ring,methods,such,as,IDS,,SIMS,,TRS,,and,IPS.
James,,a,certified,hacker,,was,appointed,by,an,agency,to,perform,a,cyberattack,against,the,rival,company'
s,servers,with,the,intention,of,making,the,services,unavailable,to,their,customers.,James,performed,a,DoS
,attack,on,the,servers,but,he,could,not,make,the,services,unavailable.
Which,of,the,following,components,of,technical,security,controls,protected,the,servers,from,the,DoS,atta
ck?,,ANS,-,Network,security,devices,-,
Network,security,devices,such,as,firewall,and,IDS,are,used,to,filter,and,detect,malicious,traffic,,thus,prote
cting,the,organization,from,threats.
, Which,of,the,following,protocols,is,an,application,layer,protocol,used,for,sending,digitally,signed,and,encr
ypted,email,messages?,,ANS,-,S/MIME,-,
Secure/multipurpose,internet,mail,extensions,(S/MIME),is,used,for,sending,digitally,signed,and,encrypted
,messages,to,ensure,confidentiality,,integrity,,and,non-repudiation,for,messages.
Sally,,a,security,professional,,implemented,a,protocol,for,authenticating,requests,in,computer,networks.,
The,protocol,implemented,by,Sally,is,based,on,the,client-
server,model,,and,uses,encryption,technology,and,a,"ticket",mechanism,to,prove,the,identity,of,a,user,on,
a,non-secure,network.
Identify,the,protocol,implemented,by,Sally,in,the,above,scenario.,,ANS,-,Kerberos,-,
Kerberos,is,a,network,authentication,protocol,that,is,implemented,for,authenticating,requests,in,comput
er,networks.,It,is,based,on,the,client-
server,model,,which,uses,an,encryption,technology,and,a,"ticket",mechanism,to,prove,the,identity,of,a,us
er,on,a,non-secure,network.
Identify,the,access,control,terminology,that,is,referred,to,as,an,explicit,resource,on,which,an,access,restric
tion,is,imposed.,,ANS,-,Object,-,
An,object,is,an,explicit,resource,on,which,an,access,restriction,is,imposed.,The,access,controls,implement
ed,on,the,objects,further,control,the,actions,performed,by,the,user.
Which,of,the,following,access,control,models,can,be,termed,as,need-to-
know,access,model,where,the,decision,can,be,taken,by,an,owner,to,provide,or,deny,access,to,specific,use
r,or,a,group,of,users?,,ANS,-,Discretionary,access,control,-,
Discretionary,access,control,(DAC),determines,the,access,control,taken,by,any,possessor,of,an,object,in,or
der,to,decide,the,access,control,of,a,subject,on,that,object.
Which,of,the,following,areas,is,NOT,a,part,of,the,identity,and,access,management,(IAM),framework?,,ANS,
-,Access,controls,-,
An,IAM,framework,can,be,divided,into,four,areas,,namely,,authentication,,authorization,,user,manageme
nt,,and,central,user,repository/identity,repository.,All,the,IAM,components,are,grouped,under,these,four,
areas.
Which,of,the,following,repositories,stores,attributes,related,to,the,users',identities?,,ANS,-
,User,repository,-,
QUESTIONS WITH COMPLETE SOLUTIONS
Which,of,the,following,network,security,elements,ensures,the,security,and,integrity,of,data,in,transit?,,AN
S,-,Network,Security,Protocols,-,
Network,security,protocols,implement,security,related,operations,to,ensure,the,security,and,integrity,of,
data,in,transit.,The,network,security,protocols,ensure,the,security,of,the,data,passing,through,the,networ
k.
Which,of,the,following,network,security,elements,restricts,the,access,to,organization's,resources,based,o
n,identity,management?,,ANS,-,Network,Security,Controls,-,
Network,security,controls,are,the,security,features,that,should,be,appropriately,configured,and,impleme
nted,to,ensure,network,security.,These,security,controls,work,together,to,allow,or,restrict,the,access,to,or
ganization's,resources,based,on,identity,management.
Which,of,the,following,information,assurance,principles,ensures,that,the,information,is,not,modified,or,ta
mpered,by,any,unauthorized,parties?,,ANS,-,Integrity,-,
Integrity,protects,data,and,does,not,allow,modification,,deletion,,or,corruption,of,data,without,proper,au
thorization.
