Network+ Unit 10
What feature of Windows Server allows for agentless authentication?
AD (Active Directory)
Which of the following is not one of the three AAA services provided by RADIUS and TACACS+?
Access Control
What software might be installed on a device to authenticate it to the network?
Agent
Which NGFW feature allows a network admin to restrict traffic generated by a specific game?
Application awareness
What kind of firewall blocks traffic based on application data contained within the packets?
Content-filtering firewall
What are the two primary features that give proxy servers an advantage over NAT?
Filter content and file caching
Active Directory and 389 Directory Server are both compatible with which directory access protocol?
LDAP
Only one __________ exists on a network using STP.
Root bridge
Which of the following features is common to both an NGFW and traditional firewalls?
User authentication
EAPoL is primarily used with what kind of transmission?
Wireless
What kinds of issues might indicate a misconfigured ACL?
Wrong people being able to log in.
Which of the following ACL commands would permit web-browsing traffic from any IP address to any IP address?
access-list acl_2 permit http any any
What's the essential difference between an IPS and an IDS?
IDS (intrusion detection system) creates alerts when suspicious activity happens. IPS (intrusion Prevention system) prevents traffic from reaching the network.
At what layer of the OSI model do proxy servers operate?
Layer 7
What causes most firewall failures?
Not being configured correctly
What kind of ticket is held by Kerberos's TGS?
TGT (Ticket-Granting Ticket)
Why is a BPDU filter needed at the demarc?
To disable STP on specific ports. For example, you might use a BPDU filter on the demarc, where ISP's service connects with a business's network, to prevent the ISP's WAN topology from mixing with the corporate network's topology for the purpose of plotting STP paths.
Why do network administrators create domain groups to manage user security privileges?
To simplify the process of granting rights to users
Which command on an Arista switch would require an SNMP notification when too many devices try to connect to a port?
switchport port-security
Any traffic that is not explicitly permitted in the ACL is __________, which is called the __________.
dropped, implicit deny