โ† All COMPTIA Flashcard Decks

Network+ Network Security Hardening Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Network Security Hardening flashcards as text
  1. Which type of ACL is applied closest to the traffic source to block unwanted packets as early as possible?

    Answer: Extended ACL applied inbound at the source

    Extended ACLs match both source and destination so they are most efficient when applied inbound at the source router interface.

  2. A security engineer wants to detect and block rogue DHCP servers on a network. Which switch feature accomplishes this?

    Answer: DHCP snooping

    DHCP snooping marks ports as trusted or untrusted; DHCP offers from untrusted ports are dropped, preventing rogue servers.

  3. Which hardening action should be taken for unused switch ports to prevent unauthorized device connections?

    Answer: Shut them down and assign them to an unused VLAN

    Administratively shutting down unused ports and moving them to an isolated VLAN prevents any unauthorized device from gaining network access.

  4. A network team deploys a host-based firewall on every server in the data center. This is an example of which security principle?

    Answer: Defense in depth

    Defense in depth uses multiple overlapping security layers (perimeter firewall plus host firewall) so that bypassing one layer doesn't grant full access.

  5. What is the function of IP Source Guard on a switch port?

    Answer: Filters packets so only traffic matching the DHCP snooping binding table is forwarded

    IP Source Guard uses the DHCP snooping binding table to drop packets whose source IP or MAC doesn't match the recorded lease, stopping IP spoofing.

  6. Which management plane hardening measure limits which hosts can connect to a router's SSH service?

    Answer: Configuring an ACL referenced by the VTY lines

    An access-class ACL applied to VTY lines restricts SSH access to only specified management IP addresses.

  7. A company wants to ensure that a network device's operating system has not been tampered with during boot. Which feature provides this assurance?

    Answer: Secure Boot / image signing verification

    Secure Boot and cryptographic image signing verify that the firmware/OS binary matches a trusted hash before execution.