Which,of,the,following,information,assurance,principles,ensures,that,a,party,in,a,communication,cannot,d
eny,sending,the,message?,,ANS,-,Nonrepudiation,-,
Non-repudiation,ensures,that,a,party,in,a,communication,cannot,deny,sending,the,message.
Which,of,the,following,is,NOT,a,benefit,of,network,defense?,,ANS,-,Lack,of,compliance,-,
Network,security,helps,organizations,avoid,penalties,for,lack,of,compliance.,The,real-
time,monitoring,of,data,flows,helps,organizations,enhance,their,compliance,posture.
Which,of,the,following,is,NOT,a,challenge,of,network,defense?,,ANS,-
,Abundance,of,network,security,skills,-,
Organizations,are,failing,to,defend,themselves,against,rapidly,increasing,network,attacks,owing,to,the,lac
k,of,network,security,skills.
,Which,of,the,following,network,defense,techniques,examines,the,causes,for,attacks,in,networks,by,using,f
ault-finding,mechanisms,,security,forensics,techniques,,and,post-mortem,analysis?,,ANS,-
,Retrospective,approach,-,
The,retrospective,approach,examines,the,causes,for,attacks,in,the,network.,These,include:
Fault,finding,mechanisms,such,as,protocol,analyzers,and,traffic,monitors.
Security,forensics,techniques,such,as,CSIRT,and,CERT.
Post-mortem,analysis,mechanism,including,risk,and,legal,assessments.
Danny,,a,security,professional,,wants,to,safeguard,his,organization's,network,from,hacking,attempts,and,
virus,attacks.,For,this,reason,,he,follows,a,network,defense,approach,that,examines,the,causes,for,attacks
,in,the,network,and,includes,fault,finding,,security,forensics,,and,post-mortem,analysis,techniques.
Which,of,the,following,network,defense,approaches,was,followed,by,Danny,in,the,above,scenario?,,ANS,-
,Retrospective,approach,-,
The,retrospective,approach,examines,the,causes,for,attacks,in,the,network.,These,include:
Fault,finding,mechanisms,such,as,protocol,analyzers,and,traffic,monitors.
Security,forensics,techniques,such,as,CSIRT,and,CERT.
Post-mortem,analysis,mechanism,including,risk,and,legal,assessments.
Which,of,the,following,components,of,technical,security,controls,protects,the,information,passing,throug
h,the,network,and,preserves,the,privacy,and,reliability,of,the,data?,,ANS,-,Encryption,and,protocols,-,
Encryption,and,protocols,protect,the,information,passing,through,the,network,and,preserve,the,privacy,a
nd,reliability,of,the,data.
Which,of,the,following,components,of,technical,network,security,controls,examines,the,network,devices,
and,identifies,weaknesses,in,the,network?,,ANS,-,Auditing,-,
Auditing,refers,to,the,tracking,and,examining,of,the,activities,of,network,devices,in,a,network.,This,mecha
nism,helps,in,identifying,weaknesses,in,the,network.
Which,of,the,following,protocols,provides,centralized,authentication,,authorization,,and,accounting,(AAA
),for,remote,access,servers,to,communicate,with,a,central,server?,,ANS,-,RADIUS,-,
The,Remote,Authentication,Dial-
in,User,Service,protocol,provides,centralized,authentication,,authorization,,and,accounting,(AAA),for,rem
ote-access,servers,to,communicate,with,a,central,server.
,Which,of,the,following,protocols,is,an,application,layer,protocol,that,provides,cryptographic,privacy,and,a
uthentication,for,network,communication,and,enhances,the,security,of,emails?,,ANS,-,PGP,-,
Pretty,good,privacy,(PGP),is,an,application,layer,protocol,which,provides,cryptographic,privacy,and,authe
ntication,for,network,communication.,Pretty,good,privacy,(PGP),is,an,encryption,and,decryption,compute
r,program,that,is,used,for,providing,confidentiality,and,validation,during,communication.,PGP,enhances,t
he,security,of,emails.
James,,a,network,specialist,joined,an,organization.,He,was,provided,with,administrator,privileges,,throug
h,which,he,can,access,the,files,and,servers,and,perform,administrative,activities.
