The CCNA Security v2.0 Final Exam assesses advanced knowledge in network security, focusing on control plane protection, authentication methods, and security tools like Nmap. This quiz is essential for learners aiming to master security protocols and configurations in Cisco networks.
ISAKMP SA policy
DH groups
Interesting traffic
Transform sets
Rate this question:
The Telnet connection between RouterA and RouterB is not working correctly.
The password cisco123 is wrong.
The administrator does not have enough rights on the PC that is being used.
The enable password and the Telnet password need to be the same.
Rate this question:
End-user policy
Application policy
Governing policy
Technical policy
Rate this question:
Configure 802.1x.
Configure Telnet.
Configure SSH.
Configure an ACL and apply it to the VTY lines.
Rate this question:
The enable secret password could be used in the next login attempt.
The authentication process stops.
The username and password of the local user database could be used in the next login attempt.
The enable secret password and a random username could be used in the next login attempt.
Rate this question:
They are more resource intensive.
DES weak keys use very long key sizes.
They produce identical subkeys.
DES weak keys are difficult to manage.
Rate this question:
Symmetric algorithms
Hashing algorithms
Asymmetric algorithms
Public key algorithms
Rate this question:
Authentication
Accounting
Access
Authorization
Rate this question:
The lowest bridge ID
The highest MAC address
The highest priority
The lowest IP address
Rate this question:
The wrong vty lines are configured.
AAA authorization is not configured.
The administrator has used the wrong password.
The administrator does not have enough rights on the PC that is being used.
Rate this question:
Password recovery
Password auditing
Identification of Layer 3 protocol support on hosts
TCP and UDP port scanning
Validation of IT system configuration
Rate this question:
Reactive protection against Internet attacks
Granularity control within applications
Support of TCP-based packet filtering
Support for logging
Rate this question:
RSA
DH
AES
HMAC
Rate this question:
A router interface can belong to only one zone at a time.
Service policies are applied in interface configuration mode.
Router management interfaces must be manually assigned to the self zone.
The pass action works in multiple directions.
Rate this question:
DHCP spoofing
ARP spoofing
VLAN hopping
ARP poisoning
Rate this question:
Hashes are never sent in plain text.
It is easy to generate data with the same CRC.
It is virtually impossible for two different sets of data to calculate the same hash output.
Hashing always uses a 128-bit digest, whereas a CRC can be variable length.
Rate this question:
That AAA is enabled globally on the router.
That passwords and usernames are case-sensitive.
That a default local database AAA authentication is applied to all lines.
That user access is limited to vty terminal lines.
Rate this question:
When the router boots up, the Cisco IOS image is loaded from a secured FTP location.
The Cisco IOS image file is not visible in the output of the show flash command.
The Cisco IOS image is encrypted and then automatically backed up to the NVRAM.
The Cisco IOS image is encrypted and then automatically backed up to a TFTP server.
Rate this question:
MPLS
Hairpinning
GRE
Split tunneling
Rate this question:
DHCP spoofing
DHCP starvation
STP manipulation
MAC and IP address spoofing
Rate this question:
209.165.201.1
192.168.1.3
172.16.3.1
172.16.3.3
192.168.1.1
Rate this question:
L0phtcrack
Tripwire
Nessus
Metasploit
Rate this question:
Only ports that attach to a neighboring switch
All PortFast-enabled ports
All trunk ports that are not root ports
Only ports that are elected as designated ports
Rate this question:
Split tunneling
MPLS
GRE
Hairpinning
Rate this question:
Default route
Access list
VLAN ID
NAT/PAT
Rate this question:
Reset UDP connection
Reset TCP connection
Alert
Isolate
Inoculate
Drop
Rate this question:
A class 5 certificate is more trustworthy than a class 4 certificate.
Email security is provided by the vendor, not by a certificate.
The lower the class number, the more trusted the certificate.
A vendor must issue only one class of certificates when acting as a CA.
