2.3.2 Securing Networks Quiz

2.3.2 Securing Networks Quiz Answers

1. Which security measure is typically found both inside and outside a data center facility?

  • a gate
  • exit sensors
  • security traps
  • biometrics access
  • continuous video surveillance

Explanation: Continuous video surveillance is a security measure found both inside and outside a data center facility. A gate provides outside perimeter security. Security traps, biometrics access, and exit sensors provide inside perimeter security.

2. What is hyperjacking?

  • taking over a virtual machine hypervisor as part of a data center attack
  • overclocking the mesh network which connects the data center servers
  • adding outdated security software to a virtual machine to gain access to a data center server
  • using processors from multiple computers to increase data processing power

Explanation: Hyperjacking occurs when an attacker hijacks a virtual machine (VM) hypervisor and then uses that VM to launch an attack on other data center devices.

3. Which statement accurately characterizes the evolution of threats to network security?

  • Internal threats can cause even greater damage than external threats.
  • Internet architects planned for network security from the beginning.
  • Early Internet users often engaged in activities that would harm other users.
  • Threats have become less sophisticated while the technical knowledge needed by an attacker has grown.

Explanation: Internal threats can be intentional or accidental and cause greater damage than external threats because the internal user has direct access to the internal corporate network and corporate data.

4. When considering network security, what is the most valuable asset of an organization?

  • customers
  • data
  • financial resources
  • personnel

Explanation: Data, such as research and development data, sales data, financial data, human resource and legal data, employee data, contractor data, and customer data, is likely to be the most valuable asset for an organization.

5. Which resource is affected due to weak security settings for a device owned by the company, but housed in another location?

  • cloud storage device
  • hard copy
  • removable media
  • social networking

Explanation: Cloud storage is popular and has many benefits. However data stored there could be compromised due to weak security settings.

6. In the video that describes the anatomy of an attack, a threat actor was able to gain access through a network device, download data, and destroy it. Which flaw allowed the threat actor to do this?

  • open ports on the firewall
  • lack of a strong password policy
  • a flat network with no subnets or VLANs
  • improper physical security to gain access to the building

Explanation: The company had a flat network with no subnets. The threat actor was able to access and destroy all kinds of corporate data due to a thermostat that was on the network, but was not scanned as part of the security procedures.

7. Refer to the exhibit. An IT security manager is planning security updates on this particular network. Which type of network is displayed in the exhibit and is being considered for updates?

  • CAN
  • WAN
  • SOHO
  • data center

Explanation: A distinguishing factor of campus area networks (CANs) are that they have interconnected LANs.

8. What are two security features commonly found in a WAN design? (Choose two.)

  • port security on all user-facing ports
  • VPNs used by mobile workers between sites
  • firewalls protecting the main and remote sites
  • WPA2 for data encryption of all data between sites
  • outside perimeter security including continuous video surveillance

Explanation: WANs span a wide area and commonly have connections from a main site to remote sites including a branch office, regional site, SOHO sites, and mobile workers. WANs typically connect over a public internet connection. Each site commonly has a firewall and VPNs used by remote workers between sites.

9. Which security technology is commonly used by a teleworker when accessing resources on the main corporate office network?

  • IPS
  • VPN
  • SecureX
  • biometric access

Explanation: VPNs are commonly used between corporate sites and between mobile or remote workers that connect to and use resources on the corporate network.

10. Which technology is used to secure, monitor, and manage mobile devices?

  • MDM
  • VPN
  • rootkit
  • ASA firewall4

Explanation: Mobile Device Management (MDM) is used to secure, monitor, and manage both corporate-owned and employee-owned devices such as smartphones, tablets, laptops, and desktops.

11. Match the type of hackers to the description.

Match the options as described in the table.

Black hat hackers They are unethical criminals who violate computer and network security for personal gain, or for malicious reasons, such as attacking networks.
White hat hackers They are ethical hackers who use their programming skills for good, ethical, and legal purposes. They may perform network penetration tests to compromise networks and systems by using their knowledge of computer security systems to discover network vulnerabilities.
Gray hat hackers They are individuals who commit crimes and do arguably unethical things, but not for personal gain or to cause damage. An example would be someone who compromises a network without permission and then discloses the vulnerability publicly.

12. Which term refers to the type of threat actors who are either self-employed or working for large cybercrime organizations?

==Cybercriminals

Hacktivists

State-Sponsored

Vulnerability brokers

Explanation: Definitions for the different types of threat actors are:

  • Hacktivists - a term that refers to grey hat hackers who rally and protest against different political and social ideas. Hacktivists publicly protest against organizations or governments by posting articles, videos, leaking sensitive information, and performing distributed denial of service (DDoS) attacks.
  • Cybercriminals - a term for black hat hackers who are either self-employed or working for large cybercrime organizations. Each year, cyber criminals are responsible for stealing billions of dollars from consumers and businesses.
  • State-Sponsored hackers - threat actors who steal government secrets, gather intelligence, and sabotage networks of foreign governments, terrorist groups, and corporations. Most countries in the world participate to some degree in state-sponsored hacking.
  • Vulnerability brokers - typically grey hat hackers who attempt to discover exploits and report them to vendors, sometimes for prizes or rewards.

------------=Question 11------------

Which statement describes the characteristics of the indicators of attack (IOA)?

==They focus on the motivation behind an attack and the potential means by which threat actors have, or will, compromise vulnerabilities to gain access to assets.

They focus on identifying malware files, IP addresses of servers that are used in attacks, filenames, and characteristic changes made to end system software, among others.

They are shared through the system AIS (Automated Indicator Sharing) and help to limit the size of attack surface.