Which,of,the,following,information,assurance,principles,authorizes,James,to,access,the,server,or,system,fi
les?,,ANS,-,Authentication,-,
Authentication,is,a,process,of,authorizing,users,with,the,credentials,provided,,by,comparing,them,to,thos
e,in,a,database,of,authorized,users,on,an,authentication,server,,to,grant,access,to,the,network.,It,guarant
ees,that,the,files,or,data,passing,through,the,network,is,safe.
Clark,,a,network,security,specialist,,was,assigned,to,secure,an,organization's,network.,Clark,implemented,
a,network,defense,approach,that,can,tackle,network,attacks,such,as,DoS,and,DDoS,and,includes,security,
monitoring,methods,such,as,IDS,,SIMS,,TRS,,and,IPS.
Which,of,the,following,network,defense,approaches,did,Clark,implement,in,the,above,scenario?,,ANS,-
,Reactive,approach,-,
This,approach,addresses,attacks,and,threats,that,the,preventative,approach,may,have,failed,to,avert.,DoS
,and,DDoS,attacks,are,examples,of,the,reactive,approach.,It,is,necessary,to,implement,both,preventive,an
d,reactive,approaches,to,ensure,the,security,of,the,network.,Reactive,approaches,include,security,monito
ring,methods,such,as,IDS,,SIMS,,TRS,,and,IPS.
James,,a,certified,hacker,,was,appointed,by,an,agency,to,perform,a,cyberattack,against,the,rival,company'
s,servers,with,the,intention,of,making,the,services,unavailable,to,their,customers.,James,performed,a,DoS
,attack,on,the,servers,but,he,could,not,make,the,services,unavailable.
Which,of,the,following,components,of,technical,security,controls,protected,the,servers,from,the,DoS,atta
ck?,,ANS,-,Network,security,devices,-,
Network,security,devices,such,as,firewall,and,IDS,are,used,to,filter,and,detect,malicious,traffic,,thus,prote
cting,the,organization,from,threats.
, Which,of,the,following,protocols,is,an,application,layer,protocol,used,for,sending,digitally,signed,and,encr
ypted,email,messages?,,ANS,-,S/MIME,-,
Secure/multipurpose,internet,mail,extensions,(S/MIME),is,used,for,sending,digitally,signed,and,encrypted
,messages,to,ensure,confidentiality,,integrity,,and,non-repudiation,for,messages.
Sally,,a,security,professional,,implemented,a,protocol,for,authenticating,requests,in,computer,networks.,
The,protocol,implemented,by,Sally,is,based,on,the,client-
server,model,,and,uses,encryption,technology,and,a,"ticket",mechanism,to,prove,the,identity,of,a,user,on,
a,non-secure,network.
Identify,the,protocol,implemented,by,Sally,in,the,above,scenario.,,ANS,-,Kerberos,-,
Kerberos,is,a,network,authentication,protocol,that,is,implemented,for,authenticating,requests,in,comput
er,networks.,It,is,based,on,the,client-
server,model,,which,uses,an,encryption,technology,and,a,"ticket",mechanism,to,prove,the,identity,of,a,us
er,on,a,non-secure,network.
Identify,the,access,control,terminology,that,is,referred,to,as,an,explicit,resource,on,which,an,access,restric
tion,is,imposed.,,ANS,-,Object,-,
An,object,is,an,explicit,resource,on,which,an,access,restriction,is,imposed.,The,access,controls,implement
ed,on,the,objects,further,control,the,actions,performed,by,the,user.
Which,of,the,following,access,control,models,can,be,termed,as,need-to-
know,access,model,where,the,decision,can,be,taken,by,an,owner,to,provide,or,deny,access,to,specific,use
r,or,a,group,of,users?,,ANS,-,Discretionary,access,control,-,
Discretionary,access,control,(DAC),determines,the,access,control,taken,by,any,possessor,of,an,object,in,or
der,to,decide,the,access,control,of,a,subject,on,that,object.
Which,of,the,following,areas,is,NOT,a,part,of,the,identity,and,access,management,(IAM),framework?,,ANS,
-,Access,controls,-,
An,IAM,framework,can,be,divided,into,four,areas,,namely,,authentication,,authorization,,user,manageme
nt,,and,central,user,repository/identity,repository.,All,the,IAM,components,are,grouped,under,these,four,
areas.
Which,of,the,following,repositories,stores,attributes,related,to,the,users',identities?,,ANS,-
,User,repository,-,