Module 8 - Network Security
Which of the following best describes why packet-filtering firewalls cannot protect
against application-specific attacks? - answer No firewall type can access application-
layer data within packets.
In which of the following areas do application-based proxy firewalls have an advantage
over packet-filtering firewalls? - answer Security
An IT administrator who secures a communication channel through an untrusted
network by configuring firewall software has just implemented a __________________.
- answer Virtual private network
All of the following are true statements about bastion hosts except which one? - answer
Protected by the DMZ and has internal user accounts
Which of the following firewall types keeps track of each ongoing dialogue between
internal and external systems? - answer Stateful
There are several different types of DSL technologies. Each provides specific
characteristics to best fit individual customer needs. Asymmetric DSL means which of
the following? - answerDownstream traffic flows faster than upstream traffic.
Which of the following best describes the difference between a virtual firewall that works
in bridge mode versus one that is embedded into a hypervisor? - answerBridge-mode
virtual firewall allows the firewall to monitor individual traffic links, and hypervisor
integration allows the firewall to monitor all activities taking place within a host system.
In which part of the following network diagram should Internet-accessible hosts, such as
servers, be placed? - answerPublic servers, such as web servers, must be placed in
DMZ (demilitarized zone). No external user must have direct access to the internal LAN
directly.
Describe how an attacker can launch an amplification attack by using public DNS
servers on the Internet.
Which security principle will be violated when an amplification attack happens? -
answerThe attacker must first find a bunch of open DNS resolvers, the ones that
perform recursive DNS queries on behalf of anyone on the Internet. The attacker then
must send a massive number of crafted DNS queries to these open resolvers. The
source of the crafted queries is the victim system. The DNS query is chosen in a way
that the size of the corresponding DNS response is huge in comparison to the size of
the query. For example, the query is 100 bytes, but the response is 10,000 bytes.
DNS amplification attack is a DDoS attack and targets the availability of target systems.
Which of the following best describes why packet-filtering firewalls cannot protect
against application-specific attacks? - answer No firewall type can access application-
layer data within packets.
In which of the following areas do application-based proxy firewalls have an advantage
over packet-filtering firewalls? - answer Security
An IT administrator who secures a communication channel through an untrusted
network by configuring firewall software has just implemented a __________________.
- answer Virtual private network
All of the following are true statements about bastion hosts except which one? - answer
Protected by the DMZ and has internal user accounts
Which of the following firewall types keeps track of each ongoing dialogue between
internal and external systems? - answer Stateful
There are several different types of DSL technologies. Each provides specific
characteristics to best fit individual customer needs. Asymmetric DSL means which of
the following? - answerDownstream traffic flows faster than upstream traffic.
Which of the following best describes the difference between a virtual firewall that works
in bridge mode versus one that is embedded into a hypervisor? - answerBridge-mode
virtual firewall allows the firewall to monitor individual traffic links, and hypervisor
integration allows the firewall to monitor all activities taking place within a host system.
In which part of the following network diagram should Internet-accessible hosts, such as
servers, be placed? - answerPublic servers, such as web servers, must be placed in
DMZ (demilitarized zone). No external user must have direct access to the internal LAN
directly.
Describe how an attacker can launch an amplification attack by using public DNS
servers on the Internet.
Which security principle will be violated when an amplification attack happens? -
answerThe attacker must first find a bunch of open DNS resolvers, the ones that
perform recursive DNS queries on behalf of anyone on the Internet. The attacker then
must send a massive number of crafted DNS queries to these open resolvers. The
source of the crafted queries is the victim system. The DNS query is chosen in a way
that the size of the corresponding DNS response is huge in comparison to the size of
the query. For example, the query is 100 bytes, but the response is 10,000 bytes.
DNS amplification attack is a DDoS attack and targets the availability of target systems.