โ† All ICND1 Flashcard Decks

Network Security Basics Flashcards

7 cards from real ICND1 practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network Security Basics flashcards as text
  1. Which type of VPN creates an encrypted tunnel between two routers over the public internet to connect branch offices?

    Answer: Site-to-site VPN

    A site-to-site VPN establishes a persistent encrypted tunnel between two network endpoints, typically routers, to connect geographically separated offices.

  2. What does the 'enable secret' command do differently than the 'enable password' command?

    Answer: Stores the password as an MD5 hash instead of plaintext or weak Type 7 encryption

    The 'enable secret' uses MD5 hashing, making it significantly more secure than 'enable password' which stores the password in a reversible format.

  3. Which attack exploits the IEEE 802.1Q trunking protocol to gain access to traffic on multiple VLANs?

    Answer: VLAN hopping

    VLAN hopping attacks, such as switch spoofing or double tagging, allow an attacker to send traffic to VLANs they are not authorized to access.

  4. What is the recommended best practice for securing unused switch ports?

    Answer: Shut down the ports and assign them to an unused VLAN

    Shutting down unused ports and assigning them to an unused VLAN prevents unauthorized devices from connecting to the network.

  5. Which IOS command displays the current port security settings and violation count for a specific interface?

    Answer: show port-security interface

    The 'show port-security interface' command displays port security configuration, learned MAC addresses, and any violation statistics for the specified interface.

  6. What is a 'zero-day' vulnerability?

    Answer: A security flaw exploited before the vendor has released a patch

    A zero-day vulnerability is a security flaw unknown to the vendor, meaning zero days have passed since the vendor became aware, giving no time to patch before exploitation.

  7. Which security protocol provides integrity, authentication, and optional encryption for IP packets at Layer 3?

    Answer: IPsec

    IPsec is a suite of protocols that operates at Layer 3 to provide authentication, integrity verification, and optional encryption for IP communications.