โ† All ICND1 Flashcard Decks

Network Security Basics Flashcards

7 cards from real ICND1 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Basics flashcards as text
  1. Which feature prevents rogue DHCP servers from assigning IP addresses on a network?

    Answer: DHCP snooping

    DHCP snooping filters DHCP messages and only allows DHCP server responses from trusted ports, blocking rogue DHCP servers.

  2. What type of ACL uses both source and destination IP address, port numbers, and protocol to filter traffic?

    Answer: Extended ACL

    Extended ACLs can filter traffic based on source/destination IP, protocol type, and source/destination port numbers for granular control.

  3. Which Cisco IOS command generates RSA keys needed for SSH operation?

    Answer: crypto key generate rsa

    The 'crypto key generate rsa' command creates the RSA key pair required before SSH can be enabled on a Cisco device.

  4. What is a 'man-in-the-middle' attack in the context of network security?

    Answer: An attacker intercepts and potentially alters communications between two parties

    In a man-in-the-middle attack, the attacker secretly relays and possibly modifies communications between two parties who believe they are communicating directly.

  5. Which command configures a Cisco router to use TACACS+ for login authentication?

    Answer: aaa authentication login default group tacacs+

    The 'aaa authentication login default group tacacs+' command configures TACACS+ as the authentication method for console and VTY logins.

  6. Which statement correctly describes the difference between symmetric and asymmetric encryption?

    Answer: Symmetric uses one key for both encryption and decryption; asymmetric uses a key pair

    Symmetric encryption uses a single shared secret key for both operations, while asymmetric encryption uses mathematically related public and private key pairs.

  7. What is the function of Dynamic ARP Inspection (DAI) on a Cisco switch?

    Answer: Validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing

    DAI intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table to prevent ARP spoofing and poisoning attacks.