LESSON 9
Where66should66an66administrator66place66an66internet-facing66host66on66the66network?
DMZ
Bastion66host
Extranet
Private66network66-66answer--A
A66hotel66guest66opens66their66computer66and66logs66into66the66Wi-
Fi66without66prompting66the66guest66for66a66username66and66password.66Upon66opening
66an66internet66browser,66a66splash66page66appears66that66requests66the66guest's66room
66number66and66last66name66for66authentication.66Which66type66of66authentication66is66th
e66hotel66utilizing?
Protected
Extensive
Group
Open66-66answer--D
Analyze66the66available66detection66techniques66and66determine66which66are66useful66in
66identifying66a66rogue66system66through66software66management.66(Select66all66that66a
pply.)
A.66Visual66inspection66of66ports66and66switches66will66prevent66rogue66devices66from66a
ccessing66the66network.
B.66Network66mapping66is66an66easy66way66to66reveal66the66use66of66unauthorized66prot
ocols66on66the66network66or66unusual66traffic66volume.
C.66Intrusion66detection66and66NAC66are66security66suites66and66appliances66that66comb
ine66automated66network66scanning66with66defense66and66remediation66suites66to66prev
ent66rogue66devices66from66accessing66the66network.
D.66Wireless66monitoring66can66reveal66whether66there66are66unauthorized66access66poi
nts.66-66answer--C,66D
Given66that66layer66266does66not66recognize66Time66to66Live,66evaluate66the66potential66
problems66to66determine66which66of66the66following66options66prevents66this66issue.
, ICMP
L2TP
NTP
STP66-66answer--D
Which66statement66best66describes66the66difference66between66session66affinity66and66s
ession66persistence?
With66persistence,66once66a66client66device66establishes66a66connection,66it66remains66w
ith66the66node66that66first66accepted66its66request,66while66an66application-
layer66load66balancer66uses66session66affinity66to66keep66a66client66connected66by66setti
ng66up66a66cookie.
Session66affinity66makes66node66scheduling66decisions66based66on66health66checks66an
d66processes66incoming66requests66based66on66each66node's66load.66Session66persiste
nce66makes66scheduling66decisions66on66a66first66in,66first66out66(FIFO)66basis.
With66session66affinity,66when66a66client66establishes66a66session,66it66remains66with66th
e66node66that66first66accepted66its66request,66while66an66application-
layer66load66balancer66uses66persistence66to66keep66a66client66connected66by66setting66
up66a66cookie.
Session66persistence66makes66scheduling66decisions66based66on66traffic66priority66and66
bandwidth66considerations,66while66session66affinity66makes66scheduling66decis66-
66answer--C
Which66statement66regarding66attacks66on66media66access66control66(MAC)66addresses
66accurately66pairs66the66method66of66protection66and66what66type66of66attack66it66guard
s66against?66(Select66all66that66apply.)
MAC66filtering66guards66against66MAC66snooping.
Dynamic66Host66Configuration66Protocol66(DHCP)66snooping66guards66against66MAC66s
poofing.
MAC66filtering66guards66against66MAC66spoofing.
DAI66guards66against66invalid66MAC66addresses66-66answer--B,66D
Compare66the66types66of66Distributed66Denial66of66Service66(DDoS)66attacks66and66sele
ct66the66best66example66of66a66synchronize66(SYN)66flood66attack.