Page 491 - StudyBook.pdf
P. 491

Topologies and IDS • Chapter 7  475

                      A. The traffic is passed directly as both VLAN’s are part of the same collision
                         domain

                      B. The traffic is passed directly as both VLAN’s are part of the same broadcast
                         domain

                      C. Traffic cannot move from the management to the engineering VLAN
                      D. Traffic must be passed to the router and then back to the appropriate
                         VLAN.

                  2. You have been asked to protect two Web servers from attack.You have also
                      been tasked with making sure that the internal network is also secure.What
                      type of design could be used to meet these goals while also protecting all of
                      the organization?

                      A. Implement IPSec on his Web servers to provide encryption
                      B. Create a DMZ and place the Web server in it while placing the intranet
                         behind the internal firewall
                      C. Place a honeypot on the internal network

                      D. Remove the Cat 5 cabling and replace it with fiber-optic cabling.

                  3. You have been asked to put your Security+ certification skills to use by exam-
                      ining some network traffic.The traffic was from an internal host and you must
                      identify the correct address.Which of the following should you choose?

                      A. 127.0.0.1
                      B. 10.27.3.56
                      C. 129.12.14.2

                      D. 224.0.12.10

                  4. You have been running security scans against the DMZ and have obtained the
                      following results. How should these results be interpreted?

                 C:\>nmap -sT 192.168.1.2
                 Starting nmap V. 3.91
                 Interesting ports on (192.168.1.2):
                 (The 1598 ports scanned but not shown below are in state: filtered)
                 Port   State   Service
                 53/tcp  open    DNS




                                                                              www.syngress.com
   486   487   488   489   490   491   492   493   494   495   496