They help cybersecurity personnel identify what has happened in an attack and develop defenses against the attack.

Explanation: Indicators of attack (IOA) focus more on the motivation behind an attack and the potential means by which threat actors have, or will, compromise vulnerabilities to gain access to assets. IOAs are concerned with the strategies that are used by attackers. For this reason, rather than informing response to a single threat, IOAs can help generate a proactive security approach. Indicators of compromise (IOC) can be features that identify malware files, IP addresses of servers that are used in attacks, filenames, and characteristic changes made to end system software, among others. IOCs help cybersecurity personnel identify what has happened in an attack and develop defenses against the attack. The US Cybersecurity Infrastructure and Security Agency (CISA) is leading efforts to automate the sharing of cybersecurity information with public and private organizations at no cost. CISA uses a system called Automated Indicator Sharing (AIS). AIS enables the sharing of attack indicators between the US government and the private sector as soon as threats are verified.

------------=Question 12------------

What are two reasons that internal threats from within an organization may cause greater damage than external threats? (Choose two.)

Internet users can easily conceal their attacking trails.

Internal users have better access to attacking tools.

==Internal users have direct access to the building and its infrastructure devices.

State-Sponsored hacking is typically carried out by internal users.

==Internal users may have knowledge of the corporate network, its resources, and its confidential data.

Explanation: Internal threats have the potential to cause greater damage than external threats because internal users have direct access to the building and its infrastructure devices. Employees may also have knowledge of the corporate network, its resources, and its confidential data.

------------=

Which term in network security is used to describe a potential danger to an asset such as data or the network itself?

Risk

==Threat

Exploit

Vulnerability

Explanation: Common network security terms include:

  • Threat - A potential danger to an asset such as data or the network itself.
  • Vulnerability - A weakness in a system or its design that could be exploited by a threat.
  • Exploit - The mechanism that is used to leverage a vulnerability to compromise an asset.
  • Risk - The likelihood that a particular threat will exploit a particular vulnerability of an asset and result in an undesirable consequence.

------------Question 7----------

Which statement describes the network security term attack surface?

==It is the total sum of the vulnerabilities in each system that are accessible to an attacker.

It is the likelihood that a particular threat will exploit a particular vulnerability of an asset and result in an undesirable consequence.

It is the mechanism that is used to leverage a vulnerability to compromise an asset.

It is a weakness in a system or its design that could be exploited by a threat.

Explanation: Common network security terms include:

    • Attack surface - The total sum of the vulnerabilities in each system that are accessible to an attacker.
    • Vulnerability - A weakness in a system or its design that could be exploited by a threat.
    • Exploit - The mechanism that is used to leverage a vulnerability to compromise an asset.
    • Risk - The likelihood that a particular threat will exploit a particular vulnerability of an asset and result in an undesirable consequence.

------------Question 8----------

The IT department performs a thorough assessment of security posture for the company data center operation. The risk of potential loss or compromise of critical data is identified. In discussion with the management team, a decision is reached that the critical data should be replicated to a cloud service provider and further insured with an insurance company. Which risk management strategy is employed?

Risk avoidance

==Risk transfer

Risk reduction

Risk acceptance

Explanation: There are four common ways to manage risk:

  • Risk transfer - Some or all the risk is transferred to a willing third party such as a cloud service provider or an insurance company.
  • Risk reduction - This reduces exposure to risk or reduces the impact of risk by taking action to decrease the risk. This strategy requires careful evaluation of the costs of loss, the mitigation strategy, and the benefits gained from the operation or activity that is at risk.
  • Risk avoidance - This means avoiding any exposure to the risk by eliminating the activity or device that presents the risk. By eliminating an activity to avoid risk, any benefits that are possible from the activity are also lost.
  • Risk acceptance - This is when the cost of risk management options outweighs the cost of the risk itself. The risk is accepted, and no action is taken.

Match the common data loss vectors to the description.

Match the options as described in the table.

Email/Social Networking Intercepted email or IM messages could be captured and reveal confidential information.
Improper Access Control Stolen passwords or weak passwords which have been compromised can provide an attacker easy access to corporate data.
Unencrypted Devices If the data is not stored using an encryption algorithm, then the thief can retrieve valuable confidential data from stolen corporate laptop.
Removable Media An employee could perform an unauthorized transfer of data to a USB drive. In addition, a USB drive containing valuable corporate data could be lost.

=============

Which Cisco group is responsible for investigating and mitigating potential vulnerabilities in Cisco products?

==Cisco Product Security Incident Response Team

Cybersecurity Infrastructure and Security Agency

National Cyber Security Alliance

Cisco Talos Intelligence Group

Explanation: Network security relates directly to an organization's business continuity. Many tools are available to help network administrators adapt, develop, and implement threat mitigation techniques. The Cisco Product Security Incident Response Team (PSIRT) is responsible for investigating and mitigating potential vulnerabilities in Cisco products. The Cisco Talos Intelligence Group website provides comprehensive security and threat intelligence to defend customers and protect their assets. US Cybersecurity Infrastructure and Security Agency (CISA) and the National Cyber Security Alliance (NCSA) are US government organizations to promote cybersecurity.

Question 4
What is an attack vector?

It refers to attacks carried out specifically by internal users.

It is a tool by which a threat actor uses to attack an organization.

It refers to a threat group that launches DDoS attacks.

==It is a path by which a threat actor can gain access to a server, host, or network.

Explanation: An attack vector is a path by which a threat actor can gain access to a server, host, or network. Attack vectors originate from inside or outside the corporate network.

Subscribe
Notify of
guest

0 Corrections & Clarifications