You are on page 1of 4

Cisco CCNA Security, chapter 6 Exam. 1. Which two measures are recommended to mitigate VLAN hopping attacks?

(Ch oose two.) Use a dedicated native VLAN for all trunk ports. Place all unused ports in a separate guest VLAN. Disable trunk negotiation on all ports connecting to workstation s. Enable DTP on all trunk ports. Ensure that the native VLAN is used for management traffic. 2. ated? As a recommended practice for Layer 2 security, how should VLAN 1 be tre All access ports should be assigned to VLAN 1. All trunk ports should be assigned to VLAN 1. VLAN 1 should be used for management traffic. VLAN 1 should not be used. 3. How is a reflector port used in an RSPAN configuration? It provides a dedicated connection for the IDS device. It allows an RSPAN session to be backward compatible with a SPAN session. It acts like a loopback interface in that it reflects the captur ed traffic to the RSPAN VLAN. It allows an IDS device to direct malicious traffic to it, isola ting that traffic from other areas of the network. 4. Which attack is mitigated by using port security? LAN storm VLAN hopping STP manipulation MAC address table overflow

5. Which technology is used to protect the switched infrastructure from p roblems caused by receiving BPDUs on ports that should not be receiving them? RSPAN PortFast Root guard Loop guard BPDU guard 6. Which three switch security commands are required to enable port securit y on a port so that it will dynamically learn a single MAC address and disable t he port if a host with any other MAC address is connected? (Choose three.) switchport mode access switchport mode trunk switchport port-security switchport port-security maximum 2 switchport port-security mac-address sticky switchport port-security mac-address mac-address 7. When configuring a switch port for port security, what is the default vi olation mode? protect reset restrict shutdown 8. ) Which three statements are true regarding SPAN and RSPAN? (Choose three. SPAN can send a copy of traffic to a port on another switch.

RSPAN is required for syslog and SNMP implementation. SPAN can be configured to send a copy of traffic to a destinatio n port on the same switch. SPAN can copy traffic on a source port or source VLAN to a desti nation port on the same switch. RSPAN is required to copy traffic on a source VLAN to a destinat ion port on the same switch. RSPAN can be used to forward traffic to reach an IDS that is ana lyzing traffic for malicious behavior. 9. Which Cisco endpoint security product helps maintain network stability b y providing posture assessment, quarantining of noncompliant systems, and remedi ation of noncompliant systems? Cisco Access Control Server Cisco Security Agent workstation Cisco Intrusion Prevention System router Cisco Network Admission Control appliance 10. Which attack relies on the default automatic trunking configuration on m ost Cisco switches? LAN storm attack VLAN hopping attack STP manipulation attack MAC address spoofing attack 11. With IP voice systems on data networks, which two types of attacks targe t VoIP specifically? (Choose two.) CoWPAtty Kismet SPIT virus vishing 12. Which two elements are part of the Cisco strategy for addressing endpoin t security? (Choose two.) policy compliance using products such as Cisco NAC network infection monitoring using products such as Cisco Secure ACS threat protection using products such as Cisco Security Agent attack detection using products such as Cisco NAC risk assessment compliance using products such as Cisco Security Agent 13. Which frames are spoofed in STP manipulation attacks? BPDU DTP ISL 802.1q

14.

Which option best describes a MAC address spoofing attack? An attacker gains access to another host and masquerades as the rightful user of that device. An attacker alters the MAC address of his host to match another known MAC address of a target host. An attacker alters the MAC address of the switch to gain access to the network device from a rogue host device. An attacker floods the MAC address table of a switch so that the switch can no longer filter network access based on MAC addresses. 15. What happens when the MAC address notification feature is enabled on a s

witch? An SDEE alert is generated, and the switch resets the interface when an invalid MAC address is detected. An STP multicast notification packet is forwarded to all switche s any time a change in the network topology is detected. A port violation occurs when a MAC address outside of the range of allowed addresses transmits traffic over a secure port. An SNMP trap is sent to the network management system whenever a new MAC address is added to or an old address is deleted from the forwarding ta bles. 16. Which device supports the use of SPAN to enable monitoring of malicious activity? Cisco NAC Cisco IronPort Cisco Security Agent Cisco Catalyst switch 17. An administrator wants to prevent a rogue Layer 2 device from intercepti ng traffic from multiple VLANs on a network. Which two actions help mitigate thi s type of activity? (Choose two.) Disable DTP on ports that require trunking. Place unused active ports in an unused VLAN. Secure the native VLAN, VLAN 1, with encryption. Set the native VLAN on the trunk ports to an unused VLAN. Turn off trunking on all trunk ports and manually configure each VLAN as required on each port. 18. Refer to the exhibit. Based on the output generated by the show monitor session 1 command, how will SPAN operate on the switch? All traffic transmitted from VLAN 10 or received on VLAN 20 is f orwarded to FastEthernet 0/1. All traffic received on VLAN 10 or transmitted from VLAN 20 is f orwarded to FastEthernet 0/1. Native VLAN traffic received on VLAN 10 or transmitted from VLAN 20 is forwarded to FastEthernet 0/1. Native VLAN traffic transmitted from VLAN 10 or received on VLAN 20 is forwarded to FastEthernet 0/1. 19. How many Cisco Security Agent clients can one Management Center for CSA console support? 1,000 10,000 100,000 1,000,000 20. Which three are SAN transport technologies? (Choose three.) Fibre Channel SATA iSCSI IP PBX FCIP IDE

21. If a switch is configured with the storm-control command and the action shutdown and action trap parameters, which two actions does the switch take when a storm occurs on a port? (Choose two.) The port is disabled. The switch is rebooted.

An SNMP log message is sent. The port is placed in a blocking state. The switch forwards control traffic only.

You might also like