Rate this question:
Network Address Translation
Access control lists
Security zones
Stateful packet inspection
Rate this question:
They are usually found attached to online games.
Email viruses are the most common type of them.
They replicate themselves and locate new targets.
They are responsible for some of the most destructive internet attacks.
Rate this question:
Script kiddies
Vulnerability brokers
Cyber criminals
Hacktivists
Rate this question:
Webtype
Standard
Ethertype
Extended
Rate this question:
Network security testing proactively evaluates the effectiveness of the proposal before any real threat occurs.
Network security testing is most effective when deploying new security proposals.
Network security testing is specifically designed to evaluate administrative tasks involving server and workstation access.
Network security testing is simple because it requires just one test to evaluate the new proposal.
Rate this question:
Vulnerability scanning
Password cracking
Network scanning
Integrity checker
Rate this question:
This message is a level five notification message.
This message indicates that service timestamps have been globally enabled.
This message indicates that enhanced security was configured on the vty ports.
This message appeared because a major error occurred that requires immediate action.
This message appeared because a minor error occurred that requires further investigation.
Rate this question:
Encryption for remote access connections
AAA for authenticating management access
Routing protocol authentication
NTP for consistent timestamps on logging messages
Rate this question:
Step-by-step details regarding methods to deploy company switches
Recommended best practices for placement of all company switches
Required steps to ensure consistent configuration of all company switches
List of suggestions regarding how to quickly configure all company switches
Rate this question:
The crypto map has not yet been applied to an interface.
The current peer IP address should be 172.30.2.1.
There is a mismatch between the transform sets.
The tunnel configuration was established and can be tested with extended pings.
Rate this question:
Packet filters perform almost all the tasks of a high-end firewall at a fraction of the cost.
Packet filters provide an initial degree of security at the data-link and network layer.
Packet filters represent a complete firewall solution.
Packet filters are not susceptible to IP spoofing.
Rate this question:
Register the destination website on the Cisco ASA.
Use the Cisco AnyConnect Secure Mobility Client first.
Use a web browser to visit the destination website.
First visit a website that is located on a web server in the Cisco CWS infrastructure.
Rate this question:
Authorization
Authentication
Auditing
Accounting
Rate this question:
Exec default
Connection
Exec
Network
Rate this question:
Cisco Security Manager software
AAA server
Adaptive Security Appliance
Intrusion prevention system
Rate this question:
Show ip nat translation
Show running-config
Show xlate
Show ip address
Rate this question:
It uses UDP port 500 to exchange IKE information between the security gateways.
IKE Phase 1 can be implemented in three different modes: main, aggressive, or quick.
It allows for the transmission of keys directly across a network.
The purpose of IKE Phase 2 is to negotiate a security association between two IKE peers.
Rate this question:
Traffic that is sent from the LAN and the Internet to the DMZ is considered inbound.
Traffic that is sent from the DMZ and the Internet to the LAN is considered outbound.
Traffic that is sent from the LAN to the DMZ is considered is considered inbound.
Traffic that is sent from the DMZ and the LAN to the Internet is considered outbound.
Rate this question:
Honey pot-based
Anomaly-based
Signature-based
Policy-based
Rate this question:
When a superview is deleted, the associated CLI views are deleted.
A single CLI view can be shared within multiple superviews.
A CLI view has a command hierarchy, with higher and lower views.
Only a superview user can configure a new view and add or remove commands from the existing views.
Rate this question:
Because the login delay command was not used, a one-minute delay between login attempts is assumed.
The hosts that are identified in the ACL will have access to the device.
The login block-for command permits the attacker to try 150 attempts before being stopped to try again.
These enhancements apply to all types of login connections.
Rate this question:
Quiz Review Timeline (Updated): Sep 4, 2023 +
Our quizzes are rigorously reviewed, monitored and continuously updated by our expert board to maintain accuracy, relevance, and timeliness.
Wait!
Here's an interesting quiz for you.