Network Security & Protocols Flashcards
7 cards from real CTE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network Security & Protocols flashcards as text
An attacker intercepts and relays communications between two parties without either knowing. What type of attack is this?
Answer: Man-in-the-Middle (MitM) attack
A Man-in-the-Middle attack positions the attacker between two communicating parties to intercept or alter traffic.
Which protocol is used to securely distribute and manage encryption keys in IPsec VPNs?
Answer: IKE (Internet Key Exchange)
IKE (Internet Key Exchange) handles secure key negotiation and management for IPsec security associations.
What is the primary purpose of a DMZ (Demilitarized Zone) in a network architecture?
Answer: To host public-facing services isolated from internal networks
A DMZ hosts public-facing servers (web, email) in a zone isolated from the internal network to limit breach impact.
Which SNMP version introduced authentication and encryption to address the security weaknesses of earlier versions?
Answer: SNMPv3
SNMPv3 added user-based authentication (MD5/SHA) and DES/AES encryption, addressing the clear-text vulnerabilities of v1 and v2c.
A telecom executive reviews a network diagram showing traffic being routed through inspection engines before reaching its destination. What security device architecture is this?
Answer: Next-Generation Firewall (NGFW) inline deployment
An inline NGFW intercepts and inspects all traffic before forwarding it, enabling deep packet inspection and policy enforcement.
Which attack exploits the trust relationship in DNS by injecting false records into a resolver's cache?
Answer: DNS cache poisoning
DNS cache poisoning inserts fraudulent DNS records into a resolver's cache, redirecting users to malicious sites.
In the context of telecom network hardening, what does 'defense in depth' refer to?
Answer: Layering multiple independent security controls throughout the network
Defense in depth uses multiple overlapping security layers so that failure of one control does not compromise the entire system.